Wide uses the full column for everything, text, diagrams, code, and exercises. Narrow keeps the standard reading width.
Text size
Scales the body text. Headings and code blocks keep their size.
In this section
▾
Microsoft 365 Security Architecture: Course Orientation
Module 0
MICROSOFT 365 SECURITY ARCHITECTURE · MODULE 00
Don't configure controls. Design an architecture you can defend.
A pile of individually enabled controls is not a security architecture, and it falls apart the moment an executive asks whether you are secure or an auditor asks why something is configured the way it is. This course teaches you to design Microsoft 365 as one Zero Trust architecture across identity, devices, apps, and data, justify every decision against threat and risk, and defend it. You leave with a portfolio-grade package: architecture decision records, decision matrices, a risk register, diagrams, and an executive summary. This module shows you what you'll design, the architecture you'll build toward, and how the course gets you there.
15 modules
across 4 phases
Whole estate
identity, devices, apps, data
Portfolio-grade
a package you defend
No prerequisites
every concept built up
Why this course exists
Most Microsoft 365 security is a collection of controls switched on one at a time, each in isolation, none of them connected by a decision anyone wrote down. Conditional Access exists because someone enabled it. A DLP policy runs because a project once needed it. Nobody can say what threat a given control addresses, what risk it accepts, or how the pieces fit together, so when the question comes, from an executive deciding where to spend, or an auditor asking why, there is no defensible answer. That is not architecture; it is configuration that happens to be turned on.
Architecture is the discipline of designing the whole estate as one system and being able to defend every decision in it. This course teaches that discipline. You design Microsoft 365 end to end, identity, devices, apps, and data under Zero Trust, with detection and response over the top and governance wrapping it, and for each significant choice you trace it back to a threat, weigh the options in a decision matrix, record it as an architecture decision record, and tie it to the risk it manages. The result is an architecture you can stand behind in front of a board and an auditor, not a settings export.
What you will be able to do
This course is built around the architecture you can design and defend at the end, not the features you can enable. Every module designs one domain of the estate and produces the decisions behind it.
Architect the identity foundation
Design the Entra identity model, authentication, Conditional Access, and privileged access that everything else is built on.
Design the protection stack
Architect data protection with Purview, endpoint security, and email and collaboration security across the estate.
Architect detection and response
Design the Sentinel workspace, the detection layer, incident response, and Defender XDR as the operations fabric.
Architect governance and compliance
Design identity governance and the security posture and compliance architecture that keeps the estate accountable.
Justify every decision
Work threat-informed, weigh options in decision matrices, and record each choice as an architecture decision record you can defend.
Defend it to executives
Maintain a risk register, produce diagrams and an executive summary, and present the complete architecture in the capstone.
You also leave with things you keep: a portfolio-grade architecture package, more than twenty architecture decision records, decision matrices, a risk register, architecture diagrams, and an executive summary, assembled into the complete architecture in the capstone.
The architecture you will design
The whole estate is one architecture, not a set of separate products. A Zero Trust core sits at the center, and the four domains it protects, identity, devices, apps, and data, connect to it and to each other. Detection and response runs across all of them, and governance and compliance frame the whole design. Every domain is designed against the same threats and recorded with the same rigor, so the architecture holds together and an attacker cannot slip through a seam between two controls that were never meant to meet. This course designs every part of it and connects them into one defensible whole.
You design this for Northgate Engineering, 810 staff on M365 E5 with controls in place but no documented architecture, using Entra ID, Conditional Access, PIM, Purview, Intune, Sentinel, and Defender XDR, and a free M365 E5 developer tenant with an Azure subscription gives you a live environment to design and validate against. The discipline is what carries: threat-informed design, decision records, risk-driven justification, and defensible architecture are how you architect security on any platform, so the method you learn here ports to Google Workspace, AWS, and hybrid estates. Microsoft 365 is the implementation; security architecture is the skill.
How the course is built
Fifteen modules move through four phases, then a reference. You design the identity foundation, then the protection stack, then detection and response, then governance, recording the decisions as you go and assembling everything into a complete architecture in the capstone.
What you need and who this is for
There are no prerequisites, and every concept is explained the first time it appears. This course is for anyone who has to design and defend a security posture, not just operate one: security architects, senior engineers moving into architecture, consultants and advisors who design for clients, and leads who must justify the security estate to executives and auditors.
Transferable architecture discipline
Threat-informed design, decision records, and risk-driven justification architect security anywhere. M365 is the implementation; the method ports to Google Workspace, AWS, and hybrid.
A live tenant to design against
A free M365 E5 developer tenant with an Azure subscription gives you a real environment to design and validate every domain of the architecture.
