← Back to all articles
MicrosoftSC-900Security FundamentalsMicrosoft EntraCertificationStudy Guide

Getting Started with SC-900

4 October 2026·8 min read·By Jacob
25% off
$7.99$5.99
one-time payment
Start practising →

Lifetime access · No subscription

7-day money-back guarantee

Special offer for SC-900 Practice Exams

25% off full access

Your code is valid for 24 hours.

  • ✓Practice question sets with real exam scenarios
  • ✓Detailed explanations for every answer, right or wrong
  • ✓Topic mode to drill specific exam domains
  • ✓Exam simulator timed to match the real exam format

The Microsoft Security, Compliance, and Identity Fundamentals (SC-900) exam is Microsoft's entry point into its security portfolio. It checks that you understand core ideas like Zero Trust and the shared responsibility model, and that you can match a business problem to the right Microsoft service across Entra, Defender, Sentinel, and Purview. You don't need a technical background to pass it, which makes SC-900 a popular first step for students, career switchers, compliance staff, and IT pros heading toward SC-200, SC-300, or AZ-500.

This guide walks through what the SC-900 exam covers, which services deserve most of your time, where people lose marks, and a realistic study plan.

Exam Overview

DetailValue
Exam codeSC-900
QuestionsRoughly 40-60
Time limit45 minutes
Passing score700 / 1000 (scaled)
FormatMultiple choice, multi-response, drag-and-drop, yes/no groups
Cost$99 USD (varies by region)
PrerequisitesNone
Certification validityDoesn't expire (fundamentals certs have no renewal)

The time limit is short, but the questions are conceptual. You won't be asked to write a Conditional Access policy from memory or configure a Sentinel workspace. Most questions describe a scenario and ask which service, feature, or principle fits best.

Exam Domains

DomainWeight
Describe the capabilities of Microsoft security solutions38%
Describe the capabilities of Microsoft Entra28%
Describe the capabilities of Microsoft compliance solutions22%
Describe the concepts of security, compliance, and identity12%

Security solutions is the biggest chunk, so Defender and Sentinel need real attention. The concepts domain is the smallest, but it underpins everything else. If you don't understand authentication versus authorization, the Entra questions get harder than they need to be.

Core Services and Concepts to Master

Security, Compliance, and Identity Concepts

Start here even though it's only 12%. Know the shared responsibility model and how it shifts between on-premises, IaaS, PaaS, and SaaS. Understand defense in depth as layered controls, and the three Zero Trust principles: verify explicitly, use least privilege access, and assume breach. You should also be comfortable with encryption at rest versus in transit, hashing, and the difference between authentication (proving who you are) and authorization (what you're allowed to do). Identity concepts like federation, identity providers, and directory services round this out.

Microsoft Entra ID

Entra ID (formerly Azure Active Directory) is the identity backbone of Microsoft's cloud. Learn the identity types: users, groups, service principals, managed identities, and devices. Know the authentication methods, including passwords, Windows Hello for Business, FIDO2 keys, and the Microsoft Authenticator app, plus how multifactor authentication and passwordless sign-in fit together. Self-service password reset and password protection show up regularly too.

Conditional Access and Identity Protection

Conditional Access is the policy engine that makes Zero Trust practical. Think of it as if/then logic: if a user signs in from an unknown location on an unmanaged device, then require MFA or block access. Microsoft Entra ID Protection feeds risk signals (leaked credentials, impossible travel, anonymous IP addresses) into those decisions. Expect questions that ask which feature evaluates sign-in risk versus which one enforces the response.

Identity Governance and PIM

Governance questions focus on making sure the right people have the right access for the right amount of time. Privileged Identity Management (PIM) provides just-in-time, time-bound admin roles with approval workflows. Access reviews let managers recertify who still needs access, and entitlement management bundles resources into access packages. Know the difference between Entra roles and Azure RBAC roles at a high level.

Microsoft Defender XDR

Defender XDR is the umbrella for Microsoft's extended detection and response products. You'll need to recognize what each one protects: Defender for Endpoint (devices), Defender for Office 365 (email and collaboration, including phishing and Safe Links), Defender for Identity (on-premises Active Directory signals), and Defender for Cloud Apps (a CASB for SaaS usage and shadow IT). The Microsoft Defender portal brings incidents from all of them together.

