ZYBIM TECHNOLOGIES. CYBER · INFORMATION · MANAGEMENT
Learn · Certify · Advance

The Microsoft Security Certification Roadmap

Whether you're securing your own organisation or building a career in security, Microsoft's certifications map a clear path from fundamentals to specialist. Here's the route, what each step covers, and how to prepare.

Microsoft security certifications follow a logical progression: start with the SC-900 fundamentals to build the vocabulary, then branch into a role-based associate certification for your specialism, and finally reach expert level. Every exam is taken through Pearson VUE or the Microsoft Learn portal. Prices below are US standard rates for 2026 and vary by region.

BEFORE YOU SPEND A RUPEE OR DOLLAR

How to get ready — for free — before you book an exam

You don't need to pay for a course to start. Microsoft's own learning platform is free, thorough, and written by the people who set the exams. Here's a practical way to prepare before you spend anything — so that when you do pay for an exam (or a prep course), you're ready to pass first time.

1 · Start with Microsoft Learn (free)

Every certification below links to its official Microsoft Learn path — free, self-paced modules with hands-on labs. Work through the full learning path for your target exam before anything else. It's the single best free resource, and it maps exactly to the exam objectives.

2 · Read the exam skills outline

Each exam has an official "skills measured" document listing exactly what's tested and the weighting of each area. Download it, and use it as your checklist — focus your time on the highest-weighted topics you're least confident in.

3 · Get hands-on free

Sign up for a free Microsoft 365 Developer tenant and/or an Azure free account. Certifications reward people who've actually clicked through the portals — Entra, Defender, Purview, Sentinel. Practising in a real (free) tenant beats memorising slides.

4 · Take a free practice assessment

Microsoft publishes a free official practice assessment for most role-based exams, right on the certification page. Take it near the end of your prep — if you're scoring well there, you're ready to book. If not, you've found your gaps before paying for the exam.

When is a paid course worth it? If you learn better with structured video, or you've worked through Microsoft Learn and still feel shaky, a paid prep course (linked on each certification below) can be worth it — think of it as accelerating, not replacing, the free path. Book the exam only when the free practice assessment says you're ready.

The certification roadmap

Each step below links to its free official Microsoft Learn path. Paid prep-course links are optional accelerators.

FUNDAMENTALS · START HERE

Security, Compliance & Identity Fundamentals SC-900

Exam cost: ~$99 USDPrep time: 1–3 weeksPrerequisites: none

The entry point. SC-900 gives you the language of security, compliance and identity across Microsoft cloud services — covering security principles, Microsoft Entra ID, Microsoft Defender, Microsoft Sentinel and Microsoft Purview at a concept level. No hands-on configuration required.

Best for: anyone new to Microsoft security, plus non-security roles (sales, project managers, account managers) who need to speak the language. Also the natural first rung for a security career.
What's on this exam — a 2-minute reference

Format: ~$99 USD · fundamentals level · no prerequisites · multiple-choice. The gentlest of the security certifications — concepts, not configuration.

What it covers (by weight)

  • Security, compliance & identity concepts (10–15%) — the shared-responsibility model, defence in depth, Zero Trust, common threats, and encryption basics.
  • Microsoft Entra & identity (25–30%) — what Entra ID is, authentication vs authorisation, MFA, Conditional Access, and identity protection at a conceptual level.
  • Microsoft security solutions (35–40%) — the Defender family, Microsoft Sentinel, and Secure Score — what each one is for.
  • Microsoft compliance solutions (20–25%) — Microsoft Purview, information protection, data governance, and the Service Trust Portal.
How to pass: it's a vocabulary and "what-is-this-for" exam — you're matching Microsoft products to the problems they solve. Work through the free Microsoft Learn path and take the official practice assessment; that's genuinely enough for most people.
ASSOCIATE · ROLE-BASED

Security Operations Analyst SC-200

Exam cost: ~$165 USDPrep time: 4–8 weeksPrerequisites: SC-900 recommended

The natural next step for SOC and incident-response work. SC-200 is hands-on with Microsoft Sentinel, Microsoft 365 Defender and Defender for Cloud — exactly the tools a working security operations analyst uses to detect, investigate and respond to threats. This is the certification behind the "Security Operations" assessment on our roadmap.

