What's changed: Created SC-100 Chapter 5 (Domain 4 "Application and data security": M365 protection (Microsoft Secure Score/Defender for Office 365/Defender for Cloud Apps (CASB)/Intune/Purview labels/DLP); Copilot for Microsoft 365 (permission/label inheritance/oversharing/DSPM for AI/Purview Audit); app protection (threat modeling/secure development lifecycle/workload identity/API Management/Azure WAF); data protection (discovery/classification/encryption at rest-in transit/CMK/Key Vault/Defender for Storage/Defender for Databases/Azure SQL/Synapse/Cosmos DB/Storage)).
5.1Securing Microsoft 365
Understand evaluating productivity/collaboration posture with Microsoft Secure Score, Microsoft Defender for Office 365 and Microsoft Defender for Cloud Apps, device management with Microsoft Intune, and securing Microsoft 365 data with Microsoft Purview.
In many organizations the highest-value data and user activity live in Microsoft 365 (mail, Teams, SharePoint, OneDrive). Architects measure productivity-workload posture and protect against email/SaaS threats, devices, and data in layers.
5.1.1Microsoft Secure Score and threat defense
Measure productivity/collaboration posture with Microsoft Secure Score (Defender XDR’s identity/M365 posture score) and prioritize improvement actions. Email/collaboration threats (phishing, malware, impersonation) are defended by Microsoft Defender for Office 365 (Safe Links/Safe Attachments, automated investigation), while visibility/control of SaaS apps (shadow-IT discovery, session control, data control) is handled by Microsoft Defender for Cloud Apps (CASB). Architects design how to layer M365 posture and threat defense.
5.1.2Device management with Intune and data protection with Purview
Manage devices that access M365 data with Microsoft Intune, and use Conditional Access to block devices that fail compliance policies (encryption, patching, PIN); for mobile, app protection policies enable per-app BYOD protection. The M365 data itself is classified/encrypted/exfiltration-controlled by Microsoft Purview Information Protection (sensitivity labels) and DLP. Architects combine "access only from compliant devices (Intune + CA)" with "protection that follows the data (Purview labels/DLP)" to secure both devices and data.
Cues: "M365/identity posture score" = Microsoft Secure Score. "email/collaboration threats (phishing/attachments)" = Defender for Office 365. "SaaS app visibility/control, shadow IT" = Defender for Cloud Apps (CASB). "device compliance management" = Intune (+ CA to block). "M365 data labels/encryption/DLP" = Purview.
Watch the mix-ups: (1) Distinguish Microsoft Secure Score (identity/M365 posture) from Defender for Cloud’s Secure Score (infra posture). (2) Defender for Office 365 (email/collaboration) is different from Defender for Cloud Apps (SaaS CASB). (3) Device management (Intune) and data protection (Purview) are different layers—need both.
5.1.3Section summary
- M365 posture = Microsoft Secure Score; email/collab threats = Defender for Office 365; SaaS visibility/control = Defender for Cloud Apps (CASB)
- Devices = Intune (compliance + CA block); M365 data = Purview sensitivity labels/DLP for classify/encrypt/exfiltration control
- Device protection and data protection are different layers—combine both
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. To protect M365 users from email phishing and malicious attachments/URLs, which is best?
Q2. To gain visibility into SaaS apps (including shadow IT) and control sessions/data, which is best?
Q3. To block M365 access from devices that fail compliance (encryption, PIN), which combination is best?
Q4. To apply classification/encryption/exfiltration control that follows sensitive M365 documents wherever they go, which is best?
Q5. Which metric measures productivity/collaboration (M365/identity) posture and prioritizes improvements?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

