SC-100 is about to receive a minor update, focused on branding, without there really being any real additions or removals. This is good news for those of you who are already preparing for the exam and going through some of the content referenced below.

The biggest challenges I hear about from people who are preparing for this exam, or have attempted it, is that they usually encounter something that they aren’t aware of, or at least aren’t very familiar with it. This is usually a byproduct of perhaps having strong skills in some areas of the exam, but not necessarily having exposure to other things the exam includes.

The easiest example to illustrate this could be someone who works on Azure solutions, but with very little Microsoft 365 exposure, or vice versa, which is very common in some organisations. If we convert that into what you really should be doing with this exam is making sure you aren’t just looking at the exam descriptions for topics you should be aware of but also make sure you are looking closely at the MCRA diagrams to make sure there isn’t anything lurking that you may not be aware of.

Design solutions that align with security best practices and priorities (20–25%)

Design a resiliency strategy for ransomware and other attacks based on Microsoft Security Best Practices

Design solutions that align with the Microsoft Cybersecurity Reference Architectures (MCRA) and Microsoft cloud security benchmark (MCSB)

Design solutions that align with the Microsoft Cloud Adoption Framework for Azure and the Azure Well-Architected Framework

Design security operations, identity, and compliance capabilities (25–30%)

Design solutions for security operations

Design solutions for identity and access management

Design solutions for securing privileged access

Design solutions for regulatory compliance

Design security solutions for infrastructure (25–30%)

Design solutions for security posture management in hybrid and multicloud environments

Design solutions for securing server and client endpoints

Specify requirements for securing SaaS, PaaS, and IaaS services

Evaluate solutions for network security and Security Service Edge (SSE)

Design security solutions for applications and data (20–25%)

Evaluate solutions for securing Microsoft 365

Design solutions for securing applications

Design solutions for securing an organization’s data