How to get the most
Design each domain for your own estate and write the decision down as an ADR. Keep the records and diagrams that hold up, that is how your portfolio-grade package gets built.
Do I already know this material?
Six quick scenarios across the full range of this course, from how an architect thinks to unifying a fragmented estate. Answer them to find out where you sit, and whether this course fits or it will sharpen knowledge you already have.
What most distinguishes a security architect's approach from a point-fix approach?
Buying the most products.
Designing layered, defense-in-depth controls under an assume-breach mindset, so the failure of any one control does not mean compromise, rather than patching issues one at a time.
A point fix solves today's finding; an architecture assumes controls will fail and layers them so no single failure is fatal. That assume-breach, defense-in-depth design is what makes the estate resilient rather than merely patched.
Fixing each issue as it is reported.
Trusting the network perimeter.
In a cloud-first Microsoft 365 estate, what is effectively the primary security perimeter to architect around?
Identity: with resources reachable from anywhere, who can access what under which conditions becomes the control plane the architecture is built around.
When the network no longer contains your resources, identity does. Access decisions, conditions, and privilege become the perimeter, which is why a cloud-first architecture is organised around identity rather than a firewall.
The office firewall.
The physical building.
The endpoint antivirus.
You are designing privileged access for a large estate. Which principle most reduces the blast radius of a compromised admin?
Give all admins global rights for flexibility.
Use one shared break-glass account for everyone.
Tiered, least-privilege administration with separation of duties and just-in-time elevation, so a single compromised account cannot control the whole estate.
Blast radius is decided by how much one account can do. Tiering, separation of duties, and just-in-time elevation mean a compromised admin reaches a bounded slice, not the entire estate, which is the heart of privileged-access design.
Grant standing access to everything and monitor later.
How should data protection controls be designed so they are both effective and sustainable?
Encrypt nothing; it slows users down.
Drive the controls from data classification, so the strongest protection and monitoring follow the most sensitive data rather than applying one blunt control everywhere.
Treating all data identically is either too weak for the crown jewels or too heavy for everything else. Classification lets protection scale with sensitivity, which is both more effective where it matters and sustainable elsewhere.
Apply the maximum control to all data equally.
Leave protection to each user's discretion.
Why should detection and incident response be designed into the architecture rather than bolted on afterward?
They should not; response is purely operational.
Because auditors require a diagram.
To make the architecture look complete.
Architecture determines what telemetry exists, how it is centralised, and how responders can act; if logging, correlation, and response paths are not designed in, the SOC cannot see or contain what it was never given.
A SOC can only work with what the architecture provides. If the telemetry, central workspace, and response paths are not designed in from the start, no amount of operational effort recovers the visibility and control that were never built.
An estate has many overlapping security tools that do not share signals, creating gaps and noise. What is the architectural fix?
Add more tools to cover the gaps.
Pick the cheapest tools available.
Design a coherent fabric where the platforms share signal and correlate, so detection, investigation, and response work across the estate as one rather than as disconnected islands.
Disconnected tools create both blind spots between them and duplicated noise within them. Architecting a fabric that shares and correlates signal turns isolated islands into one operating picture, which is what closes the gaps.
Let each team run its own stack independently.
This course is for you.
You will learn to architect a whole Microsoft 365 estate: identity, authentication, Conditional Access, data, endpoint, email, Sentinel, detection, and incident response as one coherent design.
You have the fundamentals. The value here is the harder half.
You think in layers, so the payoff is the back half: privileged access and data architecture, Sentinel and detection architecture, incident response architecture, the Defender XDR fabric, governance, and the complete-architecture capstone.
You handled defense-in-depth, identity as the control plane, privileged tiering, classification-driven data protection, design-for-response, and a unifying fabric, the senior end of the discipline. Take the course to sharpen what you have, close the gaps you did not expect, and turn strong instincts into a complete estate design.
You are a student of this course now, so start by deciding what you want from it. Are you here to design a full architecture from a blank estate, to justify and document one that already exists, or to build a portfolio-grade package you can take into an architect role? Name that outcome, then turn it into a study plan: which domains and phases matter most to your environment, how much time you will give it each week, and what you want to have designed and documented by the time you finish.
The rest of Module 0 sets you up to do exactly that. Work through it to see what security architecture really is, the Microsoft 365 security stack and how the domains connect, how architecture decision records work, what threat-informed architecture means, the Northgate scenario you will design for, the lab setup, and the architecture package you are building toward. Then begin Module 1.
Stuck on this lesson?
Your question goes straight to the team and we'll reply by email. Sign in to ask.