A map of the terrain, not a catalog
The cybersecurity certification market is dense and sometimes difficult to decipher. The infographic published by Excellog.Biz proposes a structuring into three major domains — Defensive Security, Offensive Security and GRC, Cloud & Leadership — which accurately reflects the reality of current professional careers.
For teams operating on Microsoft Azure and Microsoft 365, this mapping constitutes a concrete reference for prioritizing training and aligning skill development with the organization's real needs.
Scope of this article
This article analyzes the structure of the mapping and highlights certifications directly relevant to professionals in the Microsoft ecosystem. It does not constitute a registration guide or preparation program for a specific exam.
Defensive Security: three levels, clear progression
The defensive block organizes certifications according to three maturity tiers: Foundation, Practitioner and Specialist.
Foundation Level
This tier brings together entry-level certifications intended to validate basic security knowledge:
- CC (Certified in Cybersecurity — ISC2)
- Security+ (CompTIA)
- SC-900 — Microsoft Security, Compliance, and Identity Fundamentals
The SC-900 is the natural starting point for any professional working in the Microsoft ecosystem. It validates understanding of fundamental security, compliance and identity concepts in Microsoft 365 and Azure, without advanced technical prerequisites.
Practitioner Level
This tier covers daily operational roles in a SOC or incident response team:
- CySA+, BTL1, CDSA, CJDE — multi-vendor references
- SC-200 — Microsoft Security Operations Analyst
- GSEC, eCIR, eCIH — incident response specialists
The SC-200 deserves special attention: it validates the ability to detect, investigate and respond to threats via Microsoft Sentinel, Microsoft Defender XDR and Microsoft Defender for Cloud. It is today one of the most in-demand certifications for SOC analysts operating on a Microsoft tenant.
Specialist Level
At this stage, the mapping identifies specialized certifications focused on network forensics and advanced intrusion analysis:
- GCIA — GIAC Certified Intrusion Analyst
- GCDA — GIAC Certified Detection Analyst
These titles are intended for profiles with several years of experience in traffic analysis and behavioral detection.
Recommended defensive path
For a Microsoft professional, the progression SC-900 → SC-200 → GCIA constitutes a coherent path that covers theory, Microsoft tooling and analytical depth.
Offensive Security: from beginner to exploit developer
The offensive domain is structured in five levels of progression, plus an emerging category dedicated to AI.
Entry and Practical Attack
Entry-level certifications target future pentesters and red teamers early in their careers:
- PNPT, PJPT, CPTS, CEH, CWES
The Practical Attack level, heavily focused on practical implementation in real environments, is often the first reference recognized by recruiters:
- OSCP+, OSWP, OSWA — Offensive Security
- CRTP — Certified Red Team Professional
- eJPT — eLearnSecurity
The OSCP+ certification (OffSec) remains an essential reference for validating operational capacity in penetration testing, particularly on hybrid Active Directory infrastructures connected to Microsoft Entra ID.
Advanced and Expert
These levels are intended for experienced red teamers and exploit developers:
- OSEP, OSED, OSWE, OSCE3, OSEE — Offensive Security
- CRTO — Certified Red Team Operator
AI Offensive: a category to watch
The emergence of the OSAI certification in the AI Offensive category marks a structural evolution in the field. Artificial intelligence is simultaneously becoming an attack vector and a surface to secure, generating new needs for specialized offensive skills.
Emerging category
The OSAI certification and AI Offensive category are currently being structured in the industry. Verify availability and prerequisites directly with Offensive Security before planning this certification.
Governance, Cloud and Leadership: Strategic Certifications
This third block is aimed at profiles that drive security strategy at the organizational level. It is divided into two complementary areas.
Assurance Track
This track groups references for audit, management and risk management:
- CISA — Certified Information Systems Auditor (ISACA)
- CISM — Certified Information Security Manager (ISACA)
- CRISC — Certified in Risk and Information Systems Control (ISACA)
Details of these certifications are available directly on the ISACA website.
Architecture Track
Two certifications dominate this track:
- CISSP — Certified Information Systems Security Professional (ISC2)
- CCSP — Certified Cloud Security Professional (ISC2)
The CISSP is generally considered the pivotal title for a Security Architect or a CISO. It covers eight domains ranging from risk management to cryptography. The CCSP, on the other hand, is specifically oriented toward cloud security and addresses governance, architecture and compliance in multi-cloud environments — making it directly applicable to large-scale Azure deployments.
CISSP prerequisites
CISSP requires a minimum of five years of cumulative professional experience in at least two of the eight CBK (Common Body of Knowledge) domains. Without this experience, the candidate receives the title of Associate of ISC2.
Comparing the three domains: positioning and prerequisites
| Domain | Entry level | Associated Microsoft certification | Target profile |
|---|---|---|---|
| Defensive Security | SC-900 / Security+ | SC-900, SC-200 | SOC Analyst, Incident Responder |
| Offensive Security | PNPT / eJPT | No official Microsoft certification | Pentester, Red Teamer |
| GRC, Cloud & Leadership | CISA / CISM | CCSP (Azure cloud compatible) | CISO, Security Architect, Risk Manager |
Building a path aligned with your objectives
A mapping does not replace a job analysis. Before committing to a certification, three questions deserve to be asked:
- What role are you targeting in the next 12 to 24 months? The answer guides the choice between the three domains.
- What tools are in production in the organization? If Microsoft Sentinel and Microsoft Defender XDR are deployed, SC-200 brings immediate value.
- What are the formal prerequisites? CISSP requires five years of experience; OSCP+ requires prior mastery of network and system fundamentals.
For organizations primarily operating on Azure and Microsoft 365, a coherent trajectory could follow this progression:
- SC-900 → Microsoft conceptual foundation
- SC-200 → defensive operations on Microsoft tooling
- CCSP or CISSP → moving up to cloud architecture and governance
This progression covers both daily operational needs and medium-term strategic responsibilities, without disruption in the logic of skill development.
Complementary resource
Microsoft Learning offers official preparation paths for SC-900 and SC-200 directly on Microsoft Learn. These paths are free and constitute a solid starting point before investing in paid training.



