Last updated September 2026
If your SOC runs on Microsoft Defender and Sentinel, SC-200 is the analyst cert that matches the job. It’s the exam for Microsoft Certified: Security Operations Analyst Associate, and it tests the daily work: triaging incidents in Defender XDR, configuring and tuning Sentinel, writing KQL to hunt, building detections and automating responses.
It’s still active. Microsoft last updated the certification on July 28, 2026, and the English exam gets a minor update on October 21, 2026, mainly to the data ingestion objectives (Microsoft). The bigger news in Microsoft security certs this year is the retirement of AZ-500 on August 31, 2026; its replacement is the Cloud and AI Security Engineer Associate (exam SC-500) (Microsoft, Microsoft). More on what that means below.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Learn KQL before anything else
KQL runs through the whole exam, and it’s the skill you’ll use most back at work. Treat it as one topic among many and you’ll feel it on exam day. The other places people lose points:
- Knowing features, not locations. Many questions come down to where a setting lives in Defender XDR or Sentinel. If you’ve only watched videos, you’ll hesitate.
- Sentinel plumbing. Data connectors (AMA, Syslog, CEF), analytics rule types and retention tiers are specific and easy to mix up.
- Automation. Automation rules and playbooks sit inside the largest skill area. Know which does what.
- A stale study guide. Microsoft updates this exam as the products change. Re-read the study guide the week you book.
Who SC-200 fits
- SOC analysts, tier 1 through tier 3, in organizations that use Defender and Sentinel
- Incident responders and threat hunters in Microsoft environments
- Detection engineers who write analytics rules and KQL
- IT admins moving into security operations in a Microsoft 365 shop
Microsoft rates it intermediate and expects familiarity with its security, compliance and identity products, Microsoft 365, Azure, Windows, Linux and mobile operating systems, and now AI agents and Copilots. There are no formal prerequisites. If you’re new to security entirely, Security+ first will make this far easier.
SC-200 exam facts
| Item | Details |
|---|---|
| Certification | Microsoft Certified: Security Operations Analyst Associate |
| Exam | SC-200: Microsoft Security Operations Analyst |
| Status | Active; English version updated October 21, 2026 (minor changes) |
| Time | 100 minutes |
| Passing score | 700 or higher |
| Format | Proctored; may include interactive components |
| Price | $165 in the U.S.; the price depends on the country where you take it |
| Languages | English, Japanese, Chinese (Simplified and Traditional), Korean, French, German, Spanish, Portuguese (Brazil) and Italian |
| Renewal | Every 12 months, free, by passing an online renewal assessment on Microsoft Learn |
| Retakes | You can retake 24 hours after a first failed attempt; later retakes have longer waits |
Sources: Microsoft’s SC-200 certification page and SC-200 study guide (September 2026). Microsoft doesn’t publish a fixed question count; expect a mix of question types, possibly including case studies.
The three skill areas
| Skill area | Weight | What it covers |
|---|---|---|
| Manage a security operations environment | 40–45% | Automation in Defender XDR and Sentinel (automation rules, playbooks, attack disruption), configuring Sentinel roles, retention and workbooks, ingesting data with connectors (Windows events via AMA, Syslog and CEF, Azure activity logs, threat indicators), and building detections mapped to MITRE ATT&CK |
| Respond to security incidents | 35–40% | Investigating and remediating alerts from Defender for Office 365, Endpoint, Identity, Cloud Apps and Cloud, Microsoft Purview and Entra ID; investigating incidents with Security Copilot; live response on devices; and investigating Microsoft 365 activity with Purview Audit, eDiscovery and Graph activity logs |
| Perform threat hunting | 20–25% | KQL and Advanced Hunting in Defender XDR, threat analytics, hunting graphs, Sentinel hunting queries, KQL jobs in the Sentinel data lake, summary rules, and notebooks |
Weights and topics come from Microsoft’s SC-200 study guide, which lists the skills measured from October 21, 2026. Microsoft’s change log shows the domains unchanged and only minor edits to the data ingestion objectives compared with the previous version. Check the study guide before you book, because Microsoft updates this exam regularly as Defender and Sentinel change.
Eight weeks, KQL every day
This plan assumes about eight hours a week and basic security knowledge. Build a small lab tenant early, onboard a Windows VM to Defender for Endpoint and Sentinel, and generate your own alerts.
- Week 1: KQL. Learn where, summarize, join, project and time filters. KQL is everywhere on this exam, and it’s the most useful skill you’ll take back to work.
- Weeks 2 to 3: Defender XDR. Incidents and alerts, Defender for Endpoint device timelines and live response, Defender for Office 365, Identity and Cloud Apps, automated investigation and attack disruption.
- Weeks 4 to 5: Microsoft Sentinel. Workspace setup, roles, data connectors (AMA, Syslog, CEF), analytics rules (scheduled, NRT, threat intelligence), automation rules and playbooks, workbooks and data retention tiers.
- Week 6: threat hunting. Advanced Hunting, Sentinel hunting queries, the data lake, summary rules and notebooks. Map what you find to MITRE ATT&CK.
