SC-100 Study Guide
A curated learning path for the SC-100 exam: the best documentation, videos, blog posts and tutorials for every exam objective.A curated learning path for the SC-100 exam: the best documentation, videos, blog posts and tutorials for every exam objective, in the order worth studying them.
Microsoft Certified: Cybersecurity Architect Expert
Exam at a Glance
SC-100 measures whether you can work as a cybersecurity architect: translating an organization's security strategy into concrete designs and recommendations across identity, infrastructure, applications, data, AI, and security operations, always following Zero Trust principles. It is a design exam: you will weigh requirements and choose between capabilities, not click through portals.
| SC-100 | Microsoft Cybersecurity Architect |
|---|---|
| Certification | Microsoft Certified: Cybersecurity Architect Expert |
| Level | Expert (the capstone of the Microsoft security certification track) |
| Prerequisite | At least one of: Identity and Access Administrator Associate (SC-300), Security Operations Analyst Associate (SC-200), or Cloud and AI Security Engineer Associate (SC-500), required in addition to passing SC-100 |
| Exam length | 100 minutes |
| Questions | Typically 40 to 60; the number and format mix can vary |
| Passing score | 700 out of 1000 |
| Question formats | Multiple choice, multiple select, drag and drop, build list, hot area, case studies |
| Microsoft Learn access | Available within the exam; browsing is restricted and the timer continues |
| Skills measured version | July 28, 2026 |
| Renewal | Certification expires annually; renew with a free online assessment on Microsoft Learn |
| Cost | Depends on your country or region; shown when you schedule |
What the Exam Covers
The exam has four domains with nearly even weights: the two "design for infrastructure" and "operations, identity, and compliance" domains carry slightly more. Every domain asks the same underlying question: given business requirements, which Microsoft security capability or framework do you recommend, and why?
Design solutions that align with security best practices and priorities — 20-25%
Resiliency strategy for ransomware and other attacks (business-critical asset prioritization, BCDR and secure backup, privileged access), the framework layer: Microsoft Cybersecurity Reference Architectures (MCRA), Microsoft Cloud Security Benchmark (MCSB) including AI workload alignment, the Zero Trust adoption framework, the Cloud Adoption Framework (CAF) including a strategy for secure AI adoption, the Azure Well-Architected Framework, Azure landing zones, and DevSecOps process design.
Design security operations, identity, and compliance capabilities — 25-30%
Security operations design (XDR plus SIEM with Microsoft Defender XDR and Microsoft Sentinel, SOAR, centralized logging and auditing, MITRE ATT&CK coverage), identity and access management (Microsoft Entra ID in hybrid and multicloud environments, agent identities with Microsoft Entra Agent ID, Conditional Access, external identities, AD DS hardening, secrets and key management), privileged access (the enterprise access model, PIM, entitlement management, access reviews, secure admin workstations), and regulatory compliance design with Microsoft Purview, Azure Policy, and Microsoft Defender for Cloud.
Design security solutions for infrastructure — 25-30%
Security posture management in hybrid and multicloud environments (Defender for Cloud with MCSB, Secure Score, Azure Arc, Defender External Attack Surface Management, Microsoft Security Exposure Management attack paths), server and client endpoint security requirements (baselines, mobile, IoT, OT/ICS with Microsoft Defender for IoT, Windows LAPS), SaaS/PaaS/IaaS service baselines including containers and Azure AI services, and network security with Security Service Edge (Microsoft Entra Internet Access and Microsoft Entra Private Access).
Design security solutions for applications and data — 20-25%
Securing Microsoft 365 (Secure Score, Defender for Office 365, Defender for Cloud Apps, Intune, Purview, data security for Microsoft Copilot for Microsoft 365), application security (threat modeling, secure development lifecycle, workload identities, API management, Azure Web Application Firewall), and data security design (discovery and classification, encryption at rest and in transit, security for data used in AI workloads, Azure SQL, Azure Storage, Defender for Storage and Defender for Databases).
The full bullet-level list lives in the official study guide. Treat it as your checklist:
The Official SC-100 Study Guide
How This Maps to CertiAce Practice Modules
The CertiAce question bank is organized by the same four learning paths Microsoft uses for the SC-100 course, which match the four exam domains one to one, so every practice module maps directly to a scored domain:
| CertiAce practice module | What you will drill there |
|---|---|
| Design solutions that align with security best practices and priorities | Ransomware resiliency, BCDR, MCRA/MCSB/CAF/Well-Architected framework selection, Zero Trust adoption, landing zones, DevSecOps, secure AI adoption |
| Design security operations, identity, and compliance capabilities | XDR + SIEM architecture, SOAR, Conditional Access and Entra design, agent identities, privileged access, compliance tooling choices |
| Design security solutions for infrastructure | Posture management across clouds, Exposure Management, endpoint and OT/ICS requirements, service baselines, Security Service Edge |
| Design security solutions for applications and data | Microsoft 365 security evaluation, Copilot data security, application security lifecycle, WAF and API design, data protection for Azure workloads and AI |
Where SC-100 Fits
| Certification | What it validates | When to take it |
|---|---|---|
| SC-900: Security, Compliance, and Identity Fundamentals | The vocabulary of Microsoft security, a gentle on-ramp | Optional first step if you are new to Microsoft security |
| SC-300: Identity and Access Administrator Associate | Deep hands-on skill in identity and access management | Before SC-100: one of the three qualifying associate certifications |
| SC-200: Security Operations Analyst Associate | Deep hands-on skill in security operations, detection, and response | Before SC-100: one of the three qualifying associate certifications |
| SC-500: Cloud and AI Security Engineer Associate | Deep hands-on skill in cloud and AI security engineering | Before SC-100: one of the three qualifying associate certifications |
| SC-100: Cybersecurity Architect Expert (this exam) | Designing and evaluating end-to-end security architecture | You are here: the capstone of the security track |
SC-100 is not an entry point. To become a Microsoft Certified: Cybersecurity Architect Expert you must earn at least one of the following in addition to passing this exam: Microsoft Certified: Identity and Access Administrator Associate (exam SC-300), Microsoft Certified: Security Operations Analyst Associate (exam SC-200), or Microsoft Certified: Cloud and AI Security Engineer Associate (exam SC-500). Any one of the three qualifies: you do not need all of them. Just as importantly, the exam assumes you have genuinely worked in at least one security discipline: it tests judgment built on experience, not memorized features.
