Microsoft Security, Compliance, and Identity Fundamentals: SC-900 Exam Guide
SC-900 validates foundational knowledge of security, compliance, and identity concepts across Microsoft cloud-based services. It is designed for business stakeholders, students, and new or existing IT professionals who want a structured understanding of Microsoft security solutions rather than advanced implementation skills. This guide helps you decide whether your current Azure and Microsoft 365 knowledge is sufficient, which exam domains need the most study time, and whether self-paced learning or the official instructor-led course better fits your preparation plan.
What SC-900 validates and who should take it
SC-900 is a beginner-level Microsoft certification associated with Azure, the Security Engineer role, and the Security subject area. It validates foundational understanding of security, compliance, identity, and related Microsoft cloud solutions; it is not positioned as an advanced administration or security engineering exam.
The intended audience includes business stakeholders, students, and new or existing IT professionals who want to understand Microsoft security, compliance, and identity solutions. Candidates should be familiar with Microsoft Azure and Microsoft 365 and understand how these solutions span both areas.
That audience makes the exam useful for people who must discuss security controls, identity services, threat protection, or compliance capabilities without necessarily configuring every service themselves. A manager evaluating Microsoft services, an IT professional moving toward security work, and a student building a cloud foundation may all have a reasonable starting point.
The practical decision is whether you need breadth or implementation depth. If your immediate goal is to understand how Microsoft services fit together, SC-900 is aligned with that goal. If you need to deploy policies, investigate incidents, or administer identities in production, use SC-900 as a foundation and plan further role-specific study afterward.
Which skills are measured
The current study guide groups SC-900 into four domains: security, compliance, and identity concepts; Microsoft Entra capabilities; Microsoft security solutions; and Microsoft compliance solutions. Use those domains as the structure for your notes, practice review, and readiness decision.
The official study guide lists the following weight ranges: Describe the concepts of security, compliance, and identity is 10–15%; Describe the capabilities of Microsoft Entra is 25–30%; Describe the capabilities of Microsoft security solutions is 35–40%; and Describe the capabilities of Microsoft compliance solutions is 20–25%. Each percentage belongs to the named domain and should be treated as a planning signal, not as a prediction of exact question distribution.
The largest stated domain is Describe the capabilities of Microsoft security solutions at 35–40%, so it deserves the greatest share of study attention. Describe the capabilities of Microsoft Entra at 25–30% is also substantial. The concepts domain has the smallest stated range, but it supplies terminology that helps you interpret questions in the other areas.
Microsoft says the bullets beneath the measured skills illustrate how a skill may be assessed and that related topics may also appear. Most questions cover generally available features, although commonly used preview features may be tested. Check the current study guide immediately before scheduling if your preparation spans a major exam update.
The study guide identifies the skills-measured version as effective July 28, 2026. Microsoft updates exams periodically to reflect skills required for the associated role, and the English version is updated first. Localized versions are updated approximately eight weeks after the English version, although Microsoft notes that timing may vary.
How to use the domain weights
Use the weights to allocate review time after you establish a baseline. A sensible approach is to study every domain once, then spend extra sessions on Microsoft security solutions and Microsoft Entra capabilities because their stated ranges are larger. Do not skip the concepts or compliance domains simply because they carry smaller stated ranges.
Create a four-column tracker using the official domain names. For each objective, record whether you can define the service, explain its purpose, distinguish it from a related service, and identify the type of security or compliance problem it addresses. This tests understanding rather than recognition of product names.
What to learn in the security, compliance, and identity concepts domain
Start with the underlying models before memorizing Microsoft product names. This domain introduces shared responsibility, defense-in-depth, Zero Trust, encryption, hashing, data residency, data sovereignty, identity providers, authentication, authorization, directory services, and federation.
The Microsoft Learn concepts path presents shared responsibility and Zero Trust as foundational ideas for Microsoft solutions. It also covers why identity is a modern security perimeter, how identity providers enable modern authentication and single sign-on, and how federation extends trust across organizational boundaries.
Your notes should answer practical questions. What remains the customer’s responsibility when a service is hosted in the cloud? How does defense-in-depth reduce reliance on one control? What does Zero Trust change about access decisions? How are authentication and authorization different? What problem does a directory service solve?
Avoid treating encryption and hashing as interchangeable. Build a short comparison that states the purpose of each concept and the type of security outcome it supports. Similarly, keep data residency and data sovereignty separate in your notes rather than reducing both to a vague statement about where data is stored.
