SC-900: Microsoft Security, Compliance, and Identity Fundamentals

Fundamentals Security
Browse certifications
28 modules
·
~5h 5m study time
·
0 completed

Interactive Study Guide

Each module covers one exam topic with plain-English explanations, real-world scenarios, and built-in practice. Everything you need to understand and retain the material — no tab-switching required.

📖 ELI5 explanations
🔄 Flashcards
✅ Knowledge checks
📊 Compare tables
💡 Exam tips
📍 Progress tracking
Domain 1: Security, Compliance & Identity Concepts
Encryption, Hashing & GRC 11m
Loading module…
Identity: The New Security Perimeter 12m
Loading module…
Security Foundations: Shared Responsibility & Defence-in-Depth 10m
Loading module…
Zero Trust: Never Trust, Always Verify 10m
Loading module…
Domain 2: Microsoft Entra Capabilities
Authentication: Passwords, MFA & Passwordless 12m
Loading module…
Conditional Access: Smart Access Decisions 11m
Loading module…
Microsoft Entra ID: Your Identity Hub 12m
Loading module…
Entra Roles and RBAC 10m
Loading module…
Hybrid & External Identities 10m
Loading module…
Identity Governance: Entitlements and Access Reviews 11m
Loading module…
Password Protection & Self-Service Reset 10m
Loading module…
PIM and Identity Protection 11m
Loading module…
Domain 3: Microsoft Security Solutions
Azure Infrastructure Security: VNets, NSGs, Bastion & Key Vault 12m
Loading module…
Azure Network Defence: DDoS, Firewall & WAF 12m
Loading module…
Defender for Cloud Apps & Defender for Identity 11m
Loading module…
Microsoft Defender for Endpoint 10m
Loading module…
Microsoft Defender for Cloud 12m
Loading module…
Microsoft Defender for Office 365 10m
Loading module…
Defender XDR: The Unified Threat Platform 11m
Loading module…
Microsoft Sentinel: SIEM Meets SOAR 11m
Loading module…
Vulnerability Management & Threat Intelligence 10m
Loading module…
Domain 4: Microsoft Compliance Solutions
Data Classification & Sensitivity Labels 12m
Loading module…
Data Loss Prevention (DLP) 11m
Loading module…
eDiscovery & Audit 10m
Loading module…
Insider Risk Management 10m
Loading module…
The Purview Portal & Compliance Manager 11m
Loading module…
Records Management & Retention 11m
Loading module…
Service Trust Portal, Privacy Principles & Microsoft Priva 11m
Loading module…

Exam Resources

Official learning paths, exam details, skills measured, and community resources to supplement your study.

Exam Quick Facts

DetailValue
Exam CodeSC-900
TitleMicrosoft Security, Compliance, and Identity Fundamentals
LevelFundamentals
Pass Score700 / 1000
Duration45 minutes
Questions~40–60 (multiple choice, drag-and-drop)
Cost$99 USD (varies by region)
SchedulingPearson VUE / Certiport (students)
Skills UpdatedNovember 7, 2025

Official Learning Paths

Complete these four Microsoft Learn paths to cover the full syllabus:

  1. 📘 Describe the concepts of security, compliance, and identity — Core security principles, Zero Trust, identity concepts
  2. 📘 Describe the capabilities of Microsoft Entra — Identity management, authentication, access control
  3. 📘 Describe the capabilities of Microsoft security solutions — Azure security, Sentinel, Defender XDR
  4. 📘 Describe the capabilities of Microsoft compliance solutions — Purview, compliance management, information protection

📖 Study Resources

ResourceLink
📝 Official Exam PageMicrosoft Learn — SC-900
📖 Official Study GuideMicrosoft Study Guide
🎯 Free Practice AssessmentStart Practice Assessment
🖥️ Exam SandboxTry the exam interface
🎬 Exam Readiness ZoneVideo prep series
📺 John Savill’s SC-900 CramYouTube — SC-900 Cram

Skills at a Glance

Skill AreaWeight
Describe the concepts of security, compliance, and identity10–15%
Describe the capabilities of Microsoft Entra25–30%
Describe the capabilities of Microsoft security solutions35–40%
Describe the capabilities of Microsoft compliance solutions20–25%

Who is this exam for?

