
Microsoft Cybersecurity Architect Exam Ref (SC)
Master the skills required to pass the SC-100 exam and operate as a Microsoft Cybersecurity Architect. This course covers Zero Trust design, identity governance, cloud infrastructure security, threat detection, and compliance architecture across the full Microsoft security ecosystem. Every chapter is built around real architect responsibilities, giving you both the exam knowledge and the job-ready expertise to back it up.
What you will learn:
Design Zero Trust architectures using Microsoft Entra ID, Conditional Access, and Privileged Identity Management.
Configure Microsoft Sentinel workspaces, analytics rules, and automated incident response playbooks at enterprise scale.
Architect data classification and protection strategies using Microsoft Purview sensitivity labels and DLP policies.
Secure Azure landing zones with management group hierarchies, Azure Policy, and Defender for Cloud posture controls.
Integrate DevSecOps practices into CI/CD pipelines using Defender for DevOps, IaC scanning, and secrets detection.
Apply NIST CSF, MITRE ATT&CK, and Microsoft CAF security guidance to produce defensible architecture decisions.
How you study in practice Microsoft Cybersecurity Architect Exam Ref (SC)
How you practice Microsoft Cybersecurity Architect Exam Ref (SC)
For companies that want to train their team
With Dedika for Business, the course includes exercises and examples tailored to your own business and the way your company needs.
Course content
8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsCybersecurity Architecture Foundations
Cybersecurity Architecture Foundations
Lesson 1 • The Cybersecurity Architect Role
Defines responsibilities, scope, and stakeholder interactions of a security architect. Anchors the entire course by framing every subsequent topic within real job expectations.
Lesson 2 • Security Frameworks and Standards
Surveys NIST CSF, ISO 27001, CIS Controls, and MITRE ATT&CK as design references. Provides the vocabulary and structure used throughout all subsequent chapters.
Lesson 3 • Risk Management Fundamentals
Covers threat modeling, risk quantification, and risk treatment options. Connects risk decisions to architecture trade-offs explored in later chapters.
Lesson 4 • Microsoft Security Ecosystem Overview
Maps Microsoft Defender, Sentinel, Entra, Purview, and Intune to security domains. Gives students a product-to-function reference used throughout the entire course.
Lesson 5 • Zero Trust Architecture Principles
Introduces verify-explicitly, least-privilege, and assume-breach tenets. Students apply these principles as a design lens for every architecture decision in the course.
Chapter 2HideHide detailsSee detailsDesigning Identity and Access Solutions
Designing Identity and Access Solutions
Lesson 1 • Identity Governance and Lifecycle
Covers entitlement management, access packages, and lifecycle workflows. Ensures identities are provisioned and deprovisioned consistently across the enterprise.
Lesson 2 • Microsoft Entra ID Architecture
Covers tenant design, directory synchronization, and federation models. Establishes the identity foundation required for all access and governance topics ahead.
Lesson 3 • Hybrid and External Identity Scenarios
Designs cross-tenant access, external collaboration, and on-premises integration. Prepares students for complex enterprise environments common in exam scenarios.
Lesson 4 • Privileged Identity Management
Addresses just-in-time access, role activation workflows, and access reviews. Reduces standing privilege exposure, a core Zero Trust requirement.
Lesson 5 • Authentication and Authorization Design
Examines MFA, passwordless methods, and Conditional Access policy design. Students select authentication strengths appropriate to data sensitivity and user risk.
Chapter 3HideHide detailsSee detailsSecuring Microsoft Cloud Infrastructure
Securing Microsoft Cloud Infrastructure
Lesson 1 • Storage and Database Security
Applies encryption, private endpoints, and access controls to Azure storage and databases. Protects data at rest and in transit across all infrastructure tiers.
Lesson 2 • Azure Landing Zone Security Design
Covers management group hierarchy, policy inheritance, and subscription segmentation. Provides the governance scaffold on which all cloud workload security is built.
Lesson 3 • Defender for Cloud Posture Management
Uses Secure Score, regulatory compliance dashboards, and recommendations to drive improvement. Translates infrastructure risk into measurable, actionable security posture.
Lesson 4 • Network Security Architecture
Designs hub-and-spoke topologies, Azure Firewall, NSGs, and DDoS protection. Network controls are the perimeter layer supporting identity-centric Zero Trust.
Lesson 5 • Compute and Container Security
Secures virtual machines, AKS clusters, and serverless workloads using Defender for Cloud. Extends infrastructure security to modern application hosting patterns.
Chapter 4HideHide detailsSee detailsData Security and Compliance Architecture
Data Security and Compliance Architecture
Lesson 1 • Microsoft Purview Governance
Uses data map, data catalog, and data estate insights for enterprise governance. Connects data discovery to compliance reporting and risk reduction.
Lesson 2 • Data Loss Prevention Strategy
Designs DLP policies across endpoints, cloud apps, and communication channels. Prevents unauthorized data exfiltration while minimizing business disruption.
Lesson 3 • Compliance and Retention Architecture
Designs retention policies, eDiscovery workflows, and communication compliance. Satisfies legal hold and audit requirements embedded in enterprise compliance programs.
Lesson 4 • Data Classification and Sensitivity Labels
Designs classification taxonomies and applies sensitivity labels across Microsoft 365 and Azure. Classification is the prerequisite for all downstream protection controls.
Lesson 5 • Information Protection Controls
Applies encryption, rights management, and content marking to labeled data. Ensures protection travels with data regardless of storage location.