A useful study exercise is to describe a fictional employee accessing a cloud application. Identify the identity provider, authentication event, authorization decision, directory information, and any trust relationship involved. Then explain how Zero Trust and layered controls would influence the access decision. This exercise is a preparation recommendation, not an indication of a specific exam scenario.
Common mistakes with foundational terminology
Candidates often learn definitions in isolation and then confuse neighboring concepts. The remedy is to write paired distinctions: authentication versus authorization, encryption versus hashing, residency versus sovereignty, and responsibility for the cloud provider versus responsibility for the customer.
Another mistake is assuming that a familiar Microsoft product name proves understanding. For each term, add its purpose and the problem it addresses. If you cannot explain why an organization would use a capability, return to the relevant Microsoft Learn module before moving on.
How to prepare for Microsoft Entra capabilities
Study Microsoft Entra as the identity layer that connects users, applications, devices, and access decisions across Microsoft services. The objective is to understand the capabilities and their roles, not to memorize an undifferentiated list of identity terminology.
Begin with the concepts path’s treatment of identity providers, modern authentication, single sign-on, directory services, and federation. Then use the SC-900-aligned learning sequence to connect those concepts to Microsoft Entra. Your notes should show how an identity service supports sign-in, manages directory information, and participates in authorization and trust.
Use scenario prompts to test your understanding: a user needs access to several applications; an organization wants a consistent sign-in experience; an application trusts an identity provider; or an administrator needs an identity-centered control rather than a network-only control. For each prompt, explain the relevant capability in plain language and identify what it does not accomplish.
Do not spend most of your time clicking through administrative interfaces unless the material specifically requires it. SC-900 is a fundamentals assessment. A lab can reinforce a concept, but a lab without a written explanation may leave you unable to distinguish related capabilities in a question.
When reviewing, say the service or capability name only after stating the requirement. For example, begin with the access or identity problem, then identify the Microsoft Entra capability that addresses it. This reverses the common memorization habit and makes product comparisons easier.
How to cover Microsoft security solutions efficiently
The security-solutions domain has the largest stated weight range, so organize it by security function: infrastructure protection, security management, security information and event management, security orchestration and response, threat protection, and security assistance.
The Microsoft Learn security-solutions path includes core infrastructure security services in Azure, Azure security management, Microsoft Sentinel, Microsoft Defender XDR, and Microsoft Security Copilot. It identifies Sentinel as a cloud-native SIEM and SOAR solution and describes Defender XDR as protecting across endpoints, identities, email, and applications.
Build a service map rather than a glossary. Put each named solution in a row and record the primary problem it addresses, the environment or signal source it relates to, and the security activity it supports. For example, distinguish infrastructure protection from centralized security information and event management, and distinguish threat protection across multiple surfaces from security management recommendations.
Pay particular attention to boundaries. A security management service may bring together policies, standards, recommendations, secure score, workload protection plans, and AI security capabilities. Sentinel is associated with collecting and analyzing security information and supporting orchestration and response. Defender XDR addresses threat protection across several attack surfaces. These are related parts of a security program, not interchangeable labels.
Microsoft Security Copilot is included in the current security-solutions learning path. Learn its introductory terminology, how it processes prompts, the elements of an effective prompt, and how the solution can be enabled. Do not turn this into an advanced artificial-intelligence study project; focus on the introductory capability described in the learning material.
Use a single incident storyline as a review tool. Start with a suspicious signal, identify where it might be detected, determine which service helps investigate or correlate information, and then identify the response or protection capability involved. The purpose is to practice service selection, not to reproduce live exam questions or predict a particular question format.
A practical comparison method
For every security solution, complete four sentences: “This capability is for…,” “It helps with…,” “It should not be confused with…,” and “It connects to the wider security process by….” This forces you to understand purpose, scope, contrast, and relationship.
If two services still seem interchangeable, return to the relevant module and draw a boundary between them. A candidate who can explain why a service is appropriate is better prepared than one who has only copied a product description.
Pitfalls in the security domain
A frequent error is studying only threat protection and overlooking Azure infrastructure and security management. Another is treating SIEM, SOAR, XDR, and cloud security management as synonyms. Keep the functions separate and revisit the official learning path when your notes use broad phrases such as “monitors everything” or “secures the cloud.”
How to study Microsoft compliance solutions
Treat compliance as a governance and information-protection area rather than as another name for threat detection. The SC-900 assessment explicitly includes Microsoft compliance solutions, and the preparation sequence connects this area with Microsoft Purview and Microsoft’s privacy principles.
