SC-100 logo
Focused certification exam prep
Start practice

SC-100 Exam Domains 2026: Complete Guide to All 4 Content Areas

TL;DR
  • SC-100 has four domains; Domains 2 and 3 together carry 50-60% of the exam weight.
  • Expect 40-60 questions, including case studies, in a 120-minute Pearson VUE appointment.
  • Passing score is 700 on a 100-1000 scale; the fee is $165 USD before taxes.
  • The current skills-measured version (effective July 28, 2026) adds Microsoft Entra Agent ID, AI workload data security, Purview Audit, and Security Exposure...

How the Four Domains Fit Together

Microsoft Cybersecurity Architect (SC-100) is not organized as a checklist of Azure portal tasks. It's structured around four functional areas that mirror how a real cybersecurity architect operates: setting strategy, running security operations and identity programs, hardening infrastructure, and protecting applications and data. Each domain measures whether you can translate business risk into an actionable architecture, not whether you remember menu paths.

The four official domains, with their published weightings, are:

  • Domain 1: Design solutions that align with security best practices and priorities (20-25%)
  • Domain 2: Design security operations, identity, and compliance capabilities (25-30%)
  • Domain 3: Design security solutions for infrastructure (25-30%)
  • Domain 4: Design security solutions for applications and data (20-25%)

Notice that Domains 2 and 3 sit in the middle of the exam blueprint and together account for 50-60% of everything you'll be tested on. That single fact should shape your entire study plan. If you're still mapping out your overall approach, the SC-100 Study Guide 2026 walks through a full first-attempt strategy, while this article focuses specifically on what lives inside each content area.

Refresh Alert: The skills-measured document took effect July 28, 2026, following prior refreshes in November 2025 and April 2026. The latest update folded in agent identity design with Microsoft Entra Agent ID, a strategy for secure AI adoption, AI workload data security, Microsoft Purview Audit for centralized logging, and Microsoft Security Exposure Management attack paths - all genuinely new architectural territory, not cosmetic wording changes.

Domain 1: Design Solutions That Align with Security Best Practices and Priorities (20-25%)

This domain sets the tone for the entire exam. Instead of asking "how do you configure X," it asks "given this organization's risk profile, what should the security strategy look like?" You're expected to reason through Zero Trust principles, evaluate business risk against technical controls, and design governance that spans hybrid and multicloud environments.

Domain 1: What You Must Master

Candidates should be comfortable translating executive priorities into architectural decisions and defending trade-offs.

  • Zero Trust strategy design across identity, network, endpoint, and data pillars
  • Aligning security posture with regulatory, industry, and organizational risk appetite
  • Designing a strategy for secure AI adoption, including governance for AI tools and agents
  • Integrating security into DevSecOps and platform engineering practices
  • Evaluating and recommending Microsoft security capabilities against existing investments

Expect scenario stems that describe a company's current controls and ask you to identify the highest-priority gap or the most appropriate strategic recommendation. This domain rewards judgment, not memorization - a theme covered in more depth in How Hard Is the SC-100 Exam? Complete Difficulty Guide 2026.

Domain 2: Design Security Operations, Identity, and Compliance Capabilities (25-30%)

This is the single largest domain on the exam and one of the two that together make up more than half the exam. It blends three traditionally separate disciplines - SecOps, identity, and compliance - into one architectural lens.

Domain 2: What You Must Master

  • Security operations strategy: SIEM/XDR architecture, detection engineering, incident response workflows
  • Identity and access architecture, including privileged access strategy and lifecycle governance
  • Agent identity design using Microsoft Entra Agent ID for autonomous and semi-autonomous AI agents
  • Centralized logging and audit strategy using Microsoft Purview Audit
  • Regulatory compliance architecture and data governance requirements

The addition of Microsoft Entra Agent ID is one of the more consequential updates in the current version. It requires architects to reason about identity for non-human, AI-driven agents - a distinct problem from traditional user and service principal identity. Expect at least a few scenario-based items asking you to design least-privilege access and lifecycle controls for agents interacting with enterprise data.

Key Takeaway

Because Domain 2 carries the heaviest weight, dedicate extra review time to identity governance patterns and the newer Entra Agent ID and Purview Audit content before attempting practice exams.

Domain 3: Design Security Solutions for Infrastructure (25-30%)

This domain is the other half of the exam's heavyweight middle. It covers securing compute, networking, and hybrid/multicloud infrastructure at an architectural level - again, not step-by-step configuration.

Domain 3: What You Must Master

  • Network security architecture: segmentation, perimeter design, hybrid connectivity
  • Multicloud and hybrid infrastructure security patterns, including IaaS and PaaS workloads
  • Container, Kubernetes, and DevOps pipeline security design
  • Using Microsoft Security Exposure Management attack paths to prioritize remediation across the estate
  • Designing for resilience: backup, disaster recovery, and ransomware containment strategy

The addition of Security Exposure Management attack paths reflects a broader shift toward exposure-based prioritization rather than isolated vulnerability lists. Expect questions that give you a partial attack path graph and ask which mitigation breaks the chain most effectively, rather than which single CVE to patch first.

Domain 4: Design Security Solutions for Applications and Data (20-25%)

The final domain focuses on protecting the application layer and the data that flows through it - including the newest and most exam-relevant addition: securing AI workloads.

