Updated September 2026: SC-200 is still active. Microsoft last updated the certification on July 28, 2026, and the English version of the exam gets a minor update on October 21, 2026, mainly to the data ingestion objectives (Microsoft). Separately, Microsoft retired the Azure Security Engineer Associate certification and its AZ-500 exam on August 31, 2026; its replacement is the Cloud and AI Security Engineer Associate (exam SC-500) (Microsoft, Microsoft).
Microsoft SC-200 is the exam for the Microsoft Certified: Security Operations Analyst Associate certification. It tests whether you can run a security operations center (SOC) on Microsoft’s tools: triage alerts and incidents in Microsoft Defender XDR, configure and tune Microsoft Sentinel, write KQL queries to hunt for threats, build detections and automate responses. If your organization runs on Microsoft 365 and Azure, this is the most job-relevant analyst certification you can earn.
This guide covers who SC-200 is for, the exam facts, the three skill areas, what the AZ-500 retirement means for you, the cost, a study plan, career value, and how SC-200 compares with CySA+, Security+ and the AWS Certified Security – Specialty exam. For the wider picture, see Best Cybersecurity Certifications in 2026.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Who SC-200 is for
- SOC analysts (tier 1 to tier 3) in organizations that use Microsoft Defender and Sentinel
- Incident responders and threat hunters who work in Microsoft environments
- Detection engineers who write analytics rules and KQL queries
- IT administrators moving into security operations in a Microsoft 365 shop
Microsoft rates the certification as intermediate. It expects familiarity with Microsoft security, compliance and identity products, Microsoft 365, Azure, Windows, Linux and mobile operating systems, and now AI agents and Copilots. There are no formal prerequisites.
SC-200 exam facts (2026)
| Item | Details |
|---|---|
| Certification | Microsoft Certified: Security Operations Analyst Associate |
| Exam | SC-200: Microsoft Security Operations Analyst |
| Status | Active; English version updated October 21, 2026 (minor changes) |
| Time | 100 minutes |
| Passing score | 700 or higher |
| Format | Proctored; may include interactive components |
| Price | $165 in the U.S.; the price depends on the country where you take it |
| Languages | English, Japanese, Chinese (Simplified and Traditional), Korean, French, German, Spanish, Portuguese (Brazil) and Italian |
| Renewal | Every 12 months, free, by passing an online renewal assessment on Microsoft Learn |
| Retakes | You can retake 24 hours after a first failed attempt; later retakes have longer waits |
Sources: Microsoft’s SC-200 certification page and SC-200 study guide (September 2026). Microsoft doesn’t publish a fixed question count; expect a mix of question types, possibly including case studies.
The three SC-200 skill areas
| Skill area | Weight | What it covers |
|---|---|---|
| Manage a security operations environment | 40–45% | Automation in Defender XDR and Sentinel (automation rules, playbooks, attack disruption), configuring Sentinel roles, retention and workbooks, ingesting data with connectors (Windows events via AMA, Syslog and CEF, Azure activity logs, threat indicators), and building detections mapped to MITRE ATT&CK |
| Respond to security incidents | 35–40% | Investigating and remediating alerts from Defender for Office 365, Endpoint, Identity, Cloud Apps and Cloud, Microsoft Purview and Entra ID; investigating incidents with Security Copilot; live response on devices; and investigating Microsoft 365 activity with Purview Audit, eDiscovery and Graph activity logs |
| Perform threat hunting | 20–25% | KQL and Advanced Hunting in Defender XDR, threat analytics, hunting graphs, Sentinel hunting queries, KQL jobs in the Sentinel data lake, summary rules, and notebooks |
Weights and topics come from Microsoft’s SC-200 study guide, which lists the skills measured from October 21, 2026. Microsoft’s change log shows the domains unchanged and only minor edits to the data ingestion objectives compared with the previous version. Check the study guide before you book, because Microsoft updates this exam regularly as Defender and Sentinel change.
AZ-500 retired: what it means for SC-200 candidates
Microsoft retired the Azure Security Engineer Associate certification, the AZ-500 exam and its renewal assessments on August 31, 2026. You can no longer earn or renew it (Microsoft). Microsoft’s replacement is the Cloud and AI Security Engineer Associate certification, earned by passing exam SC-500, available since July 21, 2026 (Microsoft).
- SC-200 is not affected. It remains the Microsoft certification for SOC analysts.
- SC-500 is the engineering track. Its study guide covers identity, access and governance (20–25%), securing storage, databases and networking (25–30%), securing compute (20–25%), and managing security posture (20–25%), including securing AI workloads (Microsoft).
- Which one first? If you investigate alerts and incidents, take SC-200. If you design and implement security controls in Azure, take SC-500. Many people eventually hold both.
- If you held AZ-500: it can’t be renewed, so plan on SC-500 if you need a current Azure security engineering credential.
What SC-200 costs
- Exam: $165 in the U.S. Prices vary by country.
- Training: Microsoft Learn’s SC-200 learning paths, a free practice assessment, and an exam sandbox are all free. Instructor-led courses from Microsoft Learning Partners cost extra.
