Microsoft Cybersecurity Architect Expert
SC-100 · ● Active · Expert · Microsoft
The SC-100 is Microsoft's capstone security architecture credential, assessing your ability to design zero-trust security strategies across hybrid, multicloud, and on-premises infrastructure. Updated April 2026 with emerging topics including exposure management, cloud-native application protection, and AI/Copilot security governance.
Exam facts
| Field | Value |
|---|---|
| Cost | $165 USD (regional pricing varies slightly) |
| Duration | ~100 minutes exam time within ~120-minute seat time (no traditional labs) |
| Questions | 40–60 questions; mix of multiple choice, multiple response, case studies |
| Passing | 700 / 1000 scaled |
| Format | Multiple choice, multiple response, scenario-based questions |
| Delivery | Pearson VUE (online proctored or test center) |
| Languages | English (primary); localized versions ~8 weeks after English updates) |
| Valid | 3 years from passing date |
| Renewal | Retake exam or complete continuing education units |
| Prerequisites | Required: One of — AZ-500 (Azure Security Engineer Associate), SC-200 (Security Operations Analyst), SC-300 (Identity & Access Administrator), or MS-500 (retired June 2023, valid until June 2024) |
| Released | Mid-2022 |
| Last Updated | April 27, 2026 (English version; localized versions follow 8 weeks) |
| Retiring | N/A — Active, no retirement announced |
Vendor source — Microsoft Learn: SC-100 Certification ↗
Official exam page — Exam SC-100: Microsoft Cybersecurity Architect ↗
Study guide — Study Guide for Exam SC-100 ↗
Exam objectives & blueprint — SC-100 Skills Measured ↗
About
The SC-100 is Microsoft's expert-level security architecture certification, targeting seasoned security professionals and architects who design comprehensive zero-trust security strategies. Launched mid-2022 and significantly updated April 2026, the exam now emphasizes emerging threat vectors: exposure management, cloud-native application protection (CNAPP), and security governance for AI/Copilot in Microsoft 365. Unlike the associate-level SC-200 (SOC-focused) or SC-300 (identity-focused), SC-100 requires architectural breadth across infrastructure, identity, operations, data, and applications — balanced with deep strategic thinking.
Key distinctions from prerequisites:
- AZ-500 (Azure Security Engineer): Infrastructure and compliance focus; SC-100 adds strategic identity architecture, SOC design, and application security by design.
- SC-200 (Security Operations Analyst): Detection and response focus; SC-100 shifts to security strategy, governance, and prevention architecture.
- SC-300 (Identity and Access Administrator): Identity administration focus; SC-100 broadens to zero-trust architecture spanning all security domains.
You must hold at least one associate credential (AZ-500, SC-200, or SC-300) to earn the full expert designation. Typical candidates have 5+ years in security roles, with hands-on experience in Azure/Entra/Defender and exposure to hybrid or multicloud architectures. The exam targets roughly 2/3 security engineers seeking architectural advancement and 1/3 existing architects validating cross-stack expertise. Passing rate is estimated at 45–55%, making it more challenging than most Azure associate exams.
Domain context — Security / Architecture
Enterprise and cloud security strategy, design, and governance at the architectural level: threat modeling, zero-trust frameworks, incident response, identity federation, compliance mapping, and security-architecture alignment across hybrid, multicloud, and on-premises infrastructure.
