- You need a scaled score of 700 or higher out of 1000 to pass SC-100.
- Domains 2 and 3 together carry 50-60% of the exam weight, more than any other combination.
- Expect 40-60 questions in a 120-minute appointment, including case studies and drag-and-drop items.
- The exam fee is $165 USD before taxes or MCT/Partner discounts, paid through Pearson VUE.
The Passing Score: 700 on a 100-1000 Scale
Microsoft reports Cybersecurity Architect (SC-100) results on a scaled range of 100 to 1000, and the threshold to pass is 700. That number is fixed and published by Microsoft - it does not shift based on how many people take the exam that month, how difficult your specific question set was, or any curve applied after the fact. If your score report shows 700 or above, you passed; anything below, you did not, regardless of how close you got.
This is worth stating plainly because a lot of exam-prep content online conflates SC-100 with other credentials that happen to share the same three-letter, three-digit code. This article covers Microsoft's Cybersecurity Architect exam only, and every number here - the 700 cut score, the 165 dollar fee, the domain weights - comes from Microsoft's own published exam facts for this specific certification.
What a Scaled Score Actually Measures
Because scoring is scaled rather than raw, Microsoft never publishes a simple "get X out of Y questions right" formula, and it does not release pass rates for SC-100 or any other certification. Trying to reverse-engineer an exact question count you can afford to miss is a waste of prep time. Instead, treat 700 as a signal that you need consistent competence across all four domains - not stellar performance in your favorite area covering for gaps elsewhere.
The exam is designed to test architectural judgment, not memorization of portal menus or PowerShell syntax. Questions ask you to evaluate trade-offs, recommend a Zero Trust approach for a given scenario, or choose the right Microsoft security service for a stated business constraint. If you're used to exams that reward rote recall, this is a meaningful adjustment - one covered in more depth in our SC-100 difficulty guide, which breaks down why this exam feels harder than its associate-level prerequisites.
Key Takeaway
Stop hunting for a "minimum correct answer count." Focus on being reliably solid across all four domains, since the scaled scoring model rewards consistency over spikes of brilliance in one area.
Question Format and Why Guessing Rarely Works
Candidates typically see 40 to 60 questions inside a 120-minute appointment, delivered through Pearson VUE at a test center or via online proctoring. The format mix includes:
- Multiple choice and multiple response items
- Drag-and-drop sequencing and matching questions
- Hot area selections within diagrams or text
- Yes/no statement series tied to a shared scenario
- Full case studies with multi-part questions built around one detailed business scenario
Case studies matter a lot for how you should pace yourself. A single case study can present a company's existing hybrid environment, compliance obligations, and security incidents, then ask you five or six questions that each require you to reason from that same context. Skimming the scenario costs you points across every linked question, not just one. Build extra time into your pacing plan for these sections rather than treating every question as a 2-to-3-minute standalone item.
How Domain Weighting Shapes Your Score
SC-100 measures four domains, and understanding their relative weight is the single most useful thing you can do before building a study plan:
| Domain | Weight | Focus |
|---|---|---|
| Domain 1 | 20-25% | Design solutions that align with security best practices and priorities |
| Domain 2 | 25-30% | Design security operations, identity, and compliance capabilities |
| Domain 3 | 25-30% | Design security solutions for infrastructure |
| Domain 4 | 20-25% | Design security solutions for applications and data |
Domains 2 and 3 together account for 50 to 60 percent of the exam. That is more than half your score determined by security operations/identity/compliance design and infrastructure security design combined. If you allocate study time evenly across four domains without weighting for this, you're under-preparing for the majority of the exam. Our full SC-100 exam domains guide breaks down every subtopic inside each of these four areas in detail.
Domain 2: Security Operations, Identity, and Compliance
This is the single largest domain and one you cannot shortcut. Candidates need fluency in designing SIEM/SOAR strategies, identity governance patterns, and regulatory compliance postures at an architectural level.
- Zero Trust identity architecture and conditional access strategy
- Agent identity design using Microsoft Entra Agent ID, added in the most recent exam refresh
- Compliance and regulatory strategy mapped to Microsoft Purview capabilities
- Microsoft Purview Audit for centralized logging across workloads
Domain 3: Security Solutions for Infrastructure
This domain leans on your ability to architect protections spanning hybrid and multicloud infrastructure, not just single-tenant Azure setups.
