Microsoft 365 Security Architecture

Master Microsoft 365 Security Architecture

Design, justify, implement, and defend a Zero Trust security architecture for Microsoft 365 that protects every user, device, app, and data; across Entra ID, Defender XDR, Purview, Intune, and hybrid environments. Turn complex M365 security controls into a resilient, measurable security posture that executives understand and attackers cannot bypass.

Included with Specialist, from $29/month, or $289/year and save 25%. Preview the first module free, no account needed.
Practice included: scored investigation scenarios, plus the Practice Hub.
View Pricing Take End of Course Exam → 40 CPE Credits

What you'll be able to do

✓Design and implement a comprehensive Zero Trust security architecture across the full Microsoft 365 ecosystem
✓Deploy and optimise Microsoft Defender XDR, Entra ID Conditional Access, Intune, Purview, and Microsoft Sentinel for integrated protection
✓Justify security architecture decisions with clear risk metrics, executive presentations, and business-aligned documentation
✓Configure secure identity, endpoint, application, data, and compliance controls that hold in hybrid environments
✓Proactively hunt, detect, and respond to advanced threats targeting Microsoft 365
✓Continuously assess, measure, and improve your organization's overall M365 security posture
ARC501 | Specialist tier | 15 modules across 4 phases | 36–40 hours at your own pace | 40 CPE credits

Course Syllabus

Every module and every lesson. The first three modules are open; the rest open on a click.

Download the full syllabus (PDF)

Phase 1: Identity Foundation

Module 0Course OrientationCourse Preview

What Microsoft 365 Security Architecture teaches: design, justify, and defend one Zero Trust architecture across identity, devices, apps, and data, with detection, response, and governance, and walk away with a portfolio-grade package of ADRs, decision matrices, a risk register, diagrams, and an executive summary. The architecture you'll design, the artifacts you keep, and how the course is structured. Start here.

Show 8 lessonsHide lessons
  1. 0.1MSA0.1 What Security Architecture Actually IsPreview
  2. 0.2MSA0.2 The M365 Security Stack as ArchitecturePreview
  3. 0.3MSA0.3 Architecture Decision RecordsPreview
  4. 0.4MSA0.4 Threat-Informed ArchitecturePreview
  5. 0.5MSA0.5 Your Tenant Baseline AssessmentPreview
  6. 0.6MSA0.6 Lab Setup and Cost ManagementPreview
  7. 0.7MSA0.7 Your Architecture PackagePreview
  8. 0.8Module SummaryPreview
Module 1Entra ID Identity Architecture

The foundation. Every authentication, every authorization, every access decision in M365 flows through Entra ID. This module teaches you to design the identity layer, tenant architecture, identity types and their attack surfaces, hybrid identity, directory structure, the identity lifecycle, naming governance, and group architecture, as deliberate architectural decisions with documented reasoning, mapped dependencies, and honest risk statements.

Show 15 lessonsHide lessons
  1. 1.1MSA1.1 Tenant Architecture. The Boundary That Constrains Everything
  2. 1.2MSA1.2 Identity Types in Entra ID
  3. 1.3MSA1.3 The Attack Surface of Each Identity Type
  4. 1.4MSA1.4 Hybrid Identity Architecture
  5. 1.5MSA1.5 Hybrid Identity. What Breaks and What's Legacy
  6. 1.6MSA1.6 Directory Structure and Administrative Units
  7. 1.7MSA1.7 The Identity Lifecycle. Joiner, Mover, Leaver
  8. 1.8MSA1.8 Stale Identities and Access Accumulation
  9. 1.9MSA1.9 Naming Conventions and Governance Foundations
  10. 1.10MSA1.10 Group Architecture
  11. 1.11MSA1.11 NE Identity Assessment
  12. 1.12MSA1.12 Module Lab. Identity Baseline
  13. 1.13MSA1.13 Guided Walkthrough. The Identity Layer as a System
  14. 1.14Module Summary
  15. 1.15Check My Knowledge

Phase 2: Protection Stack

Module 6Endpoint Security Architecture

Design device trust as an architectural pillar, compliance policies that evaluate real security properties across four platforms, configuration baselines that prevent drift, custom compliance scripts for settings built-in rules can't check, BYOD strategy with app protection, MDE as a real-time risk signal, ASR rules promoted from audit to block, automated response boundaries, endpoint privilege management, and Autopilot provisioning that delivers compliant devices from the first sign-in.

