GitHub Certifications: A Practical Guide to the Credential Ecosystem
GitHub’s certification ecosystem, delivered through Microsoft Learn and maintained by GitHub for the GitHub-specific credentials described here, covers foundational use, enterprise administration, and advanced security. It serves non-developers, developers, administrators, DevOps professionals, security practitioners, and other GitHub users. This overview explains what each available path is intended to validate, how the exams differ, which preparation resources are official, and what evidence of readiness to look for before choosing a sensible next step.
Start with the role you want to validate
The right GitHub credential depends first on whether you use GitHub, administer an enterprise environment, or secure software delivery workflows. The available paths in the supplied official material are GitHub Foundations, GitHub Administration, and GitHub Advanced Security.
GitHub Foundations is the broad entry point. Its audience includes non-developers, developers, and GitHub users who want to validate foundational knowledge of GitHub collaboration, contribution, repositories, project management, and modern development practices. The certification page labels it Beginner and associates it with roles including Administrator, App Maker, Developer, DevOps Engineer, Solution Architect, and Student.
GitHub Administration is a role-focused intermediate credential for system administrators, software developers, application administrators, and IT professionals who already have experience administering GitHub Enterprise. Its scope includes identity and access, enterprise governance, GitHub Actions, secure development features, and usage optimization. It is relevant to people supporting GitHub Enterprise Cloud or Server and working with development, security, and operations teams.
GitHub Advanced Security is also presented as an Intermediate certification, but its center of gravity is different. It is intended for experienced software-development and security professionals who have hands-on experience securing software-development workflows with GitHub Advanced Security. The candidate profile includes securing code, secrets, and dependencies, configuring features, triaging alerts, remediating findings, and applying policies, workflows, and automation.
These paths are not simply successive exams in a mandatory ladder. Foundations may be a sensible first credential for someone learning GitHub fundamentals, while an experienced administrator or security professional may have a more direct reason to prepare for a role-specific credential. Use the audience description and assessed skills as the primary selection evidence rather than choosing by title alone.
What GitHub Foundations covers
GitHub Foundations is the best fit when your immediate need is a broad working vocabulary for Git and GitHub rather than enterprise ownership or specialized security operations. The exam tests whether a candidate understands the platform’s basic concepts, collaboration model, and everyday capabilities.
The GH-900 study guide organizes the assessment into seven areas: Git and GitHub basics, GitHub repositories, collaboration using GitHub, modern development practices, project management, privacy, security and administration, and the GitHub community. The largest stated area is understanding Git and GitHub basics at 25–30% of the exam. Other domains are allocated 10–15%, 10–15%, 10–15%, 5–10%, 10–15%, and 5–10% respectively, as listed in the study guide.
The fundamentals scope is broader than committing code. Candidates should be able to distinguish Git from GitHub, explain repositories, commits, and branches, understand GitHub accounts, organizations, and enterprise options, and recognize the GitHub Flow. The study guide also includes Markdown, GitHub Desktop, GitHub Mobile, repository management, collaboration, projects, privacy, security, administration, and community concepts.
The official Foundations learning path reinforces this breadth. Its Part 1 contains eight modules and introduces Git, GitHub features and products, repository management, commits, branches, merging, GitHub Copilot, code scanning, Codespaces, GitHub Projects, and Markdown. Microsoft Learn estimates the path at 6 hours 44 minutes. That estimate describes the learning path, not the exam or a guaranteed preparation time.
A useful readiness signal is that you can explain how a change moves through a repository: create or choose a branch, make commits, open and review a pull request, and connect the work to collaboration or project tracking. You should also be comfortable identifying when repository, project, security, or account settings affect the way people work. The exam is not limited to a developer’s command-line routine.
When GitHub Administration is the better choice
Choose GitHub Administration when your work involves setting policy, controlling access, operating an enterprise environment, or helping an organization use GitHub consistently. The official audience profile expects intermediate GitHub Enterprise Administration experience, so reading about administration without practicing it is a weak substitute for operational familiarity.
The GH-100 assessment is divided into five domains. Managing GitHub identities and access represents 15–20%; administering the GitHub Enterprise environment represents 10–15%; implementing secure software development and compliance represents 25–30%; managing GitHub Actions represents 20–25%; and monitoring and optimizing GitHub usage represents 10–15%. The two largest areas therefore concern secure development and compliance and GitHub Actions, but the credential still requires coverage of identity, enterprise administration, and optimization.
The identity and access domain points toward practical administrative decisions such as managed users versus personal accounts, SAML SSO, 2FA, SCIM, team synchronization, identity providers, authentication, authorization, roles, permissions, teams, policies, rulesets, and auditing access. These are organization-level responsibilities, not merely user-profile settings.
The enterprise domain extends into organization and enterprise configuration. The secure-development and compliance domain connects administrative controls with security practices. GitHub Actions is treated as an administrative capability as well as a development automation tool. The monitoring and optimization area includes GitHub Support and diagnostics, evaluating enterprise usage patterns, identifying adoption and underused features, interpreting usage reports for metered products, and recommending license and resource optimization strategies.
