- SC-100 is Microsoft's expert-level architecture exam, delivered via Pearson VUE for $165 USD before discounts.
- You need a score of 700 or higher on a 100-1000 scale to pass.
- Domains 2 and 3 together carry 50-60% of the exam weight, more than domains 1 and 4 combined.
- Passing SC-100 alone isn't enough - you also need an active SC-200, SC-300, or AZ-500 to earn the Cybersecurity Architect Expert title.
What Is A SC-100?
SC-100 is Microsoft's exam code for Microsoft Cybersecurity Architect, an expert-level assessment that measures whether a candidate can design end-to-end security strategy across identity, operations, infrastructure, applications, and data. It is owned and published by Microsoft and delivered through Pearson VUE, either at a physical test center or as an online proctored exam from home or office.
Unlike associate-level Microsoft exams that test configuration steps inside a portal, SC-100 tests architectural judgment. You are given business constraints, existing hybrid environments, and compliance requirements, and you have to recommend the right Zero Trust design, the right governance model, or the right sequencing of a security transformation. That framing is the single biggest thing people misunderstand when they first hear the name "SC-100" - it is not a hands-on skills exam, it is a design and decision-making exam.
If you're still orienting yourself around the terminology, our companion pieces on SC-100 Meaning and What Does SC-100 Stand For? go deeper into how Microsoft frames the "cybersecurity architect" role itself.
Who Takes SC-100 and Why
SC-100 is aimed at practitioners who already work in security but are moving from "implementer" to "designer." Typical candidates include:
- Security engineers or analysts moving into an architecture or lead role
- Identity or infrastructure specialists who need to speak credibly about Zero Trust strategy
- Consultants advising multiple organizations on Microsoft security tooling and governance
- IT leaders who need a vendor-recognized way to validate strategic security knowledge
Because the exam assumes hands-on familiarity with Microsoft Entra, Defender, Purview, and Azure security tooling, it is rarely someone's first Microsoft certification. Most candidates arrive already holding - or actively working toward - one of the associate-level exams that also serve as prerequisites for the expert credential. If you want a full breakdown of what "eligible" actually means here, see SC-100 Requirements 2026.
Exam Format and Registration Mechanics
SC-100 registration and delivery mechanics are straightforward but worth knowing before you book anything:
- Delivery: Pearson VUE, at a test center or online proctored
- Fee: $165 USD in the United States, before tax, before any Microsoft Certified Trainer or Microsoft Partner Network discount
- Scoring: 100 to 1000 scale; 700 or greater passes
- Length: a 120-minute appointment, typically containing 40 to 60 questions
- Question types: multiple choice, multiple response, drag-and-drop, hot area, yes/no series, and full case studies
The case study format deserves extra attention. You'll read a multi-paragraph scenario describing an organization's current environment, its regulatory obligations, and its stated goals, then answer several questions that reference that same scenario. There's no shortcut around reading comprehension here - the correct answer is often the one that satisfies a constraint buried in paragraph three, not the technically "best" security control in isolation.
Key Takeaway
Budget your 120 minutes with case studies in mind: skim the entire scenario once before answering any attached questions, since later questions sometimes clarify earlier ambiguity.
For a granular look at exactly how the 700 threshold works and what it means in practice, read SC-100 Passing Score 2026. And if cost planning matters to your decision (discounts, retake fees, bundle options), SC-100 Certification Cost 2026 breaks down the full pricing picture.
The Four SC-100 Domains
SC-100 is organized into four domains. Two of them - operations/identity/compliance and infrastructure - together make up 50 to 60 percent of the exam, so your study time should not be split evenly four ways.
Domain 1: Design solutions that align with security best practices and priorities (20-25%)
This domain covers Zero Trust strategy, governance frameworks, and how to translate business risk into a coherent security roadmap.
- Zero Trust principles applied across identity, network, and data
- Aligning security strategy with regulatory and compliance requirements
- Evaluating security posture using Microsoft Security Exposure Management attack paths
Domain 2: Design security operations, identity, and compliance capabilities (25-30%)
This is one of the two heaviest domains. It blends SecOps design (SIEM/XDR strategy), identity architecture, and governance/compliance design.
- Designing centralized logging and auditing, including Microsoft Purview Audit
- Identity governance, privileged access strategy, and agent identity design with Microsoft Entra Agent ID
- Incident response and security operations integration patterns
Domain 3: Design security solutions for infrastructure (25-30%)
The other heavyweight domain, covering hybrid and multi-cloud infrastructure security design.
- Network security architecture across on-premises, hybrid, and multi-cloud
- Securing compute, containers, and DevOps pipelines
- Designing for resilience, including backup and recovery strategy
Domain 4: Design security solutions for applications and data (20-25%)
This domain focuses on application security design and, increasingly, AI-specific data protection.
