
Engage in the SC-100 Microsoft Cybersecurity Architect course with sims, featuring hands-on demonstrations, browser-based simulations, and a personal lab to master insider risk policy and exam objectives.
Explore foundational concepts of on premise Active Directory domain services, RAR and DMZ, and virtualization, along with Microsoft 365 and Azure cloud services, including IaaS, PaaS, and SaaS.
Explore the foundations of Microsoft domains and Active Directory, including domain controllers, replication, Kerberos and LDAP, DNS, GPOs, and the shift from on-prem to cloud and virtualized networks.
Explore legacy directory services and modern security, including VPN and RAAS, DMZs, and virtualization, highlighting how firewalls, two-firewall DMZs, and elasticity enable secure remote access and scalable cloud-ready infrastructure.
Explore cloud services with IaaS, PaaS, and SaaS, and how Azure and Microsoft 365 link infrastructure with intro ID (formerly Azure AD) and Azure AD Connect.
Embrace the reality that Microsoft cloud services continually change, stay agile as menus move and buttons rename, and monitor updates or contact the instructor for major changes.
Microsoft renames Azure Active Directory to IntraID and updates portal links such as admin.Microsoft.com and defender.Microsoft.com. A portals.examlabpractice.com page provides the latest links and a downloadable text file.
John Christopher invites questions and teaches how to search official Microsoft docs for fast, reliable answers. He highlights course updates, assignments, certificates, and Udemy as the source for exam questions.
Understand why exam objectives aren't in learning order, and how the course presents concepts from foundational to advanced in a logical sequence, sometimes renaming or combining objectives across videos.
Explore how the SC-100 Microsoft cybersecurity architect course covers a wide range of topics with hands-on learning and review for all levels.
Earn your certificate of completion by watching all course videos. Ignore assignments, and stay tuned for the final video that explains how to receive your certificate.
Practice hands-on skills through course assignments and external simulations hosted at portal.microsoft.com. Read the description, open the link in a new tab, complete, and submit—note: simulations don’t affect certification.
Set up a personal lab with Microsoft 365 and Azure, use a free Office 365 E5 trial to activate Microsoft 365 E5, and note regional limits and 30-day Teams trial.
Create a free Microsoft 365 account, start a 30-day trial with an E5 license (or alternatives), verify by phone, and navigate licensing, portal changes, and cancellation through course simulations.
Discover how to start the Azure free trial on portal.azure.com to receive $200 credit for 30 days, plus free services for a year, and the option to switch to pay-as-you-go.
Implement business resiliency goals in Azure and Microsoft 365, focusing on zero-trust, high availability, and disaster recovery. Support data durability, compliance, risk assessments, threat modeling, criticality analysis, and continuous monitoring.
Understand ransomware in the Microsoft environment and apply backup and restore strategies along with privileged access controls to mitigate and recover from attacks.
Learn to secure backups with Azure backup, covering via Mars agent and Mab server, backing up VMs, storage accounts, and file shares, plus policy, recovery services vault, and restore workflows.
Discover how to manage updates with Azure Update Manager, assess update readiness, and deploy patches across Azure VMs, Arc-enabled servers, and on-premises machines using Azure policies.
Learn how to easily redo simulations after completing an assignment by navigating to summary, returning to the assignment, opening instructions, and accessing the simulation link.
Explore the zero trust model by verifying explicitly, authenticating every entity, and enforcing least privilege with conditional access policies, just-in-time administration, and just-enough access across users, devices, and data.
Explore how the Microsoft 365 defender suite links endpoint, email, identity, and cloud apps to orchestrate defenses, issue alerts, and enable automated response.
Navigate the relationship between Microsoft 365 Defender and Purview and explore their admin centers in the security blade and the compliance blade; note licensing activation may take 45 minutes.
Explore insider risk management in Microsoft Purview, using policy templates, alerts, and case workflows to detect, investigate, and escalate data spillage, IP theft, and regulatory compliance violations with eDiscovery premium.
Learn how to license, configure, and create insider risk management policies in Microsoft Purview, including policy categories, indicators, and analytics.
Implement the zero trust rapid modernization plan (RaMP) to rapidly deploy security protections, identify stakeholders, and strengthen critical processes with layered controls across identities, devices, apps, and networks.