- Security strategy for hybrid and multicloud workloads
- Network security architecture patterns and segmentation strategy
- Microsoft Security Exposure Management attack paths, another addition from the latest refresh
- Privileged access strategy across infrastructure layers
Where Points Are Won and Lost
The current version of SC-100 took effect July 28, 2026, following refreshes in November 2025 and April 2026. That most recent update introduced several topics that trip up candidates who studied from older materials: agent identity design with Microsoft Entra Agent ID, a defined strategy for secure AI adoption, security controls for AI workload data, Microsoft Purview Audit for centralized logging, and attack path analysis through Microsoft Security Exposure Management. If your study source predates July 2026, you have a real gap.
Most questions still cover generally available (GA) features, but Microsoft notes that commonly used preview features can appear too - a detail candidates often overlook when they assume anything in preview is automatically out of scope. If a preview capability has meaningful adoption in real deployments (AI workload security controls are a good example right now), study it as if it could show up.
Because Microsoft doesn't publish pass rates or a breakdown of where candidates lose points, treat this as directional guidance rather than a guarantee. Our SC-100 pass rate analysis goes further into what's known and unknown about candidate outcomes on this exam.
A Domain-Aligned Prep Schedule
Generic study techniques only help if you point them at the right material at the right time. Given that Domains 2 and 3 carry the most weight, your schedule should reflect that instead of splitting time evenly across four equal blocks.
Domain 1 + Foundations
- Review Zero Trust principles and security best-practice frameworks
- Study governance and risk strategy design patterns
Domain 2 (Heaviest Weight)
- Identity, SecOps, and compliance architecture design
- New content: Entra Agent ID and Purview Audit logging
Domain 3 (Heaviest Weight)
- Hybrid/multicloud infrastructure security design
- New content: Security Exposure Management attack paths
Domain 4 + Case Study Practice
- Application and data security design, AI workload data security
- Full-length case study drills under timed conditions
Spacing your review of Domains 2 and 3 across three total weeks instead of one reflects their combined 50-60% weight - and it gives spaced repetition of dense identity and infrastructure content, rather than cramming, more time to stick. For a fuller week-by-week walkthrough with resource recommendations, see the SC-100 study guide.
Registration, Fees, and Retake Mechanics
SC-100 is delivered through Pearson VUE, either at a physical test center or as an online proctored exam you take from home or office. The exam fee is $165 USD in the United States before taxes, and before any discount available to Microsoft Certified Trainers or Microsoft Partner Network members. Pricing and any regional variation are covered in detail in our SC-100 certification cost breakdown, and scheduling windows and appointment logistics are covered in the SC-100 exam dates guide.
If you don't hit 700 on your first attempt, you can register again - Microsoft's standard retake policies apply. Rather than immediately rebooking, use your score report's domain-level feedback to identify which of the four domains dragged your score down, then concentrate remaining study time there before scheduling again.
Key Takeaway
Budget for the $165 fee plus a realistic buffer for a possible retake, and don't schedule a second attempt until you've specifically addressed the domain that cost you the most points.
What Happens After You Pass
Hitting 700 on SC-100 is a major milestone, but it does not by itself award the Microsoft Certified: Cybersecurity Architect Expert credential. Microsoft requires an active associate-level prerequisite alongside SC-100 - one of SC-200, SC-300, or AZ-500. If you haven't already earned one of those, passing SC-100 puts you on hold until you do. Full prerequisite mechanics are laid out in our SC-100 requirements guide.
Once you hold both SC-100 and a qualifying prerequisite, the Expert certification is active for one year and renews at no cost through an unproctored online assessment on Microsoft Learn - no need to retake the full proctored exam annually. If you're still deciding whether the investment of time and the $165 fee is worthwhile given your career goals, our SC-100 ROI analysis and SC-100 salary guide look at that question from different angles, and you can start building exam-day confidence with realistic scenario questions on the SC-100 practice test platform.
FAQ
You need a scaled score of 700 or higher out of a possible 1000. Microsoft does not publish a raw percentage-correct equivalent because scoring is weighted by question difficulty.
No. Microsoft does not release pass rate statistics for SC-100 or its other certifications, so any specific percentage you see cited elsewhere is not an official figure.
Candidates typically see 40 to 60 questions across multiple choice, multiple response, drag-and-drop, hot area, yes/no series, and case study formats within a 120-minute appointment.
Domain 2 (security operations, identity, and compliance) and Domain 3 (infrastructure security) together make up 50-60% of the exam, more weight than Domains 1 and 4 combined.
No. You also need an active SC-200, SC-300, or AZ-500 associate certification to earn the Microsoft Certified: Cybersecurity Architect Expert credential.