SC-100 : Microsoft Cybersecurity Architect
- Security operators
Training Overview
This “Microsoft Cybersecurity Architect” training will equip you with essential skills to develop and evaluate cybersecurity strategies in key areas such as Zero Trust, governance, risk and compliance (GRC), and SecOps.
Additionally, you will master the design and architecture of secure solutions using Zero Trust principles.
The training also guides you through the specific security requirements for various cloud service models, including SaaS, PaaS, and IaaS.
SC-100 : Microsoft Cybersecurity ArchitectLearning objectives
Trainees will be able to:
- Design solutions that align with best practices and security priorities
- Design features related to security operations, identities, and compliance
- Design security solutions for applications and data
- Design security solutions for infrastructure.
To participate in this “SC-100 Microsoft Cybersecurity Architect” training, you must have previously completed one of these courses: “SC-200: Microsoft Security Operations Analyst,” “SC-300: Microsoft Identity and Access Administrator,” or “SC-401: Microsoft Information Protection Administrator.”
Explore Zero Trust frameworks and best practices
- Describe common security antipatterns and the role of best practices for cybersecurity architects.
- Describe the concept of Zero Trust and its core principles.
- Describe the purpose and scope of CAF, WAF, MCRA, and MCSB.
- Describe the Zero Trust adoption framework and the approach to rapid modernization.
- Describe how the different best practice frameworks relate to each other.
Design security solutions that comply with the Cloud Adoption Framework (CAF) and the Well-Architected Framework (WAF)
- Understand the CAF framework and how it can be used to accelerate and secure an organization’s move to the cloud.
- Understand the WAF framework and how it can be used to design cloud solutions that adhere to sound design principles, including security.
Design solutions that align with Microsoft Cybersecurity Reference Architecture (MCRA) and Microsoft Cloud Security Benchmark (MCSB)
- Use the Microsoft Cybersecurity Reference Architecture (MCRA) to design more secure solutions.
- Use the Microsoft Cloud Security Benchmark (MCSB) to design more secure solutions.
- Design solutions with best practices for security features and controls.
- Design solutions for protection against insider threats, external attacks, and supply chain attacks.
- Design solutions for AI security.
Design a resiliency strategy for ransomware and other attacks by following Microsoft’s security best practices
- Understand common cyber threats like ransomware.
- Learn how to support business resiliency.
- Design configurations for secure backup and recovery.
- Design solutions to manage security patches.
Design regulatory compliance solutions
- Translate compliance requirements into security solutions using Zero Trust principles.
- Meet compliance requirements with Microsoft Purview, including AI governance models.
- Design a solution to meet privacy requirements with Microsoft Priva.
- Design Azure Policy solutions to meet security and compliance requirements.
- Assess infrastructure compliance in multicloud environments using Microsoft Defender for Cloud.
Design solutions to manage identity and access
- Design access policies for SaaS, PaaS, IaaS, hybrid, and multicloud resources using identity, networking, and application controls.
- Design a solution for Microsoft Entra ID, including hybrid and multicloud environments.
- Design a solution for external identities, including B2B Collaboration and Customer Identity.
- Design a solution for agent identities using the Microsoft Entra agent ID.
- Design modern authentication and authorization policies.
- Validate the alignment of Conditional Access with Zero Trust.
- Specify the requirements for securing Active Directory Domain Services.
- Design a solution for secret, key, and certificate management.
Design solutions to secure privileged access
- Understand privileged access and the enterprise access model.
- Design identity governance solutions.
- Design a solution to secure cloud tenant administration.
- Design for managing entitlements to use cloud infrastructure.
Design solutions for security operations
- Design security operations capabilities across hybrid and multicloud environments.
- Design centralized logging and auditing.
- Design security information and event management (SIEM) solutions.
- Design a detection and response solution that includes Extended Detection and Response (XDR).
- Design an automated security orchestration response (SOAR) solution.
- Design security workflows.
- Design and evaluate threat detection with the MITRE ATT&CK infrastructure.
Modernize Identity and Data Security
- Explore identity lifecycle gaps, guest access risks, and monitoring limitations.
- Learn how these challenges align with Zero Trust principles.
- Apply architectural reasoning to assess threats and design secure solutions.
Modernize user access control and threat resilience
- Explore the operational and security challenges commonly associated with fragmented identity systems, legacy infrastructure, and inconsistent access governance.
- Learn how to apply zero trust principles using Microsoft technologies to modernize access control, improve threat detection, and enforce compliance in hybrid environments.
- Apply architectural reasoning to assess threats and design secure solutions.
