AdvancedSC-100-001

SC-100 Microsoft Cybersecurity Architect Expert

Design enterprise security architectures aligned to Zero Trust, Essential Eight and the ACSC ISM

The SC-100 is the capstone Microsoft security certification — the only Expert-level exam in the security track. This programme prepares security architects to design Zero Trust access models, govern multi-cloud security postures, evaluate GRC strategies, and advise executive stakeholders. Every design scenario is grounded in Australian context: ASD Essential Eight, ACSC Information Security Manual, Privacy Act 1988, and APRA CPS 234 for regulated entities.

40 hours (5 days intensive or 10 weeks part-time)
New course
Certificate Included
SC-100 Microsoft Cybersecurity Architect Expert

At a Glance

Who it's for

  • Senior security architects designing enterprise-wide Zero Trust programmes
  • CISO-track engineers preparing for the SC-100 Expert certification
  • Security leads in regulated Australian industries (finance, healthcare, government)
  • Architects holding SC-200, SC-300 or SC-401 who want the capstone Expert credential

Course Details

Duration:40 hours (5 days intensive or 10 weeks part-time)
Format:Live online architecture workshop — 5 days intensive or 10 weeks part-time
Next intake:September 2026 — register your interest at educ4te.com
Alignment:Preparation for Microsoft Certified: Cybersecurity Architect Expert (Exam SC-100). Prerequisite: one of SC-200, SC-300, SC-401, or SC-500 Associate.

Course Overview

The SC-100 Microsoft Cybersecurity Architect Expert programme is the peak of the Microsoft security certification ladder. It moves beyond tool configuration into architectural thinking — how to design a security strategy that spans identity, data, applications, infrastructure, and operations across hybrid and multi-cloud environments. The curriculum maps directly to the four SC-100 domains: design Zero Trust strategy and architecture; evaluate Governance, Risk and Compliance (GRC) technical strategies; design security for infrastructure; and design security for data and applications. In the Australian context, every design scenario references the ASD Essential Eight, the ACSC Information Security Manual, APRA CPS 234 (for banking and insurance architects), and the Privacy Act 1988 obligations that shape data security architecture. The programme assumes holders of the SC-200, SC-300, SC-400, or SC-500 Associate certifications, building architectural depth on top of existing platform knowledge.

What You'll Learn

Design a Zero Trust strategy spanning identity, network, devices, applications, and data for enterprise-scale Australian organisations
Evaluate and recommend GRC technical strategies aligned to ACSC ISM, Essential Eight, and APRA CPS 234
Design a ransomware resilience architecture covering backup strategy, network segmentation, and incident response runbooks
Architect multi-cloud security posture management using Microsoft Defender for Cloud across Azure, AWS, and GCP
Design data security and privacy architectures aligned to Privacy Act 1988 and Australian Privacy Principles
Advise C-suite and board stakeholders on security investment trade-offs and residual risk acceptance
Pass the Microsoft SC-100 Expert-level exam with structured design scenario practice

Course Curriculum

Module 1: Zero Trust Strategy and Architecture Design

8 hours
  • Zero Trust principles and the Microsoft Zero Trust framework — identity, devices, network, applications, data, infrastructure
  • Designing a Zero Trust access model for a hybrid Australian enterprise
  • Evaluate identity providers, conditional access design, and continuous access evaluation
  • Network Zero Trust: micro-segmentation, Azure Firewall, Private Link, and SD-WAN considerations
  • Mapping Zero Trust controls to ASD Essential Eight Maturity Level 2 and 3 requirements

Module 2: Governance, Risk and Compliance Technical Strategy

8 hours
  • Evaluate regulatory compliance requirements for Australian entities: APRA CPS 234, Privacy Act 1988, Essential Eight
  • Design a Microsoft Purview compliance architecture for data residency, classification, and retention
  • Assess and recommend privacy-by-design controls for AI workloads using Microsoft Copilot
  • Build a risk acceptance framework and design residual risk treatment strategies
  • Translate GRC requirements into technical architecture decisions and security controls

Module 3: Security Architecture for Infrastructure

8 hours
  • Design server and container security posture using Defender for Servers and Defender for Containers
  • Architect privileged access workstations and tiered administration for Essential Eight compliance
  • Design storage, database, and backup security controls for ransomware resilience
  • Multi-cloud security posture management: Defender for Cloud, CSPM, and regulatory compliance workbooks
  • Network security design: DDoS protection, WAF, Azure Firewall Premium, and TLS inspection