Show 16 lessonsHide lessons
  1. 6.1MSA6.1 Endpoint Trust as an Architectural Pillar
  2. 6.2MSA6.2 Windows Compliance Policy Design
  3. 6.3MSA6.3 iOS, macOS, and Android Compliance
  4. 6.4MSA6.4 The Compliance Tier Model
  5. 6.5MSA6.5 Configuration Baseline Design
  6. 6.6MSA6.6 Configuration Drift and Baseline Lifecycle
  7. 6.7MSA6.7 App Protection Without Device Enrollment
  8. 6.8MSA6.8 MDE as the Risk Signal
  9. 6.9MSA6.9 Attack Surface Reduction Architecture
  10. 6.10MSA6.10 Automated Investigation and Endpoint Privilege Management
  11. 6.11MSA6.11 Autopilot and Device Lifecycle
  12. 6.12MSA6.12 Your Endpoint Architecture
  13. 6.13MSA6 Module Lab. Endpoint Security Deployment
  14. 6.14MSA6 Guided Walkthrough. Connecting the Endpoint Architecture
  15. 6.15Module Summary
  16. 6.16Check My Knowledge

Phase 3: Detection & Response

Phase 4: Governance & Capstone

Module 14Capstone: The Complete Architecture

Assemble, defend, threat-model, and present the complete M365 security architecture built across Modules 0–13, producing the portfolio-grade deliverable that survives your departure.

Show 6 lessonsHide lessons
  1. 14.1MSA14.1 Architecture Package Assembly
  2. 14.2MSA14.2 Architecture Review Simulation
  3. 14.3MSA14.3 Threat Model Walkthrough
  4. 14.4MSA14.4 Executive Presentation
  5. 14.5MSA14.5 What Changes Next Quarter
  6. 14.6Module Summary

Phase 0: Course Resources

ResourcesCookbooks

Ordered procedures for the architecture work that recurs: deploying a policy without an outage, reducing standing privilege, assessing a tenant, and retiring a control.

Show 7 lessonsHide lessons
  1. 1Deploying a Conditional Access Policy
  2. 2Reducing Standing Privilege
  3. 3Assessing an Unfamiliar Tenant
  4. 4Retiring a Control
  5. 5Onboarding an Acquired Tenant
  6. 6Verifying Emergency Access
  7. 7Reviewing a Proposed Design
ResourcesLab Setup

Building a tenant where you can deploy architecture, break it, and see what the controls actually do, without touching anything anyone depends on.

Show 5 lessonsHide lessons
  1. 1The Tenant and What It Costs
  2. 2Building a Population Worth Testing
  3. 3Deploying the First Controls
  4. 4Breaking It on Purpose
  5. 5Verify, and What the Lab Cannot Teach
ResourcesWalkthroughs

Architecture decisions worked end to end, including the ones where the correct answer was to deploy nothing and the ones where the design was right and still failed.

Show 6 lessonsHide lessons
  1. 1The Control That Was Already There
  2. 2The Privilege That Was Not a Role
  3. 3The Design That Should Not Ship
  4. 4The Question the Tenant Cannot Answer
  5. 5The Tenant Nobody Documented
  6. 6The Saving That Would Have Cost More
ResourcesPlaybooks

What to do when a decision is forced on you: a merger, an audit finding, a regulator, a breach elsewhere, a budget cut, or a product retirement.

Show 7 lessonsHide lessons
  1. 1A Merger Adds a Tenant
  2. 2An Audit Finding Lands
  3. 3A Regulator Changes the Requirement
  4. 4A Breach Elsewhere Forces a Review
  5. 5The Budget Is Cut
  6. 6A Product You Depend On Is Retired
  7. 7A Control You Deployed Causes an Outage
ResourcesPlayground

Every practice surface available for this course, what each one actually gives you, and where the gaps are.

ResourcesReferences & Further Reading

Microsoft documentation, security frameworks, compliance standards, threat intelligence, and vendor references used throughout the MSA course.

Course Completion

CompletionCourse Exam

Microsoft 365 Security Architecture end-of-course exam: a three-phase simulation testing whether you can apply the method to a situation the course did not walk through.

Show 1 lessonHide lessons
  1. 1Course Completion. Microsoft 365 Security Architecture

Course overview

The Microsoft 365 Security Architecture course is built specifically for Security Architects, Engineers, and Administrators who design, justify, implement, and defend M365 security posture. You'll gain hands-on expertise to:

✓ Architect and implement a complete Zero Trust security framework across the entire Microsoft 365 stack
✓ Deploy and optimize Microsoft Defender XDR, Entra ID Conditional Access, Intune, Purview, and Microsoft Sentinel for maximum protection
✓ Justify security investments with clear risk reduction metrics and executive-ready documentation
✓ Design secure configurations for identities, endpoints, applications, data, and compliance controls

By the end, you'll have the strategic and technical mastery to own your organization's Microsoft 365 security architecture, confidently defending it against modern threats while aligning security outcomes with business goals.

