Microsoft 365 Security Architecture
Master Microsoft 365 Security Architecture
Design, justify, implement, and defend a Zero Trust security architecture for Microsoft 365 that protects every user, device, app, and data; across Entra ID, Defender XDR, Purview, Intune, and hybrid environments. Turn complex M365 security controls into a resilient, measurable security posture that executives understand and attackers cannot bypass.
What you'll be able to do
Course Syllabus
Every module and every lesson. The first three modules are open; the rest open on a click.
Download the full syllabus (PDF)
Phase 1: Identity Foundation
What Microsoft 365 Security Architecture teaches: design, justify, and defend one Zero Trust architecture across identity, devices, apps, and data, with detection, response, and governance, and walk away with a portfolio-grade package of ADRs, decision matrices, a risk register, diagrams, and an executive summary. The architecture you'll design, the artifacts you keep, and how the course is structured. Start here.
Show 8 lessonsHide lessons
- 0.1MSA0.1 What Security Architecture Actually IsPreview
- 0.2MSA0.2 The M365 Security Stack as ArchitecturePreview
- 0.3MSA0.3 Architecture Decision RecordsPreview
- 0.4MSA0.4 Threat-Informed ArchitecturePreview
- 0.5MSA0.5 Your Tenant Baseline AssessmentPreview
- 0.6MSA0.6 Lab Setup and Cost ManagementPreview
- 0.7MSA0.7 Your Architecture PackagePreview
- 0.8Module SummaryPreview
The foundation. Every authentication, every authorization, every access decision in M365 flows through Entra ID. This module teaches you to design the identity layer, tenant architecture, identity types and their attack surfaces, hybrid identity, directory structure, the identity lifecycle, naming governance, and group architecture, as deliberate architectural decisions with documented reasoning, mapped dependencies, and honest risk statements.
Show 15 lessonsHide lessons
- 1.1MSA1.1 Tenant Architecture. The Boundary That Constrains Everything
- 1.2MSA1.2 Identity Types in Entra ID
- 1.3MSA1.3 The Attack Surface of Each Identity Type
- 1.4MSA1.4 Hybrid Identity Architecture
- 1.5MSA1.5 Hybrid Identity. What Breaks and What's Legacy
- 1.6MSA1.6 Directory Structure and Administrative Units
- 1.7MSA1.7 The Identity Lifecycle. Joiner, Mover, Leaver
- 1.8MSA1.8 Stale Identities and Access Accumulation
- 1.9MSA1.9 Naming Conventions and Governance Foundations
- 1.10MSA1.10 Group Architecture
- 1.11MSA1.11 NE Identity Assessment
- 1.12MSA1.12 Module Lab. Identity Baseline
- 1.13MSA1.13 Guided Walkthrough. The Identity Layer as a System
- 1.14Module Summary
- 1.15Check My Knowledge
Design an authentication architecture that stops real attacks, beyond enabling MFA.
Show 14 lessonsHide lessons
- 2.1MSA2.1 Authentication Methods. The Security Analysis
- 2.2MSA2.2 How AiTM Attacks Work. Why Phishing Resistance Matters
- 2.3MSA2.3 Phishing-Resistant Authentication Design
- 2.4MSA2.4 The Passwordless Roadmap
- 2.5MSA2.5 Legacy Authentication. Kill It or Manage It
- 2.6MSA2.6 Service Account and Workload Authentication
- 2.7MSA2.7 Authentication Strength Policies
- 2.8MSA2.8 SSPR Architecture
- 2.9MSA2.9 Token Protection and Session Security
- 2.10MSA2.10 Authentication Architecture Assessment
- 2.11MSA2.11 Module Lab. Authentication Implementation
- 2.12MSA2.12 Guided Walkthrough. The Authentication Architecture as a System
- 2.13Module Summary
- 2.14Check My Knowledge
Design a systematic CA framework that's maintainable, auditable, and resilient to bypass.
