SC-900: the starting point for security, compliance, and identity in the Microsoft cloud
Back to Learn
SC-900Introduction

Microsoft SC-900 Certification Study

SC-900: the starting point for security, compliance, and identity in the Microsoft cloud

Introduction to the Microsoft Security, Compliance, and Identity Fundamentals certification and to the complete learning journey

Edition aligned with the exam skills outline updated for July 28, 2026

Microsoft Certified: Security, Compliance, and Identity Fundamentals badge surrounded by cloud, identity, and compliance icons

Introduction: why start with SC-900?

Digital security is no longer a concern exclusive to specialized teams. Compromised identities, data leaks, misconfigurations, excessive permissions, and compliance failures can affect any organization that relies on cloud services. In this scenario, understanding how to protect people, applications, devices, data, and workloads has become an essential competency for technology professionals, managers, students, and participants in digital transformation projects.

The SC-900 - Microsoft Security, Compliance, and Identity Fundamentals - exam was created to validate precisely this fundamental knowledge. It presents Microsoft's integrated view of security, compliance, and identity, connecting universal concepts, such as Zero Trust, defense in depth, authentication, authorization, encryption, governance, and data protection, to the solutions available in Microsoft Azure, Microsoft 365, Microsoft Entra, Microsoft Defender, Microsoft Sentinel, and Microsoft Purview.

The certification does not require the candidate to be an expert in deployment, forensic investigation, or advanced administration. The goal is to demonstrate that they understand the role of each concept and service, know how to recognize the problem that a given tool solves, and can differentiate solutions that, although belonging to the same ecosystem, address distinct needs. In other words, the SC-900 verifies whether the candidate has a coherent view of how Microsoft technologies work together to reduce risks, control access, protect resources, detect threats, and support regulatory requirements.

More than memorizing names

Proper preparation does not consist of memorizing a list of products. The student needs to understand the reasoning behind each solution: what the risk is, which capability acts on that risk, which signals it uses, which actions it can take, and which limitations prevent it from being confused with another tool.

What the SC-900 exam is

SC-900 is the exam associated with the Microsoft Certified: Security, Compliance, and Identity Fundamentals certification. Microsoft classifies it as a beginner-level assessment and directs it at people who want to learn the fundamentals of security, compliance, and identity across cloud-based Microsoft services. The audience includes students, early-career IT professionals, experienced professionals who have started working with Microsoft solutions, business stakeholders, and anyone who needs to understand how Azure and Microsoft 365 address protection, control, and governance in an integrated way.

The exam grants 45 minutes for the assessment and requires a minimum score of 700 points to pass. Questions may use different formats, including single choice, multiple-response selection, Yes/No statements, matrices, and short scenarios. The candidate is not assessed only on the ability to repeat a definition. They must read the requirement, identify the most important words, and choose the solution that meets the scenario without attributing to it functions that belong to another product.

The version of the skills outline considered in this track organizes the exam into four major areas. Security, compliance, and identity concepts represent 10% to 15% of the assessment; Microsoft Entra, 25% to 30%; Microsoft security solutions, 35% to 40%; and Microsoft compliance solutions, 20% to 25%. This distribution shows that the exam begins with the fundamentals but devotes most of its weight to the practical capabilities of identity solutions, threat protection, infrastructure security, and data governance.

Skills measured at a glance

Skill areas of the SC-900 exam and their weights.
Skill areaWeight
Describe the concepts of security, compliance, and identity10-15%
Describe the capabilities of Microsoft Entra25-30%
Describe the capabilities of Microsoft security solutions35-40%
Describe the capabilities of Microsoft compliance solutions20-25%
Bar chart with the weight of each exam area: concepts 10-15%, Microsoft Entra 25-30%, security solutions 35-40%, and compliance solutions 20-25%
Security solutions carry the largest share of the exam, followed by Microsoft Entra and compliance.

Who this track was created for

The track was designed to serve different profiles without assuming deep experience in cybersecurity. A student can use it as a first structured view of the Microsoft ecosystem. A support, infrastructure, development, data, or cloud professional can consolidate concepts that appear in daily work but are often known only in a fragmented way. A manager or business participant can better understand the controls, responsibilities, and risks involved in projects that use Microsoft 365 and Azure.

  • Students who want to begin a path in security, identity, cloud, or compliance.
  • IT professionals who need to understand the purpose of Microsoft solutions before moving on to implementation and operation.
  • Developers, architects, and engineers who work with applications protected by Microsoft Entra ID, Azure, and Microsoft 365.
  • Governance, risk, audit, privacy, and data protection professionals who need to communicate with technical teams.
  • People who intend to earn the SC-900 certification and want preparation oriented to the real style of the questions.

Although it is a fundamentals certification, general familiarity with cloud computing, networking, Microsoft Azure, and Microsoft 365 helps you make the most of the content. Whenever any of this knowledge is needed, the track will provide enough context for the reader to follow the explanation without depending on advanced experience.

