Instiq
Chapter 5 · Application and data security·v1.0.0·Updated 7/16/2026·~14 min

What's changed: Created SC-100 Chapter 5 (Domain 4 "Application and data security": M365 protection (Microsoft Secure Score/Defender for Office 365/Defender for Cloud Apps (CASB)/Intune/Purview labels/DLP); Copilot for Microsoft 365 (permission/label inheritance/oversharing/DSPM for AI/Purview Audit); app protection (threat modeling/secure development lifecycle/workload identity/API Management/Azure WAF); data protection (discovery/classification/encryption at rest-in transit/CMK/Key Vault/Defender for Storage/Defender for Databases/Azure SQL/Synapse/Cosmos DB/Storage)).

5.1Securing Microsoft 365

Key points

Understand evaluating productivity/collaboration posture with Microsoft Secure Score, Microsoft Defender for Office 365 and Microsoft Defender for Cloud Apps, device management with Microsoft Intune, and securing Microsoft 365 data with Microsoft Purview.

In many organizations the highest-value data and user activity live in Microsoft 365 (mail, Teams, SharePoint, OneDrive). Architects measure productivity-workload posture and protect against email/SaaS threats, devices, and data in layers.

5.1.1Microsoft Secure Score and threat defense

Measure productivity/collaboration posture with Microsoft Secure Score (Defender XDR’s identity/M365 posture score) and prioritize improvement actions. Email/collaboration threats (phishing, malware, impersonation) are defended by Microsoft Defender for Office 365 (Safe Links/Safe Attachments, automated investigation), while visibility/control of SaaS apps (shadow-IT discovery, session control, data control) is handled by Microsoft Defender for Cloud Apps (CASB). Architects design how to layer M365 posture and threat defense.

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.