A practical readiness test is whether you can reason through the consequences of a configuration choice across users, organizations, repositories, teams, workflows, and policy. Experience with only an individual repository may establish Foundations knowledge, but it does not by itself demonstrate the enterprise perspective described for GH-100. The study guide recommends training and hands-on experience before taking the exam.
Choose GitHub Advanced Security for a security-centered path
GitHub Advanced Security is the focused option for candidates who already work with code, secrets, dependencies, alerts, and secure development workflows. It should not be treated as a general introduction to GitHub security: the official profile expects familiarity with GitHub fundamentals, CI/CD, secure development concepts, and hands-on GHAS experience.
The assessment has six domains. Describing GitHub security suites, features, and the ecosystem accounts for 15–20%. Configuring and using secret protection accounts for 15–20%; configuring and using supply chain security accounts for 15–20%; configuring and using code security accounts for 10–15%; security operations, prioritization, and remediation accounts for 15–20%; and GitHub Security Suites administration accounts for 10–15%.
The scope follows a prevention-to-response workflow. A prepared candidate should understand how security suites and features fit together, protect secrets, address dependency and supply-chain risk, use code security capabilities, prioritize findings, remediate alerts, and administer security controls. The official description specifically refers to securing code, secrets, and dependencies across the software development lifecycle.
This path may suit a security professional who works with development teams, a developer responsible for secure delivery, or an administrator whose main specialization is GitHub security. It may be less suitable as a first GitHub credential if you still need to learn repositories, pull requests, Actions, or basic account and organization concepts. In that situation, Foundations or structured introductory training can establish the platform context before specialized study.
The certification page states that Microsoft provides the exam while GitHub maintains the exam and associated certification. That distinction matters when researching policies, updates, or credential ownership. The page also links to the GH-500 study guide and an exam sandbox, which should be checked for the current exam experience and preparation information.
Use official preparation resources in layers
The most reliable preparation approach is to combine the relevant Microsoft Learn overview, the exam study guide, hands-on work, and the official practice experience. Each resource answers a different readiness question, so completing only one of them can leave gaps.
Begin with the certification page for the path you are considering. It identifies the intended audience, assessed skills, exam policy links, language information, practice assessment, exam sandbox, and certification resources. The sandbox lets you interact with different question types in the exam interface. That is useful for understanding the assessment environment, but it is not a replacement for knowing the subject matter.
Next, use the matching study guide. GH-900 describes the topics that may appear and links to additional resources. GH-100 provides the skills measured for enterprise administration and notes that most questions cover general availability features, while commonly used Preview features may also appear. Exam content can change, so study guides and exam pages should be checked again before scheduling.
For a Foundations candidate, Microsoft Learn’s Introduction to GitHub module is a direct starting point. It is a Beginner module estimated at 1 hour 45 minutes and covers issues, notifications, branches, commits, and pull requests. Its learning objectives also include repository management, GitHub Flow, issues and discussions, and notifications and subscriptions. The GitHub Foundations learning path supplies a broader sequence across eight modules.
For administration, use a practice environment that lets you work with the kinds of controls named in the GH-100 objectives: identities, access, enterprise settings, governance, Actions, security, support diagnostics, reporting, and optimization. For Advanced Security, practice the complete lifecycle from enabling or configuring controls through reviewing alerts, prioritizing them, and applying remediation or policy decisions. The point is not to memorize menu locations; it is to understand why a control is used and what its operational effect is.
Finish with the official practice assessment and review the reports from previous attempts. Treat weak domains as a study plan. A strong practice result is useful evidence about question familiarity, but it does not prove that you have real administrative or security experience.
Build readiness from tasks, not topic recognition
You are closer to exam readiness when you can perform or explain the relevant work without relying on a list of feature names. The appropriate evidence differs by path.
For Foundations, demonstrate that you can navigate a repository, explain the relationship between branches, commits, and pull requests, use issues or discussions for collaboration, and understand how projects organize work. Add exposure to GitHub products and core concepts covered by the learning path, including code scanning, Copilot, Codespaces, Projects, and Markdown. You do not need to turn the overview into a programming course, but you should be able to describe what each capability is for and how it fits into a GitHub workflow.
For Administration, practice decisions involving account and enterprise boundaries, authentication, team and repository access, policies, rulesets, Actions, compliance, reporting, and optimization. Ask yourself whether you can explain the difference between granting access and governing how that access is used. Also consider whether you have seen both the human and technical sides of administration: supporting users, diagnosing issues, coordinating with teams, and interpreting usage information.
For Advanced Security, use scenarios that require more than enabling a feature. Practice identifying whether an issue concerns a secret, dependency, code finding, workflow, policy, or operational process; decide how to prioritize it; and explain how remediation should be tracked. The official candidate profile emphasizes configuring security features, triaging and remediating alerts, and using policies, workflows, and automation.
