Passed SC-100 last week — identity management section was the sleeper topic
Passed SC-100 with an 812 last Thursday. I've been a cloud security architect for three years, Azure-heavy, previously held AZ-500 and MS-500. I thought this exam would be a straightforward extension of what I already knew. It mostly was, but there were a few areas I underweighted in my prep that I want to flag for anyone getting ready.
The identity and access management architecture questions hit harder than I expected. Not the mechanics of Conditional Access or PIM — I know those cold. It was the governance and design questions: when to use which identity pattern for a hybrid environment, how to architect zero-trust identity at an enterprise scale, which controls to layer when you have on-prem AD plus Entra ID plus a bunch of SaaS apps. The SC-100 practice tests I used covered this material but the real exam went deeper on the architectural tradeoffs.
The MCRA (Microsoft Cybersecurity Reference Architecture) is worth reading in full, not just skimming. I skimmed it. I noticed on the exam. The sections on identity and on security operations are especially testable at the architectural reasoning level.
Four weeks of prep, roughly 90 minutes a day. Solid foundation from AZ-500 made a real difference. Happy to answer questions.
The MCRA callout is useful — thanks. Most prep guides treat it as supplementary. Sounds like it's more load-bearing than that for the actual exam questions.
What resources did you use beyond the MCRA? I have AZ-500 and SC-200 and I'm planning SC-100 for Q3. Trying to figure out if official Microsoft Learn is enough or if I need a third-party course.
The hybrid identity architecture questions are where I see most people struggle. There's a real gap between "I know how Entra ID works" and "I can design an identity architecture for 50,000 users across three countries with regulatory requirements." The latter is what SC-100 tests.
812 on SC-100 is a solid score. That exam has a reputation for being harder than the other SC-series in terms of requiring genuine architectural reasoning vs recall. Congrats.
The zero-trust framing runs through the entire exam. If you're prepping and haven't fully internalized the Microsoft Zero Trust model (identity, endpoints, apps, data, infrastructure, networks), that's worth doing before you sit. Every section connects back to it.
Congrats on the pass! Identity management was my sleeper too. I spent way too much time drilling Zero Trust architecture and barely touched the identity governance stuff — then the exam hit me with like five questions on entitlement management and access reviews that I wasn't fully ready for. The thing that actually saved me was grinding through sc 100/questions/security posture management the night before, which got me thinking more holistically about how identity fits into the overall posture picture instead of treating it as its own silo.
If you've got AZ-500 under your belt you'll recognize a lot of the concepts, but don't assume that means you can skim the identity sections. The exam wants you to reason about design decisions, not just recall features. That shift in thinking is what I'd focus on if I were starting over.
Related Discussions
- Finally passed CBP — here's what actually made the difference for me8 replies
- How long does it realistically take to study for the CMA?8 replies
- Failed the CDIA — what to do differently the second time7 replies
- Time management during CBSA exam — how fast are you supposed to go?7 replies
- Deep dive: exam prep for the CSA — tips from someone who almost failed it7 replies