- Application security lifecycle and API protection strategy
- A strategy for secure AI adoption across the organization
- AI workload data security design considerations
For a domain-by-domain study plan with more granular subtopics and Microsoft Learn mappings, see SC-100 Exam Domains 2026: Complete Guide to All 4 Content Areas.
| Domain | Weight | Core Focus |
|---|---|---|
| 1. Best practices & priorities | 20-25% | Zero Trust strategy, governance, exposure management |
| 2. Ops, identity, compliance | 25-30% | SecOps design, identity governance, Purview Audit, agent identity |
| 3. Infrastructure | 25-30% | Hybrid/multi-cloud network and compute security |
| 4. Applications & data | 20-25% | App security lifecycle, AI adoption strategy, AI data security |
Prerequisites and the Credential You Actually Earn
Here's a detail that trips up a lot of candidates: passing SC-100 by itself does not award any certification. To earn Microsoft Certified: Cybersecurity Architect Expert, you need an active associate-level prerequisite in addition to SC-100 - specifically one of:
- SC-200 (Security Operations Analyst)
- SC-300 (Identity and Access Administrator)
- AZ-500 (Azure Security Engineer)
This structure is intentional. Microsoft wants architects who have already demonstrated depth in at least one operational specialty before they're certified to design across all of them. If you haven't sorted out your prerequisite path yet, SC-100 Requirements 2026: Eligibility, Prerequisites & How to Qualify walks through how to choose between the three options based on your background.
What Changed in the Latest Skills-Measured Update
The skills measured on SC-100 aren't static. The current version took effect July 28, 2026, following earlier refreshes in November 2025 and April 2026. Most exam content still reflects generally available (GA) Microsoft features, though commonly used preview features can also appear - so "it's still in preview" is not a safe reason to skip a topic if it's already widely deployed.
The most recent refresh specifically added:
- Agent identity design using Microsoft Entra Agent ID - relevant as organizations deploy autonomous AI agents that need their own governed identities
- A strategy for secure AI adoption, spanning governance, data boundaries, and risk acceptance for AI workloads
- AI workload data security considerations, distinct from traditional application data protection
- Microsoft Purview Audit for centralized logging across Microsoft 365 and Azure services
- Microsoft Security Exposure Management attack paths, used to reason about posture and prioritize remediation
If you studied from older material or a friend's notes from a prior version of the exam, these five areas are the ones most likely to be missing. Cross-check your prep against a current source - our SC-100 Cheat Sheet 2026 is kept aligned to the current skills-measured document specifically so you can spot gaps quickly.
How to Sequence Your Study Around the Domains
Generic study advice - spaced repetition, timed practice, flashcards - works for any exam. What matters more for SC-100 is sequencing, because the domains build on each other and two of them dominate the weighting.
Domain 1 foundations
- Zero Trust principles and how Microsoft frames them across identity, network, endpoint, and data
- Exposure Management attack path concepts as a way to talk about risk, not just controls
Domain 2 (heaviest weight)
- SecOps and SIEM/XDR design patterns
- Identity governance, PIM, and agent identity design with Entra Agent ID
- Purview Audit and centralized logging design
Domain 3 (heaviest weight)
- Hybrid and multi-cloud network security architecture
- Container, DevOps, and compute security design
- Resilience and recovery strategy
Domain 4 and case study drills
- Application security lifecycle and AI adoption strategy
- AI workload data security
- Full-length case study practice under timed conditions
This isn't a rigid calendar - some candidates with strong identity backgrounds will compress Domain 2, while infrastructure specialists may need less time on Domain 3. The point is to allocate study hours roughly proportional to exam weight rather than treating all four domains equally. Our SC-100 Study Guide 2026: How to Pass on Your First Attempt expands this into a full week-by-week plan with resource recommendations, and How Hard Is the SC-100 Exam? Complete Difficulty Guide 2026 explains why the case-study format catches people off guard even when they know the content cold.
Maintaining the Certification
Once you've earned the Cybersecurity Architect Expert credential, it doesn't last forever without upkeep. The certification expires annually, but renewal is free and done through an unproctored online assessment on Microsoft Learn - there's no need to retake SC-100 itself or pay another exam fee just to stay current. Set a calendar reminder well before the expiration date, since Microsoft Learn renewal assessments become available a set window before expiry, and letting the certification lapse means starting the full exam process over.
Microsoft doesn't publish pass rates for SC-100, so treat any specific pass-rate number you see elsewhere with skepticism. For an honest, data-grounded discussion of what's actually knowable about difficulty and outcomes, see SC-100 Pass Rate 2026: What the Data Shows.
If you're still weighing whether the time and cost investment makes sense for your career stage, Is the SC-100 Certification Worth It? Complete ROI Analysis 2026 and SC-100 Salary Guide 2026 cover the career-impact side, while SC-100 Jobs looks at the kinds of roles that list this credential as a differentiator. Once you're ready to lock in a date, SC-100 Exam Dates 2026: Testing Windows, Deadlines & Scheduling covers scheduling logistics, and structured prep options are covered in SC-100 Training.
FAQ
SC-100 is Microsoft's expert-level Cybersecurity Architect exam, testing the ability to design security strategy across operations, identity, infrastructure, applications, and data rather than configure individual tools.
Not by itself. You also need an active associate-level certification - SC-200, SC-300, or AZ-500 - to earn the Microsoft Certified: Cybersecurity Architect Expert title.
It's a 120-minute Pearson VUE exam with roughly 40 to 60 questions, mixing multiple choice, multiple response, drag-and-drop, hot area, yes/no series, and full case studies, scored on a 100-1000 scale with 700 needed to pass.
The version effective July 28, 2026 added agent identity design with Microsoft Entra Agent ID, secure AI adoption strategy, AI workload data security, Microsoft Purview Audit, and Microsoft Security Exposure Management attack paths.
No. The credential expires annually but renews at no cost through an unproctored assessment on Microsoft Learn, not by retaking the SC-100 exam.