- How the Four Domains Fit Together
- Domain 1: Security Best Practices and Priorities
- Domain 2: Security Operations, Identity, and Compliance
- Domain 3: Security Solutions for Infrastructure
- Domain 4: Security Solutions for Applications and Data
- How the Domains Show Up in the Exam Format
- Weighting Strategy: Where to Spend Study Hours
- Who Hires for These Skills
- Registration, Fees, and Scoring
- FAQ
- SC-100 has four domains; Domains 2 and 3 together carry 50-60% of the exam weight.
- Expect 40-60 questions, including case studies, in a 120-minute Pearson VUE appointment.
- Passing score is 700 on a 100-1000 scale; the fee is $165 USD before taxes.
- The current skills-measured version (effective July 28, 2026) adds Microsoft Entra Agent ID, AI workload data security, Purview Audit, and Security Exposure...
How the Four Domains Fit Together
Microsoft Cybersecurity Architect (SC-100) is not organized as a checklist of Azure portal tasks. It's structured around four functional areas that mirror how a real cybersecurity architect operates: setting strategy, running security operations and identity programs, hardening infrastructure, and protecting applications and data. Each domain measures whether you can translate business risk into an actionable architecture, not whether you remember menu paths.
The four official domains, with their published weightings, are:
- Domain 1: Design solutions that align with security best practices and priorities (20-25%)
- Domain 2: Design security operations, identity, and compliance capabilities (25-30%)
- Domain 3: Design security solutions for infrastructure (25-30%)
- Domain 4: Design security solutions for applications and data (20-25%)
Notice that Domains 2 and 3 sit in the middle of the exam blueprint and together account for 50-60% of everything you'll be tested on. That single fact should shape your entire study plan. If you're still mapping out your overall approach, the SC-100 Study Guide 2026 walks through a full first-attempt strategy, while this article focuses specifically on what lives inside each content area.
Domain 1: Design Solutions That Align with Security Best Practices and Priorities (20-25%)
This domain sets the tone for the entire exam. Instead of asking "how do you configure X," it asks "given this organization's risk profile, what should the security strategy look like?" You're expected to reason through Zero Trust principles, evaluate business risk against technical controls, and design governance that spans hybrid and multicloud environments.
Domain 1: What You Must Master
Candidates should be comfortable translating executive priorities into architectural decisions and defending trade-offs.
- Zero Trust strategy design across identity, network, endpoint, and data pillars
- Aligning security posture with regulatory, industry, and organizational risk appetite
- Designing a strategy for secure AI adoption, including governance for AI tools and agents
- Integrating security into DevSecOps and platform engineering practices
- Evaluating and recommending Microsoft security capabilities against existing investments
Expect scenario stems that describe a company's current controls and ask you to identify the highest-priority gap or the most appropriate strategic recommendation. This domain rewards judgment, not memorization - a theme covered in more depth in How Hard Is the SC-100 Exam? Complete Difficulty Guide 2026.
Domain 2: Design Security Operations, Identity, and Compliance Capabilities (25-30%)
This is the single largest domain on the exam and one of the two that together make up more than half the exam. It blends three traditionally separate disciplines - SecOps, identity, and compliance - into one architectural lens.
Domain 2: What You Must Master
- Security operations strategy: SIEM/XDR architecture, detection engineering, incident response workflows
- Identity and access architecture, including privileged access strategy and lifecycle governance
- Agent identity design using Microsoft Entra Agent ID for autonomous and semi-autonomous AI agents
- Centralized logging and audit strategy using Microsoft Purview Audit
- Regulatory compliance architecture and data governance requirements
The addition of Microsoft Entra Agent ID is one of the more consequential updates in the current version. It requires architects to reason about identity for non-human, AI-driven agents - a distinct problem from traditional user and service principal identity. Expect at least a few scenario-based items asking you to design least-privilege access and lifecycle controls for agents interacting with enterprise data.
Key Takeaway
Because Domain 2 carries the heaviest weight, dedicate extra review time to identity governance patterns and the newer Entra Agent ID and Purview Audit content before attempting practice exams.
Domain 3: Design Security Solutions for Infrastructure (25-30%)
This domain is the other half of the exam's heavyweight middle. It covers securing compute, networking, and hybrid/multicloud infrastructure at an architectural level - again, not step-by-step configuration.
Domain 3: What You Must Master
- Network security architecture: segmentation, perimeter design, hybrid connectivity
- Multicloud and hybrid infrastructure security patterns, including IaaS and PaaS workloads
- Container, Kubernetes, and DevOps pipeline security design
- Using Microsoft Security Exposure Management attack paths to prioritize remediation across the estate
- Designing for resilience: backup, disaster recovery, and ransomware containment strategy
The addition of Security Exposure Management attack paths reflects a broader shift toward exposure-based prioritization rather than isolated vulnerability lists. Expect questions that give you a partial attack path graph and ask which mitigation breaks the chain most effectively, rather than which single CVE to patch first.
Domain 4: Design Security Solutions for Applications and Data (20-25%)
The final domain focuses on protecting the application layer and the data that flows through it - including the newest and most exam-relevant addition: securing AI workloads.