Show 17 lessonsHide lessons
- 3.1MSA3.1 Conditional Access as the Policy Engine
- 3.2MSA3.2 Policy Design Methodology
- 3.3MSA3.3 The Baseline Policy Set
- 3.4MSA3.4 Tiered Access Policies
- 3.5MSA3.5 Device-Based Conditional Access Policies
- 3.6MSA3.6 Application-Specific Conditional Access Policies
- 3.7MSA3.7 Named Locations and Network Controls
- 3.8MSA3.8 Break-Glass Accounts and Emergency Access
- 3.9MSA3.9 Policy Lifecycle and Change Management
- 3.10MSA3.10 Exception Management
- 3.11MSA3.11 CA Policy Audit and Compliance Evidence
- 3.12MSA3.12 Hybrid Conditional Access
- 3.13MSA3.13 The Complete Conditional Access Architecture
- 3.14MSA3 Module Lab. CA Framework Deployment
- 3.15MSA3 Guided Walkthrough. The CA Framework as a System
- 3.16Module Summary
- 3.17Check My Knowledge
Phase 2: Protection Stack
Design a privilege model where administrative access is earned temporarily, not granted permanently.
Show 13 lessonsHide lessons
- 4.1MSA4.1 The Privilege Problem in M365
- 4.2MSA4.2 Entra ID Role Architecture
- 4.3MSA4.3 PIM Design and Deployment
- 4.4MSA4.4 Privileged Access Workstations
- 4.5MSA4.5 Service Principal and Managed Identity Governance
- 4.6MSA4.6 Cross-Tenant and B2B Privilege
- 4.7MSA4.7 Emergency Access Architecture
- 4.8MSA4.8 Securing Microsoft Copilot and AI Workloads
- 4.9MSA4.9 The Complete Privileged Access Architecture
- 4.10MSA4 Module Lab. Privileged Access Deployment
- 4.11MSA4 Guided Walkthrough. The Privilege Architecture as a System
- 4.12Module Summary
- 4.13Check My Knowledge
Design a data protection framework that controls what happens to sensitive data after a legitimate user has access to it.
Show 12 lessonsHide lessons
- 5.1MSA5.1 Data Classification Strategy
- 5.2MSA5.2 Sensitivity Label Architecture
- 5.3MSA5.3 DLP Policy Architecture
- 5.4MSA5.4 Information Barriers
- 5.5MSA5.5 DLP Channels
- 5.6MSA5.6 Retention Architecture
- 5.7MSA5.7 Insider Risk Management
- 5.8MSA5.8 Complete Architecture
- 5.9MSA5 Module Lab. Data Protection Deployment
- 5.10MSA5 Guided Walkthrough. Data Protection as a System
- 5.11Module Summary
- 5.12Check My Knowledge
Design device trust as an architectural pillar, compliance policies that evaluate real security properties across four platforms, configuration baselines that prevent drift, custom compliance scripts for settings built-in rules can't check, BYOD strategy with app protection, MDE as a real-time risk signal, ASR rules promoted from audit to block, automated response boundaries, endpoint privilege management, and Autopilot provisioning that delivers compliant devices from the first sign-in.
Show 16 lessonsHide lessons
- 6.1MSA6.1 Endpoint Trust as an Architectural Pillar
- 6.2MSA6.2 Windows Compliance Policy Design
- 6.3MSA6.3 iOS, macOS, and Android Compliance
- 6.4MSA6.4 The Compliance Tier Model
- 6.5MSA6.5 Configuration Baseline Design
- 6.6MSA6.6 Configuration Drift and Baseline Lifecycle
- 6.7MSA6.7 App Protection Without Device Enrollment
- 6.8MSA6.8 MDE as the Risk Signal
- 6.9MSA6.9 Attack Surface Reduction Architecture
- 6.10MSA6.10 Automated Investigation and Endpoint Privilege Management
- 6.11MSA6.11 Autopilot and Device Lifecycle
- 6.12MSA6.12 Your Endpoint Architecture
- 6.13MSA6 Module Lab. Endpoint Security Deployment
- 6.14MSA6 Guided Walkthrough. Connecting the Endpoint Architecture
- 6.15Module Summary
- 6.16Check My Knowledge
Design the protection architecture for the attack surface where most breaches begin, email and collaboration.
