For Security Architects, Engineers, and Administrators Who Design, Justify, Implement, and Defend M365 Security Posture
Microsoft 365 Security Architecture
Design the architecture. Document every decision. Validate it stops real attacks.
Fifteen modules take you from Entra ID identity architecture through authentication strategy, Conditional Access design, privileged access, data protection, endpoint security, email defense, Sentinel workspace design, detection architecture, incident response, Defender XDR operations, identity governance, compliance mapping, and a capstone that assembles everything into a portfolio-grade architecture package with 30+ Architecture Decision Records.
What you'll be able to do
Who this course is for
“I configured M365 security but I can’t explain why I chose those settings.” You deployed Conditional Access policies, enabled MFA, turned on Defender features. If the auditor asks why you chose those specific settings over the alternatives, you don’t have a documented answer. This course builds the ADR for every decision — context, options, trade-offs, and rationale.
“My CISO asked for our security architecture and I don’t have one.” You have portal configurations. You don’t have an architecture document that explains how identity, endpoint, data protection, and detection work together as a system. This course produces the 30+ ADRs, decision matrices, risk register, and executive summary that constitute an actual architecture.
“We’re going through an ISO 27001 audit and I need documented decisions.” The auditor wants evidence that each control was selected deliberately, that alternatives were considered, and that the trade-offs were accepted with awareness. An ADR is that evidence. This course builds the ADR library mapped to ISO 27001, NIST CSF, and CIS controls.
“The previous architect left and nobody knows why anything is configured this way.” Undocumented architecture is untransferable architecture. When the person who built it leaves, the knowledge leaves. This course teaches you to document every decision so your successor understands the rationale without asking you.
“I want to move into security architecture from engineering.” The difference between engineering and architecture is documentation and justification. Engineers configure controls. Architects design systems, document decisions, and defend them to stakeholders. The portfolio you build in this course — ADRs, risk register, executive summary — is what you bring to architecture interviews.
“We’re on E3 and I need to justify the E5 upgrade to the CFO.” Every module includes the E3 vs E5 trade-off analysis — what you get, what you lose, and where the licensing boundary creates security gaps. The executive summary at the end makes the business case for the security investment in terms the CFO can evaluate.
Whatever your background — if the subject interests you and you’re willing to put in the work, this course is for you.
Before and after this course
Your M365 security is a collection of portal settings. Conditional Access policies exist but nobody can explain why the session timeout is 8 hours instead of 4, why compliant device is required for some apps but not others, or what happens if the break-glass account is compromised.
The auditor asks for your Conditional Access architecture. You screenshot 12 policies from the portal. They ask which attack patterns each policy defends against. You don’t have a documented answer.
Sentinel is deployed with template analytics rules. Purview DLP is on but nobody configured the policies. Intune compliance policies exist for some device types. Each product was configured independently. Nobody designed them as a system.
The security architect left six months ago. Nobody knows why the CA policies are scoped the way they are, why certain groups are excluded from PIM, or whether the Sentinel workspace design was intentional or accidental.
Every security control has an ADR that documents what was decided, what alternatives were considered, what trade-offs were accepted, and what triggers a review. The architecture is the documentation, not the portal settings.
The auditor gets the ADR library mapped to ISO 27001 controls. Each decision record links the control to the threat it addresses, the verification query that proves it works, and the exception register that documents what’s excluded and why.
Identity, endpoint, data protection, email defense, detection, and response are designed as a system. Each layer’s decision matrices reference the others. The Sentinel workspace design connects to the detection architecture which connects to the incident response playbooks.
Your successor opens the architecture package and understands every decision without asking you. The ADRs explain the reasoning. The decision matrices show what was compared. The risk register tracks what was accepted. The architecture survives staff changes.
How the course works
Four layers build from identity foundations through protection and detection to the complete architecture package:
Architecture thinking methodology, Entra ID design, authentication strategy, Conditional Access policy framework with persona model, privileged access with PIM and break-glass governance.
Purview data protection architecture, Intune endpoint security baselines, Defender for Office 365 email defense, collaboration security. E3 vs E5 trade-off analysis in every module.
Sentinel workspace architecture, log connector strategy, detection rule framework, incident response integration, Defender XDR operations design. Every detection validated with attack simulation.
Identity governance and lifecycle, compliance mapping (ISO 27001, NIST CSF, CIS), and the capstone: assemble the complete architecture package with executive summary, risk register, and 30+ ADRs.
What the content looks like
This is a real Architecture Decision Record from the Conditional Access module. Every security control in this course gets an ADR before it gets a portal configuration — the document that explains why you built it this way:
The ADR documents what was decided, what was considered, and what triggers a change. When the auditor asks “why 4 hours?” the answer is in the decision record. When your successor inherits the architecture, the reasoning is self-contained. Every module teaches at this level — design the control, document the decision, deploy, validate.
Usage rights and disclaimer
Course materials: Licensed for individual professional development. You may deploy configurations, detection rules, scripts, and policies from this course in your organization’s production environment. You may not redistribute course content, share account credentials, or republish course materials.
Architecture configurations: All PowerShell commands, Graph API queries, Conditional Access policies, PIM configurations, and Purview policies are provided as-is. Test every configuration in report-only or simulation mode before enforcement. Ridgeline Cyber Defence is not responsible for operational impact from deployed configurations.
Fictional environment: All scenarios use the fictional Northgate Engineering environment. Any resemblance to real organizations is coincidental.
Version and changelog
Current version: 1.0 | Last updated: May 2026
2026 — v1.0: Course launch. 15 modules (MSA0–MSA14) across 4 layers. Complete M365 security architecture from identity foundations through detection, XDR operations, and capstone assembly. 30+ ADRs, decision matrices, risk register, executive summary.
This course is actively maintained. Architecture patterns are updated as Microsoft capabilities evolve and the M365 platform changes.
End of Course Exam
Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.
Requires 80% course completion. One random scenario per attempt. Certificate issued on pass.