Keep a gap log with three columns: the objective, the task or explanation you can currently complete, and the evidence you still need. Map every gap to the official study guide or Microsoft Learn resource. This prevents broad, unfocused reading and makes your preparation responsive to the credential you actually selected.
Understand delivery, scoring, language, and renewal details
The three certification pages describe proctored assessments with 100 minutes to complete the exam, and they note that interactive components may be included. The official exam sandbox is therefore worth using before scheduling, particularly if you have not taken a Microsoft Learn credential assessment with interactive elements.
The study guides state that a score of 700 or greater is required to pass for GH-900 and GH-100. The certification pages also state that an unsuccessful first attempt can be retaken after 24 hours, while the waiting period for later retakes varies. Check the current exam policy rather than assuming that one retake rule covers every attempt or credential.
Language availability is credential-specific in the supplied pages. GitHub Foundations and GitHub Advanced Security list English, Spanish, Portuguese (Brazil), Korean, and Japanese. GitHub Administration lists English. The study guides explain that if an exam is not available in your preferred language, you can request an additional 30 minutes, and that localized versions may not be updated on the same schedule as English. Confirm the current Schedule Exam information before booking.
The pages state that price is based on the country or region where the exam is proctored. Because no universal price is supplied here, readers should use the official scheduling flow for the applicable location rather than relying on a copied figure.
Microsoft Learn recommends registering with a personal Microsoft account for these exams. The certification pages warn that using an organizational work or school account can cause exam records to be lost and unrecoverable if the candidate leaves that organization. Connecting the certification profile to Microsoft Learn supports scheduling and renewal functions and the ability to share or print certificates.
The study guides state that Microsoft associate, expert, and specialty certifications expire annually and can be renewed by passing a free online assessment on Microsoft Learn. That renewal statement is a Microsoft certification policy described in the guides; check the specific credential page and current renewal instructions to confirm how it applies to the credential you hold.
Use GitHub with adjacent Microsoft workflows when relevant
GitHub certification preparation should remain focused on GitHub, but some readers work in environments that connect GitHub with Azure DevOps. In that case, understanding the integration can clarify why administration and traceability skills matter beyond a single repository.
Microsoft documents integration points between Azure Boards, Azure Pipelines, GitHub, and GitHub Enterprise. Azure Boards can link GitHub commits, pull requests, branches, and issues to work items, while Azure Pipelines can provide build traceability for YAML pipelines using a GitHub repository. The documented integration also includes pull request insights and status information in Azure Boards.
This material is not a separate GitHub certification requirement in the supplied evidence, and it should not be added to a study plan merely because it appears in an adjacent Microsoft page. It is useful when your role spans GitHub and Azure DevOps or when you need to understand how development activity connects to planning and delivery. The practical question is whether your target role expects you to administer or operate that connected workflow.
The same principle applies to GitHub products in the Foundations learning path. Learn them because they support your intended work and because they appear in the relevant objectives, not because collecting every adjacent technology automatically makes a credential choice better.
Make the final path decision with five questions
A short decision checklist can prevent an appealing credential title from masking a poor fit. Answer these questions before committing to a study plan.
First, what work do you perform now or want to perform next: everyday GitHub collaboration, enterprise administration, or secure development and security operations? Foundations, Administration, and Advanced Security align to those three broad needs in the supplied official descriptions.
Second, what evidence do you already have? Foundational repository and collaboration experience supports GH-900 preparation. Enterprise identity, access, governance, Actions, and optimization experience points toward GH-100. Hands-on work with GHAS, code, secrets, dependencies, alert triage, and remediation points toward GH-500.
Third, which official domain list contains the work you cannot yet explain? Use that answer to choose training and practical exercises. A credential with familiar terminology but unfamiliar tasks is not necessarily the right next step.
Fourth, does the exam’s language, scheduling, proctoring, account, and policy setup work for you? Verify current details on the official certification page, especially language availability, price by region, account registration, accommodations, and retake rules.
Fifth, what will you do with the credential after earning it? A sensible choice should connect to a real responsibility, such as participating effectively in GitHub collaboration, operating enterprise controls, or improving secure software delivery. The certification can structure learning, but the value of preparation comes from understanding and applying the capabilities represented by the selected path.
Conclusion
GitHub’s available certification paths support different decisions rather than one universal progression. Start with GitHub Foundations if you need platform-wide fundamentals, consider GitHub Administration if you manage enterprise environments, and choose GitHub Advanced Security when your work centers on securing code, secrets, dependencies, and development workflows. Validate the choice against the official audience profile and domain breakdown, then prepare with Microsoft Learn, the matching study guide, hands-on practice, the exam sandbox, and the practice assessment. Recheck official pages before scheduling because exam policies, language information, and assessed skills can change.
Related exams
- GitHub-Actions exam — GitHub Actions Certificate Exam
- GitHub-Advanced-Security exam — GitHub Advanced Security GHAS Exam
- GitHub-Copilot exam — GitHub CopilotCertification Exam
- GitHub-Foundations exam — GitHub FoundationsExam