Best for: aspiring or current SOC analysts, incident responders, and anyone running detection and response in a Microsoft environment.
What's on this exam — a 2-minute reference

Format: pass 700/1000 · ~$165 USD · ~100–120 min · 40–60 questions (multiple-choice, drag-drop, case studies). Renews free yearly via a Microsoft Learn assessment. Scenario-based — it tests judgment, not recall.

What it covers (by weight)

  • Manage a security operations environment (40–45%) — configuring Microsoft Sentinel (data connectors, Log Analytics workspace, analytics rules, automation rules, playbooks, watchlists) and the Defender XDR portal.
  • Respond to security incidents (35–40%) — triage, investigate, contain and remediate across the Defender family; alerts vs incidents; attack disruption.
  • Perform threat hunting (20–25%) — advanced hunting with KQL, MITRE ATT&CK mapping, and hypothesis-driven investigation.

Concepts worth knowing cold

  • The Defender family — Endpoint (devices/EDR), Office 365 (email), Identity (on-prem AD), Cloud Apps (SaaS/CASB), Cloud (Azure/multicloud posture), all unified in Defender XDR.
  • Sentinel building blocks — connectors, analytics rules (scheduled, NRT, Fusion, anomaly), incidents vs alerts, automation rules vs playbooks, entity mapping.
  • KQL — you must read it fluently (where, summarize, project, join, ago) and know which table a log lives in; you won't write complex queries from scratch.
Exam logic: "reduce false positives" → tune/suppress, don't disable. "Automatically respond going forward" → automation rule + playbook. "Investigate across products" → Defender XDR unified incident. Know alert (one signal) vs incident (the case).
ASSOCIATE · ALTERNATIVE PATH

Identity & Access Administrator SC-300

Exam cost: ~$165 USDPrep time: 4–8 weeksPrerequisites: SC-900 recommended

Choose this instead of (or alongside) SC-200 if your focus is identity. SC-300 covers Microsoft Entra ID in depth — identity governance, conditional access, authentication methods, and access management. Given that identity is the number-one attack surface, this is a high-value specialism.

Best for: identity and access administrators, and anyone whose security work centres on Entra ID and conditional access.
What's on this exam — a 2-minute reference

Format: pass 700/1000 · ~$165 USD · ~100–120 min · 40–60 questions (multiple-choice, drag-drop, case studies). Renews free yearly. Scenario-based — favours "least privilege" and "least effort" answers.

What it covers (by weight)

  • Implement & manage user identities (20–25%) — Entra ID, hybrid identity sync (Password Hash Sync, Pass-Through Auth, Federation), external identities (B2B/B2C).
  • Authentication & access management (25–30%) — MFA methods, the authentication-methods policy, SSPR, and Conditional Access (the single most-tested topic) and Identity Protection.
  • Workload identities (20–25%) — app registrations vs enterprise apps/service principals, delegated vs application permissions, managed identities.
  • Identity governance (20–25%) — PIM (just-in-time access), entitlement management/access packages, access reviews, lifecycle workflows.

Concepts worth knowing cold

  • Conditional Access — signals → decisions → enforcement; always test new policies in report-only mode first; keep break-glass accounts excluded.
  • PIM — eligible (must activate) vs active assignment; use it whenever a scenario says "without standing/permanent access."
  • App registration vs enterprise app vs service principal — distinguish these every time you see "application" in a question.
  • User risk (compromised credentials) vs sign-in risk (this sign-in looks suspicious).
Exam logic: if two answers work, pick the one needing fewer permissions (least privilege) or a built-in feature over custom scripting. "Before rolling out to everyone" → report-only mode or a pilot group.
ASSOCIATE · AZURE WORKLOADS

Azure Security Engineer AZ-500

Exam cost: ~$165 USDPrep time: 6–10 weeksPrerequisites: Azure fundamentals + experience

The certification for securing Azure workloads — managing identity and access, platform protection, security operations, and securing data and applications across Azure. If your organisation runs infrastructure in Azure (the focus of our Cloud Infrastructure assessment), this is the credential that proves you can secure it.

