HomeRoadmaps › GH-100
Beta exam • verified August 19, 2026

GH-100 GitHub Enterprise Administrator Roadmap

Prepare through operational decisions: enterprise identity and access, deployment and support, secure software governance, GitHub Actions and runners, audit evidence, adoption, licensing, and cost optimization.

Exam code: GH-1005 official domains100-minute exam pageSuggested pace: 6-8 weeks
Beta and results caveat: The official pages verified on August 19, 2026 support scheduling and list skills measured as of July 2026, while this course labels GH-100 as beta. Verify the current certification page and study guide before booking. Microsoft states that beta candidates do not receive an immediate score. Scores are generally released about 10 days after the exam goes live—approximately 10-12 weeks after the beta period begins—but timing varies and can reach about 14 weeks.

Current GH-100 blueprint

The official audience profile expects experience administering GitHub Enterprise environments, including identity and access, GitHub Actions, enterprise governance, secure software capabilities such as GitHub Advanced Security, and collaboration with development, security, and operations teams. The role supports both GitHub Enterprise Cloud and GitHub Enterprise Server.

15-20%Manage identities and access
10-15%Administer enterprise environment
25-30%Secure software and compliance
20-25%Manage GitHub Actions
10-15%Monitor and optimize usage
1

Identity architecture and least privilege

Week 1

Separate identity ownership, authentication, provisioning, group membership, and authorization. Practice with synthetic users only.

  • Compare Enterprise Managed Users with enterprises that use personal accounts
  • Explain EMU lifecycle control, profile control, enterprise-only collaboration, and public contribution restrictions
  • Distinguish SAML or supported OIDC authentication from SCIM provisioning
  • Use a supported partner IdP path and understand unsupported mixed-provider risk
  • Model joiner, mover, soft deprovision, reactivation, and irreversible hard deprovision
  • Connect SCIM groups to enterprise or organization teams and understand reconciliation
  • Keep repository access assignment on GitHub even when team membership comes from the IdP
  • Apply enterprise, organization, team, repository, billing, audit, and support roles by least privilege
  • Audit effective access rather than assuming SSO grants authorization
  • Protect setup identities, provisioning tokens, certificates, recovery codes, and break-glass procedures
2

Enterprise environment, deployment, licensing, and support

Week 2

Choose the right GitHub Enterprise deployment and know which team owns an operational problem.

  • Compare GHEC with EMU, GHEC data residency with EMU, GHEC personal accounts, and GHES
  • Understand dedicated GHE.com data-residency scenarios and verify current feature differences
  • Explain customer responsibilities for GHES infrastructure, availability, backups, capacity, upgrades, and hotpatches
  • Define standards for branching, reviews, releases, workflow ownership, and administrator delegation
  • Distinguish unique enterprise users from Actions, storage, Copilot, and Advanced Security usage
  • Understand combined GHEC and GHES license synchronization and identity deduplication
  • Review inactive, suspended, pending, and duplicated account conditions before reclaiming seats
  • Check GitHub Status before escalating a suspected platform incident
  • Gather timeline, impact, version, diagnostics, and GHES support bundles securely
  • Recognize that external IdP, cloud networking, and third-party integration configuration can be outside GitHub Support scope
3

Secure software governance and compliance

Weeks 3-4

Build the highest-weight domain as a system: policy, prevention, detection, response, evidence, and integration governance.

  • Create enterprise and organization policies with documented ownership and inheritance
  • Use branch, tag, and push rulesets with precise targets and narrow bypass controls
  • Start rulesets in Evaluate mode, inspect rule insights, then activate deliberately
  • Understand ruleset layering and the most-restrictive outcome for overlapping rules
  • Configure eligible secret scanning and push protection and rotate an exposed credential before history cleanup
  • Configure CodeQL default or advanced setup by language and workflow need
  • Use the dependency graph, Dependabot alerts, dependency review, updates, and security advisories appropriately
  • Define triage, remediation, dismissal, exception, verification, and incident-response ownership
  • Govern GitHub Apps, OAuth Apps, and PATs by owner, scope, repositories, expiration, approval, and continued need
  • Use audit search, export, API, webhooks, or streaming according to latency and retention requirements
4

GitHub Actions, reusable components, runners, and secrets

Weeks 5-6

Administer workflow supply chain, execution identity, runner trust, network access, and deployment authority as connected controls.

