What's changed: Created SC-100 Chapter 1 (Domain 1 "Design solutions that align with security best practices and priorities": Zero Trust 3 principles/6 pillars/Conditional Access/RaMP; MCRA/MCSB/Defender for Cloud/Secure Score/defenses by attack type; CAF/WAF/Azure landing zones/Azure Policy/DevSecOps/workload identity; resiliency/business-critical assets/BCDR/immutable backups/Azure Backup/Site Recovery/ransomware priorities/security updates).
1.2Aligning to best practices with MCRA and MCSB
Understand how to align capabilities and controls to best practices using the Microsoft Cybersecurity Reference Architectures (MCRA) and the Microsoft cloud security benchmark (MCSB), designing against insider, external, and supply-chain attacks.
Architects must objectively show that a design aligns with industry best practices. Microsoft provides two distinct artifacts for this: MCRA, a map of the design, and MCSB, a measurable baseline.
1.2.1MCRA: a map of capabilities
MCRA (Microsoft Cybersecurity Reference Architectures) is a reference set of diagrams that organizes which defensive capability each Microsoft product provides across identity, the SOC, endpoints, hybrid/multicloud, and OT/IoT. Architects compare MCRA against their current capability map to find gaps and translate them into a Zero Trust strategy. MCRA is a starting point for design, not a pass/fail measure.
1.2.2MCSB: a measurable benchmark
MCSB (Microsoft cloud security benchmark) enumerates concrete controls across network, identity management, privileged access, data protection, and logging/threat detection. It ships as a built-in initiative in Microsoft Defender for Cloud, which auto-evaluates the environment against MCSB and surfaces Secure Score. For requirements to "continuously measure and improve alignment to best practices," choose MCSB + Defender for Cloud, not MCRA.
1.2.3Defenses by attack type
Best practices emphasize different controls per attack type. For insider attacks, layer least privilege, separation of duties, and Insider Risk Management (Purview); for external attacks, MFA, posture management, and threat detection; for supply-chain attacks, software-provenance verification (secure development, dependency/artifact verification, least-privilege workload identity). Architects place these on the MCRA capability map and close gaps while measuring with MCSB.
Decision cues: "reference architecture / capability map / design starting point" = MCRA. "benchmark / list of controls / auto-evaluated in Defender for Cloud / Secure Score / continuous measurement" = MCSB. "Assess alignment to regulatory standards" also = Defender for Cloud (MCSB + regulatory compliance dashboard).
Watch the mix-ups: (1) MCRA is not a measurement tool (measure with MCSB + Defender for Cloud). (2) MCSB is not Azure-only—Defender for Cloud evaluates AWS/GCP multicloud too. (3) Do not confuse Secure Score (Defender for Cloud, infrastructure posture) with Microsoft Secure Score (Defender XDR, identity/M365 posture).
1.2.4Section summary
- MCRA = reference architecture mapping Microsoft products’ defensive capabilities (a design map, not a measure)
- MCSB = a benchmark of concrete controls; Defender for Cloud auto-evaluates it and surfaces Secure Score (multicloud)
- By attack type: insider (least privilege/Insider Risk), external (MFA/posture/detection), supply chain (secure dev/verification)
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. To continuously auto-evaluate the environment against best-practice controls and drive improvement via a score, which is best?
Q2. Which reference artifact organizes "which Microsoft product provides which defensive capability" as a design starting point?
Q3. You want to benchmark AWS and GCP too in Defender for Cloud. Which is true of MCSB?
Q4. Which design best defends against supply-chain attacks?
Q5. Which combination most directly reduces insider risk?