Explore how the Microsoft Cloud Adoption Framework guides security and governance through strategy, planning, readiness, and continuous optimization to securely migrate to Azure and Microsoft 365.
Explore the Azure well-architected framework to design secure, resilient Azure environments through ongoing checklists across cost optimization, security, reliability, operational excellence, and performance efficiency.
Explore how Azure landing zones act as a framework for secure, scalable deployments using subscriptions and management groups, with identity and access management and governance controls.
Explore the devsecops process model by planning and developing with security at the forefront, integrating threat modeling, secure coding, secure commits, security testing, and continuous improvement.
Secure hybrid and multi-cloud environments by maintaining security posture, enforcing multi-factor authentication and conditional access, keeping systems updated, and using centralized visibility with Microsoft Defender and Sentinel.
Assess standard versus premium auditing in Microsoft Purview, noting E3/E5 licensing implications; standard provides 90-day retention and basic search, while premium enables multi-year retention, retention policies, and intelligent insights.
Enable auditing in Microsoft Purview by assigning the auditing manager role, turning on audit recording, and verifying with PowerShell, while ensuring appropriate licenses are in place.
Explore the Microsoft Purview audit in the portal and filter by activities like email and exchange. Search by keywords and users, then export results to Excel for analysis.
Develop threat hunting skills by exploring Kusto Query Language (KQL) in Microsoft Defender, running queries across Microsoft 365 Defender tables, using pipelines, take, project, and join to reveal insights.
Master extended detection and response (XDR) with Microsoft 365 Defender, unifying identity, endpoints, cloud apps, and on-prem logs for holistic security. Leverage threat intelligence and automated responses to detect threats.
Learn how Microsoft Sentinel combines siem and sim concepts with secure orchestration and automated response, centralizing data with connectors, analytics, and playbooks to detect, investigate, and respond to threats.
Plan and configure a log analytics workspace for a Microsoft Sentinel deployment, review prerequisites and pricing, then create and attach a Sentinel workspace with a 30-day free trial.
Explore SIEM and SOAR concepts in Microsoft Sentinel, a cloud-native security analytics platform that centralizes data from devices, users, and on-prem environments, enabling threat detection, investigations, and automated playbooks.
Microsoft Sentinel ingests and normalizes data from diverse sources via data connectors, centralizing it into a common format for cloud and on-premises environments.
Learn how Sentinel analytics rules detect threats and anomalies using scheduled queries, incidents from Defender alerts, fusion rules, ML behavior analytics, and near real-time analytics.
Create a Microsoft Sentinel analytics rule and an incident creation rule. Configure keywords such as password, trigger on incident creation, and enable automation like changing status and assigning owners.
Explore built-in scheduled rules in Microsoft Sentinel, inspect their Kusto query language logic, and configure frequency, incidents, and grouping to automate alerts.
Configure a near-real-time analytics rule in Microsoft Sentinel to monitor sign-in events with a KQL query, triggering a low-severity alert for bad login attempts and automated response rules.
Explore how to configure automation rules in Microsoft Sentinel to support soar, streamline incident response, automate alert triage, enrich incident data, and notify stakeholders using triggers, conditions, and actions.
Learn to use Microsoft Sentinel hunting queries from the Content Hub to tailor data from connectors, filter providers, and run or customize KQL queries for threat hunting.
Explore the MITRE ATT&CK framework and knowledge base, and see how Microsoft Sentinel maps detections across reconnaissance to discovery with viewable rules.
Explore IaaS, PaaS, and SaaS in Microsoft cloud services and how Azure delivers virtual machines and platforms. Understand redundancy, service level agreements, and pay models for these offerings.
Compare IaaS, PaaS, and SaaS use cases, showing when to manage operating systems and hardware versus relying on platform or software services, with Azure Active Directory and Office 365 examples.
Manage external identities for B2B, B2B direct connect, and B2C across multi-tenant and multi-cloud environments. Activate access with separate intra ID directories to protect customer-facing apps and partner collaborations.
Configure cross-tenant and external collaboration settings in Entra ID to control inbound and outbound B2B access. Manage guest invitations and guest user permissions, plus trust and conditional access options.
Explore decentralized identities with Microsoft Entra Verified ID, linking digital IDs to government credentials to enable trusted, MFA-backed access for external users across directory services.
