A Guide to Microsoft's New Security Certification Paths

  • Microsoft
  • Security
  • Certification
  • Published by: MARIA FORSBERG on Mar 15, 2021
Group classes

As Canadian businesses continue their rapid digital transformation, the cybersecurity landscape has grown increasingly complex. Adapting to remote work models and evolving threats requires a new level of security expertise. Recognizing this, Microsoft has shifted its certification approach, moving from broad certifications to a series of focused, role-based tracks. This guide is designed to help you navigate these new pathways and identify the ideal certification for your career goals.

The Evolution from Generalist to Specialist Certifications

Previously, Microsoft offered comprehensive security certifications like the Microsoft 365 Security Administrator Associate (MS-500) and the Microsoft Azure Security Engineer Associate (AZ-500). While valuable, these certifications covered a vast range of technologies—sometimes over a dozen in a few days. This broad-stroke approach provided a solid intermediate overview but often lacked the depth required for specialized architect or analyst roles and didn't fully cover emerging tools like Azure Sentinel.

In response, Microsoft has introduced four in-depth security, compliance, and identity certifications that are more focused and align with specific job functions.

Foundational Knowledge: The SC-900 for All Professionals

The SC-900 Microsoft Security, Compliance and Identity Fundamentals track is the perfect entry point into the Microsoft security ecosystem. This one-day course provides a comprehensive overview of security and compliance features across both Microsoft 365 and Azure. It is designed for a broad audience, including those in technical, sales, or management roles.

Participants will grasp core security methodologies, understand identity concepts like Azure AD and Multi-Factor Authentication, and be introduced to powerful tools like Azure Sentinel, Microsoft Defender, and Endpoint Manager (Intune). The curriculum offers a high-level understanding of how these technologies work together to protect an organisation.

This foundational path is ideal for:

  • Professionals in sales or management who need to understand Microsoft's security capabilities.
  • IT newcomers or administrators seeking a fundamental grasp of security and compliance features across M365 and Azure.
  • Anyone holding an MS-900 or AZ-900 certification looking for the next step in their learning journey.

Explore the Microsoft Security, Compliance and Identity Fundamentals (SC-900) track here.

For Front-Line Defenders: The SC-200 Operations Analyst Path

The Microsoft Security Operations Analyst (SC-200) certification is tailored for those on the front lines of cyber defence. This three-day track equips you with the skills for log analysis, threat hunting, and incident response using Microsoft's powerful security stack. It centres on Microsoft 365 Defender, Azure Defender, and Azure Sentinel.

You'll learn to detect and remediate threats, manage security alerts, and configure device protection. A key focus is on using the Kusto Query Language (KQL) to build custom analytics, automate responses, and manage incidents within Azure Sentinel, Microsoft's state-of-the-art SIEM solution. This course enables you to protect not just Azure services, but also AWS and Google Cloud environments.

This analyst path is ideal for:

  • Experienced administrators aiming to master Sentinel and advanced security operations.
  • Security architects, analysts, and incident responders tasked with protecting the enterprise.
  • Professionals with experience in other SIEM solutions who want to leverage Microsoft's integrated security tools.

Learn more about the training- and certification track here.

For Identity Gatekeepers: The SC-300 Access Administrator Path

Identity is the new security perimeter, and the Microsoft Identity and Access Administrator (SC-300) track provides the skills to manage it. This three-day course focuses on administering, auditing, and securing identities and applications in cloud-only and hybrid environments. It uses technologies like Azure AD, Azure AD Connect, Conditional Access, and Privileged Identity Management (PIM).

The curriculum covers everything from implementing hybrid identity synchronization with on-premise Active Directory to advanced authentication scenarios like MFA and SSO. You will also learn to publish and secure hybrid apps, manage entitlements, and analyze activity with Azure Log Analytics to ensure robust identity governance.

This administrator path is ideal for:

  • Microsoft 365 and Azure administrators who need to design and implement robust identity synchronization and security.
  • IT professionals responsible for auditing identity compliance and securing access to applications.
  • Delegates who hold an MS-100 or MS-101 certification and wish to specialize in identity management.

Learn more about the training- and certification track here.

For Data Stewards: The SC-400 Information Protection Path

In an era of stringent data privacy laws like Canada's PIPEDA, protecting information is paramount. The SC-400 Microsoft Information Protection Administrator certification is for professionals tasked with ensuring data compliance and security in Microsoft 365.

This two-day course delves into designing archiving strategies, protecting data with Data Loss Prevention (DLP) policies, and conducting eDiscovery investigations. You will learn to use sensitive information types, trainable classifiers, and sensitivity labels to manage and protect corporate data. It also covers Microsoft Information Protection, Cloud App Security, and Records Management to ensure end-to-end data governance.

This protection path is ideal for:

  • Administrators who design and implement compliance, archiving, and data protection tools in Microsoft 365.
  • Auditors and security administrators responsible for data governance and responding to regulatory requirements.
  • Professionals holding an MS-500 or MS-101 certification aiming to specialize in information protection.

Learn more about the training and certification track here.

Ready to Choose Your Specialization?

Microsoft's new security tracks offer clear, role-based paths to deepen your expertise and advance your career. Whether you are building a foundation, defending the front lines, managing identities, or protecting data, there is a certification designed for you. Explore the available dates and course details on the links below:

Microsoft Security, Compliance and Identity Fundamentals (SC-900)

Microsoft Security Operations Analyst (SC-200)

Microsoft Identity and Access Administrator (SC-300)

Microsoft Information Protection Administrator (SC-400)

 

Our team is here to help if you have any questions. Please reach out to us for guidance on your certification journey.

SC-200 Microsoft Security Operations Analyst SC-300 Microsoft Identity and Access Administrator SC-400 Microsoft Information Protection Administrator Learn more about the training & certification track here Microsoft Information Protection Administrator
A group of people discussing the latest Microsoft Azure news

Unlimited Microsoft Training

Get Unlimited access to ALL the LIVE Instructor-led Microsoft courses you want - all for the price of less than one course. 

  • 60+ LIVE Instructor-led courses
  • Money-back Guarantee
  • Access to 50+ seasoned instructors
  • Trained 50,000+ IT Pro's

Basket

{{item.CourseTitle}}

Price: {{item.ItemPriceExVatFormatted}} {{item.Currency}}