What you will learn and be able to do

By the end of the track, the reader will have developed two complementary capabilities. The first is academic and professional: understanding how security, identity, and compliance concepts and solutions relate to each other. The second is exam-oriented: recognizing the assessment pattern, interpreting scenarios, identifying the correct tool, and eliminating alternatives that describe real products but are inadequate for the presented requirement.

  • Explain the shared responsibility model in on-premises, IaaS, PaaS, and SaaS environments, identifying what belongs to the cloud provider and what remains the customer's responsibility.
  • Interpret the principles of Zero Trust, defense in depth, encryption, hashing, governance, risk, and compliance.
  • Differentiate identification, authentication, authorization, federation, single sign-on, directory service, and identity provider.
  • Recognize users, groups, devices, applications, service principals, managed identities, external identities, and hybrid identities in Microsoft Entra ID.
  • Compare MFA, passwordless authentication, Windows Hello for Business, FIDO2, Microsoft Authenticator, SSPR, and password protection.
  • Choose among Conditional Access, RBAC, Microsoft Entra roles, PIM, Access Reviews, Identity Protection, and other governance capabilities.
  • Differentiate Azure Firewall, WAF, NSG, DDoS Protection, Azure Bastion, and Azure Key Vault according to the type of resource and risk protected.
  • Explain CSPM, workload protection, Secure Score, recommendations, policies, and plans of Microsoft Defender for Cloud.
  • Distinguish SIEM, SOAR, and XDR and recognize the role of Microsoft Sentinel, Microsoft Defender XDR, and the products integrated into the Defender ecosystem.
  • Understand classification, sensitivity labels, DLP, retention, records management, insider risk, eDiscovery, auditing, and data governance in Microsoft Purview.
  • Answer scenario questions using keywords, product boundaries, and comparisons between similar solutions.

Expected outcome

The reader will not finish the track merely knowing that a tool exists. They should be able to explain why it exists, in which scenario it should be used, which solutions it integrates with, and why other alternatives do not meet the same requirement.

How the exam turns concepts into questions

The practice tests analyzed show that the assessment tends to alternate between direct definitions and small scenarios. Some questions present a sentence to complete; others request two or three correct answers; many use Yes/No statements. Questions in which all the alternatives correspond to real Microsoft products are also frequent, which forces the candidate to know not only the correct answer but also the function of the incorrect options.

Words such as “always”, “only”, “automatically”, “before”, “solely”, and “all” deserve special attention. A tool may offer a given capability without performing it in every scenario. For example, Conditional Access can require MFA, but not every Conditional Access policy requires MFA. Microsoft Entra ID Protection can detect leaked credentials and produce risk signals, but it is not a solution for assigning users to groups based on that risk. This level of precision is central to success on the exam.

For this reason, the chapters of this track will combine conceptual explanations with comparisons, scenarios, boundaries, exam keywords, true or false statements, and commented questions. The purpose is to build enough understanding to face new questions, and not only to reproduce the answers of the practice tests already known. After studying the 17 chapters, 12 complete practice tests will be made available for training, allowing the student to practice the style of the questions, assess their command of the topics, identify points that still need review, and build more confidence before taking the SC-900 exam.

How the track is organized

The track contains 17 chapters, organized in a progression that begins with the fundamentals and advances to identity, infrastructure security, threat detection and response, privacy, compliance, and data governance. The total estimated load is 645 minutes, approximately 10 hours and 45 minutes. The time serves as a reference for reading and study; topics that require more comparison or review may demand additional dedication.

Chapters 1 and 2 build the conceptual base. Chapters 3 to 6 go deeper into Microsoft Entra. Chapters 7 to 13 present security solutions and threat protection. Chapters 14 to 17 focus on trust, privacy, Microsoft Purview, compliance, and data governance. This division follows the general logic of the exam and helps the student form relationships between concepts, instead of studying each product in isolation.

Map of the 17 chapters grouped into four blocks: chapters 1 and 2 on fundamentals, 3 to 6 on Microsoft Entra, 7 to 13 on security and threats, and 14 to 17 on compliance and governance
The 17 chapters follow four thematic blocks that track the logic of the exam.

Summary of the 17 chapters

Chapter 1 — Fundamentals of security, compliance, and responsibility in the cloud

Introduces the shared responsibility model and shows how the obligations of Microsoft and the customer change across on-premises, IaaS, PaaS, and SaaS environments. The chapter also introduces defense in depth, the triad of confidentiality, integrity, and availability, Zero Trust, encryption, hashing, protection of data at rest, in transit, and in use, as well as governance, risk, compliance, data residency, sovereignty, and privacy.