Explore how to investigate threats with sign-in and audit logs in Microsoft Entra ID, filter events by time and activity, and analyze authentication details, conditional access, and reports.
Microsoft Entra Identity Protection, formerly Azure AD Identity Protection, detects, investigates, and remediates identity-based risks from risky sign-ins and risky users using risk signals and conditional access.
Configure intra-identity protection using conditional access policies in intra-id, applying risk-based controls for user and sign-in risk, enforcing multi-factor authentication and policy-driven access.
Explore threat intelligence integration from Entra Identity Protection into MS Defender, and learn how to investigate risky users using Microsoft 365 Defender with alerts, timelines, and device and location insights.
Learn how multi-factor authentication strengthens security by combining different factors—something you know, something you have, and something you are—using real-world examples like smart cards, phones, and the authenticator app.
Configure multi-factor authentication in Microsoft Entra ID using per-user MFA or conditional access, and manage authentication methods like FIDO2 keys and Microsoft Authenticator to secure hybrid and cloud environments.
Enable self service password reset (SPR) in Microsoft Entra ID on portal.azure.com to reduce admin load, selecting all users or a group, and configure authentication methods and security questions.
Understand how conditional access uses signals from identities, devices, applications, and data within a zero trust framework. Learn how real-time risk detection, app protection, and policy enforcement guard resources.
Create and manage conditional access policies in Azure AD, assign to users or groups, target cloud apps, set conditions like risk levels, and enforce blocks under a zero trust strategy.
Discover Microsoft Defender for cloud, a cloud-native protection platform unifying DevSecOps, CSPM, and cloud workload protection across multi-cloud environments to secure applications.
Design and configure workflow automation in Microsoft Defender for Cloud with a logic app in Azure, linking alerts and recommendations to actions like email notifications via Outlook.com.
Configure email notifications for Microsoft Defender for Cloud by editing the subscription's environment settings in portal.azure.com, selecting notification recipients and severity levels, and optionally managing via JSON.
Learn to create and manage alert suppression rules in Defender for Cloud by assigning a security administrator, building custom rules, and simulating suppression to reduce alert noise.
Generate sample alerts and incidents in Microsoft Defender for Cloud to explore security events. Open portal.azure.com, open defender for cloud, and use sample alerts tab to create and view them.
Remediate alerts and incidents using Microsoft Defender for Cloud recommendations, review security alerts and secure score, and apply high severity remediation steps such as MFA and IAM adjustments in Azure.
Manage alerts and incidents in Microsoft Defender for cloud via the portal, view full details, take action, suppress alerts, and trigger automated responses.
Explore Microsoft Defender for Cloud threat intelligence reports and security alerts in portal.azure.com, and learn to read PDFs that summarize brute-force attacks and offer analysis links for staying informed.
Explore microsoft defender for identity, formerly azure atp, and how it monitors on-prem and cloud activity to detect, investigate, and triage attacks, including the kill chain and lateral movement.
Learn how to enable Microsoft Defender for Identity, install a sensor on an on-premises domain, and configure directory service and action accounts to mitigate threats.
Create and manage an Azure Key Vault to securely store secrets, keys, and certificates, with centralized access, monitoring, and logging, integrating with disk encryption, SQL TDE, and app services.
Control access to the Azure Key Vault by configuring vault access policy or Azure role based access control, then assign permissions for keys, secrets, and certificates to admins.
Explore how to manage keys, secrets, and certificates in Azure Key Vault, including RSA and EC keys, HSM options, exportable and immutable policies, and certificate signing requests.
Delete the resource group to remove the Azure Key Vault and storage account, then move on.
Design and enforce an enterprise access model with a control plane to secure on-premise and cloud assets, implementing least privilege, privileged identity management, and zero trust.
Explore role-based access control (rbac) in Microsoft Azure and Microsoft 365, and learn least privilege, identity governance, and privileged identity management with just-in-time administration.
Explore how to implement role-based access control in Entra ID and Azure, define role definitions, assign permissions, and use privileged identity management for temporary admin access.
Create a custom role in Microsoft Intro ID, select permissions, and assign it to a user. Manage built-in and custom roles, and delete a custom role when needed.
Demonstrates how to apply role-based access control in azure resources, using scopes from resource to management group, with iam blades and role assignments like contributor, reader, and backup operator.