Chapter 5HideHide detailsSee detailsSecurity Operations and Threat Detection
Security Operations and Threat Detection
Lesson 1 • Threat Detection with Analytics Rules
Creates scheduled, NRT, and fusion analytics rules using KQL and UEBA signals. Translates threat intelligence into automated, high-fidelity alert generation.
Lesson 2 • Incident Investigation and Response
Designs incident workflows, investigation graphs, and playbook automation. Reduces mean time to respond by embedding automation into the SOC process.
Lesson 3 • Microsoft Sentinel Architecture Design
Covers workspace design, data connector selection, and cost optimization strategies. A well-designed Sentinel deployment is the foundation of all detection capabilities.
Lesson 4 • Threat Intelligence and MITRE Mapping
Incorporates threat intelligence feeds, TAXII connectors, and MITRE coverage analysis. Aligns detection coverage to known adversary techniques for gap identification.
Lesson 5 • Microsoft Defender XDR Integration
Integrates Defender for Endpoint, Office 365, Identity, and Cloud Apps into unified XDR. Correlates signals across domains to surface multi-stage attack chains.
Chapter 6HideHide detailsSee detailsApplication and DevSecOps Security
Application and DevSecOps Security
Lesson 1 • Microsoft Defender for DevOps
Configures Defender for DevOps to surface code, pipeline, and infrastructure-as-code risks. Provides a unified security view across GitHub and Azure DevOps environments.
Lesson 2 • DevSecOps Pipeline Integration
Embeds static analysis, dependency scanning, and secrets detection into Azure DevOps and GitHub. Shifts security left by automating checks at every pipeline stage.
Lesson 3 • Secure Application Design Principles
Applies threat modeling, secure coding standards, and API security to application architecture. Establishes security requirements before a single line of code is written.
Lesson 4 • Secrets and Key Management
Designs Azure Key Vault access policies, managed identities, and certificate lifecycle management. Eliminates hardcoded credentials and centralizes cryptographic asset control.
Lesson 5 • Container and Supply Chain Security
Secures container images, registries, and software supply chains using Defender and signing tools. Addresses emerging attack vectors targeting build and deployment pipelines.
Chapter 7HideHide detailsSee detailsEndpoint and Hybrid Workload Security
Endpoint and Hybrid Workload Security
Lesson 1 • Endpoint Vulnerability Management
Uses Defender Vulnerability Management to prioritize and remediate endpoint weaknesses. Closes the loop between detection, risk scoring, and remediation tracking.
Lesson 2 • Microsoft Intune Endpoint Management
Designs enrollment profiles, compliance policies, and configuration baselines in Intune. Endpoint compliance is a key signal in Conditional Access and Zero Trust decisions.
Lesson 3 • Microsoft Defender for Endpoint
Configures attack surface reduction, EDR, and automated investigation for managed endpoints. Provides the detection and response layer for all managed device types.
Lesson 4 • Mobile and BYOD Security Design
Applies app protection policies and MAM-without-enrollment to personal devices. Balances employee privacy with corporate data protection requirements.
Lesson 5 • Hybrid and On-Premises Workload Security
Extends Azure Arc, Defender for Servers, and Update Management to on-premises workloads. Ensures consistent security posture across cloud and legacy infrastructure.
Chapter 8HideHide detailsSee detailsSecurity Architecture Governance and Strategy
Security Architecture Governance and Strategy
Lesson 1 • Security Posture Measurement and Reporting
Builds KPIs, dashboards, and executive reporting using Secure Score and Sentinel workbooks. Translates technical metrics into business-relevant risk communication.
Lesson 2 • Enterprise Security Architecture Frameworks
Applies SABSA, TOGAF security extensions, and Microsoft CAF security to architecture decisions. Provides the formal methodology for producing defensible, documented designs.
Lesson 3 • Regulatory and Privacy Compliance Design
Maps privacy regulations, data residency requirements, and audit controls to architecture decisions. Embeds compliance into design rather than treating it as an afterthought.
Lesson 4 • Security Roadmap and Stakeholder Alignment
Produces prioritized security roadmaps and communicates risk trade-offs to executive stakeholders. Culminates the course by connecting all technical skills to strategic leadership.
Lesson 5 • Security Resilience and Business Continuity
Designs backup, disaster recovery, and ransomware resilience using Azure native services. Ensures security architecture supports recovery objectives, not just prevention.
Your valid completion certificate
This course is for you:
Security engineers: ready to expand scope from implementation to architectural ownership.
Cloud administrators: managing Azure environments and seeking a formal security specialization.
IT managers: responsible for security decisions but lacking a structured design methodology.
SOC analysts: aiming to move beyond detection work into proactive security design roles.
Compliance officers: needing deeper technical grounding to translate regulations into architecture.
Career changers: bringing IT experience and targeting high-demand cybersecurity architect positions.
What our students say
Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to switch platforms... I thank you for everything you do, I've already recommended you to other people...

I like how the lessons are straight to the point and how I can switch chapters and skip content I don't need.

I like the content and the presentation style and video transcription, which speeds up the process!

The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.

Top trainings
FAQ
Who is Dedika?
Is the certificate valid in the United States?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course




















