GH-900 Exam Guide: What to Learn, How to Prepare, and When to Schedule
GH-900 validates foundational knowledge of GitHub, including Git, repositories, collaboration, project management, modern development practices, security, administration, and the GitHub community. It is intended for non-developers, developers, and other GitHub users who want to confirm that foundation. This guide helps you decide whether your current experience is sufficient, which study areas deserve the most time, how to use Microsoft’s preparation resources, and what to verify before scheduling the assessment.
Is GH-900 the right certification for you?
GH-900 is a beginner-level GitHub certification for people who need to understand how GitHub is used to collaborate, contribute, organize work, and support software development. Microsoft identifies non-developers, developers, and other GitHub users as suitable candidates, so prior professional development experience is not presented as a requirement.
The certification is a reasonable target if you can explain the purpose of Git and GitHub, recognize how repositories and branches support change management, and follow the logic of issues, pull requests, and project tracking. It is less suitable as a first step if terms such as commit, branch, repository, or pull request are entirely unfamiliar; begin with the introductory learning path before setting an exam date.
The Microsoft certification page classifies GitHub Foundations as beginner level, with GitHub as the product and DevOps as the subject area. Its listed role contexts include Administrator, App Maker, Developer, DevOps Engineer, and Solution Architect. Those role labels describe possible relevance, not a requirement to hold one of those jobs.
What the exam validates in practical terms
The exam tests whether you can select and explain appropriate GitHub concepts and features in common situations. For example, preparation should enable you to distinguish a Git concept from a GitHub service, choose an appropriate collaboration tool, recognize an access or visibility consideration, and understand where automation or project tracking fits into a workflow.
Treat the exam as a fundamentals assessment rather than a test of advanced administration or specialist security implementation. The study guide says most questions cover generally available features, although preview features may appear when they are commonly used. That makes current Microsoft Learn material more useful than an old list of isolated definitions.
Which skills carry the most weight?
Start with the domain that has the largest published range: understanding Git and GitHub basics accounts for 25–30% of GH-900. The remaining domains are narrower but collectively cover repositories, collaboration, development practices, projects, security and administration, and community participation.
The percentages below are from the January 2026 revision of Microsoft’s study guide. They are planning ranges, not a promise about the number of questions or a substitute for reading the detailed objectives. Allocate study time by domain, then check each objective rather than assuming that a low-weight domain can be ignored.
The seven measured domains
Understanding Git and GitHub basics accounts for 25–30% of GH-900. This area includes version-control purpose and benefits, the difference between Git and GitHub, repositories, commits, branches, GitHub accounts, organizations, enterprise options, GitHub Flow, Markdown, GitHub Desktop, and GitHub Mobile.
Working with GitHub repositories accounts for 10–15% of GH-900. Prepare for repository structure and important files such as README, LICENSE, CONTRIBUTING, CODEOWNERS, and SECURITY; repository creation and organization; file management; visibility and repository metrics; and maintenance practices.
Collaborating using GitHub accounts for 10–15% of GH-900. The study guide includes issues, pull requests, discussions, links between pull requests and issues, templates, filters, assignments, notifications, Gists, Wikis, and GitHub Pages.
Applying modern development practices accounts for 10–15% of GH-900. This domain covers GitHub Actions, GitHub Copilot, Copilot plans and capabilities, GitHub Codespaces, development containers, and the difference between github.dev and Codespaces.
Managing projects with GitHub accounts for 5–10% of GH-900. Review GitHub Projects and layout options, issues, labels, milestones, workflows, saved replies, assignees, and project insights.
Understanding privacy, security, and administration accounts for 10–15% of GH-900. The objectives include 2FA, passkeys, repository and organization permissions and roles, Enterprise Managed Users, organization-wide Copilot policy management, repository visibility, branch protection rules, teams, and organization roles.
Exploring the GitHub community accounts for 5–10% of GH-900. Study open-source benefits, GitHub Sponsors, GitHub’s support for open-source projects, following users and organizations, GitHub Marketplace, InnerSource, forks, templates, and discoverable repositories.
How to interpret the weighting
The weighting suggests a sensible sequence: build the Git and GitHub model first, then connect it to repository work and collaboration. Do not turn the ranges into a calculation of expected question counts. Microsoft publishes skill percentages, but the supplied official material does not provide a question count or a fixed distribution for an individual assessment.