How this course works

Architecture is the discipline of making decisions that later decisions depend on. This course runs the same loop for every layer it designs, and the layers are deliberately in dependency order.

1. Decide, and write down why. An architecture is a set of decisions with reasons attached. Without the reason, the next person reverses it and nobody knows what broke.

2. Design against the attack, not the feature list. Each layer is built from what it has to stop rather than from what the product can do.

3. Check the layer against the one beneath it. Conditional Access rests on authentication methods, detection rests on workspace design, and a strong layer on a weak one is a weak layer.

4. Make the failure mode explicit. Every control blocks somebody, every log has a retention, every design has a cost. An architecture that hides these gets overruled in an incident.

5. Produce something that outlives you. Decision records, not diagrams. The diagram shows the state; the record explains why it is that state.

The capstone assembles the complete architecture from every layer designed along the way.

What this course assumes

No minimum experience and no prerequisite course. Each service is introduced from what it does architecturally rather than from how it is administered.

What makes it go faster: an estate you are responsible for, because every design decision in the course has a real counterpart in it. Not required.

What this course does not cover: hands-on administration of each service, incident response process and forensics. This course decides what should exist; the operational courses run it.

Who this course is for

You're a Security Architect, Security Engineer, or Microsoft 365 Administrator responsible for designing, justifying, implementing, and defending your organization's Microsoft 365 security posture. This course is built for you if you want to:

✓ Move from tactical configuration to strategic, enterprise-grade security architecture
✓ Master the integration of Defender XDR, Entra ID, Intune, Purview, and Sentinel into a cohesive Zero Trust model
✓ Gain the confidence to justify security investments and defend your architecture to executives and auditors
✓ Build resilient controls that protect identities, endpoints, applications, and sensitive data at scale

In short: if you're ready to own and defend a modern Microsoft 365 security architecture that actually works against today's threats, this course is for you.

What you'll learn

By the end of this Microsoft 365 Security Architecture course you will be able to:

✓ Architect and implement a complete Zero Trust security framework across Microsoft 365 and hybrid environments
✓ Design and optimize Conditional Access policies, Privileged Identity Management, and device compliance strategies
✓ Deploy and tune Microsoft Defender XDR, Defender for Cloud Apps, and Microsoft Sentinel for unified threat detection and response
✓ Implement data loss prevention (DLP), information protection, and Purview compliance solutions
✓ Secure identities, endpoints, applications, and data with integrated Microsoft security controls
✓ Measure, report, and continuously improve your M365 security posture with meaningful metrics

Key course takeaways

✓ Build and defend a production-grade Zero Trust Microsoft 365 security architecture organizations can rely on
✓ Integrate Microsoft Defender XDR, Entra ID, Intune, Purview, and Sentinel into a cohesive, layered defense
✓ Confidently justify and present security architecture decisions to technical and executive stakeholders
✓ Proactively reduce risk by eliminating common attack paths targeting identities, endpoints, and data
✓ Operationalize automated security controls, compliance workflows, and continuous posture improvement
✓ Become the go-to Microsoft 365 Security Architect who transforms security from a cost center into a strategic business enabler

Things you need to know

What are the prerequisites for this course?

There are no prerequisites. The course teaches M365 security architecture from first principles. Familiarity with the Microsoft 365 admin center and Entra ID will help you move faster through the early modules, but neither is required. Every concept is explained at first use.

What are the device requirements?

A device with a modern browser. Access to a Microsoft 365 E5 tenant (a developer subscription if you qualify for one, otherwise a 30-day E5 trial) and an Azure subscription for Sentinel workspace deployment. The course walks you through tenant and workspace setup in Module 0.

How will the course benefit your career?

Security architecture is one of the most in-demand disciplines in cybersecurity. Organizations need people who can design integrated security systems across the M365 stack, not just configure individual products. This course gives you the skills to architect Zero Trust infrastructure, document decisions with ADRs, and present security investments to executives.

The demand for security architects who can bridge technical implementation and business justification continues to grow as organizations move from product-by-product configuration to integrated security architecture.

Usage rights and disclaimer

Course materials: Licensed for individual professional development. You may deploy configurations, detection rules, scripts, and policies in your production environment. You may not redistribute course content or share account credentials.

Architecture configurations: All PowerShell commands, Graph API queries, Conditional Access policies, PIM configurations, and Purview policies are provided as-is. Test every configuration in report-only or simulation mode before enforcement. Ridgeline Cyber Defence is not responsible for operational impact from deployed configurations.

Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
1scenario
Take End of Course Exam

One random scenario per attempt. Certificate issued on pass.