Demonstrate how to view and assign roles across Microsoft 365 and Azure AD, explaining shared directory services and Defender XDR and Purview permissions for privileged access.
Master Microsoft Entra privileged identity management (PIM) to grant time-bound, just-in-time privileged access with approvals, MFA, justification, and audit history across Azure AD and Microsoft services.
Learn to implement Microsoft Entra privileged identity management (PIM) to grant temporary access, manage eligible and active roles, and perform just-in-time activations with multi-factor authentication.
Discover how entitlement management streamlines identity governance by packaging access to apps, groups, SharePoint, and teams into configurable access packages with multi-stage approvals and policies.
Create a medical catalog in identity governance to group project resources and plan access packages, using a Microsoft 365 group and example user to illustrate entitlement management.
Learn to create an access package in Azure portal's Identity Governance, enabling entitlement management by linking groups, apps, and SharePoint sites with approvals and lifecycle controls.
Learn how to request access to an access package in Azure AD entitlement management, verify membership in the Medical Project Users group, and access SharePoint, Teams, and apps.
Explore how identity governance uses Azure AD access reviews in Microsoft Entra to periodically revoke unnecessary guest and user access, with configurable reviewers, recurrence, and audit trails.
Explore privileged access workstations and Azure Bastion integration to secure privileged endpoints, isolate admin tasks, enforce zero trust, and reduce attack surface.
Identify your organization's compliance requirements before deploying security solutions, using Microsoft Purview to monitor communication and enforce data lifecycle, retention, and DLP across HIPAA, GDPR, PCI DSS.
Explore Microsoft Purview's compliance manager to monitor compliance score, set alerts, apply data classifications and sensitivity labels, and manage retention, DLP, e-discovery, and insider risk.
Enable privacy management with Microsoft Priva by assigning roles and permissions, activating the trial, and identifying personal data across GDPR and CCPA compliance.
Create a privacy risk management policy with Microsoft Purview templates to detect overexposed data, configure GDPR and PII-focused regulations, specify locations, and test before activation.
Discover how Azure policy enforces security and compliance by defining allowed locations, applying policy to a resource group, and managing not compliant resources with remediation and status checks.
Explore Microsoft Defender for cloud's regulatory compliance features in Azure, review regulatory standards like HIPAA, PCI DSS, and GDPR, view controls, read more, download reports, and manage compliance settings.
Assess regulatory compliance in Microsoft Defender for Cloud using the Microsoft Cloud Security Benchmark to identify met and unmet controls and strengthen across multi-cloud environments.
Explore Microsoft Defender for Cloud and the security posture secure score, view recommendations, and implement remediation steps such as enforcing multi-factor authentication with conditional access to strengthen your Azure environment.
Explore how Microsoft Secure Score in Defender measures your security posture across identity, data, devices, and apps, and guides with recommended actions like multi-factor authentication to strengthen your environment.
Onboard Defender for servers within Defender for Cloud to monitor servers across Azure, AWS, Google Cloud; plan 1 provides posture management, plan 2 adds extended detection and threat analytics.
Enable Defender for servers in Microsoft Defender for cloud to unlock log analytics, Azure Monitor, vulnerability assessments, and agentless scanning for your virtual machines.
Enable Microsoft Defender for App Service to monitor and protect Azure App Services, detect threats via sandbox analysis, threat intelligence, and dangling DNS detection, and enable it in portal.azure.com.
Azure Arc offers a single pane of glass to manage Azure and non-Azure resources, bridging on-prem and multi-cloud environments to Azure Resource Manager.
Unify DevOps security visibility with Defender for Cloud by linking GitHub repositories, scanning code for vulnerabilities, triaging findings by priority, and strengthening cloud resources across the development life cycle.
learn how Microsoft Defender external attack surface management provides an external view of your online infrastructure by continuously discovering assets like domains, hosts, IP addresses, SSL certificates, and CVE data.
We really hope you'll agree, this training is way more then the average course on Udemy!
