hub

AZ-500 ↔ SC-100 Unified Study Guide — Strategy & Map

This is the vault hub. It defines the single learning strategy that covers both certifications at once, the order to study in, and how the three content tiers fit together. Every note in the vault is linked from here.


The sequencing principle

Interleave by shared concept, never by exam. Each unit teaches the AZ-500 operational/engineering skill first, then attaches the SC-100 architecture/design layer for the SAME concept as a small delta — so SC-100 is learned as a design extension of fresh hands-on knowledge rather than as a separate second pass.

The chain is dependency-ordered and ROI-weighted:

  1. Identity is front-loaded as the Zero Trust control plane and the universal prerequisite for every later unit.
  2. The chain then follows the natural exposure boundary: the network perimeter, then the workloads inside it (data/storage/Key Vault, then compute/containers).
  3. Next comes the high-weight posture/governance layer (Defender for Cloud — AZ-500’s 30–35% domain) that observes and governs those workloads.
  4. Then the SecOps/SIEM/XDR/SOAR telemetry layer that consumes signals from everything below.
  5. Finally, a single capstone fuses the SC-100-only application/M365 data-protection domain with the cross-cutting strategy synthesis (MCRA, CAF/WAF, Zero Trust/RaMP, landing zones, BCDR, DevSecOps) that integrates every prior unit.

SC-100 topics with no AZ-500 operational analog (Purview/Priva compliance, the M365 Defender suite, framework/strategy design) are distributed onto their nearest conceptual host rather than segregated into exam-sliced units — honoring interleave-by-concept. The one exception is the deliberately cross-cutting strategy layer, which is a legitimate synthesis concept of its own.


Total study time

≈ 68 hours, calibrated to interleaved review (Sentinel/Defender daily-driver familiarity) rather than from-scratch learning. The proposer spread was 62–75 hours; the midpoint of 68 is the recommendation.


The ordered unit map (AZ-500 ↔ SC-100 interleave + prereqs)

#Unit (note)AZ-500 operates…SC-100 designs/evaluates…Prereqs
1Unit 1 — Identity, Access & Privileged AccessRBAC, PIM, MFA, Conditional Access, app/service/managed identities, OAuth consentEntra ID hybrid/multicloud, modern auth (CAE/risk/protected actions), external ID, enterprise access model, workload identities, CIEM, AD DS hardening(none — front-loaded)
2Unit 2 — Secure Networking & Edge ProtectionNSG/ASG, UDR, VNet peering/VPN/vWAN, Firewall, Private Link/Endpoints, App Gateway, Front Door, WAF, DDoSNetwork-design evaluation; Entra Internet Access (SWG) + Entra Private Access (SSE)Unit 1
3Unit 3 — Data, Storage & Key ManagementStorage access/SAS, soft-delete/immutable WORM, BYOK/CMK, TDE, Always Encrypted, DDM, Key Vault RBAC/rotation/backupSecrets/keys/certs strategy, data discovery/classification, at-rest/in-transit encryption design, SQL/Synapse/Cosmos/Storage data security, Defender for Storage & DatabasesUnit 1
4Unit 4 — Secure Compute, Containers & Endpoint BaselinesBastion/JIT, disk encryption (ADE/host/confidential), AKS isolation+auth, ACI/ACA monitoring, ACR accessServer/endpoint/IoT/OT/container baselines, Windows LAPS, Defender for IoT (OT/ICS), Azure AI services securityUnits 1, 2, 3
5Unit 5 — Posture, Governance, Multicloud & ComplianceAzure Policy, backup/asset controls, Defender for Cloud Secure Score/CSPM/CWPP, Defender for Servers/DVM/agentless, EASM, multicloud connectors, DevOps SecurityPosture mgmt (MCSB, Exposure Mgmt attack paths), Arc hybrid/multicloud, EASM design, Azure Policy design, regulatory compliance, Purview & PrivaUnits 2, 3, 4
6Unit 6 — Security Operations: Sentinel, Defender XDR, SOARDCRs, Sentinel connectors/analytics rules/automation, Defender for Cloud alert ops + workflow automationXDR+SIEM detection/response, centralized logging (Purview Audit), hybrid/multicloud monitoring, SOAR, IR/hunting/incident-mgmt workflows, MITRE ATT&CK coverageUnit 5
7Unit 7 — Capstone: Apps, M365 Data Protection & StrategyAPIM security configuration (the lone AZ-500 hook)App-lifecycle/threat-modeling/WAF, API security design, M365 stack (Defender O365/MDCA/Intune/Purview/Copilot), MCRA/MCSB, CAF/WAF, Zero Trust/RaMP, landing zones, BCDR/ransomware, DevSecOpsUnits 1–6

How to use this guide — the three tiers + Appendix

Every unit is written in three progressive tiers. Read them in order on a first pass; on later passes, drop down to the tier that matches your time and confidence.