Module 4: Security Architecture for Applications and Data

8 hours
  • Evaluate application security requirements and recommend SDL practices for cloud-native workloads
  • Design API security, OAuth 2.0 flows, and secret management using Azure Key Vault
  • Architect data classification and sensitivity labelling using Microsoft Purview Information Protection
  • Design Microsoft Defender for Cloud Apps policies for SaaS data governance
  • Privacy Act 1988 breach notification architecture: detection, assessment, and OAIC reporting workflows

Module 5: Security Operations Architecture and Incident Response

8 hours
  • Design a Microsoft Sentinel SIEM architecture for Australian organisations: connectors, analytics, SOAR playbooks
  • Architect a threat intelligence integration using Microsoft Defender Threat Intelligence
  • Design incident response runbooks for ransomware, BEC, and identity compromise scenarios
  • Build a security operations metrics framework: MTTD, MTTR, and Essential Eight maturity reporting
  • SC-100 exam preparation: architecture case studies, design scenario walkthroughs, and mock exam

Who Should Attend

  • Senior security architects owning enterprise Zero Trust and multi-cloud security strategy
  • Lead security engineers moving from platform implementation into architecture and design
  • CISO-track practitioners who need to defend investment decisions to boards and audit committees
  • Security leads in APRA-regulated banking, insurance and superannuation entities working to CPS 234
  • Commonwealth and state government security architects working within the ACSC Information Security Manual
  • Consultants and IRAP-adjacent assessors designing Microsoft security architectures for Australian clients

Prerequisites

Before enrolling, please ensure you meet these requirements:

  • • A current Microsoft Security Associate certification — SC-200, SC-300, SC-401 or SC-500
  • • Three or more years of hands-on security architecture, engineering or consulting experience
  • • Practical working knowledge of Microsoft Defender XDR, Microsoft Entra ID and Microsoft Purview
  • • Familiarity with at least one non-Azure cloud platform (AWS or GCP) for the multi-cloud posture module
  • • Microsoft 365 E5 or Azure subscription with Owner access for the design lab exercises

Delivery, Format and Logistics

Delivery Mode

Live online architecture workshop — 5 days intensive or 10 weeks part-time

Maximum 10 participants — architecture design workshops with whiteboard sessions

What You'll Need

  • Holder of at least one Microsoft Security Associate certification (SC-200, SC-300, SC-401, or SC-500)
  • Three or more years of hands-on security architecture or engineering experience
  • Microsoft 365 E5 or Azure subscription with Owner access for design lab exercises
  • Working knowledge of Microsoft Defender XDR, Entra ID, and Purview

What You'll Receive

  • 40 hours of instructor-led design workshops with whiteboard sessions
  • Five end-to-end architecture case studies drawn from Australian enterprise and government scenarios
  • Zero Trust reference architecture templates and design decision records you keep
  • GRC mapping workbook covering ACSC ISM, Essential Eight, APRA CPS 234 and Privacy Act 1988
  • Microsoft Defender for Cloud multi-cloud posture lab across Azure, AWS and GCP
  • Timed SC-100 mock exam with design scenario walkthroughs and answer rationale
  • Recorded sessions and course materials for 12 months
  • Certificate of completion and post-course architecture review clinic

Frequently Asked Questions

Not Ready to Enrol?

Join our mailing list to receive updates about courses, resources, and cybersecurity insights tailored for Australian organisations.

By subscribing, you agree to receive email updates from Educ4te. You can unsubscribe at any time. We respect your privacy and will never share your information.

$1599AUD
$1999EARLY BIRD

Early-bird rate — apply your promo code at checkout.

1

Secure payment via Stripe · Promo codes accepted

Next Intake

September 2026 — register your interest at educ4te.com

Format

Live online architecture workshop — 5 days intensive or 10 weeks part-time

Group & Enterprise Options

Discounted rates available for teams of 3+ delegates. Contact us for in-house delivery options.

What's Included

  • 40 hours of instructor-led design workshops with whiteboard sessions
  • Five end-to-end architecture case studies drawn from Australian enterprise and government scenarios
  • Zero Trust reference architecture templates and design decision records you keep
  • GRC mapping workbook covering ACSC ISM, Essential Eight, APRA CPS 234 and Privacy Act 1988
  • Microsoft Defender for Cloud multi-cloud posture lab across Azure, AWS and GCP
  • Timed SC-100 mock exam with design scenario walkthroughs and answer rationale
  • Recorded sessions and course materials for 12 months
  • Certificate of completion and post-course architecture review clinic

Have questions about this course?