SC-100 is Microsoft’s expert-level Cybersecurity Architect exam. As of October 4, 2026, the live English exam still uses the skills measured as of July 28, 2026. Microsoft has already published a minor update that takes effect on October 21, 2026, but the four top-level domain weights remain unchanged. Candidates testing before October 21 should therefore prepare against the current July 28 outline, while candidates testing on or after that date should use the revised wording.
The current SC-100 blueprint has four weighted areas: Design solutions that align with security best practices and priorities at 20–25%; Design security operations, identity, and compliance capabilities at 25–30%; Design security solutions for infrastructure at 25–30%; and Design security solutions for applications and data at 20–25%. Microsoft requires a score of 700 or greater to pass.
The role begins with strategy, resilience and Zero Trust
The first domain asks architects to translate security priorities into enterprise capabilities. Current objectives include business resiliency, ransomware mitigation, secure backup/restore across hybrid and multicloud environments, security-update strategy and prioritization of privileged access.
The architect is expected to connect technical design with business-critical assets and continuity objectives, not merely select security products.
MCRA, MCSB, CAF and Well-Architected shape architecture decisions
The current guide explicitly references Microsoft Cybersecurity Reference Architectures, Microsoft Cloud Security Benchmark, Cloud Adoption Framework for Azure and Azure Well-Architected Framework. Candidates should understand how these sources guide security capabilities, cloud governance, landing zones and DevSecOps.
A SC-100 architecture perspective is strongest when frameworks are used to justify design choices rather than memorized as separate acronyms.
AI security is now embedded in the best-practices domain
The live outline includes secure AI adoption and AI solutions aligned with Microsoft Cloud Security Benchmark. The architect should consider data exposure, identity, model/application access, logging, governance and development controls around AI services.
AI security is treated as part of enterprise architecture rather than an isolated specialty.
Security operations, identity and compliance is 25–30%
Security operations covers XDR, SIEM, centralized logging/auditing, hybrid/multicloud monitoring, SOAR, incident response, threat hunting and MITRE ATT&CK coverage. Microsoft Sentinel and Microsoft Defender XDR appear as core platforms in this area.
The architect’s job is to design how telemetry, detection, investigation and automated response fit together across the environment.
Identity architecture now includes agent identities
The July 2026 outline explicitly includes Microsoft Entra Agent ID and Conditional Access for agent identities. It also covers SaaS/PaaS/IaaS/hybrid/multicloud access, Entra ID, external identities, decentralized identity, modern authentication, continuous access evaluation, risk scoring and protected actions.
A Conditional Access model is useful because SC-100 expects identity policy to align with Zero Trust rather than become a list of independent authentication features.
Privileged access is a distinct architectural problem
Current objectives include the enterprise access model, Entra PIM, entitlement management, access reviews, Active Directory resilience, cloud-tenant administration, cloud infrastructure entitlement management and secure privileged workstations/remote access.
Privileged access should therefore be designed as a separate security tier with stronger controls, reduced standing permissions and more rigorous monitoring.
Compliance design uses Purview, Azure Policy and Defender for Cloud
Candidates should translate regulatory requirements into controls, design Microsoft Purview solutions, use Azure Policy for security/compliance requirements and validate alignment with standards/benchmarks through Microsoft Defender for Cloud.
The exam distinguishes compliance evidence and governance from technical detection. These tools can cooperate but solve different architectural needs.
Infrastructure security is 25–30%
This domain includes security posture management in hybrid/multicloud environments, Defender for Cloud, Microsoft Secure Score, Azure Arc, Defender EASM and Microsoft Security Exposure Management attack paths, security insights and initiatives.
A Defender for Cloud perspective is important because posture management now goes beyond isolated recommendations into attack-path and exposure-aware prioritization.
Endpoints, workloads, networks and SSE are all in scope
SC-100 covers server/client endpoint baselines, mobile devices, IoT/embedded systems, OT/ICS with Defender for IoT, SaaS/PaaS/IaaS baselines, containers, orchestration, web workloads and Azure AI services. Network-security objectives include Microsoft Entra Internet Access and Microsoft Entra Private Access as Security Service Edge capabilities.
The architect must connect identity, device, workload and network controls into one Zero Trust design rather than rely on a perimeter-only model.
Applications and data make up the final 20–25%.
This domain covers Microsoft 365 security posture, Defender for Office 365, Defender for Cloud Apps, Intune, Purview and Copilot for Microsoft 365 data security/compliance. Application security includes threat modeling, secure lifecycle strategy, development standards, workload identities, API security and Azure WAF.
Data security includes discovery/classification, encryption at rest/in transit, Key Vault, infrastructure encryption, data used in AI workloads, Azure SQL/Synapse/Cosmos DB, Azure Storage and Defender for Storage/Databases.
The October 21 update is minor but date awareness matters
Microsoft’s published change log says the October 21 update keeps the same four weighted domains and makes minor changes under security operations and Microsoft 365 security. That means most current July 28 preparation remains relevant, but candidates testing after October 21 should refresh those objective bullets from the live study guide.
The audience profile is itself a scope boundary. Microsoft expects candidates to have experience implementing or administering identity and access, platform protection, security operations, data and AI security, application security and hybrid/multicloud infrastructure, with expert depth in at least one area. SC-100 is therefore not an entry-level survey; it assumes you can reason across specialist domains from an architect’s perspective.
The resilience objective puts business-critical assets ahead of technology. If an organization cannot identify which services must recover first, it cannot design ransomware resilience effectively. Backup architecture, privileged-access isolation, recovery credentials and dependency mapping need to be tied to business-continuity objectives.
Security updates also appear in the best-practices domain because patching is an architecture concern at enterprise scale. Different platforms, maintenance windows, internet exposure and business criticality affect prioritization. The architect should design a governance and deployment model that keeps systems current without creating unacceptable operational risk.
