Microsoft Security Certifications, Ranked: What Actually Moves You Up
All right class.
You're in a SOC. You've been triaging incidents for two years, you're good at it, and you've worked out that being good at it is not the same as being promoted for it. So you go looking for the next thing, and the internet tells you the answer is a certification.
Here's the problem with that advice in 2026. Microsoft has spent this year respeccing the skill tree underneath you. AZ-500 is gone. SC-400 has been gone for over a year. There's a new engineer cert with a new name, half the exams got an AI transplant in July, and the roadmap you bookmarked in 2024 is now actively wrong.
So let's rank them. Not by how impressive they sound, but by what each one does for somebody who already has the job and wants a better one.

How I ranked them
Does it get you past the filter? Most certs do one job: they stop a recruiter binning your CV in the first nine seconds. That's a real job. It's just a smaller job than the marketing suggests.
Does it teach you anything you didn't have? Some of these will change how you work. Others will confirm what you already do all day and hand you a badge for it.
Does it survive a technical interview? The person across the table has the same cert. They will find out in about four minutes whether you learned it or memorised it (unless they memorised it as well 🙃)
What's its half-life? A cert on a stable technology lasts. A cert on something Microsoft renamed twice this year does not.
What changed in 2026, because most of the advice out there is stale
AZ-500 retired on 31 August 2026. Gone. You can't sit it and you can't renew it. If you already hold it, it stays on your transcript and stays verifiable, but the renewal assessment went with the exam, so it will eventually lapse and there's nothing you can do about that.
Microsoft removed a node from the skill tree that a lot of us had already spent points on, and there's no refund and no respec token.
SC-500 replaces it. Exam name: Implementing End-to-End Security Controls for Cloud and AI Workloads. Credential: Cloud and AI Security Engineer Associate. It went to beta on 15 May 2026 and general availability on 21 July 2026. There's no conversion, no transition exam, and no discount for holding the old one. If you want the current cloud security badge, you sit the whole thing.
SC-400 retired back on 31 May 2025 and became SC-401, Information Security Administrator Associate.
SC-900, SC-200 and SC-100 all updated on 28 July 2026. If you're studying from a course recorded last year, you're studying the wrong syllabus.
SC-730 appeared, which is a Cybersecurity Business Professional credential aimed at executives and business users. Not at you. More on that in D tier.
S tier
SC-200, Security Operations Analyst
The only Microsoft cert that maps one-to-one onto the job you're already doing. Defender XDR, Sentinel, KQL, incident response, threat hunting, and since the July update, Security Copilot and AI service management as well.
Here's the honest framing, because I hold it and I'm not going to oversell it. SC-200 is not hard if you actually work in a Microsoft SOC. You'll recognise most of it. That's the point. It's not a challenge, it's a receipt.
It sits in S tier for a reason that has nothing to do with difficulty: not having it is a flag. If you're a Microsoft-shop SOC analyst applying for a Microsoft-shop role, the absence of SC-200 makes a hiring manager wonder why. There's no good answer to that question that fits on a CV.
Get it, stop talking about it, move on.
SC-100, Cybersecurity Architect
The one that changes what roles you're considered for rather than how you compare within your current one.
SC-100 is an expert-level exam about designing security capability rather than operating it. Zero Trust strategy, security operations design, identity and compliance architecture, infrastructure, applications and data. It's the cert that moves the conversation from "can you investigate this incident" to "how should we be set up so this incident is smaller".
It's also the one people rush and fail. SC-100 assumes you have implemented something, somewhere, at scale. Sit it after two or three years of doing the work and it's fair. Sit it as your second exam and it's a very expensive way to find out that reading about architecture and doing it are different activities.
If you want out of the queue and into consulting, presales, or architecture, this is the one worth the effort.
A tier
SC-300, Identity and Access Administrator
The strongest second cert for a SOC analyst, and the one I'd argue for hardest.
Look at where your incidents actually come from. Token theft, consent phishing, risky sign-ins, service principals nobody remembers creating, Conditional Access gaps somebody left open in 2023. Identity is where the attacks are, and it's where the interesting architecture conversations happen.
SC-300 also gives you something SC-200 doesn't: the ability to talk to the identity team as a peer rather than as somebody raising a ticket. That's a career move disguised as an exam.
Applied Skills, particularly Defender XDR and Sentinel SIEM operations
Massively underrated, and I suspect that's because they're free and people assume free means worthless.
Applied Skills are lab-based assessments. You get a live environment and a list of tasks, and you either do them or you don't. Defend against cyberthreats with Microsoft Defender XDR asks you to configure the environment, manage devices, run investigations and hunt with KQL. Configure SIEM security operations using Microsoft Sentinel does the same on the Sentinel side.
No proctoring, no fee, no multiple choice. You cannot pattern-match your way through a lab.
They carry less weight than a certification with recruiters, which is a fair criticism and the reason they're A rather than S. But they prove something a certification cannot, and in a technical interview "I did the lab assessment" is a much better sentence than "I passed the exam".
B tier
SC-500, Cloud and AI Security Engineer
A good engineering certification wearing a slightly ambitious hat.
The bulk of it is what AZ-500 always was, and that content was solid: identity, networking, storage and database security, Defender for Cloud, Sentinel. Then there's a fourth domain covering AI workload security, which is where the new name comes from.