Domain 4: What You Must Master

  • Application security architecture across the SDLC, from design review to runtime protection
  • Data classification, encryption, and information protection strategy
  • AI workload data security: protecting training data, prompts, and outputs in AI-integrated applications
  • API security design and secure integration patterns for third-party and partner services
  • Data residency, sovereignty, and lifecycle management in regulated environments

AI workload data security deserves special attention because it's genuinely new content, not a rebranding of older data-loss-prevention topics. You should be able to design controls that prevent sensitive data leakage through AI copilots, agents, and retrieval-augmented generation pipelines - a scenario type that didn't exist in earlier versions of this exam.

How the Domains Show Up in the Exam Format

Regardless of which domain a question targets, the format stays consistent: candidates typically see 40 to 60 questions inside a 120-minute appointment, delivered as a mix of multiple choice, multiple response, drag-and-drop, hot area, yes/no series, and full case studies. Case studies are where domain knowledge gets tested most rigorously - a single case study can pull from all four domains within one long scenario, asking you to recommend a strategy (Domain 1), design the identity and logging model (Domain 2), secure the network (Domain 3), and protect the data layer (Domain 4) for the same fictional organization.

Most questions cover generally available features, though commonly used preview features - like newer Entra Agent ID capabilities - can appear. Because the exam tests architectural judgment rather than portal configuration, memorizing button locations won't help; you need to practice reasoning through trade-offs the way you would in a real design review.

DomainWeightPrimary Focus
Domain 1: Best Practices & Priorities20-25%Zero Trust strategy, secure AI adoption, governance
Domain 2: Operations, Identity, Compliance25-30%SecOps, Entra Agent ID, Purview Audit, compliance
Domain 3: Infrastructure25-30%Network, hybrid/multicloud, attack path prioritization
Domain 4: Applications & Data20-25%App security, data protection, AI workload data security

Weighting Strategy: Where to Spend Study Hours

With Domains 2 and 3 together making up 50-60% of the exam, a simple four-week allocation lets you weight your effort proportionally instead of splitting time evenly across all four areas.

Week 1

Domain 1 Foundations

  • Zero Trust design patterns and secure AI adoption strategy
  • Review governance and regulatory alignment scenarios
Week 2

Domain 2 Deep Dive

  • Identity architecture, Entra Agent ID, and Purview Audit logging design
  • Practice SecOps and compliance case studies since this domain carries the most weight
Week 3

Domain 3 Deep Dive

  • Network segmentation, hybrid/multicloud patterns, and Security Exposure Management attack paths
  • Work through infrastructure resilience and DR scenarios
Week 4

Domain 4 & Full Review

  • Application and AI workload data security
  • Mixed case-study drills pulling from all four domains

This isn't a generic template - it's sequenced specifically around SC-100's weighting, with the two heaviest domains placed back-to-back in weeks two and three when your retention is strongest. For a broader breakdown of pacing and resources, see the SC-100 Study Guide 2026, and pair your review with full-length practice exams on our practice test platform to see how domain weighting actually plays out in scored simulations.

Who Hires for These Skills

Because the domains span strategy, operations, infrastructure, and application security, SC-100 holders are typically targeted for senior, architecture-level roles rather than hands-on administrator positions. Organizations look for this breadth when hiring cloud security architects, principal security engineers, and consultants who need to design controls spanning Azure, hybrid, and multicloud estates. If you're evaluating whether the credential fits your career path, SC-100 Jobs and Is the SC-100 Certification Worth It? Complete ROI Analysis 2026 go deeper into role types and long-term value.

Registration, Fees, and Scoring Mechanics

SC-100 is owned and published by Microsoft and delivered through Pearson VUE, either at a test center or as an online proctored exam. The fee is $165 USD in the United States before taxes and before any discounts for Microsoft Certified Trainers or Microsoft Partner Network members. Scores are reported on a 100-1000 scale, and you need 700 or greater to pass.

Important: Passing SC-100 by itself does not award the Microsoft Certified: Cybersecurity Architect Expert credential. You also need an active associate-level prerequisite - SC-200, SC-300, or AZ-500. The certification then renews annually at no cost through an unproctored assessment on Microsoft Learn.

For the full fee breakdown, discount eligibility, and renewal cost details, see SC-100 Certification Cost 2026: Complete Pricing Breakdown. If you're still confirming eligibility before you register, SC-100 Requirements 2026 covers the prerequisite chain in detail, and SC-100 Passing Score 2026 explains exactly how the 700-point threshold is calculated.

Frequently Asked Questions

Which SC-100 domain should I study first?

Domain 1 works well as a starting point because it establishes the strategic vocabulary - Zero Trust, risk alignment, secure AI adoption - that Domains 2, 3, and 4 all build on.

Are Domain 2 and Domain 3 really the most important?

Yes. Microsoft's published blueprint places both at 25-30% each, meaning together they account for 50-60% of the exam, more than the other two domains combined.

Do I need hands-on Azure experience to answer domain questions?

The exam tests architectural judgment rather than portal configuration, so conceptual understanding of design trade-offs matters more than memorizing exact configuration steps.

Will the new AI-related topics be a large share of the exam?

Microsoft Entra Agent ID, secure AI adoption strategy, AI workload data security, and Security Exposure Management attack paths were added in the most recent refresh, but they're distributed across Domains 1, 2, 3, and 4 rather than forming a separate section.

Does passing all four domains guarantee the Expert certification?

No. You must also hold an active SC-200, SC-300, or AZ-500 associate certification alongside a passing SC-100 score to earn Microsoft Certified: Cybersecurity Architect Expert.

Ready to pass your SC-100 exam?

Put this into practice with free SC-100 questions across every exam domain.