Microsoft Cybersecurity ArchitectStudy guide
The expert certification for designing Zero Trust-based security solutions (SC-100).
About Microsoft Cybersecurity Architect (SC-100)
Microsoft Cybersecurity Architect (SC-100) is a Professional / Expert-level certification from Microsoft. This page organizes the exam scope into a 5-chapter, 20-section study guide and lets you check your understanding with exam-style practice questions. A good flow is to read the chapters below in order, then test yourself via "Practice questions."
Exam domains (approximate weighting)
- Design solutions that align with security best practices and priorities~22%
- Design security operations, identity, and compliance capabilities~28%
- Design security solutions for infrastructure~28%
- Design security solutions for applications and data~22%
Weights are approximate guidance for the live exam. Each domain is covered in detail in the chapters and sections below.
Official exam information: https://learn.microsoft.com/en-us/credentials/certifications/resources/study-guides/sc-100
1Security strategy and best practices
- 1.1Zero Trust and RaMP
Understand Zero Trust (verify explicitly, least privilege, assume breach) across its six defense pillars (identity/endpoints/apps/data/infrastructure/network) and the prioritized adoption path of the Rapid Modernization Plan (RaMP), from an architect’s perspective.
- 1.2Aligning to best practices with MCRA and MCSB
Understand how to align capabilities and controls to best practices using the Microsoft Cybersecurity Reference Architectures (MCRA) and the Microsoft cloud security benchmark (MCSB), designing against insider, external, and supply-chain attacks.
- 1.3CAF, WAF, Azure landing zones, and DevSecOps
Understand security/governance strategy based on the Cloud Adoption Framework (CAF) and the Azure Well-Architected Framework (WAF), implementing governance via Azure landing zones, and designing a DevSecOps process aligned to CAF.
- 1.4Resiliency, BCDR, and ransomware defense
Understand a security strategy aligned to business resiliency goals, identifying and prioritizing threats to business-critical assets, secure backup & restore (BCDR) for hybrid/multicloud, ransomware mitigation (prioritizing BCDR and privileged access), and evaluating security updates.
2Security operations (SecOps)
- 2.1Detection and response with XDR and SIEM
Understand the roles of Microsoft Defender XDR (cross-domain detection/response across identity/endpoints/email/SaaS) and Microsoft Sentinel (cloud-native SIEM), an integrated XDR+SIEM detection/response design, and monitoring for hybrid/multicloud.
- 2.2SOAR and incident-response automation
Understand SOAR (orchestration and automated response) with Microsoft Sentinel and Defender XDR, automation rules and playbooks, designing incident response/threat hunting/incident management workflows, and UEBA.
- 2.3Centralized logging/auditing and multi-environment monitoring
Understand centralized logging and auditing including Microsoft Purview Audit, monitoring design supporting hybrid/multicloud, and approaches to log ingestion, retention, and isolation.
- 2.4MITRE ATT&CK and detection coverage
Understand evaluating threat-detection coverage using MITRE ATT&CK matrices (Enterprise, Mobile, ICS) and designing/evaluating incident-response, threat-hunting, and incident-management workflows.
3Identity, privileged access, and compliance
- 3.1Entra ID and hybrid/external identity
Understand identity design for hybrid/multicloud centered on Microsoft Entra ID, hybrid-identity sync/authentication options, external identities (B2B, decentralized), and identity/network/application controls for access to SaaS/PaaS/IaaS/on-prem.
- 3.2Modern authentication/authorization and Conditional Access
Understand a modern authentication/authorization strategy including Conditional Access, continuous access evaluation (CAE), risk scoring, and protected actions; validating Conditional Access alignment with Zero Trust; AD DS hardening; and managing secrets/keys/certificates.
- 3.3Securing privileged access and CIEM
Understand assigning/delegating privileged roles via the enterprise access model, Entra Privileged Identity Management (PIM)/entitlement management/access reviews, cloud infrastructure entitlement management (CIEM), secure workstations for privileged access (PAW), and securing cloud-tenant administration.
- 3.4Designing for regulatory compliance
Understand translating compliance requirements into security controls, addressing compliance via Microsoft Purview, privacy via Microsoft Priva, Azure Policy, and evaluating alignment with regulatory standards/benchmarks via Microsoft Defender for Cloud.
4Infrastructure security
- 4.1Posture management with Defender for Cloud
Understand posture evaluation with Microsoft Defender for Cloud (including MCSB) and Microsoft Secure Score, integrated posture across hybrid/multicloud, selecting cloud workload protection (CWPP), and integrating hybrid/multicloud via Azure Arc.
- 4.2Exposure Management and external attack surface (EASM)
Understand requirements and priorities for a posture-management process using Microsoft Security Exposure Management (attack paths, attack-surface reduction, security insights, initiatives) and Microsoft Defender External Attack Surface Management (Defender EASM).
- 4.3Securing servers, endpoints, and OT/IoT
Understand securing servers/client endpoints (multi-OS, mobile, baselines, Windows LAPS), IoT/embedded and OT/ICS (Microsoft Defender for IoT), and security requirements for SaaS/PaaS/IaaS (containers, container orchestration, Azure AI services security).
- 4.4Network security and Security Service Edge (SSE)
Understand evaluating network designs for security alignment, Security Service Edge (SSE) including Microsoft Entra Internet Access (secure web gateway) and Microsoft Entra Private Access, and Zero Trust networking.
5Application and data security
- 5.1Securing Microsoft 365
Understand evaluating productivity/collaboration posture with Microsoft Secure Score, Microsoft Defender for Office 365 and Microsoft Defender for Cloud Apps, device management with Microsoft Intune, and securing Microsoft 365 data with Microsoft Purview.
- 5.2Data security for Microsoft 365 Copilot
Understand evaluating data security and compliance controls for Microsoft 365 Copilot: inheritance of existing access permissions and sensitivity labels, curbing oversharing, and applying Purview auditing and DLP.
- 5.3Securing applications
Understand evaluating the application portfolio posture, assessing business-critical apps via threat modeling, a full-lifecycle application-security strategy and secure-development standards, authentication via workload identity, API management and security, and Azure Web Application Firewall (WAF).
- 5.4Securing data
Understand data discovery/classification, prioritizing data-threat mitigation, encryption at rest/in transit (Azure Key Vault, infrastructure encryption), data protection for Azure workloads (Azure SQL, Azure Synapse Analytics, Azure Cosmos DB) and Azure Storage, and Microsoft Defender for Storage/Databases.