Microsoft Defender for Cloud and Azure Network Security

Defender for Cloud is a cloud security posture management (CSPM) and workload protection tool. It produces a Secure Score, gives hardening recommendations, and maps your environment against regulatory standards. On the network side, know what network security groups, Azure Firewall, Azure DDoS Protection, Azure Bastion, and Web Application Firewall each do. A classic question asks which service lets admins RDP into VMs without exposing public IPs. That's Bastion.

Microsoft Sentinel

Sentinel is Microsoft's cloud-native SIEM and SOAR. It collects data through connectors, detects threats with analytics rules, lets analysts investigate incidents and hunt with KQL, and automates responses with playbooks built on Logic Apps. The key distinction: Sentinel aggregates and correlates signals from many sources, including non-Microsoft ones, while Defender products protect specific workloads.

Microsoft Purview and Priva

Purview covers the compliance domain. Know sensitivity labels (classify and protect content with encryption or markings), retention labels and policies (keep or delete content for a set period), and data loss prevention (stop sensitive data from leaving through email, Teams, or endpoints). Also cover Compliance Manager and its compliance score, eDiscovery, Audit, insider risk management, and communication compliance. Microsoft Priva focuses on privacy risk and subject rights requests. The Service Trust Portal is where Microsoft publishes its own audit reports and compliance documentation.

Common Exam Traps

Most lost marks on SC-900 come from mixing up services that sound alike. Defender for Cloud, Defender XDR, and Sentinel all deal with threats, but they solve different problems: posture and workload protection, workload-specific detection, and organization-wide SIEM respectively. If a question mentions collecting logs from many sources and correlating them, it's Sentinel.

Labels are the other big trap. Sensitivity labels protect content, retention labels control how long content is kept, and DLP policies prevent sharing. A question about stopping credit card numbers from being emailed externally is DLP, not a sensitivity label.

Watch for Compliance Manager versus Secure Score too. Compliance Manager tracks regulatory compliance in Microsoft 365, while Secure Score measures security posture. And don't confuse Entra ID Protection, which detects risk, with Conditional Access, which acts on it.

Finally, read the qualifiers. Words like "minimize administrative effort," "just-in-time," or "without a public IP" usually point straight at one answer.

Study Plan

WeekFocusActivities
Week 1Concepts and Microsoft EntraMicrosoft Learn SC-900 path modules 1 and 2. Make notes on Zero Trust, shared responsibility, and authentication methods.
Week 2Security solutionsDefender XDR products, Defender for Cloud, Sentinel, and Azure network security. Build a one-page comparison table.
Week 3Compliance solutions and reviewPurview labels, DLP, Compliance Manager, eDiscovery, and Priva. Start timed practice exams and review every explanation.

Two to three weeks is plenty for most people studying an hour a day. If you already work in Microsoft 365 or Azure, you might be ready in a week. Complete beginners should stretch it to four.

The free Microsoft Learn SC-900 learning path is the official starting point, and it maps directly to the skills outline. Microsoft also runs free Virtual Training Days for SC-900 that sometimes include an exam voucher discount. If you have an Azure or Microsoft 365 trial, clicking through the Entra admin center, the Defender portal, and the Purview portal makes the service names stick far better than reading alone.

Practice questions are where it comes together. SC-900 rewards fast recognition of which service fits which scenario, and that only builds with repetition. Our practice sets include detailed explanations for every option, so you learn why the distractors are wrong, not just which answer is right.

Final Thoughts

SC-900 is one of the more approachable Microsoft certifications, but the overlapping product names catch plenty of people off guard. Focus on what each service is for, learn the Zero Trust vocabulary, and drill scenario questions until the distinctions feel automatic.

When you're ready to test yourself, try our SC-900 Practice Exams. The first set is free, and each question comes with a full explanation to help you close any gaps before exam day.

Ready to test your knowledge?

SC-900 Practice Exams

Put what you've learned to the test with practice questions that mirror the real exam.

Start Practising →