AZ-500 ↔ SC-100 Unified Study Guide — Strategy & Map
This is the vault hub. It defines the single learning strategy that covers both certifications at once, the order to study in, and how the three content tiers fit together. Every note in the vault is linked from here.
The sequencing principle
Interleave by shared concept, never by exam. Each unit teaches the AZ-500 operational/engineering skill first, then attaches the SC-100 architecture/design layer for the SAME concept as a small delta — so SC-100 is learned as a design extension of fresh hands-on knowledge rather than as a separate second pass.
The chain is dependency-ordered and ROI-weighted:
- Identity is front-loaded as the Zero Trust control plane and the universal prerequisite for every later unit.
- The chain then follows the natural exposure boundary: the network perimeter, then the workloads inside it (data/storage/Key Vault, then compute/containers).
- Next comes the high-weight posture/governance layer (Defender for Cloud — AZ-500’s 30–35% domain) that observes and governs those workloads.
- Then the SecOps/SIEM/XDR/SOAR telemetry layer that consumes signals from everything below.
- Finally, a single capstone fuses the SC-100-only application/M365 data-protection domain with the cross-cutting strategy synthesis (MCRA, CAF/WAF, Zero Trust/RaMP, landing zones, BCDR, DevSecOps) that integrates every prior unit.
SC-100 topics with no AZ-500 operational analog (Purview/Priva compliance, the M365 Defender suite, framework/strategy design) are distributed onto their nearest conceptual host rather than segregated into exam-sliced units — honoring interleave-by-concept. The one exception is the deliberately cross-cutting strategy layer, which is a legitimate synthesis concept of its own.
Total study time
≈ 68 hours, calibrated to interleaved review (Sentinel/Defender daily-driver familiarity) rather than from-scratch learning. The proposer spread was 62–75 hours; the midpoint of 68 is the recommendation.
The ordered unit map (AZ-500 ↔ SC-100 interleave + prereqs)
| # | Unit (note) | AZ-500 operates… | SC-100 designs/evaluates… | Prereqs |
|---|---|---|---|---|
| 1 | Unit 1 — Identity, Access & Privileged Access | RBAC, PIM, MFA, Conditional Access, app/service/managed identities, OAuth consent | Entra ID hybrid/multicloud, modern auth (CAE/risk/protected actions), external ID, enterprise access model, workload identities, CIEM, AD DS hardening | (none — front-loaded) |
| 2 | Unit 2 — Secure Networking & Edge Protection | NSG/ASG, UDR, VNet peering/VPN/vWAN, Firewall, Private Link/Endpoints, App Gateway, Front Door, WAF, DDoS | Network-design evaluation; Entra Internet Access (SWG) + Entra Private Access (SSE) | Unit 1 |
| 3 | Unit 3 — Data, Storage & Key Management | Storage access/SAS, soft-delete/immutable WORM, BYOK/CMK, TDE, Always Encrypted, DDM, Key Vault RBAC/rotation/backup | Secrets/keys/certs strategy, data discovery/classification, at-rest/in-transit encryption design, SQL/Synapse/Cosmos/Storage data security, Defender for Storage & Databases | Unit 1 |
| 4 | Unit 4 — Secure Compute, Containers & Endpoint Baselines | Bastion/JIT, disk encryption (ADE/host/confidential), AKS isolation+auth, ACI/ACA monitoring, ACR access | Server/endpoint/IoT/OT/container baselines, Windows LAPS, Defender for IoT (OT/ICS), Azure AI services security | Units 1, 2, 3 |
| 5 | Unit 5 — Posture, Governance, Multicloud & Compliance | Azure Policy, backup/asset controls, Defender for Cloud Secure Score/CSPM/CWPP, Defender for Servers/DVM/agentless, EASM, multicloud connectors, DevOps Security | Posture mgmt (MCSB, Exposure Mgmt attack paths), Arc hybrid/multicloud, EASM design, Azure Policy design, regulatory compliance, Purview & Priva | Units 2, 3, 4 |
| 6 | Unit 6 — Security Operations: Sentinel, Defender XDR, SOAR | DCRs, Sentinel connectors/analytics rules/automation, Defender for Cloud alert ops + workflow automation | XDR+SIEM detection/response, centralized logging (Purview Audit), hybrid/multicloud monitoring, SOAR, IR/hunting/incident-mgmt workflows, MITRE ATT&CK coverage | Unit 5 |
| 7 | Unit 7 — Capstone: Apps, M365 Data Protection & Strategy | APIM security configuration (the lone AZ-500 hook) | App-lifecycle/threat-modeling/WAF, API security design, M365 stack (Defender O365/MDCA/Intune/Purview/Copilot), MCRA/MCSB, CAF/WAF, Zero Trust/RaMP, landing zones, BCDR/ransomware, DevSecOps | Units 1–6 |
How to use this guide — the three tiers + Appendix
Every unit is written in three progressive tiers. Read them in order on a first pass; on later passes, drop down to the tier that matches your time and confidence.