Domain 4: What You Must Master
- Application security architecture across the SDLC, from design review to runtime protection
- Data classification, encryption, and information protection strategy
- AI workload data security: protecting training data, prompts, and outputs in AI-integrated applications
- API security design and secure integration patterns for third-party and partner services
- Data residency, sovereignty, and lifecycle management in regulated environments
AI workload data security deserves special attention because it's genuinely new content, not a rebranding of older data-loss-prevention topics. You should be able to design controls that prevent sensitive data leakage through AI copilots, agents, and retrieval-augmented generation pipelines - a scenario type that didn't exist in earlier versions of this exam.
How the Domains Show Up in the Exam Format
Regardless of which domain a question targets, the format stays consistent: candidates typically see 40 to 60 questions inside a 120-minute appointment, delivered as a mix of multiple choice, multiple response, drag-and-drop, hot area, yes/no series, and full case studies. Case studies are where domain knowledge gets tested most rigorously - a single case study can pull from all four domains within one long scenario, asking you to recommend a strategy (Domain 1), design the identity and logging model (Domain 2), secure the network (Domain 3), and protect the data layer (Domain 4) for the same fictional organization.
Most questions cover generally available features, though commonly used preview features - like newer Entra Agent ID capabilities - can appear. Because the exam tests architectural judgment rather than portal configuration, memorizing button locations won't help; you need to practice reasoning through trade-offs the way you would in a real design review.
| Domain | Weight | Primary Focus |
|---|---|---|
| Domain 1: Best Practices & Priorities | 20-25% | Zero Trust strategy, secure AI adoption, governance |
| Domain 2: Operations, Identity, Compliance | 25-30% | SecOps, Entra Agent ID, Purview Audit, compliance |
| Domain 3: Infrastructure | 25-30% | Network, hybrid/multicloud, attack path prioritization |
| Domain 4: Applications & Data | 20-25% | App security, data protection, AI workload data security |
Weighting Strategy: Where to Spend Study Hours
With Domains 2 and 3 together making up 50-60% of the exam, a simple four-week allocation lets you weight your effort proportionally instead of splitting time evenly across all four areas.
Domain 1 Foundations
- Zero Trust design patterns and secure AI adoption strategy
- Review governance and regulatory alignment scenarios
Domain 2 Deep Dive
- Identity architecture, Entra Agent ID, and Purview Audit logging design
- Practice SecOps and compliance case studies since this domain carries the most weight
Domain 3 Deep Dive
- Network segmentation, hybrid/multicloud patterns, and Security Exposure Management attack paths
- Work through infrastructure resilience and DR scenarios
Domain 4 & Full Review
- Application and AI workload data security
- Mixed case-study drills pulling from all four domains
This isn't a generic template - it's sequenced specifically around SC-100's weighting, with the two heaviest domains placed back-to-back in weeks two and three when your retention is strongest. For a broader breakdown of pacing and resources, see the SC-100 Study Guide 2026, and pair your review with full-length practice exams on our practice test platform to see how domain weighting actually plays out in scored simulations.
Who Hires for These Skills
Because the domains span strategy, operations, infrastructure, and application security, SC-100 holders are typically targeted for senior, architecture-level roles rather than hands-on administrator positions. Organizations look for this breadth when hiring cloud security architects, principal security engineers, and consultants who need to design controls spanning Azure, hybrid, and multicloud estates. If you're evaluating whether the credential fits your career path, SC-100 Jobs and Is the SC-100 Certification Worth It? Complete ROI Analysis 2026 go deeper into role types and long-term value.
Registration, Fees, and Scoring Mechanics
SC-100 is owned and published by Microsoft and delivered through Pearson VUE, either at a test center or as an online proctored exam. The fee is $165 USD in the United States before taxes and before any discounts for Microsoft Certified Trainers or Microsoft Partner Network members. Scores are reported on a 100-1000 scale, and you need 700 or greater to pass.
For the full fee breakdown, discount eligibility, and renewal cost details, see SC-100 Certification Cost 2026: Complete Pricing Breakdown. If you're still confirming eligibility before you register, SC-100 Requirements 2026 covers the prerequisite chain in detail, and SC-100 Passing Score 2026 explains exactly how the 700-point threshold is calculated.
Frequently Asked Questions
Domain 1 works well as a starting point because it establishes the strategic vocabulary - Zero Trust, risk alignment, secure AI adoption - that Domains 2, 3, and 4 all build on.
Yes. Microsoft's published blueprint places both at 25-30% each, meaning together they account for 50-60% of the exam, more than the other two domains combined.
The exam tests architectural judgment rather than portal configuration, so conceptual understanding of design trade-offs matters more than memorizing exact configuration steps.
Microsoft Entra Agent ID, secure AI adoption strategy, AI workload data security, and Security Exposure Management attack paths were added in the most recent refresh, but they're distributed across Domains 1, 2, 3, and 4 rather than forming a separate section.
No. You must also hold an active SC-200, SC-300, or AZ-500 associate certification alongside a passing SC-100 score to earn Microsoft Certified: Cybersecurity Architect Expert.