Best for: Azure administrators and engineers responsible for securing cloud infrastructure, and consultants delivering Azure security work.
What's on this exam — a 2-minute reference

Format: pass 700/1000 · ~$165 USD · associate level · scenario-based. Renews free yearly. Hands-on with the Azure portal — think "what would I configure here?"

What it covers (by weight)

  • Manage identity & access (25–30%) — Entra ID for Azure workloads, Conditional Access, PIM, managed identities, and securing Azure AD DS.
  • Secure networking (20–25%) — NSGs, Azure Firewall, WAF, DDoS protection, Private Link/Private Endpoints, and network segmentation.
  • Secure compute, storage & databases (20–25%) — VM/container hardening, Key Vault, storage encryption and access, and SQL/database security.
  • Manage security operations (25–30%) — Microsoft Defender for Cloud (Secure Score, CSPM, workload protection), Azure Policy governance, and Sentinel basics.
Exam logic: prefer native/managed Azure capabilities over custom builds; use Key Vault for secrets (never hardcode); apply governance at the right scope with Azure Policy and management groups. Practising in a free Azure account matters more here than for the fundamentals exam.
EXPERT · ARCHITECTURE

Cybersecurity Architect SC-100

Exam cost: ~$165 USDPrep time: 8–12 weeksPrerequisites: an associate cert (SC-200/300/AZ-500)

The expert tier. SC-100 is about designing security strategy — Zero Trust architecture, governance, risk and compliance, and securing infrastructure, applications and data at an organisational level. This is the architect's credential, earned after you have hands-on associate-level certification.

Best for: senior security professionals moving from administration into security architecture and strategy.
What's on this exam — a 2-minute reference

Format: pass 700/1000 · ~$165 USD · expert level · you must already hold SC-200, SC-300 or AZ-500. This is a "given this business constraint, which design is right?" exam — not "how do I configure X."

What it covers (by weight)

  • Design solutions aligned with best practices (20–25%) — Zero Trust strategy and Microsoft's reference frameworks (MCRA, CAF, WAF).
  • Design security operations, identity & compliance (25–30%) — org-wide Conditional Access, SIEM/SOAR strategy, and GRC mapped to Purview Compliance Manager and Defender for Cloud.
  • Design infrastructure security (25–30%) — Zero Trust networking, multicloud/hybrid via Defender for Cloud, and the shared-responsibility model.
  • Design application & data security (20–25%) — secure SDLC (threat modelling), secrets management, data classification/DLP, and emerging AI/Copilot security.

Concepts worth knowing cold

  • Zero Trust — verify explicitly, least-privilege access, assume breach. When two options tie, pick the one that verifies explicitly and assumes breach.
  • The frameworks — MCRA (technical architecture), CAF (adoption), WAF (workload design). Name-drop familiarity is enough.
  • Scope words matter — "across the organisation / at scale / all subsidiaries" → a policy or framework-level design, not a one-off config (that's a trap answer at this level).
Exam logic: identify the business driver first (cost, compliance, risk, time-to-value) — it usually eliminates half the options. If AWS/GCP/on-prem is mentioned, cross out any Azure-only answer. Think "what would a CISO defend to a board," not "what would an engineer configure."

Certifications prove knowledge — assessments prove your posture. While you build your team's skills, see where your Microsoft environment actually stands today, free.

Run the free security assessment

Some course links above are affiliate links: if you enrol through them, Zybim may earn a commission at no extra cost to you. We only recommend Microsoft's official learning paths (always free) and reputable training platforms. Exam fees are paid directly to Microsoft/Pearson VUE and are not affiliate-linked. Prices and exam details are current as of 2026 — always confirm on Microsoft Learn before booking.