Security Architecture

For Security Architects, Engineers, and Administrators Who Design, Justify, Implement, and Defend M365 Security Posture

Microsoft 365 Security Architecture

Design the architecture. Document every decision. Validate it stops real attacks.

Fifteen modules take you from Entra ID identity architecture through authentication strategy, Conditional Access design, privileged access, data protection, endpoint security, email defense, Sentinel workspace design, detection architecture, incident response, Defender XDR operations, identity governance, compliance mapping, and a capstone that assembles everything into a portfolio-grade architecture package with 30+ Architecture Decision Records.

What you'll deploy
30+ Architecture Decision Records covering every M365 security layer
Complete Conditional Access policy framework with persona model
Sentinel workspace design with detection rule framework
Executive summary and risk register for board presentation
M365 SECURITY ARCHITECTURE — FOUR LAYERS LAYER 1 — IDENTITY FOUNDATION Entra ID · Authentication · Conditional Access · Privileged Access MSA0–MSA4 · Every decision documented as an ADR LAYER 2 — PROTECTION STACK Data Protection · Endpoint Security · Email Defense · Collaboration MSA5–MSA7 · E3 vs E5 trade-off in every module LAYER 3 — DETECTION AND RESPONSE Sentinel · Detection Rules · Incident Response · Defender XDR MSA8–MSA11 · Every detection validated with attack simulation LAYER 4 — GOVERNANCE AND CAPSTONE Identity Governance · Compliance Mapping · Executive Presentation MSA12–MSA14 · The complete architecture package 15 modules · 30+ ADRs · Built on your own M365 tenant
View Pricing Take End of Course Exam → 40 CPE Credits

What you'll be able to do

Design a complete M365 identity, authentication, and Conditional Access architecture with ADRs
Build a phishing-resistant authentication strategy with passwordless rollout roadmap
Architect a 15-policy Conditional Access framework with persona model and break-glass
Eliminate standing privilege with PIM, role architecture, and Copilot governance
Design data protection architecture with sensitivity labels, DLP, and insider risk
Produce a portfolio-grade architecture package with 30+ ADRs and executive summary
Specialist tier | 15 modules across 4 phases | 36–40 hours at your own pace | 40 CPE credits | 2 free modules — no account needed | Updated May 2026
Course Agenda View all 17 modules

Who this course is for

“I configured M365 security but I can’t explain why I chose those settings.” You deployed Conditional Access policies, enabled MFA, turned on Defender features. If the auditor asks why you chose those specific settings over the alternatives, you don’t have a documented answer. This course builds the ADR for every decision — context, options, trade-offs, and rationale.

“My CISO asked for our security architecture and I don’t have one.” You have portal configurations. You don’t have an architecture document that explains how identity, endpoint, data protection, and detection work together as a system. This course produces the 30+ ADRs, decision matrices, risk register, and executive summary that constitute an actual architecture.

“We’re going through an ISO 27001 audit and I need documented decisions.” The auditor wants evidence that each control was selected deliberately, that alternatives were considered, and that the trade-offs were accepted with awareness. An ADR is that evidence. This course builds the ADR library mapped to ISO 27001, NIST CSF, and CIS controls.

“The previous architect left and nobody knows why anything is configured this way.” Undocumented architecture is untransferable architecture. When the person who built it leaves, the knowledge leaves. This course teaches you to document every decision so your successor understands the rationale without asking you.

“I want to move into security architecture from engineering.” The difference between engineering and architecture is documentation and justification. Engineers configure controls. Architects design systems, document decisions, and defend them to stakeholders. The portfolio you build in this course — ADRs, risk register, executive summary — is what you bring to architecture interviews.

“We’re on E3 and I need to justify the E5 upgrade to the CFO.” Every module includes the E3 vs E5 trade-off analysis — what you get, what you lose, and where the licensing boundary creates security gaps. The executive summary at the end makes the business case for the security investment in terms the CFO can evaluate.

Whatever your background — if the subject interests you and you’re willing to put in the work, this course is for you.

Before and after this course

Before

Your M365 security is a collection of portal settings. Conditional Access policies exist but nobody can explain why the session timeout is 8 hours instead of 4, why compliant device is required for some apps but not others, or what happens if the break-glass account is compromised.

The auditor asks for your Conditional Access architecture. You screenshot 12 policies from the portal. They ask which attack patterns each policy defends against. You don’t have a documented answer.

