SC-100 logo
Focused certification exam prep
Start practice

What Is SC-100?

TL;DR
  • SC-100 is Microsoft's expert-level exam for designing cybersecurity strategy, not a hands-on configuration test.
  • Passing requires a scaled score of 700 or higher out of 1000, delivered via Pearson VUE for $165 USD.
  • Domains 2 and 3 together carry 50-60% of exam weight, making them the priority for study time.
  • SC-100 alone doesn't grant the certification - you also need SC-200, SC-300, or AZ-500 as a prerequisite.

What SC-100 Actually Is

SC-100 is the exam code for Microsoft Cybersecurity Architect, an expert-level Microsoft certification exam owned and published by Microsoft. It's built for security professionals who already understand individual security domains - identity, cloud infrastructure, operations, applications - and now need to design a coherent security strategy across all of them. Instead of asking "how do you configure this setting," SC-100 asks "what architecture would you recommend and why."

This distinction matters more than most candidates expect. If you've spent your career in hands-on security engineering roles, the shift to architectural reasoning can feel unfamiliar even when you know the underlying technology cold. For a deeper breakdown of why that shift trips people up, see How Hard Is the SC-100 Exam? Complete Difficulty Guide 2026.

Not a Standalone Badge: Passing SC-100 doesn't hand you a certification by itself. It's one piece of the Microsoft Certified: Cybersecurity Architect Expert credential, which also requires an active associate-level prerequisite. More on that below.

Exam Format, Fee, and Registration

SC-100 is delivered through Pearson VUE, either at a physical test center or as an online proctored exam from your own location. In the United States, the fee is $165 USD before taxes, and before any discount that might apply through the Microsoft Certified Trainer program or Microsoft Partner Network membership. For a full pricing breakdown including how those discounts and regional pricing can shift the total, see SC-100 Certification Cost 2026: Complete Pricing Breakdown.

Inside the 120-minute appointment, candidates typically encounter 40 to 60 questions in a mix of formats: multiple choice, multiple response, drag-and-drop, hot area, yes/no series, and full case studies that present a fictional organization's environment and ask you to make several linked design decisions about it. Case studies are where the "architect" framing really shows up - you're evaluating trade-offs across cost, compliance, and risk rather than picking the technically "correct" single answer.

Scoring uses Microsoft's standard 100-to-1000 scale, and you need 700 or greater to pass. Microsoft does not publish official pass rates for SC-100, so treat any specific percentage you see elsewhere with skepticism - for a grounded look at what's actually knowable about difficulty and outcomes, read SC-100 Pass Rate 2026: What the Data Shows.

Key Takeaway

Because SC-100 leans on case studies and scenario judgment rather than command syntax, memorizing portal steps won't get you to 700. Practice reasoning through trade-offs instead.

The Four SC-100 Domains

Microsoft organizes SC-100 into four skills-measured domains. Two of them together account for roughly half to more than half of the exam, so understanding the weighting is as important as understanding the content.

Domain 1: Design solutions that align with security best practices and priorities (20-25%)

Covers Zero Trust strategy, security posture evaluation, and translating business priorities into architectural decisions.

  • Aligning recommendations with frameworks like MCRA and MCSB
  • Building strategy around ransomware resilience and incident readiness

Domain 2: Design security operations, identity, and compliance capabilities (25-30%)

The largest single domain, spanning SecOps architecture, identity design, and regulatory compliance posture.

  • SIEM/SOAR integration patterns and logging strategy
  • Identity governance, conditional access, and now agent identity design

Domain 3: Design security solutions for infrastructure (25-30%)

Focuses on hybrid and multicloud infrastructure protection, network security, and workload segmentation.

  • Landing zone and segmentation strategy across Azure and hybrid environments
  • Attack path analysis using Microsoft Security Exposure Management

Domain 4: Design security solutions for applications and data (20-25%)

Covers application security lifecycle design and data protection, including newer AI-specific data risks.

  • DevSecOps integration and application threat modeling
  • AI workload data security and secure AI adoption strategy

Domains 2 and 3 together make up 50-60% of the exam, so a study plan that treats all four domains as equal weight is misallocating time. For the complete breakdown of subtopics inside each domain, see SC-100 Exam Domains 2026: Complete Guide to All 4 Content Areas.

DomainWeightCore Focus
Domain 120-25%Best practices and strategic alignment
Domain 225-30%SecOps, identity, compliance
Domain 325-30%Infrastructure security architecture
Domain 420-25%Application and data security

Who Takes SC-100 and Why

SC-100 is aimed at security architects, senior security engineers, and consultants who advise organizations on cloud and hybrid security design rather than only operating tools day to day. It's common among people already working in Azure-heavy environments who want a credential that reflects strategic, cross-domain expertise instead of a single product specialty.

Because it sits at the top of Microsoft's security certification stack, organizations often use it as a signal that someone can own security architecture decisions, not just execute a runbook. Whether that translates into concrete hiring or pay advantages depends heavily on role and market - for an honest look at both sides, see Is the SC-100 Certification Worth It? Complete ROI Analysis 2026 and SC-100 Salary Guide 2026: Complete Earnings Analysis. If you're browsing openings that specifically call it out, SC-100 Jobs covers the kinds of titles where it appears.

