What's changed: Created SC-100 Chapter 5 (Domain 4 "Application and data security": M365 protection (Microsoft Secure Score/Defender for Office 365/Defender for Cloud Apps (CASB)/Intune/Purview labels/DLP); Copilot for Microsoft 365 (permission/label inheritance/oversharing/DSPM for AI/Purview Audit); app protection (threat modeling/secure development lifecycle/workload identity/API Management/Azure WAF); data protection (discovery/classification/encryption at rest-in transit/CMK/Key Vault/Defender for Storage/Defender for Databases/Azure SQL/Synapse/Cosmos DB/Storage)).
5.4Securing data
Understand data discovery/classification, prioritizing data-threat mitigation, encryption at rest/in transit (Azure Key Vault, infrastructure encryption), data protection for Azure workloads (Azure SQL, Azure Synapse Analytics, Azure Cosmos DB) and Azure Storage, and Microsoft Defender for Storage/Databases.
Ultimately, data is what we protect. Architects start from "where is what sensitive data (discovery/classification)," then layer encryption, access, and threat detection, protecting high-value data first.
5.4.1Discovery/classification and encryption
First, use data discovery and classification (Microsoft Purview information protection/sensitivity labels) to know "where the sensitive data is" and set mitigation priorities. Then design encryption: encryption at rest (on by default; use customer-managed keys (CMK) in Azure Key Vault/Managed HSM as needed) and encryption in transit (TLS), with double-layer infrastructure encryption. Key management—"who holds the keys (Microsoft-managed vs customer-managed)"—directly ties to compliance requirements. Architects organize "encryption by sensitivity and key custody" as design decisions.
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

