SC-200 certifies the daily work of a security operations analyst: configuring and tuning Defender XDR and Sentinel, ingesting and correlating data across the SIEM, building detections, responding to live incidents across email, identity, and cloud workloads, and hunting threats with KQL. It's the credential hiring managers screen for when a role is built around the SOC itself — investigation, response, and hunting — rather than the identity (SC-300) or data-protection (SC-401) seats elsewhere in Microsoft's security family. Seventh step of the Microsoft 365 track, and the most operationally hands-on credential in it.
Source: U.S. Bureau of Labor Statistics, Information Security Analysts (security operations track) · May 2024 wage data, 2024–2034 growth projection
Self-paced access, AI Coach on every lesson, full-length practice exams, and a free course retake if you complete the readiness gate and still don't pass your exam on the first attempt. Exam registration and voucher are purchased separately, directly through the certifying body.
See the full curriculum100% self-paced online — study on your schedule, no bootcamp seat to book.
Training a whole team on SC-200? Fund a Training Bank account for any amount, then assign any course to any employee — self-serve, published discount tiers, no sales call.
Set up your team account