Read full deep dive — Microsoft Azure + Entra + Defender → (file not yet created)
Topics covered
2026 exam blueprint (updated April 27, 2026), weighted by exam question percentage:
Design solutions that align with security best practices and priorities (20–25%)
- Assess organizational security posture and readiness
- Develop a security strategy aligned with business objectives
- Design zero-trust architecture (principles, governance, rollout phases)
- Identify security risks and vulnerabilities (threat modeling)
- Recommend security solutions aligned with risk appetite
- Evaluate third-party risk and supply-chain security
Design security operations, identity, and compliance capabilities (25–30%)
- Design security operations center (SOC) strategy and processes
- Design identity and access solutions (Microsoft Entra, hybrid identity, passwordless)
- Design secure remote access (Conditional Access, network segmentation, VPN)
- Design governance, risk, and compliance (GRC) technical architecture
- Design audit, logging, and monitoring strategies (Sentinel, Defender for Cloud)
- Design incident response and threat-intelligence capabilities
Design security solutions for infrastructure (25–30%)
- Secure hybrid and multicloud infrastructure
- Design network security solutions (firewalls, WAF, DDoS, NSGs, Azure Firewall)
- Design endpoint and device protection (Intune, Defender, hardening baselines)
- Design data security for infrastructure (encryption at rest/transit, key management, Azure Key Vault)
- NEW (2026): Design exposure management and cloud-native application protection (CNAPP)
- Design infrastructure segmentation and hardening
Design security solutions for applications and data (20–25%)
- Design secure application development (SDLC, DevSecOps, threat modeling)
- Design authentication and authorization in applications (OAuth, SAML, passwordless, API security)
- Design data classification, encryption, and loss prevention (DLP, IRM, TDE)
- Design compliance for sensitive data (GDPR, HIPAA, PCI-DSS, SOC2)
- NEW (2026): Design data security and compliance for Copilot for Microsoft 365
- Design secrets and credential management (Azure Key Vault, identity-based access)
Source: Official SC-100 Exam Skills Measured ↗
Common skills at Security / Architecture · Expert
Shared architectural competencies for the Security/Architecture domain at expert level — not specific to SC-100.
- Zero-trust architecture design, governance, and phased rollout strategy
- Enterprise threat modeling and attack-surface reduction
- Security posture assessment and risk quantification for C-suite communication
- Compliance framework design and mapping (ISO 27001, SOC2, HIPAA, GDPR, PCI-DSS, NIST CSF)
- Identity and access governance at scale (IAM, federation, lifecycle)
- Incident response and forensics strategy (not operational response, but governance)
- Network security architecture (segmentation, microsegmentation, zero-trust networking)
- Data security and privacy by design (classification, encryption, DLP, residency)
- Third-party and supply-chain security risk assessment
- Cloud security architecture (shared responsibility, multicloud governance)
- Executive stakeholder management and security ROI communication
Recommended courses at Security / Architecture · Expert
| Provider | Title | Cost | URL |
|---|---|---|---|
| Microsoft Learn (official) | SC-100 Learning Path (complete collection of modules) | Free | ↗ |
| Microsoft Learn (official) | Exam Readiness Zone: SC-100 Videos | Free | ↗ |
| John Savill's Technical Training | SC-100 Study Playlist (13 videos, YouTube) | Free | ↗ |
| Pluralsight | SC-100: Microsoft Cybersecurity Architect Expert | $29–$299/month | ↗ |
| Udemy | SC-100: Microsoft Cybersecurity Architect Expert Course 2026 | $14–$99 | ↗ |
| Coursera | Exam Prep SC-100: Microsoft Certified Cybersecurity Architect Expert | $39–$49/month | ↗ |
Course-selection rule: Prioritize the official Microsoft Learn path for exam-aligned coverage. John Savill's videos are excellent for rapid review (each ~30 min). Pluralsight and Udemy fill gaps in hands-on scenarios. Coursera adds interactive quizzes. Avoid generic "Azure security" courses — focus on SC-100–specific material.
Practice exams
| Provider | Title | Cost | URL |
|---|---|---|---|
| MeasureUp (official) | SC-100 Practice Test (120 questions; cert & practice modes) | $99–$149 | ↗ |
| Whizlabs | SC-100: Microsoft Cybersecurity Architect | $49–$99 | ↗ |
| Microsoft via MinHub/GovStore | Official SC-100 Practice Test | $99 | ↗ |
Practice exam guidance: MeasureUp is the official partner and provides the most authentic exam experience (120 questions across all four domains, with performance analytics). Plan to score 80%+ on practice before attempting the live exam. Most successful candidates do 2–3 practice exams spaced over 2–4 weeks of study.