Show 16 lessonsHide lessons
- 7.1MSA7.1 Email Threat Surface Audit
- 7.2MSA7.2 EOP Baseline Protection
- 7.3MSA7.3 Safe Links Architecture
- 7.4MSA7.4 Safe Attachments Architecture
- 7.5MSA7.5 Anti-Phishing and Impersonation Protection
- 7.6MSA7.6 Attack Simulation and User Resilience
- 7.7MSA7.7 SPF and DKIM. Domain Authentication
- 7.8MSA7.8 DMARC and ARC. Policy Enforcement
- 7.9MSA7.9 Teams Security Architecture
- 7.10MSA7.10 SharePoint and OneDrive External Sharing
- 7.11MSA7.11 Post-Delivery Response Architecture
- 7.12MSA7.12 Complete Email and Collaboration Architecture
- 7.13MSA7 Module Lab. Email and Collaboration Security Deployment
- 7.14Guided Walkthrough. Email and Collaboration Security
- 7.15Module Summary
- 7.16Check My Knowledge
Phase 3: Detection & Response
Design the detection and investigation infrastructure, workspace topology, data connectors, log tiering, RBAC, and content deployment for Microsoft Sentinel.
Show 16 lessonsHide lessons
- 8.1MSA8.1 Workspace Design Decisions
- 8.2MSA8.2 Workspace Cost Modeling
- 8.3MSA8.3 M365 Data Connectors
- 8.4MSA8.4 Azure and Third-Party Connectors
- 8.5MSA8.5 Log Tier Architecture
- 8.6MSA8.6 Data Collection Rules and Transformation
- 8.7MSA8.7 Workspace RBAC Architecture
- 8.8MSA8.8 Table-Level and Resource-Context Access
- 8.9MSA8.9 Content Hub and Solution Deployment
- 8.10MSA8.10 Workbook and Hunting Architecture
- 8.11MSA8.11 Workspace Health and Cost Monitoring
- 8.12MSA8.12 Complete Sentinel Architecture
- 8.13MSA8 Module Lab. Sentinel Workspace Deployment
- 8.14Guided Walkthrough. Sentinel Workspace Architecture
- 8.15Module Summary
- 8.16Check My Knowledge
Design the detection rule framework, analytics rule architecture, identity and email detection patterns, privileged activity monitoring, data exfiltration detection, alert tuning, and detection coverage measurement.
Show 16 lessonsHide lessons
- 9.1MSA9.1 Detection Philosophy. What to Detect and Why
- 9.2MSA9.2 Analytics Rule Types and Architecture
- 9.3MSA9.3 Identity-Based Detection. Credential Compromise
- 9.4MSA9.4 Identity-Based Detection. Privilege Abuse and Lateral Movement
- 9.5MSA9.5 Email-Based Detection Patterns
- 9.6MSA9.6 Endpoint Detection Architecture
- 9.7MSA9.7 Data Exfiltration Detection
- 9.8MSA9.8 Cloud App and OAuth Detection
- 9.9MSA9.9 Alert Tuning and False Positive Management
- 9.10MSA9.10 Detection Coverage Measurement
- 9.11MSA9.11 Detection-as-Code and Rule Lifecycle
- 9.12MSA9.12 Complete Detection Architecture
- 9.13MSA9 Module Lab. Detection Architecture Deployment
- 9.14Guided Walkthrough. Detection Architecture
- 9.15Module Summary
- 9.16Check My Knowledge
Design the incident response architecture, automation rules, containment playbooks, evidence preservation, incident workflows, communication procedures, and post-incident review.
Show 16 lessonsHide lessons
- 10.1MSA10.1 IR Architecture vs IR Execution
- 10.2MSA10.2 Automation Rules and Playbook Architecture
- 10.3MSA10.3 Automated Investigation and Response (AIR)
- 10.4MSA10.4 Containment Architecture. Identity Actions
- 10.5MSA10.5 Containment Architecture. Endpoint and Network
- 10.6MSA10.6 Evidence Preservation and Forensic Readiness
- 10.7MSA10.7 Incident Classification and Severity Framework
- 10.8MSA10.8 Incident Workflow and Assignment Architecture
- 10.9MSA10.9 Communication and Escalation Architecture
- 10.10MSA10.10 Post-Incident Review and Lessons Learned
- 10.11MSA10.11 IR Playbook Library
- 10.12MSA10.12 Complete Response Architecture
- 10.13MSA10 Module Lab. Response Architecture Deployment
- 10.14Guided Walkthrough. Response Architecture
- 10.15Module Summary
- 10.16Check My Knowledge
Design the XDR operations architecture, unified schema, cross-domain correlation, attack disruption, custom detection rules, incident orchestration, Sentinel coexistence, and unified RBAC.
