Protego field desk
Security Best Practices and Priorities / 20-25% of exam

L2.MCRA, MCSB & Zero Trust Architecture

Course outlineLesson 2 of 18

Use Microsoft reference architectures and benchmarks as decision frameworks, then turn Zero Trust principles into enforceable identity, device, network, application, data, and AI controls.

Use frameworks for different jobs

The Microsoft Cybersecurity Reference Architectures show how security capabilities relate across an enterprise. The Microsoft Cloud Security Benchmark provides control guidance for cloud services. Zero Trust supplies the operating principles: verify explicitly, use least privilege, and assume breach.

Do not treat any framework as a product checklist. Start with the target business capability, map trust boundaries and attack paths, then use the frameworks to test whether the proposed controls cover the design.

Design by control objective

ObjectiveExample design evidence
Verify explicitlyIdentity, device, risk, and session signals
Least privilegeScoped roles, PIM, access reviews, workload identity
Assume breachSegmentation, detection, recovery, protected administration
Govern consistentlyPolicy-as-code and measurable control ownership

Cover insider, external, and supply-chain attacks

External attackers, insiders, and compromised suppliers cross different entry points but often converge on identity and data. Layer preventive controls with detection and recovery. For supply chains, include source integrity, dependency governance, artifact signing, deployment authorization, and vendor access boundaries.

Include AI workloads

Apply the same control objectives to AI services: managed identities, private connectivity where required, data classification, model and prompt protections, logging, human approval for high-impact actions, and monitoring for unsafe output or data exposure.

Exam Focus Points
  • MCRA shows capability relationships; MCSB provides cloud security control guidance
  • Zero Trust means verify explicitly, use least privilege, and assume breach
  • Translate frameworks into evidence and ownership instead of copying a checklist
  • AI solutions still require identity, data, network, logging, and governance controls
Knowledge Check

1. What is the best way to use MCRA and MCSB when evaluating a proposed architecture?