Microsoft Certified: Cybersecurity Architect Expert
Before You Start
The exam assumes broad security experience with expert depth in at least one area. Check yourself against this table. Anything unfamiliar is where your preparation should start:
| Area | You should be comfortable with |
|---|---|
| Zero Trust principles | Verify explicitly, least privilege, assume breach, and what they mean in a real design decision |
| Identity and access | Microsoft Entra ID, Conditional Access, PIM and identity governance concepts, hybrid identity with AD DS |
| Security operations | What Microsoft Defender XDR and Microsoft Sentinel each do, how SIEM/XDR/SOAR fit together, incident response basics |
| Platform protection | Microsoft Defender for Cloud, security baselines, network security concepts, hybrid and multicloud (Azure Arc) awareness |
| Data and application security | Microsoft Purview at a high level, encryption options, how applications authenticate with workload identities |
Step-by-Step Study Plan
How long you need depends on where you start. Treat these estimates as planning guidance and adjust them to your starting knowledge and weekly study hours:
| Your starting point | Suggested prep time |
|---|---|
| Working in security architecture or design reviews today | 2 to 4 weeks |
| Strong in one security discipline, thinner across the rest | 4 to 8 weeks |
Step 1: Read the Official Study Guide
Skim the full skills-measured list once, and mark every bullet you could not confidently design a solution for. That marked-up list is your personal syllabus: everything else in this plan exists to clear it. Note how many bullets start with "design", "evaluate", or "recommend": that is the altitude the exam tests at.
Step 2: Schedule Your Exam
Choose a realistic target date after reviewing the skills list and your available study time. A date on the calendar turns studying into a countdown, so pick one using the prep-time table above and plan backwards from it.
Certification and Exam Details Page
Step 3: Work Through the Official Course Material
Complete the four SC-100 learning paths on Microsoft Learn: they match the four exam domains exactly. Each path ends with a case-study module: do not skip those, because any case studies on the real exam use the same analyze-requirements-then-design format.
Official Learning Path Course Page
Step 4: Study the Frameworks Like a Practitioner
A large share of SC-100 comes down to knowing which framework answers which question: MCRA for reference architectures, MCSB for prescriptive controls, CAF for adoption and governance, Well-Architected for workload design, the Zero Trust adoption framework for organizational rollout. Read each one's overview and practice articulating in one sentence when you would reach for it. That exact discrimination is what the exam rewards.
Step 5: Benchmark Your Knowledge
Use CertiAce to benchmark your readiness module by module. The practice modules map to the exam domains as shown above, so use the module mapping and the topics behind your missed questions to identify the skills-measured areas to revisit. Microsoft also offers a free official practice assessment. Aim for consistent performance across every module, not one lucky high score; if a topic is unstable, go back to the docs for that capability.
Step 6: Take the Exam
The day before, review only your weak topics: no brand-new material. On exam day, read each question for the requirements that discriminate: qualifiers like minimize cost, minimize administrative effort, or least privilege usually decide between two otherwise-plausible designs. Eliminate options that only satisfy half the requirements.
Worth knowing before you sit down:
- Microsoft Learn is available during the exam in a split screen. Use it to check details you genuinely need: the timer keeps running, and the exam is deliberately too long to look up every answer. Browsing is limited to Microsoft Learn itself (no Q&A, practice assessments, or profile), and personal notes and other websites are unavailable.
- You can take unscheduled breaks, but the clock keeps running and you cannot return to questions you already saw.
- Case studies lock when you leave them: finish each one before moving on, because you cannot revisit its questions afterwards.
- Try the exam sandbox beforehand so the question formats and interface hold no surprises: Exam Sandbox
Additional Learning Resources
| Resource | Type | Why it is useful |
|---|---|---|
| Free Official Practice Assessment | Practice | Microsoft's own question-style preview, free |
| Exam Readiness Zone: SC-100 | Video series | Microsoft Certified Trainer prep videos per exam domain |
| Microsoft Cybersecurity Reference Architectures | Docs hub | The MCRA diagrams the exam expects you to know how to use |
| Zero Trust Guidance Center | Docs hub | Zero Trust principles, the adoption framework, and deployment guidance |
| Microsoft Cloud Security Benchmark | Docs hub | The prescriptive control catalog behind posture and baseline questions |
| Microsoft Defender for Cloud documentation | Docs hub | Posture management, regulatory compliance, and workload protection (a heavy exam area) |
| Microsoft security documentation | Docs hub | The entry point to every security product doc the exam draws from |
| Security, compliance, and identity community hub | Community | Microsoft's official SCI community: announcements and discussions |
Realistic SC-100 exam-style questions with instant feedback and detailed explanations.
Practice SC-100 now