Tier 1 — Cheat Sheet (-Cheat)
Dense, table-heavy, exam-trap-focused last-mile review. Memorize-the-distinctions material: the two RBAC systems, PIM license/assignment shapes, the four disk-encryption options, analytics-rule types, framework deltas. Use the cheat sheet the day before the exam and for spaced repetition. It assumes you already understand the why.
Tier 2 — High-ROI (-High-ROI)
The understand-once-pass-both layer. Each unit’s 5–6 highest-weight concepts are taught with a worked scenario, then an explicit AZ-500 (operate) vs SC-100 (design) split. This is the tier that does the heavy lifting: master it and you answer the bulk of both exams. Start here if you have limited time and conceptual gaps.
Tier 3 — Full Guide (-Full)
Complete, fact-checked coverage of every objective in the unit, end to end, with the operate↔architect throughline made explicit in a closing table. Read this for surfaces you’re weak on or that map to unfamiliar day-job areas. Where a concept belongs to another unit, it is referenced by Wikilink, not re-taught — so the Full guides compose without duplication.
The Appendix
The Appendix — Cross-Reference & Exam Index is the connective tissue: the AZ-500↔SC-100 objective-to-unit index, the consolidated exam-trap/gotcha list, the currency-drift alerts (CIEM moved to Defender for Cloud; MMA retired; ADE retiring 2028; Azure-portal Sentinel retiring 2027), and the cross-unit concept map. Use it to confirm full objective coverage and to find which unit hosts any given objective.
All notes in this vault
Hub
- 00-Strategy-and-Map (this note)
Unit 1 — Identity, Access & Privileged Access
- Unit 1 — Identity, Access & Privileged Access — Cheat
- Unit 1 — Identity, Access & Privileged Access — High-ROI
- Unit 1 — Identity, Access & Privileged Access — Full
Unit 2 — Secure Networking & Edge Protection
- Unit 2 — Secure Networking & Edge Protection — Cheat
- Unit 2 — Secure Networking & Edge Protection — High-ROI
- Unit 2 — Secure Networking & Edge Protection — Full
Unit 3 — Data, Storage & Key Management
- Unit 3 — Data, Storage & Key Management — Cheat
- Unit 3 — Data, Storage & Key Management — High-ROI
- Unit 3 — Data, Storage & Key Management — Full
Unit 4 — Secure Compute, Containers & Endpoint Baselines
- Unit 4 — Secure Compute, Containers & Endpoint Baselines — Cheat
- Unit 4 — Secure Compute, Containers & Endpoint Baselines — High-ROI
- Unit 4 — Secure Compute, Containers & Endpoint Baselines — Full
Unit 5 — Posture, Governance, Multicloud & Compliance
- Unit 5 — Posture, Governance, Multicloud & Compliance — Cheat
- Unit 5 — Posture, Governance, Multicloud & Compliance — High-ROI
- Unit 5 — Posture, Governance, Multicloud & Compliance — Full
Unit 6 — Security Operations: Sentinel, Defender XDR, SOAR
- Unit 6 — Security Operations — Cheat
- Unit 6 — Security Operations — High-ROI
- Unit 6 — Security Operations — Full
Unit 7 — Capstone: Apps, M365 Data Protection & Strategy
- Unit 7 — Capstone — Cheat
- Unit 7 — Capstone — High-ROI
- Unit 7 — Capstone — Full
Appendix
Documented dissent (alternative pacings)
The 7-unit skeleton is high-confidence majority consensus, but a few boundaries have defensible alternatives:
- Identity granularity — could be split into foundations (RBAC/MFA) vs privileged-access/Zero-Trust (PIM/CA/enterprise access model) for finer pacing without breaking dependency order.
- Key Vault placement — folded into Unit 3 (Data) here; a learner could isolate a standalone “crypto core” reused by storage/disk/database. Residual coupling: disk encryption lives in Unit 4 but Key Vault/CMK is taught in Unit 3, so Unit 4 lightly back-references it.
- Posture sequencing — placed after the workloads it governs (Unit 5). A design-first learner could front-load framework theory, but hands-on posture remediation still needs the workloads to exist.
- Capstone size — Unit 7 is the heaviest (~14h of SC-100 design). A learner may prefer to split it into “apps/M365 data” and “strategy synthesis” for a cleaner 8-unit plan.
- Defender for Servers / EASM — kept in Unit 5 (posture) with all Defender for Cloud plan enablement, so compute hardening (Unit 4) and its matching Defender-for-Servers protection are taught one unit apart.