Shared responsibility model showing the customer's and Microsoft's responsibilities across on-premises, IaaS, PaaS, and SaaS environments
Figure 1 — In the shared responsibility model, the boundary between customer and provider changes according to the service model.

Chapter 2 — Identity as the new security perimeter

Explains why identity has come to occupy the center of security decisions in cloud and hybrid work environments. The reader will differentiate identification, authentication, authorization, and identity administration and will study identity providers, directory services, Active Directory Domain Services, Microsoft Entra ID, single sign-on, trust between domains, and federation between organizations and applications.

Chapter 3 — Microsoft Entra ID, identity types, and hybrid environments

Introduces the Microsoft Entra family and the role of Microsoft Entra ID as a cloud-based identity and access management service. The chapter covers tenants, users, groups, devices, applications, workload identities, service principals, managed identities, and agent identities, as well as hybrid identity, Microsoft Entra Connect, synchronization, B2B collaboration, guests, and external identities.

Chapter 4 — Secure authentication, MFA, and passwordless technologies

Explores the authentication methods supported by Microsoft Entra ID, such as passwords, Microsoft Authenticator, temporary codes, tokens, biometrics, Windows Hello for Business, and FIDO2 keys. The student will understand authentication factors, MFA, passwordless authentication, security defaults, self-service password reset, and mechanisms for protection against weak, known, or leaked passwords.

Chapter 5 — Conditional Access, RBAC, and secure access to resources

Shows how access decisions can consider identity, application, location, device, risk, and request context. The chapter details Conditional Access signals, conditions, grant controls, and session controls, and differentiates Microsoft Entra roles, Azure roles, and RBAC. It also contextualizes Global Secure Access, Microsoft Entra Internet Access, Microsoft Entra Private Access, and the concept of Security Service Edge.

Chapter 6 — Governance, privileges, and identity protection

Introduces the identity lifecycle and the capabilities of Microsoft Entra ID Governance, including access reviews, access packages, and entitlement management. The reader will study PIM, Just-in-Time privileged access, temporary activation, approval, justification, MFA, and auditing, as well as Identity Protection, user risk, sign-in risk, leaked credentials, and risk-based remediation policies.

Chapter 7 — Microsoft Security Copilot and artificial intelligence for security

Introduces Microsoft Security Copilot as an artificial-intelligence-based assistance capability for security teams. The chapter explains prompts, context, data sources, plugins, response generation, and human validation, showing how the tool can support incident investigation, script analysis, queries, threat summaries, and report production. The content is treated as a current complement to the Microsoft ecosystem.

Chapter 8 — Protection of networks, applications, and secrets in Azure

Presents the main Azure infrastructure security services. The reader will learn to differentiate Azure DDoS Protection, Azure Firewall, Web Application Firewall, virtual networks, subnets, and Network Security Groups. They will also study Azure Bastion for RDP and SSH connections without direct exposure of a public IP, and Azure Key Vault to store secrets, passwords, certificates, tokens, and cryptographic keys.

Chapter 9 — Security posture and workload protection

Focuses on Microsoft Defender for Cloud and the areas of Cloud Security Posture Management and Cloud Workload Protection. The chapter covers Secure Score, recommendations, policies, initiatives, regulatory standards, resource inventory, misconfigurations, risk prioritization, and protection plans for servers, databases, storage, containers, and other workloads, including in hybrid and multicloud environments.

Chapter 10 — Microsoft Sentinel, SIEM, SOAR, and incident response

Explains SIEM and SOAR and presents Microsoft Sentinel as a cloud-native platform for collection, correlation, detection, investigation, hunting, and response. The student will learn about data connectors, analytics rules, alerts, incidents, queries, workbooks, playbooks based on Azure Logic Apps, and integrations with Microsoft Defender XDR and Security Copilot.

Chapter 11 — Microsoft Defender XDR, incidents, and unified portal

Introduces the concept of Extended Detection and Response and shows how Microsoft Defender XDR correlates signals from endpoints, identities, emails, applications, and cloud services. The chapter differentiates events, alerts, incidents, and evidence and explains the incident queue, advanced hunting, action center, automated investigation, assets, reports, and tracking of at-risk users and devices.

Chapter 12 — Microsoft Defender products ecosystem

Details the main components integrated into Defender XDR. Microsoft Defender for Office 365 will be related to the protection of emails, links, attachments, and collaboration; Defender for Endpoint, to prevention and response on devices; Defender for Cloud Apps, to SaaS, Shadow IT, and session controls; and Defender for Identity, to the analysis of on-premises Active Directory signals and the detection of identity-targeted threats.

Chapter 13 — Vulnerabilities, threat intelligence, and exposure management

Presents Microsoft Defender Vulnerability Management, Microsoft Defender Threat Intelligence, and Microsoft Security Exposure Management. The student will study vulnerability discovery and prioritization, indicators of compromise, threat actors and infrastructure, campaigns, attack surface, attack paths, critical assets, and exposure-reduction initiatives, as well as applications of Security Copilot in investigations and hunting.