Start by learning the compliance problem before the product capability. Ask whether the requirement concerns discovering and governing data, protecting sensitive information, retaining or disposing of information, demonstrating compliance, or applying privacy principles. Then connect the requirement to the relevant Microsoft solution described in the official learning material.
The official concepts path includes data residency and data sovereignty, while the SC-900 preparation sequence identifies Microsoft Purview and Microsoft’s privacy principles as a dedicated part of the learning plan. Keep these ideas visible in your notes because compliance questions can combine a governance concept with a service capability.
Use comparison cards with three fields: the organizational requirement, the type of information or process involved, and the Microsoft capability that supports it. Add a fourth field explaining the limit of the capability. This prevents a common mistake in fundamentals preparation: assuming that a compliance service automatically makes an organization compliant without appropriate configuration, processes, or accountability.
Review compliance after security concepts but before your final practice cycle. By that point, you should be able to distinguish protection against threats from governance of information and organizational obligations. The two areas interact, but they answer different business questions.
Which official preparation route fits your background
Use self-paced Microsoft Learn when you need flexible sequencing and a way to revisit unfamiliar concepts. Choose instructor-led training when you need a fixed structure, direct explanations, and scheduled study time. Microsoft provides both routes, and the official SC-900 course content aligns with the exam objective domain.
The official course is beginner-level, lasts one day, and requires general networking and cloud-computing concepts, general IT knowledge or experience in an IT environment, and general understanding of Azure and Microsoft 365. The course is broad, so candidates with no security background may benefit from first completing the recommended cybersecurity primer.
The self-paced preparation paths divide the work into four parts: security, compliance, and identity concepts; Microsoft Entra; Microsoft security solutions; and Microsoft Purview and Microsoft’s privacy principles. The concepts path has two modules, while the security-solutions path has five modules. Use those paths as the core sequence rather than collecting unrelated videos and notes.
Microsoft Learn modules are bite-sized, interactive skill builders available at your own pace and in multiple languages. That makes them suitable for short study sessions, but do not confuse completion with readiness. After each module, close the page and explain the ideas without looking at the text.
The official preparation guidance also points candidates toward study guides, exam-preparation videos when available, instructor-led courses, and Practice Assessments. Select resources that answer a specific weakness. Adding more material without identifying the weakness usually creates a larger collection of notes rather than better recall.
When an Azure account helps
The learning paths provide an option to get started with Azure, including a pay-as-you-go or free-trial route. Treat hands-on access as optional reinforcement, not as an unstated prerequisite. The official concepts learning path lists no prerequisites, while the instructor-led course describes general background knowledge expected before attendance.
If you use a lab, write down what the exercise demonstrates and what it does not demonstrate. Avoid creating paid resources or changing security settings without understanding the account and subscription implications.
A practical study roadmap
A staged roadmap works better than repeated broad reading: establish the baseline, learn the four domains, build service comparisons, test recall, and then verify readiness against the current official materials. The schedule below is a recommendation, not a Microsoft requirement.
First, read the SC-900 study guide and copy its four official domain names into a progress tracker. Mark each objective as unfamiliar, partly understood, or explainable. Do this before taking a Practice Assessment so that the result can reveal gaps rather than simply provide reassurance.
Next, complete the concepts path. Learn shared responsibility, defense-in-depth, Zero Trust, encryption, hashing, data residency, data sovereignty, authentication, authorization, identity providers, directory services, single sign-on, and federation. At the end, write a one-page comparison sheet using your own wording.
Then study Microsoft Entra. Connect identity concepts to access and trust scenarios. Do not move on until you can explain the difference between an identity capability and a general network or threat-protection capability.
Give the largest study block to Microsoft security solutions. Follow the official security-solutions learning path and create a service map covering Azure infrastructure security, Azure security management, Microsoft Sentinel, Microsoft Defender XDR, and Microsoft Security Copilot. Use incident and service-selection scenarios to test the boundaries between them.
Study compliance solutions through the Microsoft Purview and privacy-principles material. Add data governance concepts to your comparison sheet and distinguish compliance objectives from threat-detection objectives.
Use the Practice Assessment only after the first learning pass. Microsoft describes Practice Assessments as a way to experience question style, wording, and difficulty, assess readiness, identify areas needing further preparation, and fill knowledge gaps. Review every missed or uncertain answer by domain and return to the source material.