The SC-900 is Microsoft’s entry-level security certification. It’s aimed at anyone who wants to understand the fundamentals of security, compliance, and identity (SCI) across Microsoft cloud services. You don’t need a security background — it’s designed for business stakeholders, IT professionals, and students alike.

If you’re familiar with Microsoft Azure and Microsoft 365, and want to understand how Microsoft secures its cloud platforms, this is the right starting point. It’s also a great stepping stone toward SC-200 (Security Operations Analyst) and SC-300 (Identity and Access Administrator).


Describe the concepts of security, compliance, and identity (10–15%)

This is the smallest domain but sets the foundation for everything else. It covers core security principles that apply to any cloud platform — not just Microsoft. Make sure you understand Zero Trust, defense-in-depth, and the shared responsibility model, as these concepts appear throughout the exam.

Describe security and compliance concepts

Define identity concepts

Identity is the “new security perimeter” — in a world of cloud and remote work, verifying who someone is matters more than which network they’re on. This section covers the building blocks: authentication vs authorisation, identity providers, directory services, and federation.


Describe the capabilities of Microsoft Entra (25–30%)

Microsoft Entra ID (formerly Azure Active Directory) is Microsoft’s cloud identity service. This is the second-largest domain on the exam and covers how organisations manage identities, authenticate users, control access, and govern who can do what. If you’ve used Azure AD before, much of this will feel familiar — but note the rebranding to “Microsoft Entra.”

Describe function and identity types of Microsoft Entra ID

Describe authentication capabilities of Microsoft Entra ID

How do users prove they are who they say they are? This section covers authentication methods (passwords, biometrics, FIDO2 keys), MFA, and how Microsoft protects against password attacks like spray and brute force.

Describe access management capabilities of Microsoft Entra ID

Once someone is authenticated, what can they access? Conditional Access lets you create policies like “require MFA when connecting from outside the office,” while RBAC controls what actions users can perform on specific resources.

Describe identity protection and governance capabilities of Microsoft Entra

Identity governance is about making sure the right people have the right access for the right amount of time. This section covers access reviews (periodic checks that access is still needed), Privileged Identity Management (just-in-time admin access), and Identity Protection (automated risk detection).


Describe the capabilities of Microsoft security solutions (35–40%)

This is the largest domain on the exam — expect the most questions here. It spans Azure infrastructure security (firewalls, NSGs, DDoS protection), security management (Defender for Cloud), threat detection (Sentinel), and the Defender XDR suite. Focus your study time here.

Describe core infrastructure security services in Azure

These are the foundational Azure services that protect your network and resources. Think of them as layers: DDoS protection at the edge, Azure Firewall and WAF for traffic filtering, VNets and NSGs for network segmentation, Bastion for secure remote access, and Key Vault for secrets management.

Describe security management capabilities of Azure

Microsoft Defender for Cloud is the central hub for security management in Azure. It provides a security score, recommendations, and policies to improve your security posture. Understand the difference between basic CSPM (free) and enhanced workload protection (paid).

Describe capabilities of Microsoft Sentinel

Microsoft Sentinel is Microsoft’s cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration Automated Response) solution. It collects data from across your environment, detects threats using analytics and AI, and can automatically respond to incidents.

Describe threat protection with Microsoft Defender XDR

Microsoft Defender XDR (Extended Detection and Response) is a suite of security products that protect endpoints, email, identities, and cloud apps. Each product focuses on a specific attack surface. Understanding which Defender product covers which area is key for the exam.


Describe the capabilities of Microsoft compliance solutions (20–25%)

Compliance is about making sure your organisation follows rules — industry regulations, government laws, and internal policies. Microsoft Purview is the central platform for compliance management, information protection, and data governance. This domain also covers insider risk, eDiscovery, and audit capabilities.

Describe Microsoft Service Trust Portal and privacy principles

Describe compliance management capabilities of Microsoft Purview

The Purview portal is your one-stop-shop for compliance. Compliance Manager gives you a score and actionable recommendations to improve your compliance posture — similar to how Defender for Cloud works for security.

Describe information protection, data lifecycle management, and data governance capabilities of Microsoft Purview

This is where data protection happens. Sensitivity labels classify and protect documents and emails. Data Loss Prevention (DLP) policies prevent sensitive data from leaving your organisation. Records management handles retention and deletion of content based on regulatory requirements.