What Changed in the Latest Refresh

The current skills-measured version of SC-100 took effect July 28, 2026, following earlier refreshes in November 2025 and April 2026. Microsoft updates SC-100 periodically to keep pace with how its security stack evolves, and most exam questions still cover generally available features - though commonly used preview features can and do show up.

The most recent refresh introduced several notable additions:

  • Agent identity design using Microsoft Entra Agent ID, reflecting the rise of AI agents as first-class identities needing governance
  • Strategy for secure AI adoption, positioning AI rollout as a security architecture decision, not just an application feature
  • AI workload data security, extending data protection thinking into AI pipelines and model interactions
  • Microsoft Purview Audit for centralized logging across the environment
  • Microsoft Security Exposure Management attack paths, bringing exposure-based risk visualization into infrastructure design

If you studied from older material, these are the areas most likely to catch you off guard. Cross-reference your prep against a current source rather than assuming last year's notes still map cleanly - the SC-100 Exam Dates 2026: Testing Windows, Deadlines & Scheduling guide is useful for confirming which version of the exam you'll actually sit for based on when you register.

AI Topics Aren't Optional: Agent identity and AI workload data security aren't niche add-ons - they now sit inside Domains 2 and 4, which together carry a substantial share of exam weight. Skipping them is a real scoring risk.

SC-100 vs. the Full Certification

One of the most misunderstood mechanics of SC-100 is that passing it does not, by itself, award a credential. To earn the Microsoft Certified: Cybersecurity Architect Expert title, you need an active associate-level prerequisite in addition to a passing SC-100 score - specifically one of SC-200, SC-300, or AZ-500. If you already hold one of those, SC-100 is the capstone exam. If you don't, you'll need to plan for both.

Once earned, the certification isn't permanent - it expires annually and is renewed at no cost through an unproctored online assessment on Microsoft Learn, so there's no retake fee involved in staying current year over year. For the full eligibility picture, including how the prerequisite requirement interacts with scheduling, see SC-100 Requirements 2026: Eligibility, Prerequisites & How to Qualify.

Key Takeaway

Check your prerequisite status before you book SC-100. Passing the exam without an active SC-200, SC-300, or AZ-500 means you still won't hold the Cybersecurity Architect Expert title.

How to Approach Preparation

Because SC-100 rewards judgment over recall, cramming facts the week before rarely works well. A more effective approach sequences study around the domain weights: spend early weeks building comfort with Domain 2 and Domain 3 content since they carry the most weight, then layer in Domain 1's strategic framing and Domain 4's application/data topics, and finish with case-study practice that forces you to combine all four.

Weeks 1-2

Identity, SecOps, and Compliance (Domain 2)

  • Study Zero Trust identity patterns and conditional access design
  • Review Microsoft Purview Audit and agent identity concepts
Weeks 3-4

Infrastructure Architecture (Domain 3)

  • Work through hybrid and multicloud segmentation scenarios
  • Practice reading Microsoft Security Exposure Management attack paths
Week 5

Strategy and Best Practices (Domain 1)

  • Map recommendations to Zero Trust and ransomware resilience frameworks
Week 6

Applications, Data, and Case Studies (Domain 4)

  • Focus on AI workload data security and DevSecOps integration
  • Run full case-study practice combining all four domains

For a more detailed week-by-week plan with resource recommendations, see SC-100 Study Guide 2026: How to Pass on Your First Attempt. And once you're confident in the material, running full-length practice questions on our SC-100 practice test platform is one of the fastest ways to find out whether you can actually apply concepts under case-study conditions, not just recognize them.

It's also worth memorizing the mechanics that have nothing to do with content: the 700-point passing threshold, the 120-minute window, and the fee structure. A quick reference like SC-100 Cheat Sheet 2026: One-Page Review of Must-Know Facts or SC-100 Passing Score 2026: Exactly What You Need to Pass can save you from avoidable surprises on exam day. If you'd like more practice reasoning through case-study style questions before booking your appointment, start with a full practice exam to gauge where you stand across all four domains.

FAQ

Is SC-100 a beginner certification?

No. It's an expert-level exam that assumes you already have hands-on security experience and typically an associate-level prerequisite like SC-200, SC-300, or AZ-500.

How many questions are on the SC-100 exam?

Candidates typically see 40 to 60 questions across a 120-minute appointment, including case studies, drag-and-drop, and yes/no series formats.

What score do I need to pass SC-100?

You need a scaled score of 700 or greater out of a possible 1000.

Does passing SC-100 automatically make me certified?

No. You also need an active associate-level prerequisite - SC-200, SC-300, or AZ-500 - to earn the Microsoft Certified: Cybersecurity Architect Expert credential.

Do I need to renew SC-100 every year?

The resulting certification expires annually, but renewal is free and completed through an unproctored online assessment on Microsoft Learn.

Ready to pass your SC-100 exam?

Put this into practice with free SC-100 questions across every exam domain.