Books
| Title | Author(s) | Publisher | Year | ISBN | URL |
|---|---|---|---|---|---|
| Exam Ref SC-100 Microsoft Cybersecurity Architect | Yuri Diogenes, Sarah Young, Mark Simos, Gladys Rodriguez | Microsoft Press / Pearson | 2023 | 978-0-13-799-730-5 | ↗ |
| Microsoft Cybersecurity Architect Exam Ref SC-100 | Dwayne Natwick, Graham Gold, Abu Zobayer | Packt Publishing | 2024 | 978-1-83-620-851-8 | ↗ |
Book rule: The Microsoft Press edition (2023) is the official study guide and aligns perfectly with the original SC-100 blueprint. The Packt edition (2024) offers updated threat landscape coverage and deeper treatment of 2024–2025 emerging topics (exposure management, CNAPP) but predates the April 2026 exam update. Use the Packt edition for architectural depth; use the Microsoft Press edition for exam-aligned breadth.
Typical job titles at Security / Architecture · Expert
Cybersecurity Architect · Cloud Security Architect (Azure focus) · Principal Security Architect · Senior Security Architect · Security Architect (Microsoft stack) · Solutions Architect – Security · Lead Cloud Solution Architect – Security · Enterprise Security Architect
(Job titles drawn from current postings on LinkedIn, Indeed, ZipRecruiter, and Microsoft Careers that list SC-100, AZ-500 + SC-100, SC-300, or SC-200 as required or strongly preferred.)
Who should pursue SC-100?
Ideal candidates:
- Security Engineers with 4+ years in Azure/Entra/Defender environments seeking advancement to architectural roles
- Cloud Security Architects validating cross-stack expertise across infrastructure, identity, and applications
- Solutions Architects with a security focus moving toward principal/enterprise architect roles
- IT Infrastructure Architects broadening security knowledge to design zero-trust enterprise solutions
- Security Operations Leaders transitioning from SOC/incident response to strategic security design
Less ideal (not required, but helpful context):
- Only if you have hands-on Azure/Azure AD/Microsoft Sentinel experience (else, start with AZ-500 or SC-200)
- Not for pure compliance/GRC roles without infrastructure architecture exposure
- Not a first certification in IT (prerequisite cert required; AZ-500 is broadest entry path)
Career impact:
- Salary lift: 10–20% median increase over non-certified security architects in equivalent roles
- Role access: Unlocks principal/staff security architect, lead cloud architect, and enterprise security architect positions
- Credibility: Signals architectural breadth to C-suite and enterprise clients; valued in financial, healthcare, government sectors
- Opportunity: High demand for multicloud security architects; SC-100 + AWS equivalent (or CISSP) highly marketable
Salary
| Region | Range | Source |
|---|---|---|
| USD | $150,000–$280,000+ (target roles) | Glassdoor ↗ · Robert Half Salary Guide ↗ · Levels.fyi ↗ |
| ZAR | R180,000–R450,000 annually | Pnet ↗ · PayScale ZA ↗ · CareerJunction ↗ |
| GBP | £90,000–£180,000 | IT Jobs Watch ↗ · Hays ↗ |
Salary notes: Expert-level security architects command substantial premiums in regulated industries (finance, healthcare, government). SC-100 holders typically earn 10–20% more than AZ-500–only architects in equivalent roles. Remote-capable roles (hybrid/multicloud focus) trend toward the higher end. ZAR figures reflect South African market indices (as of May 2026); GBP reflects UK London/South East premium. For regional benchmarking, verify with local job boards and salary surveys in your region.