Show 16 lessonsHide lessons
- 11.1MSA11.1 The Unified Advanced Hunting Schema
- 11.2MSA11.2 Signal Correlation Architecture
- 11.3MSA11.3 Cross-Domain Incident Correlation
- 11.4MSA11.4 Attack Disruption Architecture
- 11.5MSA11.5 AIR in the Unified Fabric
- 11.6MSA11.6 Advanced Hunting Across Domains
- 11.7MSA11.7 Custom Detection Rules in Defender XDR
- 11.8MSA11.8 Incident Orchestration in the Unified Portal
- 11.9MSA11.9 Sentinel-XDR Coexistence Architecture
- 11.10MSA11.10 Data Flow and Duplication Management
- 11.11MSA11.11 Unified RBAC Architecture
- 11.12MSA11.12 Complete XDR Operations Architecture
- 11.13MSA11 Module Lab. XDR Operations Deployment
- 11.14MSA11 Guided Walkthrough. XDR as an Integrated System
- 11.15Module Summary
- 11.16Check My Knowledge
Phase 4: Governance & Capstone
Design the identity governance architecture, access reviews, entitlement management, lifecycle workflows, HR-driven provisioning, workload identity governance, agent identity governance, and PIM integration.
Show 16 lessonsHide lessons
- 12.1MSA12.1 The Governance Problem
- 12.2MSA12.2 Access Reviews. Scope and Design
- 12.3MSA12.3 Access Reviews. Automation and Decisions
- 12.4MSA12.4 Entitlement Management. Access Packages
- 12.5MSA12.5 Entitlement Management. Auto-Assignment and Lifecycle
- 12.6MSA12.6 Lifecycle Workflows. Joiner
- 12.7MSA12.7 Lifecycle Workflows. Mover and Leaver
- 12.8MSA12.8 HR-Driven Provisioning Architecture
- 12.9MSA12.9 Workload Identity Governance
- 12.10MSA12.10 Agent Identity Governance
- 12.11MSA12.11 PIM Governance Integration
- 12.12MSA12.12 Complete Governance Architecture
- 12.13MSA12 Module Lab. Governance Deployment
- 12.14MSA12 Guided Walkthrough. Governance as a System
- 12.15Module Summary
- 12.16Check My Knowledge
Design the security posture measurement and compliance architecture, Secure Score interpretation, Compliance Manager assessments, framework mapping across ISO 27001, SOC 2, NIST CSF, and UK frameworks, maturity roadmaps, and executive communication.
Show 16 lessonsHide lessons
- 13.1MSA13.1 The Posture Problem
- 13.2MSA13.2 Secure Score. Honest Interpretation
- 13.3MSA13.3 Compliance Manager. Assessment Architecture
- 13.4MSA13.4 Compliance Manager. Evidence and Automation
- 13.5MSA13.5 Mapping Controls to ISO 27001
- 13.6MSA13.6 Mapping Controls to SOC 2 and NIST CSF
- 13.7MSA13.7 Mapping Controls to UK Frameworks
- 13.8MSA13.8 Maturity Roadmaps and Gap Analysis
- 13.9MSA13.9 Communicating Security Architecture to Leadership
- 13.10MSA13.10 The NE Posture Assessment
- 13.11MSA13.11 Continuous Posture Monitoring
- 13.12MSA13.12 Complete Posture and Compliance Architecture
- 13.13Module Lab. Posture and Compliance Baseline
- 13.14Guided Walkthrough
- 13.15Module Summary
- 13.16Check My Knowledge
Assemble, defend, threat-model, and present the complete M365 security architecture built across Modules 0–13, producing the portfolio-grade deliverable that survives your departure.
Phase 0: Course Resources
The commands, queries and decision criteria behind every architecture domain in the course, with what each answer settles and what it leaves open.
Show 14 lessonsHide lessons
- 1Identity Architecture
- 2Authentication Architecture
- 3Conditional Access
- 4Privileged Access
- 5Data Protection
- 6Endpoint Security
- 7Email and Collaboration
- 8Sentinel Workspace
- 9Detection Architecture
- 10Incident Response
- 11Defender XDR
- 12Identity Governance
- 13Posture and Compliance
- 14Cadences and Graph Reference
Ordered procedures for the architecture work that recurs: deploying a policy without an outage, reducing standing privilege, assessing a tenant, and retiring a control.