- Week 7: Purview, Entra ID and Security Copilot. Investigating with Purview Audit and eDiscovery, compromised identities in Entra ID, and incident summaries with Security Copilot.
- Week 8: practice. Take Microsoft’s free practice assessment until you score well, re-read the study guide line by line, and try the exam sandbox.
Cheap to get, free to keep
- Exam: $165 in the U.S. Prices vary by country.
- Training: Microsoft Learn’s SC-200 learning paths, a free practice assessment, and an exam sandbox are all free. Instructor-led courses from Microsoft Learning Partners cost extra.
- Lab: A Microsoft 365 developer or trial tenant and an Azure free account let you practice with Defender and Sentinel. Watch Sentinel data ingestion costs and delete resources when you finish.
- Renewal: Free every year through the online renewal assessment.
- Discounts: Microsoft runs Virtual Training Days and other events that sometimes include exam discounts, and Exam Replay offers lower-cost retakes.
That free annual renewal is a real advantage: SC-200 costs $165 once and nothing to maintain, as long as you pass the renewal assessment each year.
AZ-500 is gone: SC-200, SC-500 or both?
Microsoft retired the Azure Security Engineer Associate certification, the AZ-500 exam and its renewal assessments on August 31, 2026. You can no longer earn or renew it (Microsoft). Microsoft’s replacement is the Cloud and AI Security Engineer Associate certification, earned by passing exam SC-500, available since July 21, 2026 (Microsoft).
- SC-200 is not affected. It remains the Microsoft certification for SOC analysts.
- SC-500 is the engineering track. Its study guide covers identity, access and governance (20–25%), securing storage, databases and networking (25–30%), securing compute (20–25%), and managing security posture (20–25%), including securing AI workloads (Microsoft).
- Which one first? If you investigate alerts and incidents, take SC-200. If you design and implement security controls in Azure, take SC-500. Many people eventually hold both.
- If you held AZ-500: it can’t be renewed, so plan on SC-500 if you need a current Azure security engineering credential.
What SOC managers get from SC-200
Proof you can work their tools on day one. In a Microsoft shop, an analyst who can write KQL and find their way around Defender XDR ramps up faster than one who only knows SIEM concepts in the abstract. BLS reports a median pay of $129,180 in May 2025 for information security analysts, the category that includes SOC analysts, with 21% projected growth from 2025 to 2035 (BLS). Entry-level SOC roles typically pay less, and pay climbs with incident response and detection engineering experience.
SC-200 compared with CySA+, Security+ and AWS
- SC-200 vs CySA+: CySA+ is vendor-neutral analyst training and meets DoD 8140 requirements; SC-200 is Microsoft-specific and very hands-on with Defender and Sentinel. If your employer runs Microsoft security tools, SC-200 is more directly useful; for broad job-market signaling, CySA+.
- SC-200 vs Security+: Security+ is the entry-level foundation. Take it first if you’re new to security.
- SC-200 vs the AWS Certified Security – Specialty exam: The AWS exam is advanced cloud security engineering on AWS. SC-200 is SOC operations on Microsoft. They answer different job descriptions.
- Coming from the Google Cybersecurity Certificate? SC-200 is a natural next step once you are comfortable with SIEM concepts and want Microsoft-specific skills.
Mapping out the SOC path? The certification roadmap shows where SC-200 fits.
Other analyst options are ranked in Best Cybersecurity Certifications in 2026.
Your alert queue starts with today’s news. The best analysts already know what an attack looks like before it lands in their queue. The CyberExperts Daily Brief covers it in five minutes, weekday mornings. Get tomorrow’s brief.
Short answers about SC-200
Is SC-200 still active in 2026?
Yes. Microsoft last updated the certification on July 28, 2026, and the English exam gets a minor update on October 21, 2026.
How long is the exam, and what score passes?
100 minutes, and you need 700 or higher. Microsoft doesn’t publish a fixed number of questions.
How much does SC-200 cost?
$165 in the United States. The price depends on the country where you take the exam.
Is renewal really free?
Yes. You renew every 12 months, for free, by passing an online renewal assessment on Microsoft Learn.
What happened to AZ-500?
Microsoft retired the Azure Security Engineer Associate certification, the AZ-500 exam and its renewals on August 31, 2026. The replacement is the Cloud and AI Security Engineer Associate certification, earned with exam SC-500.
Should I take SC-200 or SC-500?
SC-200 if you work in security operations, investigating alerts and hunting threats. SC-500 if you design and implement security controls in Azure and Microsoft 365.
Sources
- Microsoft Learn, Security Operations Analyst Associate (SC-200): learn.microsoft.com
- Microsoft Learn, SC-200 study guide: learn.microsoft.com
- Microsoft Learn, Azure Security Engineer Associate (AZ-500 retirement notice): learn.microsoft.com
- Microsoft Partner Center, August 2026 announcements (AZ-500 replaced by SC-500): learn.microsoft.com
- Microsoft Learn, SC-500 study guide: learn.microsoft.com
- BLS, Information security analysts: bls.gov
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.