It's B tier for practical reasons, not because it's a bad exam. If you work primarily in Microsoft 365 and Sentinel rather than Azure infrastructure, you'll spend a lot of study time on virtual network design and Key Vault access models that you will not use. SC-300 and SC-100 give a SOC analyst more per hour.
If you do own Azure workloads, move it up to A. If AZ-500 was already on your list before it retired, this is now your only route to that credential.
SC-401, Information Security Administrator
Purview, data loss prevention, insider risk, information protection, retention. Useful, well-constructed, and aimed at a team that is probably not yours.
In most organisations the people configuring DLP policies and running insider risk cases sit in compliance, legal or a dedicated data governance function, with an access model deliberately designed to keep the SOC out. Certifying for a job you're structurally prevented from doing is a strange use of a weekend.
B tier because there's a real career in data security and this is the right cert for it. Just be honest about whether that's the career you want, rather than collecting it because it starts with SC.
C tier
SC-900, Security Compliance and Identity Fundamentals
Good at exactly one job, and that job is not yours.
If you're switching into security from a helpdesk or an infrastructure role, SC-900 is the best value credential Microsoft sells. It's cheap, it takes a fortnight, and it gives you the vocabulary to work out which door to walk through next. The July 2026 update added Security Copilot content, so it's current.
But you're already in a SOC. You know what a SIEM is. Putting SC-900 on your CV underneath SC-200 does not add a credential, it subtracts credibility, because it tells the reader you're padding.
C tier for you specifically. S tier for your cousin who wants to get into the industry. It's also a fantastic one for sales, so they are not making a fool of themselves when trying to talk a bit more technical.
AZ-104 and the Azure administration foundations
Not a security certification, and I'm including it because SOC analysts keep asking whether to do it.
The knowledge is worth having. Half of what you investigate touches Azure resources, and understanding subscriptions, RBAC, networking and resource groups makes you better at your job immediately. But it competes for the same weekends as SC-300, and SC-300 does more for a security career.
Learn the Azure fundamentals. Consider not paying to prove it.
D tier
SC-730, Cybersecurity Business Professional
A perfectly reasonable credential that is not aimed at you in any way.
SC-730 is for executives, managers, compliance officers and business staff who need to make sensible decisions about security risk without being technical. Recognising phishing, understanding why IT insists on MFA, governance frameworks, talking to a security team without either party losing patience.
As an organisational security awareness tool it does real work. As a line on the CV of a SOC analyst who wants promoting, it says something you did not intend to say.
The Copilot business credentials
AB-730, AB-731 and AB-900 are Copilot and AI adoption credentials for business users, transformation leaders and Microsoft 365 administrators respectively. Fine credentials. Not security credentials. They will not move you up a security career ladder, no matter how many times AI appears in the title.
Fundamentals you already outgrew
MS-900, AZ-900 and the rest. If you have an associate-level cert, the fundamentals underneath it add nothing. Leave them off.
About the AI thing
Microsoft has put AI into everything this year. SC-500's new domain is AI workload security. SC-900 and SC-200 gained Security Copilot content in July. Across the wider portfolio, AI-102 became AI-103, DP-100 became AI-300, AZ-204 became AI-200. The pattern is consistent enough that you can predict it.
I want to be fair here, because two things are true at once and most takes only manage one.
Microsoft is right about the direction. Prompt injection, model data exfiltration, agent identity, over-permissioned AI apps reading everything a user can read. These are real problems, they arrived quickly, and a security engineer in 2027 will need to have opinions about them. Building that into the certification path is the correct call.
The certification is ahead of the practice. Almost nobody has a mature AI security operation yet. The tooling is months old, the guidance is being rewritten continuously, and the threat models are still settling. An exam can only test what's been documented, and this documentation has a very short half-life.
So the AI domain on SC-500 is worth learning and it is not the reason to sit the exam. Sit it for the cloud security engineering, which is proven, well-scoped and immediately useful. Treat the AI section as a preview of a conversation you'll be having properly in two years.
If somebody tells you an AI security certification is what makes a candidate stand out in 2026, ask them to name the last AI security incident they personally investigated. It's a short conversation.
What actually moves you up
Now the part that matters, and the part certifications quietly cannot do.
Every cert on this list is a filter. It gets your CV read. Above about the mid level, filters stop being the constraint, because everybody who reached the interview passed the same filter. What separates people at that point is evidence of work.
Concretely, the things I've watched move people from analyst to engineer to lead:
Detections you wrote. Not tuned, wrote. A custom analytic rule that caught something real, and the story of why the first two versions were wrong.
An incident you led. Not participated in. Led, including the bit where you told somebody senior something they didn't want to hear.
Something you built. A workbook, a playbook, a script that removed a recurring manual task. It doesn't need to be clever. It needs to exist and it needs to have saved somebody time.
Something you wrote down. A runbook, an internal wiki page, a blog. Writing forces you to actually understand the thing, and it's the cheapest way to be findable by people who hire.
None of that fits in a certification. All of it fits in an interview answer, and the interview is where the decision gets made.
Get SC-200 because its absence is a question you can't answer. Get SC-300 because identity is where the work is. Get SC-100 when you've done enough to deserve it. Then stop collecting badges and go build something worth talking about.
Class dismissed.