Skills validated
Concrete technologies and frameworks this exam validates:
Architecture & Strategy
- Zero-trust architecture design and governance model
- Security posture assessment and threat modeling
- Enterprise security strategy alignment with business risk
- Exposure management (attack surface, asset discovery, vulnerability prioritization)
Identity & Access
- Microsoft Entra ID (Azure AD) — advanced hybrid scenarios, federated identity, B2B/B2C
- Conditional Access policies and authentication flows
- Passwordless authentication strategies (Windows Hello, FIDO2, phone sign-in)
- Privileged access management (PAM) and just-in-time access
- Identity governance and lifecycle management
Infrastructure & Network Security
- Azure Firewall, Web Application Firewall (WAF), Azure DDoS Protection
- Network segmentation (NSGs, application security groups, UDRs, ExpressRoute)
- Endpoint protection and hardening (Windows Defender for Endpoint, Intune MDM)
- Virtual network design and zero-trust networking principles
- Hybrid network security (VPN, Azure Bastion, private endpoints)
Data & Application Security
- Data classification and labeling (Azure Information Protection, Microsoft Purview)
- Encryption at rest (Azure Storage encryption, TDE, BYOK) and in transit (TLS, Azure Disk Encryption)
- Azure Key Vault, managed identities, and secrets management
- Data Loss Prevention (DLP) policies and Insider Risk Management
- Secure application development (DevSecOps, threat modeling in SDLC)
- API security, OAuth/SAML authentication, and secret scanning
Security Operations & Monitoring
- Microsoft Sentinel (SIEM) configuration, analytics, and threat hunting
- Microsoft Defender for Cloud (advanced threat detection, compliance)
- Azure Policy and Azure Blueprints for governance and compliance automation
- Logging, auditing, and forensic readiness (Log Analytics, Application Insights)
- Incident response workflow and forensics strategy
Compliance & Governance
- Compliance framework mapping (SOC2, ISO 27001, NIST CSF, PCI-DSS, HIPAA, GDPR)
- Regulatory alignment and attestation (FedRAMP, DoD IL, etc.)
- Risk management and quantification for executive reporting
- Third-party and supply-chain security assessment
- Cloud-native application protection (CNAPP) and container security
Emerging 2026 Topics
- Exposure management and cloud-native posture (CNAPP)
- Microsoft Copilot for Microsoft 365 security and data governance
- AI security risks and guardrails in enterprise environments
Preparation timeline & study path
Recommended preparation: 6–12 weeks (depending on starting experience level)
Week 1–2: Establish foundational knowledge
- Review the official Microsoft Learn SC-100 Learning Path (free modules)
- Watch John Savill's SC-100 YouTube playlist (13 videos, ~5–6 hours)
- Read Exam Ref SC-100 chapters 1–2 (Zero Trust, posture assessment)
Week 3–5: Deep dive by domain
- Study one domain per week: Best Practices → SecOps & Identity → Infrastructure → Apps & Data
- Complete hands-on labs on Microsoft Learn for each domain
- Work through Pluralsight or Udemy course modules in parallel
Week 6–8: Practice & weak-area focus
- Take first MeasureUp practice exam (target: 75%+)
- Identify weak domains; focus additional study there
- Review Packt book chapters on emerging topics (exposure management, CNAPP, Copilot security)
Week 9–10: Full practice exams & scenario work
- Complete second MeasureUp practice test (target: 80%+)
- Try Whizlabs practice exam for variety in question styles
- Work through case-study scenarios (Azure landing zones, zero-trust rollout, incident response design)
Week 11–12: Final review & confidence building
- Review exam objectives one more time
- Complete third practice exam (target: 85%+)
- Memorize key technologies, frameworks, compliance requirements
- Schedule live exam when confident
Success factors:
- Hands-on Azure labs (Azure Portal, PowerShell, Terraform)
- Real-world architecture design experience (hybrid, multicloud)
- Familiarity with security frameworks (NIST, ISO 27001, Zero Trust)
- Practice explaining security decisions to stakeholders (soft skills matter in architecting)
Related certifications
- Prerequisite (choose one): AZ-500 Microsoft Azure Security Engineer Associate ↗ · SC-200 Microsoft Security Operations Analyst ↗ · SC-300 Microsoft Identity and Access Administrator ↗
- Often stacked with: AZ-305 Azure Solutions Architect Expert ↗ (architecture peer; both required for enterprise architect roles)
- Related specialties: AZ-700 Azure Network Engineer Expert ↗ · AZ-900 Azure Fundamentals ↗ (foundational)
- Replaces: N/A — SC-100 is current (updated April 2026); no predecessor
- Equivalents at expert level: AWS Certified Solutions Architect – Professional ↗ (cross-cloud) · Google Cloud Architect Professional ↗ (GCP equivalent)
- Vendor overview: Microsoft Vendor Overview ↗
Key exam challenges & what to focus on
Why SC-100 is harder than prerequisite certs:
- Breadth vs. depth: Unlike AZ-500 (infrastructure-focused) or SC-200 (SOC-focused), SC-100 demands balanced knowledge across four major domains with no "primary" specialty. You must think like an architect, not an operator.