- Lab: A Microsoft 365 developer or trial tenant and an Azure free account let you practice with Defender and Sentinel. Watch Sentinel data ingestion costs and delete resources when you finish.
- Renewal: Free every year through the online renewal assessment.
- Discounts: Microsoft runs Virtual Training Days and other events that sometimes include exam discounts, and Exam Replay offers lower-cost retakes.
An eight-week SC-200 study plan
This assumes about eight hours a week and basic security knowledge. Security+ or equivalent experience helps a lot.
- Week 1: KQL. Learn where, summarize, join, project and time filters. KQL is everywhere on this exam, and it’s the most useful skill you’ll take back to work.
- Weeks 2 to 3: Defender XDR. Incidents and alerts, Defender for Endpoint device timelines and live response, Defender for Office 365, Identity and Cloud Apps, automated investigation and attack disruption.
- Weeks 4 to 5: Microsoft Sentinel. Workspace setup, roles, data connectors (AMA, Syslog, CEF), analytics rules (scheduled, NRT, threat intelligence), automation rules and playbooks, workbooks and data retention tiers.
- Week 6: threat hunting. Advanced Hunting, Sentinel hunting queries, the data lake, summary rules and notebooks. Map what you find to MITRE ATT&CK.
- Week 7: Purview, Entra ID and Security Copilot. Investigating with Purview Audit and eDiscovery, compromised identities in Entra ID, and incident summaries with Security Copilot.
- Week 8: practice. Take Microsoft’s free practice assessment until you score well, re-read the study guide line by line, and try the exam sandbox.
Is SC-200 worth it? Jobs and salary
SC-200 maps directly to SOC analyst work in Microsoft environments, and Microsoft Defender and Sentinel are common in enterprises. The U.S. Bureau of Labor Statistics reports a median pay of $129,180 in May 2025 for information security analysts, the category that includes SOC analysts, with 21% projected growth from 2025 to 2035 (BLS). Entry-level SOC roles typically pay less than the median, and pay climbs quickly with incident response and detection engineering experience.
The free annual renewal is a real advantage: SC-200 costs $165 once and nothing to maintain, as long as you pass the renewal assessment each year.
SC-200 vs CySA+, Security+ and AWS Security Specialty
- SC-200 vs CySA+: CySA+ is vendor-neutral analyst training and meets DoD 8140 requirements; SC-200 is Microsoft-specific and very hands-on with Defender and Sentinel. If your employer runs Microsoft security tools, SC-200 is more directly useful; for broad job-market signaling, CySA+.
- SC-200 vs Security+: Security+ is the entry-level foundation. Take it first if you’re new to security.
- SC-200 vs the AWS Certified Security – Specialty exam: The AWS exam is advanced cloud security engineering on AWS. SC-200 is SOC operations on Microsoft. They answer different job descriptions.
- Coming from the Google Cybersecurity Certificate? SC-200 is a natural next step once you are comfortable with SIEM concepts and want Microsoft-specific skills.
Planning your next certification? See the full certification roadmap for the order to take them by career goal.
What I would tell a friend starting SC-200
Spend your first week on KQL and keep writing queries every day until the exam. Build a small lab tenant, onboard a Windows VM to Defender for Endpoint and Sentinel, and generate some alerts. Then read the study guide line by line and make sure you can find every setting it mentions. And follow real incidents: the best SOC analysts already know what an attack looks like before it lands in their queue.
Your alert queue starts with today’s news. The CyberExperts Daily Brief covers what changed in security and why it matters, in five minutes, weekday mornings. Get tomorrow’s brief.
Frequently asked questions
Is the SC-200 exam still active in 2026?
Yes. SC-200 is active, Microsoft last updated the certification on July 28, 2026, and the English exam gets a minor update on October 21, 2026.
How long is the SC-200 exam?
100 minutes. Microsoft doesn’t publish a fixed number of questions.
What is the passing score for SC-200?
700 or higher.
How much does SC-200 cost?
$165 in the United States. The price depends on the country where you take the exam.
How do I renew SC-200?
Every 12 months, for free, by passing an online renewal assessment on Microsoft Learn.
Is AZ-500 still available?
No. Microsoft retired the Azure Security Engineer Associate certification, the AZ-500 exam and its renewals on August 31, 2026. The replacement is the Cloud and AI Security Engineer Associate certification, earned with exam SC-500.
Should I take SC-200 or SC-500?
Take SC-200 if you work in security operations, investigating alerts and hunting threats. Take SC-500 if you design and implement security controls in Azure and Microsoft 365.
Sources
- Microsoft Learn, Security Operations Analyst Associate (SC-200): learn.microsoft.com
- Microsoft Learn, SC-200 study guide: learn.microsoft.com
- Microsoft Learn, Azure Security Engineer Associate (AZ-500 retirement notice): learn.microsoft.com
- Microsoft Partner Center, August 2026 announcements (AZ-500 replaced by SC-500): learn.microsoft.com
- Microsoft Learn, SC-500 study guide: learn.microsoft.com
- BLS, Information security analysts: bls.gov
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.