Describe insider risk, eDiscovery, and audit capabilities in Microsoft Purview

Insider risk management helps detect and respond to risky activities by people inside your organisation (data theft, policy violations). eDiscovery is used to find and preserve electronic information for legal proceedings. Audit logs track who did what and when.


Skills Measured

Describe the concepts of security, compliance, and identity (10–15%)

Describe security and compliance concepts

  • Describe the shared responsibility model
  • Describe defense-in-depth
  • Describe the Zero Trust model
  • Describe encryption and hashing
  • Describe Governance, Risk, and Compliance (GRC) concepts

Define identity concepts

  • Define identity as the primary security perimeter
  • Define authentication
  • Define authorization
  • Describe identity providers
  • Describe the concept of directory services and Active Directory
  • Describe the concept of federation

Describe the capabilities of Microsoft Entra (25–30%)

Describe function and identity types of Microsoft Entra ID

  • Describe Microsoft Entra ID
  • Describe types of identities
  • Describe hybrid identity

Describe authentication capabilities of Microsoft Entra ID

  • Describe the authentication methods
  • Describe multifactor authentication (MFA)
  • Describe password protection and management capabilities

Describe access management capabilities of Microsoft Entra ID

  • Describe Conditional Access
  • Describe Microsoft Entra roles and role-based access control (RBAC)

Describe identity protection and governance capabilities of Microsoft Entra

  • Describe Microsoft Entra ID Governance
  • Describe access reviews
  • Describe the capabilities of Microsoft Entra Privileged Identity Management
  • Describe Microsoft Entra ID Protection

Describe the capabilities of Microsoft security solutions (35–40%)

Describe core infrastructure security services in Azure

  • Describe Azure distributed denial-of-service (DDoS) Protection
  • Describe Azure Firewall
  • Describe Web Application Firewall (WAF)
  • Describe network segmentation with Azure virtual networks
  • Describe network security groups (NSGs)
  • Describe Azure Bastion
  • Describe Azure Key Vault

Describe security management capabilities of Azure

  • Describe Microsoft Defender for Cloud
  • Describe Cloud Security Posture Management (CSPM)
  • Describe how security policies, standards, and recommendations improve the cloud security posture
  • Describe enhanced security features provided by cloud workload protection

Describe capabilities of Microsoft Sentinel

  • Define the concepts of security information and event management (SIEM) and security orchestration automated response (SOAR)
  • Describe threat detection and mitigation capabilities in Microsoft Sentinel

Describe threat protection with Microsoft Defender XDR

  • Describe Microsoft Defender XDR services
  • Describe Microsoft Defender for Office 365
  • Describe Microsoft Defender for Endpoint
  • Describe Microsoft Defender for Cloud Apps
  • Describe Microsoft Defender for Identity
  • Describe Microsoft Defender Vulnerability Management
  • Describe Microsoft Defender Threat Intelligence (Defender TI)
  • Describe the Microsoft Defender portal

Describe the capabilities of Microsoft compliance solutions (20–25%)

Describe Microsoft Service Trust Portal and privacy principles

  • Describe the Service Trust Portal offerings
  • Describe the privacy principles of Microsoft
  • Describe Microsoft Priva

Describe compliance management capabilities of Microsoft Purview

  • Describe the Microsoft Purview portal
  • Describe Compliance Manager
  • Describe the uses and benefits of compliance score

Describe information protection, data lifecycle management, and data governance capabilities of Microsoft Purview

  • Describe the data classification capabilities
  • Describe the benefits of Content explorer and Activity explorer
  • Describe sensitivity labels and sensitivity label policies
  • Describe data loss prevention (DLP)
  • Describe records management
  • Describe retention policies, retention labels, and retention label policies

Describe insider risk, eDiscovery, and audit capabilities in Microsoft Purview

  • Describe insider risk management
  • Describe eDiscovery solutions in Microsoft Purview
  • Describe audit solutions in Microsoft Purview

Frequently asked questions

The SC-900 questions I get from people new to Microsoft security — usually ‘is this enough to break into security?’ or ‘do I take SC-900 before SC-200 or AZ-500?’

Is SC-900 worth taking in 2026? #

Yes if you’re new to Microsoft security and need vocabulary fluency — Entra, Defender XDR, Sentinel, Purview, Zero Trust, identity protection. SC-900 is the gateway cert that makes SC-200, SC-300, and AZ-500 easier to study. If you already work in Microsoft security day-to-day, skip it and go straight to an associate. SC-900 won’t land you a security job on its own — it gets you past the vocabulary wall.

