Design security operations, identity, and compliance capabilities
Regulatory Compliance Architecture
CoreTranslate obligations into scoped controls, policy enforcement, data-governance workflows, posture evidence, ownership, and defensible exceptions across cloud and productivity estates.
Aligned to SC-100 skills measured as of October 21, 2026; candidates testing earlier should review the transition note in the lane overview.
Why this matters
Compliance becomes architectural only when prose obligations are connected to assets, owners, enforceable controls, monitored evidence, and remediation. A dashboard percentage without scope and evidence quality cannot demonstrate that outcome.
Must Know
- Translate each requirement into a control objective, applicable scope, implementation owner, evidence source, test method, review cadence, and risk-acceptance path.
- Microsoft Purview supports information protection, data lifecycle, records, audit, eDiscovery, communication compliance, insider risk, and Compliance Manager scenarios with distinct purposes.
- Azure Policy evaluates resource state and can deny, modify, deploy, or audit according to definition effects; initiatives group definitions into governed assignments.
- Defender for Cloud regulatory-compliance views assess resources against standards and recommendations, but organizations remain responsible for scoping and control interpretation.
- Compensating controls must address the same risk outcome, retain approval and evidence, and expire or be reevaluated rather than becoming permanent informal exceptions.
Compare and Distinguish
- Azure Policy enforces or assesses Azure resource configuration; Purview governs data and compliance workflows; Defender for Cloud aggregates cloud posture and regulatory assessment evidence.
- A control implementation changes or monitors the environment, while an attestation records a human claim that still requires appropriate evidence.
Scenario examples
- Scenario: A regulation requires encryption and access review for a defined data class. Think: map scope and control outcomes, enforce resource settings with policy, govern data with Purview, and retain test evidence.
- Scenario: A legacy workload cannot meet one benchmark recommendation. Think: document applicability, approve an equivalent compensating control, monitor it, and set an expiration rather than suppressing the finding silently.
Exam traps
- A built-in initiative does not determine whether every control applies to the organization's legal and technical scope.
- Suppressing a recommendation removes visibility but does not implement a compensating safeguard.
Key takeaways
- Start with applicability and asset scope before selecting a dashboard or policy effect.
- Preventive policy, data governance, and posture assessment supply different kinds of evidence.
- A compensating control must be equivalent, monitored, owned, and time-bound.
How it works
- Policy assignments continuously compare resources with definitions and can trigger effects, while remediation brings supported existing resources toward the target state.
- Compliance programs collect technical and procedural evidence, test control operation, track deficiencies, and route risk decisions.
Objects and administrative surfaces
- Requirement registers, control catalogs, policy definitions and initiatives, assignments, exemptions, remediation tasks, and evidence repositories.
- Purview solutions, Compliance Manager assessments, Defender for Cloud standards, recommendation ownership, and risk acceptances.
When to use it
- Use a unified compliance architecture when multiple frameworks must share controls without losing requirement-level traceability.
Security and governance implications
- Legal and risk teams determine applicability; control owners implement safeguards; evidence owners prove operation; accountable executives accept residual risk.
Troubleshooting signals
- If compliance percentages conflict, verify scope, standard version, exemptions, resource inventory, and evidence freshness.
- If policies create outages, review effects, parameters, assignment scope, exclusions, staged rollout, and remediation sequencing.
More detail
- Decompose obligations into testable security and data controls.
- Design Purview capabilities according to the required compliance outcome.
- Use Azure Policy and Defender for Cloud for enforcement and posture evidence without conflating them.
Ready for the quiz?
- Which artifact proves a legal requirement is implemented and operating?
- When should Azure Policy use deny instead of audit?
- What makes a compensating control defensible?
Related objectives
- D2.4.S1 — Translate compliance requirements into security controls
- D2.4.S2 — Design a solution to address compliance requirements by using Microsoft Purview
- D2.4.S3 — Design Azure Policy solutions to address security and compliance requirements
- D2.4.S4 — Evaluate and validate alignment with regulatory standards and benchmarks by using Microsoft Defender for Cloud