  • Enable Actions only where intended and restrict public actions and reusable workflows
  • Require reviewed actions to be pinned to full commit SHAs where policy supports it
  • Publish reusable workflows from a protected internal repository with controlled callers
  • Set least-privilege default GITHUB_TOKEN permissions and declare job permissions explicitly
  • Compare GitHub-hosted, larger, self-hosted, and ephemeral runner options by trust and operations
  • Use enterprise-owned runner groups for cross-organization scope and restrict selected workflows
  • Protect self-hosted runners from untrusted fork code and repository-level registration sprawl
  • Monitor runner status, updates, queue, capacity, labels, application service, proxy, DNS, firewall, and GitHub connectivity
  • Scope repository, environment, organization, and enterprise secrets to the narrowest consumers
  • Use OIDC or a third-party vault to reduce long-lived secrets and constrain external trust claims
5

Monitoring, optimization, projects, and beta readiness

Weeks 7-8

Convert platform data into responsible operating decisions, finish both labs, and keep beta expectations accurate.

  • Analyze audit events, API usage, app activity, ruleset outcomes, and security administration
  • Separate licensed entitlement from active adoption and underused features
  • Use aggregate trends for users, repositories, pull requests, Actions, security coverage, and support
  • Avoid simplistic developer ranking by commit count or unnecessary exposure of private metadata
  • Interpret Actions minutes, runner use, artifacts, logs, caches, schedules, matrices, and cancellation patterns
  • Interpret Advanced Security active and unique committer usage and current billing model
  • Optimize seats and resources only after ownership, retention, security, and compliance validation
  • Build the synthetic identity/governance and secure Actions/GHAS/runner projects
  • Use original practice questions and explain why each distractor fails
  • Recheck exam beta status and expect delayed results rather than an immediate score

PrepKloud GH-100 study surfaces

Official sources

GH-100 study guide

Confirm the July 2026 skills, audience, five domains, and objectives.

Open Microsoft Learn
GH-100 certification page

Verify current status, duration, language, scheduling, and official preparation resources.

Open certification page
Microsoft beta exam guidance

Understand why scores are delayed and when results are generally released.

Open beta guidance
Enterprise Managed Users

Study IdP-controlled lifecycle, authentication, profile ownership, roles, and collaboration restrictions.

Open GitHub Docs
Enterprise Actions policies

Review allowed actions, permissions, forks, runners, and retention controls.

Open Actions policy docs
Enterprise audit log

Understand event content, retention, search, export, API access, and streaming.

Open audit docs

Frequently asked questions

Is GH-100 still a beta exam?

This course labels GH-100 beta based on official pages verified August 19, 2026. Status can change. Verify the current Microsoft Learn certification page and study guide before scheduling rather than relying on a cached article.

When are GH-100 beta results available?

Microsoft says beta candidates do not receive an immediate score because the scoring model is not finalized. Scores are generally released about 10 days after the exam goes live, approximately 10-12 weeks after the beta period begins. Timing varies and may reach about 14 weeks depending on when the exam was taken.

What are the GH-100 domain weights?

Manage identities and access is 15-20%; administer the enterprise environment is 10-15%; secure software development and compliance is 25-30%; manage GitHub Actions is 20-25%; and monitor and optimize usage is 10-15%.

Does GH-100 cover both GitHub Enterprise Cloud and Server?

Yes. The audience profile explicitly includes Cloud and Server administration. Know deployment choices, identity patterns, licensing, policies, Actions, diagnostics, support boundaries, and the customer's additional operating responsibilities for GHES.

Are PrepKloud GH-100 materials exam dumps?

No. They are original educational materials grounded in public objectives and first-party documentation. They contain no live, recalled, leaked, marketplace, or proprietary exam items and cannot guarantee a passing result.

Integrity and independence: PrepKloud is independent and is not Microsoft or GitHub. This roadmap uses public objectives and first-party documentation and contains no exam dumps, recalled questions, marketplace copying, guaranteed predictions, legal or compliance assurance, salary promises, or employment guarantees. Product behavior, licensing, support boundaries, previews, and the beta status can change. Use synthetic identities, repositories, credentials, events, and disposable nonproduction runners for labs.

Prepare by administering a safe synthetic enterprise

Use original questions to diagnose gaps, flashcards to reinforce distinctions, and two operational projects to produce evidence.