Tag not monitored by Microsoft.
Hello @AUGUSTINE ALFRED ABA
Welcome to the Microsoft community! Your offensive security background can actually give you a strong foundation because you already understand how attackers think. The next step is translating that knowledge into identity, cloud security, detection, response, and security architecture within the Microsoft ecosystem.
Your roadmap is a good start, but I’d make one adjustment:
AZ-900 → SC-900 → SC-300 → SC-500 / SC-200 → SC-100
You don't necessarily need to complete every certification, but this gives you a clearer progression.
SC-900 is worth adding after AZ-900 because it introduces Microsoft's security, compliance, identity, Microsoft Entra, Defender, Sentinel, and Zero Trust concepts.
SC-300 is a great choice if you want strong identity expertise. It goes much deeper into Microsoft Entra ID, Conditional Access, Identity Protection, Privileged Identity Management, identity governance, authentication, and Zero Trust.
From there, I'd choose based on the role you want.
If you're targeting Cloud/Security Engineering, SC-500 is highly relevant. Microsoft is transitioning from AZ-500 to SC-500, with AZ-500 retiring on August 31, 2026. SC-500 expands the security-engineering scope into cloud and AI security.
If you're interested in the SOC/Blue Team side, I'd strongly consider SC-200 as well. It covers incident investigation, threat hunting, detection engineering, Microsoft Defender XDR, Microsoft Sentinel, Defender for Cloud, and KQL. Your offensive-security experience could be particularly useful here because understanding attacker behavior translates nicely into detection and hunting.
Most importantly, don't make certifications your entire roadmap. Build something alongside them.
Create an Azure lab and practice Entra ID, Conditional Access, RBAC, PIM, Defender for Cloud, Defender XDR and Sentinel. Generate some test security events, ingest logs into Sentinel, write KQL queries, investigate incidents, and document what you learned. A small GitHub portfolio showing what you actually configured, attacked, detected and remediated can say a lot more than a collection of badges.
Longer term, SC-100 (Cybersecurity Architect Expert) is a good target once you've built practical experience. Microsoft positions it around designing security strategies spanning identity, infrastructure, applications, data, AI, security operations, governance and Zero Trust.
Also, you've joined at a pretty good time: Microsoft is currently running the Microsoft Defender Skilling Challenge through August 21, 2026, covering Defender XDR, Sentinel and Defender for Cloud, with an opportunity for discounted SC-200 or SC-500 exam vouchers.
Microsoft Defender Skilling Challenge: https://learn.microsoft.com/en-us/security/challenge/defender-challenge?
Keep building publicly, participate here in Microsoft Q&A, and share the labs and problems you solve. That's also one of the best ways to meet people in the community who are working with these technologies every day.
Good luck with the journey, Augustine.
Please "Accept the Answer" if this information helped you. This will help us and others in the community as well.