What's changed: Created SC-100 Chapter 4 (Domain 3 "Infrastructure security": Defender for Cloud (CSPM/CWPP)/Secure Score/MCSB/Azure Arc/multicloud posture; Security Exposure Management (attack paths/attack-surface reduction/initiatives)/Defender EASM; servers/endpoints (baselines/Defender for Endpoint/Intune/Windows LAPS)/OT-ICS-IoT (Defender for IoT)/containers (Defender for Containers)/Azure AI services security; network (microsegmentation/Private Link/Azure Bastion)/SSE (Entra Internet Access/Entra Private Access/Global Secure Access)).
4.4Network security and Security Service Edge (SSE)
Understand evaluating network designs for security alignment, Security Service Edge (SSE) including Microsoft Entra Internet Access (secure web gateway) and Microsoft Entra Private Access, and Zero Trust networking.
Network still matters in Zero Trust—but the mindset shifts from "defend at the perimeter" to "verify by identity and conditions while connecting minimally." The new shape of this is SSE (Security Service Edge).
4.4.1Evaluating network design and segmentation
Architects evaluate whether the network design aligns with security requirements: microsegmentation (limit lateral movement on compromise), private connectivity (Private Link/private endpoints to avoid exposure), isolated management access (Azure Bastion for jumpbox-less RDP/SSH), and L7 defense (WAF/Front Door from the next chapter). Network controls are supplementary to identity controls but essential to "minimize blast radius" under assume-breach.
4.4.2SSE: Entra Internet Access and Private Access
Security Service Edge (SSE) inserts a cloud security layer between users and apps. Under Microsoft’s Global Secure Access, Microsoft Entra Internet Access inspects/controls traffic to the internet/SaaS as a secure web gateway (with cross-tenant protection), and Microsoft Entra Private Access provides VPN-less, identity-based minimal connectivity to internal apps (ZTNA). Architects design SSE for "replace org-wide VPN with identity-based Zero Trust access" and "conditionally inspect SaaS traffic."
Cues: "VPN-less identity-based minimal access to internal apps (ZTNA)" = Entra Private Access. "inspect/control internet/SaaS traffic via secure web gateway" = Entra Internet Access. "jumpbox-less RDP/SSH to VMs" = Azure Bastion. "avoid exposure with private connectivity" = Private Link/private endpoints.
Watch the mix-ups: (1) Distinguish Entra Internet Access (destination = internet/SaaS, SWG) from Entra Private Access (destination = internal apps, ZTNA). (2) SSE is a network control but is Zero Trust only when integrated with identity (Conditional Access)—do not substitute network alone. (3) Bastion isolates management access—a different purpose from WAF (app-layer defense).
4.4.3Section summary
- Network design = microsegmentation/Private Link/Azure Bastion to minimize blast radius (supplementary to identity)
- SSE = Entra Internet Access (SWG, internet/SaaS) and Entra Private Access (ZTNA, internal apps, VPN-less)
- SSE becomes Zero Trust when integrated with Conditional Access—not a network-only substitute
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. To replace org-wide VPN with identity-based minimal access (ZTNA) to internal apps, which is best?
Q2. To inspect/control users’ internet/SaaS-bound traffic as a secure web gateway, which is best?
Q3. For admins to reach VMs securely without a jumpbox or exposed RDP/SSH ports, which is best?
Q4. Which correctly characterizes network controls in Zero Trust?
Q5. Which correctly distinguishes Entra Internet Access from Entra Private Access?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