A practical allocation is to spend the largest block of study time on the first domain, then use the other six domains to expose gaps. Someone who works daily with pull requests may need less introductory collaboration study but more deliberate review of permissions, community features, or Copilot terminology. Your own diagnostic results should adjust the plan.
What should you learn about Git and GitHub first?
Build a clear mental model before memorizing product names. Git is the version-control system, while GitHub is the platform that supports repositories, collaboration, communication, automation, and related development services. The exam objectives connect repositories, commits, branches, and GitHub Flow, so study these concepts as a sequence rather than as unrelated vocabulary.
Use a small practice repository or a guided Microsoft Learn exercise to trace a change from an initial repository through a branch, commit, review, and merge. The purpose is not to reproduce an exam task; it is to make the relationships between the terms visible. Afterward, explain the flow in your own words without relying on a command list.
Include GitHub account, organization, and enterprise concepts in this foundation. A common mistake is to treat an organization as simply another personal account or to assume that every GitHub feature has the same scope. When studying a feature, ask whether it applies to an individual, repository, organization, or enterprise context.
A useful first-week exercise
Read the Introduction to Git and Introduction to GitHub modules in the GitHub Foundations learning path. Then create a glossary with four columns: concept, purpose, scope, and related feature. Entries might include repository, commit, branch, issue, pull request, organization, and project. Add a short scenario to each entry, such as proposing a change, recording a change, or tracking work.
Review Markdown alongside issues and pull requests rather than postponing it as a formatting topic. The objective is communication: headings, lists, links, and readable descriptions help contributors understand work. Also note when GitHub Desktop or GitHub Mobile is appropriate, since the blueprint asks you to recognize their uses rather than merely identify their names.
How should you study repositories and collaboration?
Study repository management and collaboration as one working loop: repository structure provides context, issues describe or track work, a branch isolates a change, a pull request supports review, and project features organize progress. This sequence gives each feature a job and reduces the risk of confusing similar tools.
Inspect the purpose of the key repository files named in the study guide. README communicates what a project is and how to begin; LICENSE addresses use and distribution terms; CONTRIBUTING guides participation; CODEOWNERS supports ownership and review routing; and SECURITY communicates security-reporting expectations. The exam objective is to understand their roles, not to reproduce a particular file template.
Then compare issues, pull requests, and discussions. Issues can capture work or problems, pull requests propose changes for review, and discussions support broader conversation. Practice identifying the most suitable tool from a scenario. Linking a pull request to an issue, using templates, applying filters, assigning work, and configuring notifications are all explicitly represented in the measured skills.
Repository study decisions
Do not spend all your time clicking through settings without recording why a setting matters. For each repository feature, write one decision statement: when would a team use a template, why would it monitor repository insights, what does a branch protection rule control, or how could visibility affect collaboration? Decision statements are more durable than screenshots because interfaces can change.
Include repository discovery and maintenance. The blueprint mentions stars, feature previews, repository metric dashboards, dependency insights, and best practices for maintenance and collaboration. Learn what each is intended to help a user understand or manage, while checking the current Microsoft Learn material for terminology and availability.
Collaboration practice without overbuilding
A lightweight practice workflow is enough. Open or review an issue, plan a change, create or inspect a branch, describe a pull request, connect it to the issue, and consider who should be notified or assigned. If you do not have a team repository, use the guided learning exercises and focus on the reasoning behind each step.
Also review Gists, Wikis, and GitHub Pages as different ways to document or share information. A frequent preparation error is grouping every documentation feature under “README.” The objective expects recognition of several communication options and the situations in which they serve different audiences.
What modern development practices belong in the study plan?
Modern development practices are not limited to writing code. GH-900 asks you to understand the purpose of automation, AI-assisted development, cloud development environments, and code scanning-related concepts. Learn what each service is designed to accomplish, how it relates to a repository workflow, and where its boundaries differ from neighboring services.
Use Microsoft’s GitHub learning collections selectively. The GitHub Foundations path includes modules on GitHub Actions, GitHub Copilot, GitHub Codespaces, code scanning, GitHub Projects, and Markdown. Follow the modules that correspond to your weak areas, but do not assume completion percentages or activity indicators prove readiness; verify that you can explain the objectives without notes.