Finish with retrieval practice. Hide your notes and explain each domain aloud, define paired concepts, and select an appropriate service for a plain-language requirement. If you can recognize terms but cannot explain their boundaries, keep studying rather than scheduling immediately.
Before booking, check the current study guide, exam details page, available language, and any published update information. Microsoft says exams are updated periodically and provides different skills-measured versions when an update is in progress. Your final review should match the version relevant to your planned exam date.
How to use practice results
A practice result is a diagnostic signal, not a pass guarantee. Sort weak results by official domain, then by concept: definition, purpose, comparison, or scenario application. Re-study the smallest missing concept and retest it later instead of repeating the assessment immediately.
Do not use leaked questions, exam dumps, or memorized answer lists. They do not establish understanding, may be inaccurate, and are not a substitute for the official objectives. Practice should improve reasoning about capabilities, not train recognition of copied content.
Delivery, languages, and scheduling decisions
Microsoft states that the SC-900 assessment takes 45 minutes to complete. The exam is proctored and may include interactive components. Microsoft provides an exam sandbox so candidates can experience the interface and interact with different question types before the assessment.
The certification page lists scheduling through Pearson Vue and, for students or educators, Certiport. Microsoft strongly recommends registering with a personal Microsoft account because exam records associated with an organizational work or school account may be lost and unrecoverable if you leave that organization.
The listed exam languages are English, Japanese, Chinese (Simplified), Korean, French, Spanish, Portuguese (Brazil), Russian, Arabic (Saudi Arabia), Indonesian (Indonesia), German, Chinese (Traditional), and Italian. Check the exam details page when scheduling because availability can depend on the delivery option and current listing.
Microsoft notes that Practice Assessments may be available in multiple languages, but the exam may not be available in the same languages as the Practice Assessment. Confirm the actual exam language rather than assuming that a translated practice interface guarantees a matching exam.
If the exam is not available in your preferred language, Microsoft says you can request an additional 30 minutes to complete it. If you need assistive devices, read-aloud support, extra time, or another modification, review the accommodation process before scheduling.
The study guide states that a score of 700 or greater is required to pass. Use that as the official threshold, but do not treat a practice percentage as a direct conversion to the certification score. Microsoft’s practice guidance positions practice assessments as readiness and gap-finding tools.
The certification page states that a failed certification exam may be retaken after 24 hours, while later retake intervals vary. A retake policy is a fallback, not a preparation strategy. If a first attempt does not succeed, use the score report and domain review to redesign your study plan.
What to check before booking
Confirm the current skills-measured version, exam language, delivery route, account used for registration, accommodation needs, and the official exam details. Also review any country- or region-dependent price information on Microsoft’s page rather than relying on an outdated third-party listing.
Use the sandbox before the appointment if interactive components or the exam interface are unfamiliar. The goal is to remove interface uncertainty so your final preparation can focus on the measured skills.
Final readiness check
Schedule SC-900 when you can explain all four domains, distinguish the major Microsoft capabilities by purpose, and use practice feedback to correct weaknesses. A completed learning path alone is not enough; readiness means you can retrieve and apply the concepts without depending on copied wording.
Run a final check against the official domain names. Can you explain the security, compliance, and identity models? Can you place Microsoft Entra in the identity picture? Can you separate Azure security management, Sentinel, Defender XDR, and Security Copilot by function? Can you describe the compliance and privacy purpose of Microsoft Purview-related learning?
Read the study guide’s update notes again if the skills-measured version has changed since your first study session. Because Microsoft updates English content first and localized versions may follow later, language-specific candidates should verify both the exam language and the applicable objectives.
On the day before scheduling or sitting the exam, stop collecting new resources. Review your comparison sheets, revisit only identified gaps, and confirm the account and delivery details. This is a practical recommendation; Microsoft’s official requirements remain the exam page, study guide, policies, and any accommodation instructions applicable to you.
SC-900 is a sensible starting point when you need Microsoft security, compliance, and identity vocabulary plus a map of related cloud capabilities. It should lead to a clear next decision: schedule after demonstrating foundational understanding, or continue with the domain where your explanations and practice review remain weakest.
Conclusion
Prepare from the current Microsoft study guide, follow the four-part Learn sequence, and use practice assessment feedback to target gaps rather than memorize answers. Give deliberate attention to Microsoft security solutions and Microsoft Entra while retaining the concepts and compliance domains as part of the complete assessment. Before scheduling, verify the skills version, language, account, delivery route, timing, and accommodation process on Microsoft’s official pages.