SC-100 logo
Focused certification exam prep
Start practice

What Is SC-100 Certification?

TL;DR
  • SC-100 is a Microsoft exam delivered via Pearson VUE, scored 100-1000, with 700 needed to pass.
  • Passing SC-100 alone does not grant the credential - you also need SC-200, SC-300, or AZ-500 active.
  • Domains 2 and 3 (security operations/identity/compliance and infrastructure) together carry 50-60% of the exam.
  • The current skills-measured version, effective July 28, 2026, added agent identity design with Microsoft Entra Agent ID and AI workload data security.

What Is SC-100 Certification?

Microsoft Cybersecurity Architect (SC-100) is an expert-level exam published by Microsoft and delivered through Pearson VUE, either at a physical test center or as an online proctored exam. It evaluates whether a candidate can design end-to-end security strategy across Zero Trust principles, governance, identity, infrastructure, and application/data workloads - not whether they can click through a portal. If you're wondering exactly what SC-100 is at a conceptual level, or want the plain-language version of what SC-100 means before committing to a study plan, those explainer pages are a good starting point. This article focuses specifically on how the certification is structured, priced, and scored.

Unlike associate-level Microsoft exams that test configuration steps, SC-100 leans heavily on scenario judgment. Questions describe an organization's current environment, constraints, and business goals, then ask what architecture, control, or recommendation best fits. That framing is the single biggest thing separating this exam from typical role-based certifications, and it's why generic exam-cramming approaches tend to underperform here.

Not a Standalone Badge: Passing the SC-100 exam does not by itself produce the Microsoft Certified: Cybersecurity Architect Expert credential. You also need an active associate-level prerequisite - SC-200, SC-300, or AZ-500 - held at the same time.

How the Credential Actually Works

Because SC-100 sits at the "expert" tier in Microsoft's certification structure, it is designed to be layered on top of an existing specialization rather than taken in isolation. That prerequisite requirement is one of the most misunderstood parts of the credential - plenty of candidates study for and pass the exam only to discover the certification itself hasn't been issued because their SC-200, SC-300, or AZ-500 has lapsed. If you're mapping out eligibility before you register, the detailed breakdown on SC-100 requirements walks through exactly how the prerequisite rule applies.

Once earned, the certification isn't permanent. It expires annually, but renewal is free and happens through an unproctored online assessment on Microsoft Learn rather than a full retake. That's a meaningfully lighter lift than re-sitting the proctored exam, and it reflects how quickly cloud security guidance changes - Microsoft expects architects to periodically confirm they're current, not to re-prove baseline competency every year.

Key Takeaway

Line up your associate prerequisite (SC-200, SC-300, or AZ-500) before or shortly after passing SC-100 - the exam pass alone doesn't trigger the credential.

Exam Format and Registration Details

SC-100 is priced at $165 USD in the United States before taxes, and before any discount that might apply for Microsoft Certified Trainers or Microsoft Partner Network members. That's the baseline registration cost through Pearson VUE - a full breakdown of what else factors into total spend, including retakes and renewal, is covered in the SC-100 certification cost guide.

Inside the 120-minute appointment, candidates typically see 40 to 60 questions. The format mixes several item types:

  • Multiple choice and multiple response
  • Drag-and-drop sequencing
  • Hot area selection
  • Yes/No statement series
  • Full case studies with multi-part questions tied to a single scenario

Scoring runs on a 100-to-1000 scale, and a candidate needs 700 or greater to pass. Microsoft doesn't publish the weighting formula behind that scale, and it doesn't release pass rates - if you want a realistic read on where candidates tend to struggle without invented statistics, see the SC-100 pass rate discussion and the deeper passing score breakdown.

Case Studies Matter: Because a meaningful share of questions attach to full case studies, misreading the scenario's constraints (budget, compliance obligation, existing tooling) early can cost you several questions in a row, not just one.

The Four SC-100 Domains

SC-100 is organized into four skills-measured domains. Two of them - operations/identity/compliance and infrastructure - carry the majority of the exam weight, so time allocation during prep should not be evenly split. For a question-by-question breakdown of what each domain actually tests, the SC-100 exam domains guide goes deeper than the summary below.

Domain 1: Design solutions that align with security best practices and priorities (20-25%)

Covers Zero Trust strategy, governance frameworks, and how security recommendations tie back to business risk and regulatory posture.

  • Translating business risk appetite into architectural guardrails
  • Zero Trust principles applied across identity, network, and data

Domain 2: Design security operations, identity, and compliance capabilities (25-30%)

The largest single domain. Expect scenario questions on SIEM/SOAR integration, identity governance, and compliance mapping.

  • Security operations strategy including incident response workflows
  • Identity and access architecture decisions
  • Regulatory compliance and Microsoft Purview-based governance

Domain 3: Design security solutions for infrastructure (25-30%)

Covers hybrid and multicloud infrastructure protection, network segmentation strategy, and workload-specific hardening decisions.

  • Multicloud and hybrid security architecture patterns
  • Network security segmentation and perimeter design choices

Domain 4: Design security solutions for applications and data (20-25%)

Focuses on securing the application development lifecycle and protecting sensitive data, including newer AI workload considerations.