For Copilot, focus on the capabilities and distinctions named in the study guide, including Copilot agents, agent mode, multi-model support, and differences among individual, business, and enterprise contexts. Avoid reducing the topic to “AI writes code.” The exam objective is about recognizing how GitHub Copilot supports development and how offerings or governance contexts differ.
Actions, Codespaces, and github.dev
For GitHub Actions, learn the purpose and broad function of workflow automation. Be able to relate automated work to events in a software development process without attempting to memorize every configuration detail. For Codespaces, understand the idea of a fully configured development environment hosted in the cloud and why a workspace can be accessed from a computer with internet access.
Compare Codespaces with github.dev explicitly. The blueprint asks when to use github.dev and how it differs from Codespaces, so make a two-column note describing the role of each. Add development containers to the comparison and identify why a team might want a repeatable development environment.
Code scanning is included in the recommended learning path, with CodeQL, third-party tools, and GitHub Actions named as implementation-related topics. Study the purpose of code scanning and how it fits into a secure development workflow. Do not drift into advanced security configuration unless an objective or current official learning resource requires it.
How do GitHub Projects and security objectives fit together?
Project management and security are separate domains, but both test whether you can choose an appropriate control for a practical need. Projects organize work and progress; security and administration govern identity, access, visibility, protection, and organizational policy. Study each by starting with the problem it solves rather than memorizing menu locations.
For Projects, review project and layout options, labels, milestones, workflows, saved replies, assignees, and project insights. Create a simple mapping from a need to a feature: categorize work, mark a delivery target, automate a status change, streamline a response, assign responsibility, or inspect progress. This makes the small 5–10% project-management domain efficient to review without neglecting it.
For security, understand the difference between account protection, repository access, organization administration, and enterprise governance. The objectives specifically name 2FA, passkeys, permissions, roles, Enterprise Managed Users, Copilot policy management, repository privacy, visibility settings, branch protection rules, teams, and organization roles.
Avoiding security terminology traps
Separate authentication from authorization. 2FA and passkeys concern protecting an account; permissions and roles concern what a person or team can do; visibility concerns who can see a repository; branch protection rules concern safeguards around changes. These are related but not interchangeable. Build scenario cards that ask, “What is being protected, and at what scope?”
Review organization and enterprise concepts together, then revisit them after studying repositories. A setting that makes sense for a personal repository may have a different governance implication in an organization. The goal is not to infer undocumented behavior; use the official study guide and linked learning resources for the current scope and terminology.
What does the GitHub community domain require?
The community domain tests awareness of how GitHub supports participation beyond a single private development team. Prepare to distinguish open-source engagement, InnerSource, marketplace discovery, sponsorship, following activity, forks, templates, and repository discoverability. These topics are smaller by weighting, but they are easy to overlook if your experience is limited to private repositories.
Study the purpose of each feature through a scenario. A fork can support independent contribution to an existing project; a template can help start consistently structured repositories; following can keep a user informed; Marketplace can provide discoverable tools or services; and InnerSource applies open-source principles within an organization. Confirm details in current Microsoft Learn content rather than filling gaps with assumptions about a particular project.
Do not treat open source as a synonym for “public repository.” The exam objective includes benefits, support for open-source projects, and GitHub Sponsors, so review the social and organizational concepts as well as repository visibility.
Which official resources should you use?
Use Microsoft’s GH-900 study guide as the control document, the certification page for scheduling and exam experience information, and the GitHub Foundations learning path for structured study. Microsoft also provides an exam sandbox and practice assessment on the certification page. These resources serve different purposes: scope, learning, interface familiarity, and readiness diagnosis.
The GH-900T00-A course is another official option. Microsoft lists it as a beginner GitHub Foundations course available through instructor-led or self-paced study. The course page lists a course duration of 2 days and languages of English, Japanese, Korean, Portuguese (Brazil), and Spanish. Treat the course as a structured route, not as evidence that two days is sufficient for every candidate.
A resource order that prevents duplication
Begin with the study guide and mark every objective as new, familiar, or demonstrable. Use the learning path to address the new items, and use hands-on exercises for items you marked familiar but cannot explain. Return to the study guide after each module and write a one-sentence answer for every objective.