Sentinel is deployed with template analytics rules. Purview DLP is on but nobody configured the policies. Intune compliance policies exist for some device types. Each product was configured independently. Nobody designed them as a system.

The security architect left six months ago. Nobody knows why the CA policies are scoped the way they are, why certain groups are excluded from PIM, or whether the Sentinel workspace design was intentional or accidental.

After

Every security control has an ADR that documents what was decided, what alternatives were considered, what trade-offs were accepted, and what triggers a review. The architecture is the documentation, not the portal settings.

The auditor gets the ADR library mapped to ISO 27001 controls. Each decision record links the control to the threat it addresses, the verification query that proves it works, and the exception register that documents what’s excluded and why.

Identity, endpoint, data protection, email defense, detection, and response are designed as a system. Each layer’s decision matrices reference the others. The Sentinel workspace design connects to the detection architecture which connects to the incident response playbooks.

Your successor opens the architecture package and understands every decision without asking you. The ADRs explain the reasoning. The decision matrices show what was compared. The risk register tracks what was accepted. The architecture survives staff changes.

How the course works

Four layers build from identity foundations through protection and detection to the complete architecture package:

Layer 1
Identity Foundation

Architecture thinking methodology, Entra ID design, authentication strategy, Conditional Access policy framework with persona model, privileged access with PIM and break-glass governance.

Layer 2
Protection Stack

Purview data protection architecture, Intune endpoint security baselines, Defender for Office 365 email defense, collaboration security. E3 vs E5 trade-off analysis in every module.

Layer 3
Detection & Response

Sentinel workspace architecture, log connector strategy, detection rule framework, incident response integration, Defender XDR operations design. Every detection validated with attack simulation.

Layer 4
Governance & Capstone

Identity governance and lifecycle, compliance mapping (ISO 27001, NIST CSF, CIS), and the capstone: assemble the complete architecture package with executive summary, risk register, and 30+ ADRs.

What the content looks like

This is a real Architecture Decision Record from the Conditional Access module. Every security control in this course gets an ADR before it gets a portal configuration — the document that explains why you built it this way:

Architecture Decision Record — From Module 3: Conditional Access Design

ADR-007: Session timeout for unmanaged devices

Status: Accepted

Context: Users access M365 from personal devices (BYOD). Compliant device CA policies cannot apply. Stolen session tokens from unmanaged devices have no device-binding protection. Average AiTM token replay window is 4–6 hours.

Options considered: (A) 1-hour timeout — strong security, high user friction. (B) 4-hour timeout — closes the AiTM replay window, moderate friction. (C) 8-hour timeout — low friction, leaves a 2–4 hour replay window. (D) No timeout — maximum usability, maximum risk.

Decision: Option B — 4-hour sign-in frequency for unmanaged devices accessing Exchange Online, SharePoint, and Teams.

Trade-offs: Users on personal devices re-authenticate twice per workday. Acceptable given the token replay risk. VIP exception group uses 8-hour timeout with compensating monitoring control (ADR-008).

Review trigger: Revisit if token protection becomes GA for unmanaged devices, or if user complaints exceed 10/week sustained over 30 days.

The ADR documents what was decided, what was considered, and what triggers a change. When the auditor asks “why 4 hours?” the answer is in the decision record. When your successor inherits the architecture, the reasoning is self-contained. Every module teaches at this level — design the control, document the decision, deploy, validate.

Usage rights and disclaimer

Course materials: Licensed for individual professional development. You may deploy configurations, detection rules, scripts, and policies from this course in your organization’s production environment. You may not redistribute course content, share account credentials, or republish course materials.

Architecture configurations: All PowerShell commands, Graph API queries, Conditional Access policies, PIM configurations, and Purview policies are provided as-is. Test every configuration in report-only or simulation mode before enforcement. Ridgeline Cyber Defence is not responsible for operational impact from deployed configurations.

Fictional environment: All scenarios use the fictional Northgate Engineering environment. Any resemblance to real organizations is coincidental.

Version and changelog

Current version: 1.0  |  Last updated: May 2026

2026 — v1.0: Course launch. 15 modules (MSA0–MSA14) across 4 layers. Complete M365 security architecture from identity foundations through detection, XDR operations, and capstone assembly. 30+ ADRs, decision matrices, risk register, executive summary.

This course is actively maintained. Architecture patterns are updated as Microsoft capabilities evolve and the M365 platform changes.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
1scenario
Take End of Course Exam

Requires 80% course completion. One random scenario per attempt. Certificate issued on pass.