Evaluate solutions to secure Microsoft 365
- Assess security posture for collaboration and productivity workloads
- Evaluate a Microsoft Defender XDR solution
- Assess configurations and operational practices for Microsoft 365
- Design modern authentication and authorization policies.
- Validate the alignment of Conditional Access with Zero Trust.
- Specify the requirements for securing Active Directory Domain Services.
- Design a solution for secret, key, and certificate management.
Design solutions to secure privileged access
- Understand privileged access and the enterprise access model.
- Design identity governance solutions.
- Design a solution to secure cloud tenant administration.
- Design for managing entitlements to use cloud infrastructure.
Design solutions for security operations
- Design security operations capabilities across hybrid and multicloud environments.
- Design centralized logging and auditing.
- Design security information and event management (SIEM) solutions.
- Design a detection and response solution that includes Extended Detection and Response (XDR).
- Design an automated security orchestration response (SOAR) solution.
- Design security workflows.
- Design and evaluate threat detection with the MITRE ATT&CK infrastructure.
Modernize Identity and Data Security
- Explore identity lifecycle gaps, guest access risks, and monitoring limitations.
- Learn how these challenges align with Zero Trust principles.
- Apply architectural reasoning to assess threats and design secure solutions.
Modernize user access control and threat resilience
- Explore the operational and security challenges commonly associated with fragmented identity systems, legacy infrastructure, and inconsistent access governance.
- Learn how to apply zero trust principles using Microsoft technologies to modernize access control, improve threat detection, and enforce compliance in hybrid environments.
- Apply architectural reasoning to assess threats and design secure solutions.
Evaluate solutions to secure Microsoft 365
- Assess security posture for collaboration and productivity workloads
- Evaluate a Microsoft Defender XDR solution
- Assess configurations and operational practices for Microsoft 365
Design solutions to secure server and client endpoints
- Specify security requirements for servers
- Specify security requirements for mobile devices and clients
- Specify security requirements for IoT devices and embedded systems
- Design a solution to secure operational technology (OT) and industrial control systems (ICS) with Microsoft Defender for IoT
- Specify security baselines for server and client endpoints
- Design a solution to secure remote access
Design solutions for network security
- Evaluate network designs to align with security requirements and best practices
- Design solutions for network segmentation
- Design solutions to filter traffic with network security groups
- Design solutions for network posture management
- Design solutions for network monitoring
- Evaluate solutions built on Microsoft Entra Internet Access
- Evaluate solutions that use Microsoft Entra Private Access
Secure endpoints and infrastructure
- Explore common security gaps in distributed and hybrid enterprises spanning endpoints, OT/IoT, and cloud governance.
- Learn how to analyze threats and map Microsoft security features to address risks in IT and industrial environments.
- Apply architectural reasoning to design and sequence a Zero Trust-aligned solution that secures endpoints and infrastructure end-to-end.
Last updated: 04/16/2026
In this training, we mix theory with technical workshops to quickly make you operational. Additionally, each participant receives course materials at the end of the training.
One of our consultant trainers conducts the training. With solid field experience, they make the learning process both interactive and enriching.
For assessment, the trainer regularly asks questions and uses various methods to continuously measure your progress. This approach promotes a dynamic and engaging learning experience.
After the training, we ask you to complete a satisfaction questionnaire. Your feedback helps us to maintain and constantly improve the quality of our training.
Finally, we offer the flexibility to deliver this training both in-person and remotely, and it can be customized to meet your company’s specific needs upon request.
This training prepares you for the “Microsoft SC-100: Microsoft Cybersecurity Architect” certification exam.
You can register for certification on the Microsoft site. If you would like to buy a certification voucher from us, or if you would like us to support you in this process, please contact us
You can register for one of our training courses up to two business days before it starts, if there are still available places and you signed quote.
If you have specific needs related to a disability, please do not hesitate to make a request; we are happy to adjust our services according to the type of disability.
Our Training on the same topic
SC-5006 : Enhance security operations by using Microsoft Security Copilot
SC-5008: Configure and govern entitlement with Microsoft Entra ID
SC-300 : Microsoft identity and access administrator

SC-401 : Protect sensitive information with Microsoft Purview in the AI era

SC-200 : Microsoft Security Operations Analyst

SC-900 : Introduction to Microsoft Security, Compliance, and Identity