Take Microsoft’s practice assessment after an initial study pass, not as your only preparation. Use its report to identify gaps, then revisit the relevant official module. The certification page describes practice assessments as a way to assess knowledge, understand question style, and identify areas for further preparation.
Use the exam sandbox before the assessment so the interface and interactive component possibility are not new to you. The sandbox is for understanding the environment; it is not a source of live exam content. Avoid dumps, leaked questions, or memorization-based shortcuts. They do not establish the understanding the blueprint measures and may expose you to inaccurate or unauthorized material.
What is a practical GH-900 study roadmap?
A good roadmap moves from concepts to connected workflows, then from workflows to diagnosis. Start with Git and GitHub basics, build a repository-and-collaboration exercise, study automation and project management, review security and community topics, and finish with the official practice assessment and sandbox. Adjust the pace according to your diagnostic results rather than following a fixed calendar blindly.
Stage 1: establish the vocabulary and model
Read the study-guide audience profile and the seven domain descriptions. Complete the introductory Git and GitHub modules. Your checkpoint is the ability to explain Git versus GitHub and to connect repository, commit, branch, issue, pull request, and GitHub Flow in a coherent example.
If you cannot explain why a branch or commit is useful, do not move on merely because the module is complete. Rework the concept with a small repository exercise or a written scenario. This is the highest-weight domain, so unresolved confusion here should take priority over polishing lower-weight topics.
Stage 2: trace a collaborative change
Study repository management, Markdown, issues, pull requests, discussions, notifications, Gists, Wikis, and GitHub Pages. Perform or simulate one complete change workflow. Along the way, identify repository files, select the appropriate communication tool, and record how work is assigned, filtered, linked, and reviewed.
At the end of this stage, explain not only what a feature does but why a team would select it. If your notes contain only interface labels, add scenarios. This is also the point to revisit GitHub Desktop and GitHub Mobile and record their intended use cases.
Stage 3: add development services and project tracking
Work through the relevant learning-path modules for Actions, Copilot, Codespaces, code scanning, Projects, and Markdown. Create comparison notes for Codespaces versus github.dev, GitHub Actions versus manual workflow steps, and project labels versus milestones or workflows. Use official descriptions to resolve uncertain distinctions.
Do not spend disproportionate time learning implementation syntax that the objectives do not require. GH-900 is assessing foundational understanding. Prioritize purpose, relationship, scope, and recognition of appropriate use.
Stage 4: close governance and community gaps
Review the security and administration objectives deliberately. Make separate notes for authentication, permissions, roles, visibility, branch protection, teams, organization settings, Enterprise Managed Users, and Copilot policy management. Then cover community topics such as open source, Sponsors, Marketplace, InnerSource, forks, templates, and following.
This stage is where candidates with developer-only experience often find gaps. Familiarity with commits and pull requests does not automatically demonstrate knowledge of organization administration or community features. Use the objective list as a checklist and mark a topic complete only when you can explain its practical purpose.
Stage 5: diagnose and schedule
Take the official practice assessment and review the report. Re-study weak domains, then use the sandbox to become familiar with the assessment interface. Schedule only after you can explain the objectives without relying on answer memorization and have checked the current certification page for language, delivery, timing, and registration information.
Microsoft states that a score of 700 or greater is required to pass GH-900. That threshold should be treated as an official scoring requirement, not as a target percentage for an unofficial practice test. Practice results are useful for finding gaps, but they do not guarantee an equivalent assessment outcome.
What delivery and scheduling details should you verify?
Microsoft states that GH-900 is proctored and may include interactive components, and that the assessment has 100 minutes. The certification page lists English, Spanish, Portuguese (Brazil), Korean, and Japanese. Before registering, verify the live exam-details page for the current appointment experience, available language, regional conditions, and any accommodation needs.
Microsoft lists the price as US$99 and notes that pricing is based on the country or region where the exam is proctored. The certification page directs candidates to schedule through Pearson VUE. Because scheduling and regional information can change, use the official page rather than relying on a third-party listing.
Account and language decisions
Microsoft strongly recommends registering with a personal Microsoft account. The certification page warns that using an organizational work or school account can cause exam records to be lost and unrecoverable if you leave that organization. Resolve the account choice before booking, and make sure your certification profile is connected to Microsoft Learn.
