Reviewed 30 September 2026Microsoft Learn owner sources

Microsoft certification prep for AZ-104, SC-200, and SC-300.

Use this page to prepare for three active Microsoft role-based certification paths with current Microsoft Learn objectives: Azure Administrator (AZ-104), Security Operations Analyst (SC-200), and Identity and Access Administrator (SC-300). The goal is to study the work Microsoft says each role performs rather than memorize a stale question count or an unofficial exam dump.

Microsoft changes certification objectives regularly. SC-200, for example, is scheduled for another English-language objective update on October 21, 2026. Always compare your final study plan with the current Microsoft Learn exam page before test day.

Choose by job

Start from the role you want to perform.

Microsoft's role-based credentials are easier to study when you anchor each objective to an operational responsibility. Pick one lane, build a small lab around it, and use Microsoft Learn as the final source of truth for the current blueprint.

AZ-104

Azure Administrator Associate

Choose AZ-104 if your work centers on implementing, managing, securing, and monitoring Azure infrastructure. Microsoft currently describes the role around identity and governance, storage, compute, virtual networking, and monitoring/maintenance.

Useful background: operating systems, networking, servers, virtualization, PowerShell, Azure CLI, Azure portal, ARM templates, and Microsoft Entra ID.

SC-200

Security Operations Analyst Associate

Choose SC-200 if your work centers on SOC operations, incident response, threat hunting, detection engineering, Microsoft Sentinel, Defender XDR, Defender for Endpoint, Defender for Cloud, Purview, and Entra signals.

Microsoft currently emphasizes managing the security-operations environment, responding to incidents, and performing threat hunting. KQL is a practical study priority.

SC-300

Identity and Access Administrator Associate

Choose SC-300 if your work centers on Microsoft Entra identity lifecycle, authentication, authorization, workload identities, privileged access, Conditional Access, and identity governance.

Microsoft currently frames the role around implementing user identities, authentication/access management, workload identities, and identity governance using Zero Trust principles.

Azure Administrator

AZ-104: learn the control plane by operating it.

Microsoft describes the Azure Administrator as someone who implements, manages, and monitors an organization's Azure environment. That is broader than memorizing portal locations. A useful lab should force you to make identity, network, storage, compute, governance, and monitoring decisions and then troubleshoot the consequences.

Manage identities and governance

Practice Microsoft Entra users and groups, role-based access control, subscriptions, resource groups, Azure Policy, tags, locks, and cost/governance boundaries. Be able to explain the difference between directory identity, Azure RBAC authorization, resource ownership, and policy compliance.

Implement and manage storage

Work with storage accounts, redundancy choices, access control, shared access patterns, lifecycle rules, file services, object storage, encryption, private endpoints, and network restrictions. Know what belongs in identity policy versus a storage configuration.

Deploy and manage compute

Build and operate virtual machines, availability patterns, scale sets, containers where applicable, and application-hosting options. Practice images, disks, extensions, backup, sizing, identity, networking, and the operational effect of changing a resource after deployment.

Virtual networking and monitoring

Practice VNets, subnets, routing, NSGs, DNS, peering, load-balancing concepts, private connectivity, Network Watcher, Azure Monitor, alerts, Log Analytics, and recovery signals. Troubleshooting is where separate objectives become one administrator workflow.

Owner source: Microsoft Certified: Azure Administrator Associate. Microsoft lists a 12-month renewal frequency and directs candidates to the current AZ-104 study guide from that page.

Security operations

SC-200: build investigation muscle, not product-name flashcards.

Microsoft's current SC-200 profile describes a security operations analyst who performs triage, incident response, threat hunting, and detection engineering across multi-cloud and on-premises environments. The current role spans Defender XDR, Microsoft Sentinel, Entra ID, Purview, Defender for Endpoint, and Defender for Cloud workload protections.

The exam page currently gives candidates 100 minutes for the assessment and Microsoft states that a scaled score of 700 or greater is required to pass. Treat those details as exam-day facts to verify again before scheduling because Microsoft updates exam experiences and objectives over time.

Security-operations environment

Know how data reaches Sentinel and Defender, how incidents and alerts are organized, how automation changes the response path, and how access to security tooling is controlled. Build a mental model of telemetry sources before memorizing menus.

Incident response

Practice scoping an alert, pivoting across identities, endpoints, cloud resources, email/collaboration activity, and related incidents. Capture evidence, validate the affected entity, choose containment proportional to confidence, and verify that remediation actually removed the risky state.

Threat hunting

Write KQL against representative security tables. Start with filters, projections, time windows, joins, summaries, parsing, and entity pivots. Turn a successful hunt into a repeatable analytic or detection only after you understand expected noise and data coverage.

Upcoming blueprint change: Microsoft says the English-language SC-200 certification will be updated on October 21, 2026. Use the study guide's change log to distinguish today's objectives from the upcoming version.

Owner sources: SC-200 certification page and SC-200 study guide.

Identity and access

SC-300: study identity as a lifecycle and decision system.

Microsoft's April 27, 2026 study guide describes an identity and access administrator who designs, implements, and operates identity and access management with Microsoft Entra. The role covers users, devices, Azure resources, applications, authentication, authorization, workload identities, governance, monitoring, and Zero Trust principles.

Implement and manage user identities

Practice user and group lifecycle, administrative units, external identities, licensing dependencies, hybrid identity considerations, role assignments, and the difference between directory objects and permissions on resources or applications.

Authentication and access management

Understand authentication methods, Conditional Access, risk signals, authentication strengths, passwordless options, session controls, and Global Secure Access concepts. For each policy, be able to name the subject, resource, condition, control, exception, and failure mode.

Workload identities

Study service principals, managed identities, app registrations, permissions, consent, credentials, federation, and least privilege. Human identities and workload identities share governance goals but fail differently, so practice both.

Identity governance

Practice access packages, entitlement management, access reviews, privileged access, lifecycle workflows, logging, reports, and evidence. Governance questions become easier when you ask who grants access, for how long, under which conditions, and how removal is proven.

Owner sources: SC-300 certification page and SC-300 study guide.

Study method

Use a four-pass loop for every objective.

  1. Read the owner objective. Copy the current skill statement into your notes and translate it into a concrete administrator or analyst task.
  2. Perform the task. Use a lab, sandbox, free Microsoft Learn exercise, or controlled tenant where available. Capture what you changed and what signal proves it worked.
  3. Break it deliberately. Remove a permission, misconfigure a network path, change a policy condition, feed incomplete telemetry, or create a conflicting control. Troubleshoot from symptoms back to configuration.
  4. Explain the decision. State why the chosen control fits the scenario, what alternative would be wrong, what evidence you would inspect, and what risk remains.

Practice questions without dumps

Use Microsoft's official practice assessments and exam sandbox to learn wording and interaction style. Use original scenario questions to test reasoning. Do not use recalled, copied, leaked, or live-exam questions. They age badly, undermine the credential, and train pattern matching instead of the work the certification is supposed to validate.

Track blueprint changes explicitly

Certification pages are living documents. Record the date you downloaded or reviewed an objective list. A study note should say “SC-300 objectives reviewed April 27, 2026” rather than simply “current objectives.” When Microsoft posts a change log, compare changed skills and update only the affected study modules.

Official Microsoft study resources

Reviewed September 30, 2026. Microsoft can change objectives, retirement dates, delivery details, and credential names; verify the linked Microsoft Learn page before registering.