The Microsoft Cloud Security Benchmark is broader than a single Azure configuration checklist. It provides security recommendations across identity, privileged access, data protection, asset management, logging, network security and other control families. SC-100 uses it as an architectural reference for evaluating cloud capabilities and control coverage.
Microsoft Cybersecurity Reference Architectures help candidates place controls and capabilities across enterprise scenarios. Rather than memorizing diagram shapes, understand why identity, endpoint, network, application, data, security operations and governance services are connected. The exam can describe an architecture gap without naming the reference architecture directly.
Cloud Adoption Framework and landing zones matter because security architecture has to scale into cloud governance. Management groups, subscriptions, identity, policy, networking and platform operations need consistent design. A secure landing zone creates guardrails and shared services before individual workloads multiply.
DevSecOps is also part of this strategy layer. Security requirements should enter planning, source control, build pipelines, infrastructure as code, testing and release workflows. The architect should design repeatable controls that developers can consume rather than rely on late manual review for every deployment.
The security-operations objectives expect architecture across SIEM, XDR and SOAR. SIEM centralizes/searches/correlates security data, XDR correlates detections across security domains and SOAR automates case or response workflows. One platform may overlap with another, so SC-100 questions focus on design goals rather than textbook product boundaries.
Centralized logging and auditing needs data-source design, retention, access control and compliance considerations. Collecting every log without purpose can be expensive and noisy. The architect should identify which events support detection, investigation, legal/audit or operational goals and how long they must remain available.
MITRE ATT&CK coverage is included so architects can evaluate whether detections map to meaningful adversary techniques across enterprise, mobile and ICS contexts. Coverage analysis can reveal blind spots, but “more detections” is not automatically better if they lack data quality, response ownership or business relevance.
Agent identities introduce a newer identity architecture problem. AI agents or autonomous workloads can require identities, permissions, Conditional Access-style controls, secrets and governance. An agent that can call enterprise APIs should not inherit broad human administrator permissions merely because it operates on behalf of a user.
External identities include B2B and decentralized-identity concepts because organizations collaborate beyond tenant boundaries. The architect should minimize unmanaged guest sprawl, design lifecycle/review, enforce appropriate authentication and understand which trust boundary the external user crosses.
Continuous access evaluation and risk scoring support decisions after initial sign-in. Zero Trust access should be able to respond when user, session or risk context changes rather than granting unconditional trust for a long-lived session. Protected actions add stronger policy around especially sensitive operations.
Active Directory Domain Services remains relevant because hybrid enterprises often retain on-premises identity. SC-100 expects architects to specify hardening requirements and consider resilience to common attacks, rather than assuming Entra ID eliminates legacy directory risk overnight.
Privileged Identity Management, entitlement management and access reviews solve related but different governance needs. PIM reduces standing privileged access through eligible/time-bound activation, entitlement management can package access for users/groups/resources and access reviews periodically validate whether permissions remain appropriate.
Cloud infrastructure entitlement management appears because multicloud permissions can become complex and excessive. The architecture should identify standing privileges, unused entitlements and cross-cloud access paths, then reduce permissions in ways consistent with operational needs.
Regulatory-compliance architecture should start by translating obligations into controls and evidence. Purview can address data/compliance concerns, Azure Policy can govern resource configuration and Defender for Cloud can assess posture against benchmarks. Choosing among them depends on what the requirement actually asks the organization to prove or enforce.
Security posture management now includes attack paths and external attack surface, not only isolated recommendation lists. Microsoft Security Exposure Management and Defender EASM can help identify how exposed assets and relationships combine into higher-risk paths. Architects should prioritize those paths against business-critical assets.
Endpoint requirements extend beyond Windows. The live guide explicitly mentions multiple server platforms, mobile devices/clients, IoT, embedded systems and OT/ICS. The architecture should define baseline, hardening, protection and management requirements appropriate to each device class rather than force one endpoint pattern everywhere.
Containers and orchestration appear because cloud-native workloads have image, registry, runtime, identity, network and secret risks distinct from ordinary VMs. The architect should design where scanning, admission policy, workload identity, network controls and runtime protection fit across the lifecycle.
Microsoft Entra Internet Access and Private Access bring Security Service Edge into the SC-100 infrastructure domain. Internet Access can secure web/Microsoft traffic and Private Access can provide identity-aware access to private applications. This supports a Zero Trust approach that does not treat network location as sufficient trust.
Microsoft 365 security is part of applications/data because collaboration workloads concentrate identity, email, files and sensitive content. Defender for Office 365, Defender for Cloud Apps, Intune, Purview and Secure Score contribute different parts of the posture. Copilot data-security/compliance controls add an AI-aware dimension to collaboration architecture.
Application security is explicitly lifecycle-focused. Threat modeling identifies design threats; secure development standards prevent recurring mistakes; workload identities avoid embedded secrets; API security protects programmatic interfaces; WAF adds runtime web protection. SC-100 favors a system of controls over a single perimeter appliance.
Data security spans discovery, classification, encryption, key management, databases, storage and AI use. Sensitive information can leak through application logs, prompts, training data or collaboration systems even when the database is encrypted. The architect needs a data-centric view across services.
Because the October 21 update keeps domain weights unchanged, candidates should not rebuild their entire plan two weeks before the change. Instead, keep current architecture concepts and refresh the changed security-operations and Microsoft 365 bullets once the new version becomes live. Date awareness prevents both stale preparation and unnecessary churn.
Within the broader Microsoft certification path, SC-100 is an architecture exam: the strongest candidate can justify security design across identity, operations, infrastructure, applications, data, AI, GRC and multicloud environments while keeping business priorities and Zero Trust principles visible.