SC-100T00: Microsoft Cybersecurity Architect

SC-100T00: Microsoft Cybersecurity Architect

Duration: 4 Days

This is an advanced, expert-level course. Although not required to attend, students are strongly encouraged to have taken and passed another associate level certification in the security, compliance and identity portfolio (such as AZ-500, SC-200 or SC-300) before attending this class. This course prepares students with the expertise to design and evaluate cybersecurity strategies in the following areas: Zero Trust, Governance Risk Compliance (GRC), security operations (SecOps), and data and applications. Students will also learn how to design and architect solutions using zero trust principles and specify security requirements for cloud infrastructure in different service models (SaaS, PaaS, IaaS).

This course is for experienced cloud security engineers who have taken a previous certification in the security, compliance and identity portfolio. Specifically, students should have advanced experience and knowledge in a wide range of security engineering areas, including identity and access, platform protection, security operations, securing data, and securing applications. They should also have experience with hybrid and cloud implementations. Beginning students should instead take the course SC-900: Microsoft Security, Compliance, and Identity Fundamentals.

Introduction to Zero Trust and best practice frameworks

You learn about security best practices and antipatterns, the concept of Zero Trust and its guiding principles, and key best practice frameworks including CAF, WAF, MCRA, and MCSB. You also learn about the Zero Trust adoption framework and how the frameworks relate to each other.

  • Introduction
  • Describe antipatterns and best practices
  • Describe the concept of Zero Trust
  • Describe the frameworks
  • Describe the Zero Trust adoption framework and rapid modernization plan
  • Describe how the frameworks relate to each other

Design security solutions that align with the Cloud Adoption Framework (CAF) and Well-Architected Framework (WAF)

You'll learn about the Cloud Adoption Framework (CAF) and Well-Architected Framework (WAF) and how you can use them to design more secure solutions.

  • Introduction
  • Define a security strategy
  • Understand the Cloud Adoption Framework
  • Understand the Cloud Adoption Framework secure methodology
  • Design a strategy for secure AI adoption
  • Understand Azure landing zones
  • Design security with Azure landing zones
  • Understand the Well-Architected Framework
  • Understand the Well-Architected Framework security pillar
  • Design a security and governance strategy
  • Design secure DevSecOps processes

Design solutions that align with the Microsoft Cybersecurity Reference Architecture (MCRA) and Microsoft cloud security benchmark (MCSB)

You learn about Microsoft's security frameworks—the Security Adoption Framework (SAF), Microsoft Cybersecurity Reference Architecture (MCRA), and Microsoft Cloud Security Benchmark (MCSB)—and how to use them to design secure solutions that protect against insider threats, external attacks, supply chain compromises, and AI-specific risks.

  • Introduction
  • Describe the Microsoft Cybersecurity Reference Architecture
  • Describe the Microsoft Cloud Security Benchmark
  • Design solutions with best practices for capabilities and controls
  • Design solutions with best practices for protecting against insider, external and supply chain attacks.
  • Design AI solutions that align to the Microsoft Cloud Security Benchmark
  • Design solutions that align to a Zero Trust rapid modernization plan

Design a resiliency strategy for ransomware and other attacks based on Microsoft Security Best Practices

You learn about common cyberthreats like ransomware and what kinds of attack patterns an organization must be prepared for.

  • Introduction
  • Common cyberthreats and attack patterns
  • Support business resiliency
  • Design solutions for mitigating ransomware attacks, including prioritization of BCDR and privileged access
  • Design solutions for business continuity and disaster recovery (BCDR), including secure backup and restore
  • Evaluate solutions for security updates

Design solutions for regulatory compliance

Learn how to design security solutions that address regulatory compliance requirements across multicloud environments. You'll learn to translate compliance requirements into security controls, use Microsoft Purview Compliance Manager for multicloud compliance including AI governance, address privacy requirements with Microsoft Priva, design Azure Policy solutions, and evaluate compliance using Microsoft Defender for Cloud.

  • Translate compliance requirements into security controls
  • AI compliance considerations
  • Design a solution to address compliance requirements by using Microsoft Purview
  • Address privacy requirements with Microsoft Priva
  • Address security and compliance requirements with Azure Policy
  • Evaluate and validate alignment with regulatory standards and benchmarks by using Microsoft Defender for Cloud

Design solutions for identity and access management

Design identity and access management solutions that protect organizational resources while enabling productivity. Learn how to design access strategies for different deployment models, enable secure external collaboration, implement modern authentication, and protect identity infrastructure.

  • Design a solution for access to SaaS, PaaS, IaaS, hybrid, and multicloud resources
  • Design a solution for Microsoft Entra ID, including hybrid and multicloud environments
  • Design a solution for external identities
  • Design modern authentication and authorization strategies
  • Design a solution for agent identities using Microsoft Entra Agent ID
  • Design Conditional Access policies for AI agents
  • Validate alignment of Conditional Access policies with a Zero Trust strategy
  • Specify requirements for securing Active Directory Domain Services
  • Design a solution to manage secrets, keys, and certificates

Design solutions for securing privileged access

You learn advanced techniques for designing solutions that secure privileged access using Zero Trust principles, the Enterprise Access Model, and Microsoft Entra ID governance capabilities, including considerations for AI workloads and multicloud environments.

  • Secure privileged access
  • Design privileged role assignment using the Enterprise Access Model
  • Evaluate security and governance with Microsoft Entra ID solutions
  • Design a solution to secure tenant administration
  • Design a solution for cloud infrastructure entitlement management
  • Design a solution for privileged access workstations and remote access
  • Evaluate an access review management solution

Design solutions for security operations

You learn techniques to design security operations capabilities including logging, auditing, Security Information, and Event Management (SIEM), Security Orchestration and Automated Response (SOAR), and security workflows.