- Strategic vs. tactical: Questions often ask "design a solution for X risk" rather than "configure Y service." Expect scenario-based case studies, not just configuration knowledge.
- Cross-domain integration: A single question may involve identity + network + data protection design. Siloed knowledge fails; you must understand interactions.
- Emerging 2026 topics: Exposure management and CNAPP are new; many study guides predate April 2026 update. Prioritize recent resources.
Common mistakes:
- Skipping hands-on labs: Reading Microsoft Docs is insufficient. Deploy zero-trust network, test Conditional Access policies, configure Sentinel alerts in Azure Portal.
- Not practicing with scenarios: Generic multiple-choice drills won't prepare you for architectural design questions. Use Pluralsight labs and real-world case studies.
- Ignoring the prerequisite cert: If you chose SC-200, you may lack infrastructure depth. Budget extra study time for AZ-500 topics (firewalls, encryption, network segmentation).
- Forgetting compliance frameworks: SC-100 tests ISO 27001, NIST CSF, SOC2 Type II, PCI-DSS alignment. Know how Zero Trust maps to NIST and ISO 27001.
- Underestimating time management: 40–60 questions in 100 minutes means ~1.5–2.5 minutes per question. Some scenarios are lengthy; read efficiently.
High-confidence study markers (before exam day):
- Can design a complete zero-trust architecture for a hybrid enterprise
- Can explain how to satisfy SOC2 Type II requirements using Azure services
- Can map NIST CSF functions to specific Azure capabilities
- Can design identity federation, Conditional Access, and passwordless auth flow end-to-end
- Can discuss exposure management and CNAPP in Azure context
- Can articulate trade-offs (cost vs. security, ease vs. defense) in architectural choices
- Score 85%+ on two MeasureUp practice exams with strong performance in all four domains
Sources
Official Microsoft sources:
- Microsoft Learn: SC-100 Cybersecurity Architect Expert Certification ↗
- Exam SC-100: Microsoft Cybersecurity Architect — Official Exam Page ↗
- Study Guide for Exam SC-100 ↗
- Microsoft Learn: SC-100 Learning Path (Free modules) ↗
- Exam Readiness Zone: SC-100 Videos ↗
Practice exams:
- MeasureUp SC-100 Official Practice Test ↗
- Whizlabs SC-100 Practice Exam ↗
- MinHub / GovStore: Official Microsoft Practice Test ↗
Books & Study Guides:
- Exam Ref SC-100 (Microsoft Press / Pearson) ↗
- Microsoft Cybersecurity Architect Exam Ref SC-100 (Packt, 2024) ↗
Training resources:
- John Savill's Technical Training: SC-100 Study Playlist ↗
- Pluralsight: SC-100: Microsoft Cybersecurity Architect Expert ↗
- Udemy: SC-100 Course 2026 ↗
- Coursera: Exam Prep SC-100 Specialization ↗
Salary & job market:
- Glassdoor: Microsoft Security Architect Salaries ↗
- Robert Half Salary Guide ↗
- Levels.fyi: Microsoft Security Analyst Salary Data ↗
- IT Jobs Watch: Security Architect Salary (UK) ↗
- Hays Salary Guide (UK) ↗
- Pnet: South African Job Market ↗
Industry perspectives:
Last verified: 2026-05-01 (April 27, 2026 blueprint update verified)
Parent ecosystem: Microsoft Azure + Entra + Defender (file not yet created)
Parent domain: Security / Architecture (file not yet created)
Vendor overview: Microsoft Vendor Overview