Building a tenant where you can deploy architecture, break it, and see what the controls actually do, without touching anything anyone depends on.
Architecture decisions worked end to end, including the ones where the correct answer was to deploy nothing and the ones where the design was right and still failed.
What to do when a decision is forced on you: a merger, an audit finding, a regulator, a breach elsewhere, a budget cut, or a product retirement.
Every practice surface available for this course, what each one actually gives you, and where the gaps are.
Microsoft documentation, security frameworks, compliance standards, threat intelligence, and vendor references used throughout the MSA course.
Course Completion
Microsoft 365 Security Architecture end-of-course exam: a three-phase simulation testing whether you can apply the method to a situation the course did not walk through.
Show 1 lessonHide lessons
Course overview
The Microsoft 365 Security Architecture course is built specifically for Security Architects, Engineers, and Administrators who design, justify, implement, and defend M365 security posture. You'll gain hands-on expertise to:
By the end, you'll have the strategic and technical mastery to own your organization's Microsoft 365 security architecture, confidently defending it against modern threats while aligning security outcomes with business goals.
How this course works
Architecture is the discipline of making decisions that later decisions depend on. This course runs the same loop for every layer it designs, and the layers are deliberately in dependency order.
1. Decide, and write down why. An architecture is a set of decisions with reasons attached. Without the reason, the next person reverses it and nobody knows what broke.
2. Design against the attack, not the feature list. Each layer is built from what it has to stop rather than from what the product can do.
3. Check the layer against the one beneath it. Conditional Access rests on authentication methods, detection rests on workspace design, and a strong layer on a weak one is a weak layer.
4. Make the failure mode explicit. Every control blocks somebody, every log has a retention, every design has a cost. An architecture that hides these gets overruled in an incident.
5. Produce something that outlives you. Decision records, not diagrams. The diagram shows the state; the record explains why it is that state.
The capstone assembles the complete architecture from every layer designed along the way.
What this course assumes
No minimum experience and no prerequisite course. Each service is introduced from what it does architecturally rather than from how it is administered.
What makes it go faster: an estate you are responsible for, because every design decision in the course has a real counterpart in it. Not required.
What this course does not cover: hands-on administration of each service, incident response process and forensics. This course decides what should exist; the operational courses run it.
Who this course is for
You're a Security Architect, Security Engineer, or Microsoft 365 Administrator responsible for designing, justifying, implementing, and defending your organization's Microsoft 365 security posture. This course is built for you if you want to:
In short: if you're ready to own and defend a modern Microsoft 365 security architecture that actually works against today's threats, this course is for you.
What you'll learn
By the end of this Microsoft 365 Security Architecture course you will be able to:
Key course takeaways
Things you need to know
What are the prerequisites for this course?
There are no prerequisites. The course teaches M365 security architecture from first principles. Familiarity with the Microsoft 365 admin center and Entra ID will help you move faster through the early modules, but neither is required. Every concept is explained at first use.
What are the device requirements?
A device with a modern browser. Access to a Microsoft 365 E5 tenant (a developer subscription if you qualify for one, otherwise a 30-day E5 trial) and an Azure subscription for Sentinel workspace deployment. The course walks you through tenant and workspace setup in Module 0.
How will the course benefit your career?
Security architecture is one of the most in-demand disciplines in cybersecurity. Organizations need people who can design integrated security systems across the M365 stack, not just configure individual products. This course gives you the skills to architect Zero Trust infrastructure, document decisions with ADRs, and present security investments to executives.
The demand for security architects who can bridge technical implementation and business justification continues to grow as organizations move from product-by-product configuration to integrated security architecture.
Usage rights and disclaimer
Course materials: Licensed for individual professional development. You may deploy configurations, detection rules, scripts, and policies in your production environment. You may not redistribute course content or share account credentials.
Architecture configurations: All PowerShell commands, Graph API queries, Conditional Access policies, PIM configurations, and Purview policies are provided as-is. Test every configuration in report-only or simulation mode before enforcement. Ridgeline Cyber Defence is not responsible for operational impact from deployed configurations.
Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.
End of Course Exam
Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.
One random scenario per attempt. Certificate issued on pass.