Have access to the following:
Training from an instructor of over 20 years who has trained thousands of people and also a Microsoft Certified Trainer
Lecture that explains the concepts in an easy to learn method for someone that is just starting out with this material
Instructor led hands on and simulations to practice that can be followed even if you have little to no experience
TOPICS COVERED INCLUDING HANDS ON LECTURE AND PRACTICE TUTORIALS:
Design a resiliency strategy for ransomware & other attacks based on MS Security
Working with business resiliency goals, identifying and prioritizing threats
MS ransomware best practices, including backup, restore, and privileged access
Secure backup and restore by using Azure Backup
Security updates using the Azure Update Manager
Design solutions that align with the MCRA and MCSB
Concepts of cybersecurity capabilities and controls using Zero Trust security
Concepts of MS Defender for protecting against insider and external attacks
Navigating the Microsoft Defender and Microsoft Purview admin centers
Understanding insider risk policies as a mitigation solution
Implementing insider risk management policies in Microsoft Purview
Using the Zero Trust Rapid Modernization Plan (RaMP) as your security strategy
Design solutions that align with the Microsoft CAF and WAF Frameworks
Security and governance based on Microsoft Cloud Adoption Framework (CAF)
Security and governance based on Microsoft Azure Well-Architected Framework
Using Azure landing zones for implementing and governing security
The DevSecOps process model
Design solutions for security operations
Security operations capabilities to support a hybrid or multicloud environment
Requirements for centralized logging and auditing
Setting audit permissions and enabling support
Perform threat hunting by with audit logging
Understanding the Kusto Query Language (KQL) for use in threat hunting
Detection and response concepts of extended detection and response (XDR)
Confirming we understand the concept of Microsoft Sentinel
Setting up a Log Analytics workspace and Microsoft Sentinel workspace
Confirming we understand the concepts of SIEM and SOAR
Visualizing data ingestion for use in Microsoft Sentinel
Understanding analytic rules in Microsoft Sentinel to support SIEM and SOAR
Workflow for creating security analytic rules for incident response & management
Workflow for creating built-in scheduled query rules
Workflow for creating near-real-time (NRT) analytics rules
Automation with security orchestration automated response (SOAR)
Utilizing content gallery hunting queries for threat hunting
Threat detection coverage by using MITRE ATT&CK
Design solutions for identity and access management
Understanding SaaS, PaaS, and IaaS, & how it relates to Azure hybrid/on-premise
Use cases with SaaS, PaaS, & IaaS including identity, networking, applications
External identities, business-to-business (B2B), & business-to-customer (B2C)
Managing business-to-business (B2B) settings within Entra ID
Using Entra ID external identities for a business-to-business (B2B) solution
Creating a tenant for using business-to-customer (B2C) scenarios
Decentralized identities with the help of Microsoft Entra Verified ID
Threat mitigation with sign-in logs in Microsoft Entra ID
Understanding Entra Identity Protection for continuous access evaluation
Using Entra Identity Protection for securing authentication and authorization
Threat intelligence integration from Entra Identity Protection into MS Defender
Understanding Multi Factor Authentication (MFA)
Implementing Muti Factor Authentication in Microsoft Entra ID
Implementing Self Service Password Reset (SSPR) in Microsoft Entra ID
Understanding Conditional Access Policies with a Zero Trust strategy
Implementing Conditional Access Policies with a Zero Trust strategy
Concepts of threat intelligence integration with Defender for Cloud
Design and configure workflow automation in Microsoft Defender for Cloud
Setting up email notifications within Defender for Cloud
Create and manage alert suppression rules
Generate sample alerts and incidents in Microsoft Defender for Cloud
Remediate alerts and incidents by using MS Defender for Cloud recommendations
Manage security alerts and incidents
Analyze Microsoft Defender for Cloud threat intelligence reports
Concepts of securing the various types of identities using Defender for Identity
Hybrid Active Directory Domain Services (ADDS) connections for secure identities
Creating an Azure Key Vault for secrets, keys, and certificates
Access control to secrets, keys, and certificates with Azure Key Vault
Managing secrets, keys, and certificates with Azure Key vault
Removing key vault services
Design solutions for securing privileged access
Assigning and delegating privileged roles by using the enterprise access model
Understanding RBAC for Identity governance & privileged access management
Implementing RBAC to provide privileged access management in Entra ID & Azure
Creating a custom RBAC role in Microsoft Entra ID
Using RBAC to provide access to Azure resources
Implementing RBAC to provide privileged access management in Microsoft 365