  • Describe the function of Security operations (SecOps)
  • Design monitoring to support hybrid and multicloud environments
  • Design solutions to support centralized logging and auditing
  • Design solutions for detection and response that includes extended detection and response (XDR) and security information and event management (SIEM)
  • Design a solution for security orchestration, automation, and response (SOAR)
  • Design and evaluate security workflows, including incident response, threat hunting, and incident management
  • Design and evaluate threat detection coverage by using MITRE ATT&CK matrices, including Cloud, Enterprise, Mobile, and ICS

Interactive case study: Modernizing identity and data security

Apply your cybersecurity architect skills on a real business scenario focused on identity and data security. Analyze design requirements, answer conceptual and technical questions and design a solution to meet the business needs.

  • Interactive case study
  • Interactive case study highlights

Interactive case study: Modernizing user access control and threat resilience

Apply your cybersecurity architect skills on a real business scenario focused on user access control and threat resilience. Analyze design requirements, answer conceptual and technical questions and design a solution to meet the business needs.

  • Interactive case study
  • Interactive case study highlights

Evaluate solutions for securing Microsoft 365

You learn how to evaluate security solutions for securing Microsoft 365.

  • Evaluate security posture for productivity and collaboration workloads by using metrics
  • Evaluate how Microsoft Defender for Office 365 and Microsoft Defender for Cloud Apps protect productivity workloads
  • Evaluate how Microsoft Intune protects and manages endpoints
  • Evaluate solutions for securing data in Microsoft 365 using Microsoft Purview
  • Evaluate how data security and compliance controls protect organizational data used by Microsoft 365 Copilot

Design solutions for securing applications

You learn how to secure applications, APIs and the development process using techniques like posture management, threat modeling, and secure access for workload identities.

  • Design and implement standards to secure application development
  • Design a full lifecycle strategy for application security
  • Evaluate security posture of existing application portfolios
  • Evaluate application threats with threat modeling
  • Secure access for workload identities
  • Design a solution for API management and security
  • Design a solution for secure access to applications
  • Map technologies to application security requirements

Design solutions for securing an organization's data

You learn about designing solutions that secure an organization's data using capabilities like Microsoft Purview, Defender for SQL, Defender for Storage.

  • Data security design principles and frameworks
  • Evaluate solutions for data discovery and classification
  • Evaluate solutions for encryption of data at rest and in transit, including Azure KeyVault and infrastructure encryption
  • Design data security for Azure workloads
  • Design security for data used in AI workloads
  • Design security for Azure Storage
  • Design a security solution with Microsoft Defender for SQL and Microsoft Defender for Storage

Interactive case study: Securing apps and data

Apply your cybersecurity architect skills on a real business scenario focused on securing apps and data. Analyze design requirements, answer conceptual and technical questions and design a solution to meet the business needs.

  • Interactive case study
  • Interactive case study highlights

Specify requirements for securing SaaS, PaaS, and IaaS services

You learn how to analyze security requirements for different cloud offerings (SaaS, PaaS, and IaaS), IoT workloads, web workloads, containers, and AI workloads.

  • Specify security baselines for SaaS, PaaS, and IaaS services
  • Specify security requirements for IoT workloads
  • Specify security requirements for web workloads
  • Specify security requirements for containers and container orchestration
  • Specify security requirements for AI workloads

Design solutions for security posture management in hybrid and multicloud environments

You learn how to design security posture management solutions that integrate into hybrid and multicloud scenarios using capabilities in Microsoft Defender for Cloud, Azure Arc, and Microsoft Cloud Security Benchmark (MCSB).

  • Use the Microsoft Cloud Security Benchmark to design and evaluate security posture
  • Design integrated posture management solutions that include Microsoft Defender for Cloud in hybrid and multicloud environments
  • Evaluate security posture by using Microsoft Defender for Cloud, including Secure Score
  • Design cloud workload protection with Microsoft Defender for Cloud
  • Design a solution for integrating hybrid and multicloud environments by using Azure Arc
  • Design a solution for external attack surface management
  • Posture management using Exposure management attack paths

Design solutions for securing server and client endpoints

You learn how to analyze the security requirements for different types of endpoints including servers, clients, IoT, OT, mobile, and embedded devices. These requirements take into account different platforms and operating systems and set standards for endpoint protection, hardening, and configuration.

  • Specify security requirements for servers
  • Specify security requirements for mobile devices and clients
  • Specify security requirements for IoT devices and embedded systems
  • Evaluate solutions for securing operational technology (OT) and industrial control systems (ICS) by using Microsoft Defender for IoT
  • Specify security baselines for server and client endpoints
  • Design a solution for secure remote access
  • Evaluate Windows Local Admin Password Solution (LAPS) solutions

Design solutions for network security

You learn how to design secure network solutions using techniques like network segmentation, traffic filtering, network monitoring, and posture management.

  • Evaluate network designs to align with security requirements and best practices
  • Design solutions for network segmentation
  • Design solutions for traffic filtering with network security groups
  • Design solutions for network posture management
  • Design solutions for network monitoring
  • Evaluate solutions that use Microsoft Entra Internet Access
  • Evaluate solutions that use Microsoft Entra Private Access

Interactive case study: Securing endpoints and infrastructure

Apply your cybersecurity architect skills on a real business scenario focused on endpoint and infrastructure security. Analyze design requirements, answer conceptual and technical questions and design a solution to meet the business needs.

  • Interactive case study
  • Interactive case study highlights
This class has hands-on labs provided by Go Deploy.