Four domains, with weights set by Microsoft's January 2026 update. Every domain summary below is paraphrased from the official skills outline; bullet-level objectives in Azure Mastery are tagged so you always know which domain you're being tested on and where your weak spots cluster.
Secure identity and access15–20%
The Microsoft Entra surface end-to-end. Cover identity types (members, guests, hybrid identities), authentication (passwordless, MFA, password protection), Conditional Access design (named locations, sign-in risk, session controls), Privileged Identity Management (just-in-time activation, access reviews, eligibility), and Microsoft Entra ID Protection (risky users, risky sign-ins). Plus securing access to Azure resources via RBAC, Azure ABAC, custom roles, and managed identities. Around 6–12 questions per sitting.
Secure networking20–25%
Defence-in-depth at the network layer. Configure perimeter security with Azure Firewall (rules, threat intelligence, hierarchies via Firewall Manager), Azure DDoS Protection, Web Application Firewall on Application Gateway and Front Door. Network segmentation with NSGs, application security groups, service tags. Private connectivity via Private Link, Private Endpoints, and service endpoints. Plus Azure Bastion, JIT VM access, ExpressRoute and VPN security. Around 8–15 questions.
Secure compute, storage, and databases20–25%
Harden the workload tier. Compute: VM updates and disk encryption (host encryption, ADE, customer-managed keys), Azure Kubernetes Service security (network policies, Microsoft Entra integration, secrets), App Service network restrictions and authentication, container registry signing and scanning. Storage: SAS tokens, stored access policies, customer-managed keys, immutable storage. Databases: SQL TDE, Always Encrypted, dynamic data masking, Microsoft Defender for SQL. Plus Azure Key Vault as the cross-cutting story — keys, secrets, certificates, access policies vs RBAC. Around 8–15 questions.
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel30–35%
The largest domain by weight, and the operational core of the role. Microsoft Defender for Cloud: Secure Score, regulatory compliance (Azure Security Benchmark, custom standards), workload protection plans (Servers, App Service, Storage, SQL, Containers), security recommendations and exemptions, and the Cloud Security Posture Management surface. Microsoft Sentinel: data connectors (Azure activity, Microsoft 365, Defender XDR), analytics rules and watchlists, incident investigation, hunting with KQL, automation via playbooks (Logic Apps), workbooks. Plus security alert lifecycle and Defender for Cloud → Sentinel integration. Around 12–20 questions.