Understanding Microsoft Entra Privileged Identity Management (PIM)
Implementing Microsoft Entra Privileged Identity Management (PIM)
Understanding entitlement management as an identity governance solution
Creating catalogs for entitlement management
Implementing entitlement management with Microsoft Entra Permissions Management
User access request entitlement management to an access package
Identity governance with access reviews in Microsoft Entra
Privileged Access Workstation (PAW) and bastion services
Design solutions for regulatory compliance
Determining compliance requirements for security solution adaptation
Solutions that address compliance requirements by using Microsoft Purview
Utilizing Microsoft Priva for privacy requirements
Creating Privacy Risk Management policies to meet privacy requirements
Azure Policy solutions to address security and compliance requirements
Compliance with Microsoft Defender for Cloud
Design solutions for security posture management in hybrid and multicloud
Security posture with regulatory compliance policies and MCSB
Security posture with Microsoft Defender for Cloud
Security posture with Microsoft Secure Score
Enabling support for Defender for servers within Defender for Cloud
Enabling Microsoft Defender for Servers as a cloud workload protection solution
Enabling Microsoft Defender for App Service as a cloud app protection solution
Integration with hybrid and multicloud environments by using Azure Arc
Support for Microsoft Defender for DevOps within Defender for Cloud
Utilizing Microsoft Defender External Attack Surface Management (Defender EASM)
Design solutions for securing server and client endpoints
Using Microsoft Defender for Endpoint for securing multiple platforms and OS'
Configuring settings in Microsoft Defender for Endpoint
Utilizing Microsoft Intune for mobile devices & client for endpoint protection
Managing security requirements on mobile devices & clients endpoints with Intune
Using security baselines to secure servers and client endpoints
IoT, OT and ICS security discovery using Microsoft Defender for IoT
Secure remote access with Microsoft Entra Global Secure Access
Specify requirements for securing SaaS, PaaS, and IaaS services
Security baselines for SaaS, PaaS, and IaaS services
Security in your IoT workloads
Web workload management with Azure App Service plans
Creating an Azure App Service plan
Adding an App Service for web workloads
Securing web workloads with Azure App Services
Understanding containers in Azure
Creating a container instance in Azure
Securing Azure container instances
Container orchestration with Azure Kubernetes Service (AKS)
Scaling container orchestration with Azure Kubernetes Service (AKS)
Securing container orchestration with Azure Kubernetes Service (AKS)
Design solutions for securing Microsoft 365
Posture with Microsoft Secure Score & Microsoft Defender for Cloud secure score
Requirements for a Microsoft 365 Defender security solution
Secure configuration & operational practices for Microsoft 365 workloads & data
Design solutions for securing applications
Securing existing application portfolios and business-critical applications
Standards and practices for securing the application development process
Considerations for API management and security solutions
Understanding secure access with Azure Web Application Firewall (WAF)
Use cases for implementing the Azure Front Door
Setting up an Azure Web Application Firewall (WAF) & Azure Front Door
Removing existing resources up to this point
Design solutions for securing an organization's data
Understanding data discovery and classification with Purview sensitivity labels
Managing sensitive info types for a classification data governance solution
Implementing a data governance & classification solution with sensitivity labels
Visualizing protection solutions with data at rest, data in motion & data in use
Understanding the concepts of relational databases
Setting up an Azure SQL database and connecting with SSMS
Configuring Azure SQL firewall settings for client connections
Utilizing Azure SQL dynamic masking
Utilizing Azure SQL database encryption
Understanding the concepts of non-relational data and NoSQL
Setting up an Azure Cosmos DB solution in Azure
Protection and durability with replication of an Azure Cosmos DB
Remove existing database resources
Grasping the purposes of Azure Synapse Analytics
Registering Azure Synapse as a resource provider
Creating a SQL DB and server for use with Azure Synapse Analytics
Adding an Azure Synapse workspace and Data Lake Storage account
Visualizing the concepts of SQL Pool usage with Azure Synapse Analytics
Setting up a SQL Pool for usage with Azure Synapse
Confirming we understand the concepts of Azure Storage accounts
Creating an Azure Storage account as a data storage solution
Mitigating threats to data within our Azure Storage account solution
Enabling Defender for Storage within a Azure Storage account
Utilizing Microsoft Defender for SQL as a security solution
Conclusion
Cleaning up resource
Getting a Udemy certificate
BONUS Where do I go from here?