As UK businesses accelerate their digital transformation and embrace hybrid working, the demand for specialised cybersecurity skills has never been greater. Recognising this, Microsoft has evolved its certification path from broad, all-encompassing qualifications to a set of focused, role-based security tracks. This guide is designed to help you navigate this new structure and choose the certification that aligns with your career goals.
To provide a clear path forward, Microsoft now offers four distinct training and certification tracks, each designed for a specific area of security expertise:
For anyone touching the Microsoft cloud ecosystem, the Microsoft Security, Compliance and Identity Fundamentals (SC-900) course is the perfect entry point. This one-day track provides a comprehensive overview of security and compliance concepts across both Microsoft 365 and Azure.
You'll gain a foundational understanding of core principles like Zero-Trust, explore the Microsoft Service Trust Portal, and be introduced to the full suite of security tools. Key topics include:
This course is ideal for sales or management professionals needing a high-level overview, newcomers to the Microsoft cloud, or administrators from one environment (e.g., Azure) seeking to understand the other (M365).
Explore the SC-900 curriculum and available dates here.
Once you have the fundamentals, you can specialise in a specific security domain. The following three certifications are designed for hands-on practitioners.
If your passion is threat hunting, log analysis, and incident response, the Microsoft Security Operations Analyst (SC-200) track is your path. This three-day course dives deep into using Microsoft 365 Defender, Azure Defender, and Azure Sentinel to protect an organisation.
This curriculum is intensely practical, teaching you to detect and remediate threats across your entire environment—from endpoints with Microsoft Defender for Endpoint to cloud services. You will learn to configure a Sentinel workspace, manage data connectors, write Kusto queries for threat hunting, and orchestrate automated security responses. This is the premier certification for security analysts, incident responders, and anyone working in a Security Operations Centre (SOC).
See the full training details for the SC-200 track here.
Identity is the new security perimeter. The Microsoft Identity and Access Administrator (SC-300) certification is for professionals who design, implement, and operate an organisation's identity and access management systems. This three-day course covers Azure AD, hybrid identity, and secure authentication.
You will master the skills needed to manage internal and external identities, implement robust authentication with MFA and Conditional Access, and configure hybrid identity using Azure AD Connect with strategies like PHS, PTA, and ADFS. It also covers governance using Privileged Identity Management (PIM) and access reviews, making it essential for administrators tasked with securing user and application access in hybrid environments.
Discover more about the SC-300 certification here.
In a world of complex data regulations like UK GDPR, protecting sensitive information is paramount. The Microsoft Information Protection Administrator (SC-400) track focuses on data governance, compliance, and risk management within Microsoft 365.
This two-day course teaches you how to create sensitivity labels, design data loss prevention (DLP) policies, and manage content retention. You’ll learn to implement Microsoft Information Protection, use Cloud App Security to protect data in transit, and configure records management. This certification is ideal for compliance officers, auditors, and security administrators responsible for designing and implementing an organisation's data protection strategy.
Find out how the SC-400 can advance your skills here.
Previously, certifications like the Microsoft 365 Security Administrator Associate (MS-500) and the Microsoft Azure Security Engineer Associate (AZ-500) were very broad. They covered dozens of technologies in a single exam, providing a wide but not necessarily deep understanding. For instance, the MS-500 touched upon everything from compliance and DLP to endpoint management and conditional access.
The new "SC" series effectively deconstructs these large domains into focused specialisms. Instead of a single security administrator certification, you now have dedicated paths for security operations (SC-200), identity (SC-300), and information protection (SC-400). This change reflects the real-world need for deep expertise in specific security functions, allowing professionals to build more targeted and advanced skill sets.
With this new role-based structure, Microsoft has created a clearer roadmap for career progression in cybersecurity. Whether you are starting out or looking to specialise, there is a track for you. Explore the courses below to find the perfect fit for your goals.
Microsoft Security, Compliance and Identity Fundamentals (SC-900)
Microsoft Security Operations Analyst (SC-200)
Microsoft Identity and Access Administrator (SC-300)
Microsoft Information Protection Administrator (SC-400)
If you have any questions about which track is right for you, please don't hesitate to contact our team.
Get Unlimited access to ALL the LIVE Instructor-led Microsoft courses you want - all for the price of less than one course.