How long does it take to prepare for SC-900? #

Two to four weeks of part-time study for most beginners. Less if you have any cloud or M365 background. The exam is 45 minutes, 40 to 60 questions, mostly multiple choice and drag-and-drop. Microsoft skills-updated SC-900 in November 2025 — older study material misses recent Defender XDR consolidation, Copilot for Security positioning, and Purview rebranding. Free official practice assessment is a good final check.

SC-900 vs AZ-900 — which should I take first? #

Depends on your target role. AZ-900 is Azure-focused (compute, networking, storage, governance) and the broader of the two. SC-900 is security-focused across Azure + M365 + Entra. If you’re heading into a security role, do SC-900 first. If you’re going into general cloud admin or DevOps, AZ-900 first. Both are 45-minute, $99, fundamentals exams — many people take both in the same month.

How much does SC-900 cost and what's the retake policy? #

USD $99 with regional pricing — $49 in some markets. Microsoft sometimes runs free voucher promotions through partner training events or Microsoft Learn challenges. Pearson VUE lets you sit it online with a proctor or at a test centre. Failed attempt: wait 24 hours before retake #1, then 14 days each subsequent retake — $99 per attempt.

Does SC-900 expire and do I need to renew it? #

SC-900 is a Microsoft Fundamentals cert, which means it doesn’t expire — once you pass, it’s on your transcript permanently. No renewal required. That’s different from Microsoft’s associate and expert-level certs (which need annual renewal via free Learn assessments). Fundamentals certs are earned-and-kept — useful CV credentials, but recruiters increasingly look for an associate-level cert paired with the fundamentals.

Watch & Learn

Video courses to help you prepare.

Frequently Asked Questions

1. Is SC-900 worth taking in 2026?

Yes if you're new to Microsoft security and need vocabulary fluency — Entra, Defender XDR, Sentinel, Purview, Zero Trust, identity protection. SC-900 is the gateway cert that makes [SC-200](/cert-tracker/sc-200/), [SC-300](/cert-tracker/sc-300/), and [AZ-500](/cert-tracker/az-500/) easier to study. If you already work in Microsoft security day-to-day, skip it and go straight to an associate. SC-900 won't land you a security job on its own — it gets you past the vocabulary wall.

2. How long does it take to prepare for SC-900?

Two to four weeks of part-time study for most beginners. Less if you have any cloud or M365 background. The exam is 45 minutes, 40 to 60 questions, mostly multiple choice and drag-and-drop. Microsoft skills-updated SC-900 in November 2025 — older study material misses recent Defender XDR consolidation, Copilot for Security positioning, and Purview rebranding. Free [official practice assessment](https://learn.microsoft.com/en-us/credentials/certifications/exams/sc-900/practice/assessment?assessment-type=practice&assessmentId=11) is a good final check.

3. SC-900 vs AZ-900 — which should I take first?

Depends on your target role. [AZ-900](/cert-tracker/az-900/) is Azure-focused (compute, networking, storage, governance) and the broader of the two. SC-900 is security-focused across Azure + M365 + Entra. If you're heading into a security role, do SC-900 first. If you're going into general cloud admin or DevOps, AZ-900 first. Both are 45-minute, $99, fundamentals exams — many people take both in the same month.

4. How much does SC-900 cost and what's the retake policy?

USD $99 with regional pricing — $49 in some markets. Microsoft sometimes runs free voucher promotions through partner training events or Microsoft Learn challenges. [Pearson VUE](https://learn.microsoft.com/en-us/credentials/certifications/schedule-through-pearson-vue?examUid=exam.SC-900) lets you sit it online with a proctor or at a test centre. Failed attempt: wait 24 hours before retake #1, then 14 days each subsequent retake — $99 per attempt.

5. Does SC-900 expire and do I need to renew it?

SC-900 is a Microsoft Fundamentals cert, which means it doesn't expire — once you pass, it's on your transcript permanently. No renewal required. That's different from Microsoft's associate and expert-level certs (which need annual renewal via free Learn assessments). Fundamentals certs are earned-and-kept — useful CV credentials, but recruiters increasingly look for an associate-level cert paired with the fundamentals.

20 Free Questions Practice Exam $9 →