GitHub AdministrationStudy guide
The intermediate administrator certification for managing GitHub Enterprise identities, security, Actions, and operations (GH-100).
About GitHub Administration (GH-100)
GitHub Administration (GH-100) is a Associate-level certification from GitHub. This page organizes the exam scope into a 5-chapter, 11-section study guide and lets you check your understanding with exam-style practice questions. A good flow is to read the chapters below in order, then test yourself via "Practice questions."
Exam domains (approximate weighting)
- Manage GitHub identities and access~18%
- Administer GitHub Enterprise environment~14%
- Implement secure software development and compliance~28%
- Manage GitHub Actions~25%
- Monitor and optimize GitHub usage~15%
Weights are approximate guidance for the live exam. Each domain is covered in detail in the chapters and sections below.
Official exam information: https://learn.microsoft.com/en-us/credentials/certifications/resources/study-guides/gh-100
1Manage GitHub Identities and Access
- 1.1User Identities and Authentication
Understand the difference between managed users and personal accounts, configuring/enforcing SAML SSO and 2FA, SCIM and team synchronization (implementation and differences), choosing/configuring identity providers, and GitHub’s authentication/authorization model.
- 1.2Managing Access and Permissions
Understand organization and repository roles, defining/managing enterprise teams, auditing access and permissions, and managing settings/policies/rulesets/roles—governing access along least-privilege principles.
2Administer GitHub Enterprise Environment
- 2.1Supporting Users and Standardizing Developer Processes
Understand distinguishing issues an admin can resolve from those for GitHub Support, generating support bundles and diagnostics, and defining standards for developer processes—workflows, branching, reviews, and releases.
- 2.2Deployment Scenarios and Licensing
Understand the main GitHub Enterprise deployment scenarios (GHEC with EMU, GHEC with Data Residency + EMU, GHEC with personal accounts, GHES), licensing and billing models, and monitoring license usage.
3Implement Secure Software Development and Compliance
- 3.1Security Policies and Rulesets
Understand defining organization and enterprise policies, strengthening the enterprise security posture and data protection, and implementing audit logging and reporting—how an admin sets org-wide guardrails.
- 3.2Repository Security Features
Understand configuring vulnerability alerts, secret scanning, and CodeQL; managing Dependabot and security advisories; and defining/implementing a security response plan—from an admin’s view.
- 3.3Managing API Access and Integrations
Understand configuring personal access tokens (PATs), rate limits for PATs and GitHub Apps, the difference between GitHub Apps and OAuth Apps, and approving/denying apps based on policy.
4Manage GitHub Actions
- 4.1Actions Governance and Runner Management
Understand configuring reusable actions/workflows to enterprise repositories, applying org policies for GitHub Actions, managing runner groups and GitHub-hosted/self-hosted runners, IP allow lists and networking (including Azure private networking), and monitoring/troubleshooting runner performance—from an admin’s view.
- 4.2Encrypted Secrets and Third-party Vault Integration
Understand defining the scope and access of secrets, configuring secrets at organization and repository levels, and integrating third-party vaults (secret management platforms)—from an admin’s view.
5Monitor and Optimize GitHub Usage
- 5.1Monitoring Enterprise Usage and Activity
Understand analyzing audit logs and API usage, distinguishing admin vs GitHub Support responsibilities and generating diagnostics, and evaluating usage patterns (adoption, activity, underutilized features).
- 5.2Optimizing Cost and Performance
Understand interpreting usage reports for metered products and strategies for license and resource optimization—from an admin’s view, balancing cost and performance.