The study guide says localized exams are updated approximately eight weeks after the English version is updated, although localized updates may not always follow that schedule. If GH-900 is unavailable in your preferred language, Microsoft says you can request an additional 30 minutes. Check the current scheduling information and accommodation process before relying on this option.
Retakes and readiness planning
Microsoft states that a failed certification exam can be retaken 24 hours after the first attempt; the interval for subsequent retakes varies. This is a policy detail, not a reason to schedule before you are prepared. If you need another attempt, consult the current retake policy and use the first result to target specific domains.
Connect your certification profile to Microsoft Learn before the exam. Microsoft says this connection allows you to schedule and renew exams and share and print certificates. Keeping registration and credential activity on the intended personal account reduces avoidable account-recovery problems later.
What mistakes reduce preparation quality?
The most damaging mistakes are studying outside the blueprint, memorizing disconnected definitions, ignoring lower-weight domains, and treating an unofficial question source as proof of readiness. A better approach is to map each objective to an explanation, a scenario, or an official exercise, then use the practice assessment to identify what still needs work.
Do not assume hands-on experience covers every objective. Someone who works daily with pull requests may still need to study Enterprise Managed Users, passkeys, project insights, GitHub Marketplace, or GitHub Pages. Conversely, someone from a non-development background should not skip the Git fundamentals simply because the certification is called GitHub Foundations.
Avoid relying on screenshots or old feature descriptions. The study guide notes that most questions cover GA features and may include commonly used preview features. Current official resources matter, particularly for product terminology and localized content. Keep a short “verify before exam day” list for anything that appears to have changed.
A final self-check
Before scheduling, answer these questions in writing: Can you explain Git versus GitHub? Can you describe the role of repositories, commits, branches, issues, pull requests, and Projects? Can you distinguish collaboration, automation, cloud development, account security, repository visibility, and organization administration? Can you explain when a fork, template, Marketplace tool, or InnerSource approach might be useful?
If any answer is vague, return to the corresponding objective and official learning resource. If the answer is clear but your practice assessment identifies a different weakness, follow the report. Preparation should respond to evidence about your knowledge, not to a generic number of study sessions.
What should you do after passing GH-900?
After passing, use the Microsoft Learn credentials area to confirm that the certification is associated with the account used for the exam. Microsoft’s support guidance says that a result may take up to 24 hours to sync. If the credential remains missing, follow the official credentials-support process rather than creating a second account or repeating the exam.
The Microsoft Q&A guidance explains that certificates and badges are managed through Microsoft Learn. Sign in with the same account used for GH-900, open the credentials page, locate the GitHub Foundations entry, and use the available view or print option to print to PDF or save a PDF copy. If the entry still does not appear after the stated sync period, submit a credentials-support request describing that the exam was passed but the certificate is missing.
Use the certification as a checkpoint for continued practice, not as the end of GitHub learning. The official GitHub training collection also provides paths for GitHub Actions, GitHub Advanced Security, GitHub Administration, and Copilot fundamentals. Choose a follow-on area based on the work you want to perform next, rather than collecting unrelated modules.
Your next actions for GH-900
Open the official GH-900 study guide and turn its seven domains into a checklist. Start with Git and GitHub basics, complete the relevant GitHub Foundations learning modules, and create one connected repository-and-collaboration exercise. Then review Actions, Copilot, Codespaces, Projects, security, administration, and community topics against the detailed objectives.
Take the official practice assessment to locate gaps, use the exam sandbox to inspect the interface, and verify current language, proctoring, timing, pricing, account, and scheduling information on Microsoft Learn before booking through Pearson VUE. Do not use dumps or leaked questions as a preparation method; use the blueprint and official resources to build transferable understanding.
Conclusion
GH-900 preparation is strongest when it follows the published skill domains and tests your ability to choose and explain GitHub features in context. Build the Git and GitHub foundation first, connect repositories to collaboration, then cover modern development practices, project management, governance, and community participation. Finish with Microsoft’s practice assessment and exam sandbox, correct the gaps they reveal, and verify live scheduling details before registering.
Related exams
- GH-100 exam — GitHub Administration
- GH-200 exam — GitHub Actions Exam
- GH-300 exam — GitHub Copilot Exam
- GH-500 exam — GitHub Advanced Security Exam