Tier 1 — Cheat Sheet (-Cheat)

Dense, table-heavy, exam-trap-focused last-mile review. Memorize-the-distinctions material: the two RBAC systems, PIM license/assignment shapes, the four disk-encryption options, analytics-rule types, framework deltas. Use the cheat sheet the day before the exam and for spaced repetition. It assumes you already understand the why.

Tier 2 — High-ROI (-High-ROI)

The understand-once-pass-both layer. Each unit’s 5–6 highest-weight concepts are taught with a worked scenario, then an explicit AZ-500 (operate) vs SC-100 (design) split. This is the tier that does the heavy lifting: master it and you answer the bulk of both exams. Start here if you have limited time and conceptual gaps.

Tier 3 — Full Guide (-Full)

Complete, fact-checked coverage of every objective in the unit, end to end, with the operate↔architect throughline made explicit in a closing table. Read this for surfaces you’re weak on or that map to unfamiliar day-job areas. Where a concept belongs to another unit, it is referenced by Wikilink, not re-taught — so the Full guides compose without duplication.

The Appendix

The Appendix — Cross-Reference & Exam Index is the connective tissue: the AZ-500↔SC-100 objective-to-unit index, the consolidated exam-trap/gotcha list, the currency-drift alerts (CIEM moved to Defender for Cloud; MMA retired; ADE retiring 2028; Azure-portal Sentinel retiring 2027), and the cross-unit concept map. Use it to confirm full objective coverage and to find which unit hosts any given objective.


All notes in this vault

Hub

Unit 1 — Identity, Access & Privileged Access

  • Unit 1 — Identity, Access & Privileged Access — Cheat
  • Unit 1 — Identity, Access & Privileged Access — High-ROI
  • Unit 1 — Identity, Access & Privileged Access — Full

Unit 2 — Secure Networking & Edge Protection

  • Unit 2 — Secure Networking & Edge Protection — Cheat
  • Unit 2 — Secure Networking & Edge Protection — High-ROI
  • Unit 2 — Secure Networking & Edge Protection — Full

Unit 3 — Data, Storage & Key Management

Unit 4 — Secure Compute, Containers & Endpoint Baselines

Unit 5 — Posture, Governance, Multicloud & Compliance

Unit 6 — Security Operations: Sentinel, Defender XDR, SOAR

  • Unit 6 — Security Operations — Cheat
  • Unit 6 — Security Operations — High-ROI
  • Unit 6 — Security Operations — Full

Unit 7 — Capstone: Apps, M365 Data Protection & Strategy

  • Unit 7 — Capstone — Cheat
  • Unit 7 — Capstone — High-ROI
  • Unit 7 — Capstone — Full

Appendix


Documented dissent (alternative pacings)

The 7-unit skeleton is high-confidence majority consensus, but a few boundaries have defensible alternatives:

  • Identity granularity — could be split into foundations (RBAC/MFA) vs privileged-access/Zero-Trust (PIM/CA/enterprise access model) for finer pacing without breaking dependency order.
  • Key Vault placement — folded into Unit 3 (Data) here; a learner could isolate a standalone “crypto core” reused by storage/disk/database. Residual coupling: disk encryption lives in Unit 4 but Key Vault/CMK is taught in Unit 3, so Unit 4 lightly back-references it.
  • Posture sequencing — placed after the workloads it governs (Unit 5). A design-first learner could front-load framework theory, but hands-on posture remediation still needs the workloads to exist.
  • Capstone size — Unit 7 is the heaviest (~14h of SC-100 design). A learner may prefer to split it into “apps/M365 data” and “strategy synthesis” for a cleaner 8-unit plan.
  • Defender for Servers / EASM — kept in Unit 5 (posture) with all Defender for Cloud plan enablement, so compute hardening (Unit 4) and its matching Defender-for-Servers protection are taught one unit apart.