Design solutions that align with security best practices and priorities
MCRA, MCSB, and Zero Trust
CoreUse Microsoft reference architectures, benchmark controls, and the Zero Trust adoption framework to turn threat priorities into a coherent capability roadmap, including AI workloads.
Aligned to SC-100 skills measured as of October 21, 2026; candidates testing earlier should review the transition note in the lane overview.
Why this matters
Frameworks solve different layers of the architecture problem. MCRA connects enterprise security capabilities, MCSB defines control outcomes, and the Zero Trust adoption framework sequences organizational change across technology pillars.
Must Know
- MCRA is a reference view of integrated security capabilities and responsibilities; it is not a deployable product or a substitute for organization-specific requirements.
- MCSB organizes prescriptive control guidance across areas such as network, identity, data, asset management, logging, incident response, and posture governance.
- Supply-chain architecture must address provenance, build and release integrity, dependency risk, supplier access, monitoring, and response rather than relying only on contract language.
- AI solutions inherit familiar control objectives but add model, prompt, grounding-data, agent-tool, content-safety, and evaluation boundaries that need explicit ownership.
- Zero Trust adoption is an outcome-driven transformation using verify explicitly, least privilege, and assume breach across identities, endpoints, networks, applications, infrastructure, and data.
Compare and Distinguish
- MCRA helps organize capabilities and integration; MCSB supplies control guidance; Zero Trust adoption plans the maturity journey and accountability.
- An architecture diagram shows relationships, while a benchmark assessment provides evidence of implemented control outcomes.
Scenario examples
- Scenario: A board wants a three-year security modernization roadmap across existing tools. Think: use MCRA for capability gaps and Zero Trust adoption milestones, then validate controls with MCSB-aligned evidence.
- Scenario: A team adds a grounded assistant to a regulated workflow. Think: extend benchmark controls to identity, network, data, logging, supply chain, and AI-specific content and tool boundaries.
Exam traps
- Selecting every control at once creates a catalog, not an adoption strategy tied to business risk and dependency order.
- Treating a generative AI endpoint like an ordinary stateless API misses grounding-data exposure, prompt abuse, and agent action risk.
Key takeaways
- MCRA shows how capabilities fit; MCSB states the outcomes controls must achieve.
- Zero Trust adoption turns the target state into sequenced, owned change.
- AI keeps the enterprise baseline and adds model, grounding, and tool boundaries.
How it works
- MCRA frames the target security system; benchmark controls define expected safeguards; adoption milestones move the organization toward the target.
- Evidence loops from implementation and operations back to architecture governance, allowing risk owners to adjust priorities.
Objects and administrative surfaces
- MCRA views, MCSB control domains, Zero Trust pillars, maturity targets, capability owners, and architecture decision records.
- AI asset inventory, grounding stores, model endpoints, agent tools, prompt filters, evaluations, and monitoring signals.
When to use it
- Use the combined model when an organization needs both a target architecture and a governed path from its current state.
Security and governance implications
- Assign control owners, evidence owners, risk acceptors, and architecture authorities so framework mappings lead to accountable decisions.
Troubleshooting signals
- If framework work produces duplicate tools, return to capability outcomes and integration boundaries before making product choices.
- If AI controls stop at content filtering, examine identity, grounding data, tool authorization, logging, and supply-chain exposure.
More detail
- Map capability gaps to threats against priority business assets.
- Apply MCSB-aligned requirements to conventional and AI solution components.
- Sequence Zero Trust outcomes with accountable owners and measurable evidence.
Ready for the quiz?
- When does MCRA add value beyond an MCSB assessment?
- Which AI boundaries require controls in addition to the model endpoint?
- How does a Zero Trust roadmap prove progress rather than list products?
Related objectives
- D1.2.S1 — Design solutions that align with best practices for cybersecurity capabilities and controls
- D1.2.S2 — Design solutions that align with best practices for protecting against insider, external, and supply chain attacks
- D1.2.S3 — Design AI solutions that align to the Microsoft Cloud Security Benchmark.
- D1.2.S4 — Design solutions that align with the Zero Trust adoption framework