Chapter 14 — Trust, privacy, and Service Trust Portal

Explains Microsoft's privacy principles, including control, transparency, protection, and compliance. The reader will get to know the Microsoft Service Trust Portal and the available materials, such as audit reports, certifications, regulatory documents, international standards, and trust reports, as well as understand the differences between the Service Trust Portal, Microsoft Purview, and Compliance Manager.

Chapter 15 — Data security and protection with Microsoft Purview

Presents the Microsoft Purview portal and the Information Protection capabilities. The chapter covers data discovery and classification, sensitive information types, trainable classifiers, Content Explorer, Activity Explorer, sensitivity labels, encryption, visual marks, and publishing policies. It also introduces DLP, Insider Risk Management, Adaptive Protection, and data security posture and investigation capabilities.

Chapter 16 — Compliance, retention, auditing, and investigations

Explains Compliance Manager, assessments, regulatory templates, Microsoft and customer controls, improvement actions, and Compliance Score. The student will also learn Communication Compliance, Information Barriers, Data Lifecycle Management, retention policies and labels, Records Management, eDiscovery, cases, custodians, searches, legal holds, review, evidence export, and Microsoft Purview auditing solutions.

Chapter 17 — Data governance and discovery with Microsoft Purview

Concludes the track with the fundamentals of data governance: discovery, cataloging, classification, ownership, quality, lineage, and responsible use. The chapter presents the Microsoft Purview Data Map and the Microsoft Purview Unified Catalog, explaining data products, governance domains, glossaries, search, and mechanisms that help people and organizations locate, understand, and use trusted data securely.

How to make the most of the journey

Learning will be more effective when the student does not treat the chapters as independent texts. Security, identity, and compliance form a connected system. A risk detected by Microsoft Entra ID Protection can be used in a Conditional Access policy; an incident can bring together alerts originating from different Defender products; data classified by Microsoft Purview can be protected by labels and DLP; recommendations from Defender for Cloud can guide the improvement of the posture of resources distributed across multiple subscriptions and clouds.

  1. Read the chapter seeking to understand the problem before memorizing the product.
  2. Create comparisons between similar solutions and record what each one does and does not do.
  3. Pay attention to the verbs and absolute words used in the questions.
  4. Solve the commented questions without consulting the answer and explain why the remaining alternatives are wrong.
  5. Review the chapters cumulatively, connecting identity, network, workloads, incidents, data, and compliance.
  6. Use Microsoft Learn and the official documentation to confirm changes in naming, licensing, or feature availability.

Conclusion: what you gain with this certification and with the knowledge acquired

Completing this track and earning the SC-900 certification represents more than adding a credential to your résumé. The main gain is acquiring a common language to understand and discuss security, identity, and compliance in Microsoft environments. The student comes to recognize how people, devices, applications, networks, workloads, and data can be protected by complementary controls, rather than depending on a single barrier or an isolated tool.

The certification demonstrates that the professional knows the fundamentals of an ecosystem used by organizations of different sizes and sectors. It can strengthen a transition to areas of security, cloud, identity, governance, audit, or data protection and serve as a foundation for more specialized studies. However, its value is not limited to a future role. Developers come to better understand authentication, authorization, and application identities; infrastructure professionals see networks and workloads from a risk perspective; data and compliance analysts understand classification, retention, DLP, and investigation; and managers can evaluate security decisions with more clarity.

At the end of the journey, the reader should be prepared to take the exam with confidence, interpret the presented scenarios, and recognize the appropriate solution. Even more important, they should have built a lasting understanding: knowing why access needs to be continuously verified, why permanent privileges increase risk, why data needs to be classified before being protected, why isolated alerts must be correlated into incidents, and why compliance requires actions from both the provider and the customer. As a final step of preparation, the reader will also count on 12 practice tests aimed at training for the exam, turning the knowledge built throughout the track into practice in solving, targeted review, and greater confidence for exam day.

This combination of certification and knowledge creates a solid base to keep learning. SC-900 is a starting point, not an end point. It provides the conceptual map needed to go deeper into Microsoft Entra, Microsoft Defender, Microsoft Sentinel, Microsoft Purview, Azure security, and other certifications. By mastering these fundamentals, the student stops seeing the Microsoft ecosystem as a collection of names and begins to see it as an integrated architecture of trust, protection, detection, response, and governance.

The central achievement of this track

Being able to look at a security, identity, or compliance scenario, understand the risk involved, and consciously choose the most appropriate Microsoft concept, control, or solution.

Official references used

Editorial note

The 17-chapter structure follows the study plan provided for this track. The exam-preparation approach was calibrated based on the patterns observed in the provided practice tests, preserving Microsoft Learn and the official guide as sources of truth for names, skills, and scope.