  • DevSecOps and application security architecture
  • Data security strategy, including AI workload data protection
DomainWeightCore Focus
Best practices & priorities20-25%Zero Trust, governance, risk alignment
Security operations, identity, compliance25-30%SIEM/SOAR, identity, regulatory mapping
Infrastructure solutions25-30%Hybrid/multicloud, network segmentation
Applications & data20-25%DevSecOps, data security, AI workloads

Who Hires for SC-100 Skills

The people pursuing this credential are typically already working in security - think security engineers moving into architecture roles, cloud security leads, and consultants who advise organizations on Microsoft-centric Zero Trust adoption. Because the exam assumes fluency with an associate-level specialization already, employers reading this credential on a resume generally interpret it as a signal of design-level maturity, not entry-level knowledge. If you're evaluating whether the investment fits your career trajectory, the SC-100 jobs overview and the broader ROI analysis lay out how the credential tends to be used in practice, and the salary guide discusses compensation trends without relying on invented numbers.

What's consistent across hiring conversations is that SC-100 rarely stands alone on a resume - it's almost always paired with the prerequisite specialization (identity, security operations, or infrastructure) that shaped how the candidate approached the architecture exam in the first place.

What Changed in the Latest Skills Refresh

Microsoft periodically refreshes the skills measured for SC-100, and the current version took effect July 28, 2026, following earlier refreshes in November 2025 and April 2026. Most exam content still targets generally available Microsoft features, though commonly used preview capabilities can show up as well - a nuance that catches candidates who assume everything on the exam is already fully released.

The most recent refresh introduced several topics that didn't exist in older prep material, so anyone using outdated study guides should treat these as must-know additions:

  • Agent identity design using Microsoft Entra Agent ID for governing autonomous and semi-autonomous AI agents
  • A strategy for secure AI adoption across the organization, not just individual model deployments
  • AI workload data security, extending traditional data protection thinking into generative AI pipelines
  • Microsoft Purview Audit for centralized logging across services
  • Microsoft Security Exposure Management attack paths, used to reason about lateral movement risk holistically
Refresh Risk: Study material published before mid-2026 may not mention Entra Agent ID or Security Exposure Management attack paths at all. Cross-check any resource's publish date against the July 28, 2026 skills-measured version.

Building a Domain-Aware Prep Schedule

Generic study techniques - timeboxing sessions, spaced repetition, explaining concepts aloud - genuinely help, but they only pay off when mapped onto SC-100's actual weight distribution. Since domains 2 and 3 together make up 50-60% of the exam, a schedule that spends equal time on all four domains is misallocating effort.

Week 1

Foundations and Domain 1

  • Review Zero Trust architecture principles and governance frameworks
  • Map business risk scenarios to architectural recommendations
Week 2

Domain 2 - the heaviest domain

  • Study security operations, identity governance, and Purview-based compliance
  • Practice case studies involving incident response design
Week 3

Domain 3 - infrastructure

  • Work through multicloud and hybrid segmentation scenarios
  • Review Security Exposure Management attack path concepts
Week 4

Domain 4 and refresh topics

  • Cover DevSecOps and application security patterns
  • Study AI workload data security and Entra Agent ID design

For a structured walkthrough that goes well beyond this outline, the SC-100 study guide covers pacing strategy in more depth, and if you're still calibrating how demanding this exam actually is relative to your background, how hard the SC-100 exam is breaks that down honestly. Once you've covered the domains, running full-length scenario practice on our SC-100 practice test platform is one of the most direct ways to get comfortable with the case-study format before appointment day. Many candidates also keep a condensed reference like the SC-100 cheat sheet open during final review to reinforce terminology introduced in the latest refresh.

Before you book anything, it's worth double-checking testing windows and blackout considerations on the SC-100 exam dates page, since scheduling around a busy work period can undermine even a well-planned four-week schedule. And if formal instruction fits your learning style better than self-study, structured SC-100 training options can compress the domain 2 and domain 3 learning curve considerably. Practicing scenario-based questions repeatedly on the main practice test site is also the fastest way to get a feel for how Microsoft phrases architectural trade-offs - reading about Zero Trust is different from choosing the right answer under a 120-minute clock.

Frequently Asked Questions

Is SC-100 a standalone certification?

No. Passing the SC-100 exam is necessary but not sufficient - you also need an active associate-level prerequisite (SC-200, SC-300, or AZ-500) to be awarded the Cybersecurity Architect Expert credential.

How is SC-100 scored?

Scores are reported on a scale from 100 to 1000, and a score of 700 or greater is required to pass.

What does the SC-100 exam cost?

The fee is $165 USD in the United States before taxes, and before any discount available to Microsoft Certified Trainers or Microsoft Partner Network members.

Does SC-100 expire?

Yes, the certification expires annually. It renews at no cost through an unproctored online assessment on Microsoft Learn rather than a full proctored retake.

What's new in the current version of the exam?

The skills-measured version effective July 28, 2026 added agent identity design with Microsoft Entra Agent ID, secure AI adoption strategy, AI workload data security, Microsoft Purview Audit, and Security Exposure Management attack paths.

Ready to pass your SC-100 exam?

Put this into practice with free SC-100 questions across every exam domain.