What's changed: Created SC-100 Chapter 5 (Domain 4 "Application and data security": M365 protection (Microsoft Secure Score/Defender for Office 365/Defender for Cloud Apps (CASB)/Intune/Purview labels/DLP); Copilot for Microsoft 365 (permission/label inheritance/oversharing/DSPM for AI/Purview Audit); app protection (threat modeling/secure development lifecycle/workload identity/API Management/Azure WAF); data protection (discovery/classification/encryption at rest-in transit/CMK/Key Vault/Defender for Storage/Defender for Databases/Azure SQL/Synapse/Cosmos DB/Storage)).
5.3Securing applications
Understand evaluating the application portfolio posture, assessing business-critical apps via threat modeling, a full-lifecycle application-security strategy and secure-development standards, authentication via workload identity, API management and security, and Azure Web Application Firewall (WAF).
Applications are a primary entry point for attackers. Architects design not individual bug fixes but a lifecycle strategy for application security across "design→develop→operate," plus runtime defenses (WAF, API protection, workload identity).
5.3.1Threat modeling and secure development
First evaluate the existing application portfolio posture and analyze business-critical apps via threat modeling (where/how they could be attacked). A full-lifecycle strategy from design to operation embeds secure-development standards (code/dependency/secret scanning, IaC checks, SBOM) as DevSecOps (Chapter 1). Map technology choices to requirements (authentication, data protection, auditing) and standardize rather than relying on individuals. Architects guide a design that "weaves application security into the development process."
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

