Microsoft SC-900 Exam Guide: Security, Compliance, and Identity Fundamentals
The Microsoft SC-900 exam validates foundational knowledge of security, compliance, and identity concepts together with related Microsoft cloud solutions. It is intended for business stakeholders, students, and new or existing IT professionals who want a working view of how Microsoft Azure and Microsoft 365 security capabilities fit together. This guide helps you decide whether your background is ready, which objective areas deserve the most study time, whether self-paced or instructor-led preparation suits you, and what to do before scheduling the assessment.
What does SC-900 validate?
SC-900 validates that you can recognize the purpose and capabilities of Microsoft security, compliance, and identity solutions at a foundational level. It is not positioned as a deep implementation exam. The useful outcome is being able to connect a business or technical requirement with the appropriate Microsoft concept or service family.
Microsoft describes the credential as Microsoft Certified: Security, Compliance, and Identity Fundamentals. The certification is listed at the Beginner level and is associated with Azure, the Security Engineer role, and the Security subject area. The certification page says it is intended for people who want to become familiar with SCI across cloud-based and related Microsoft services.
The exam’s assessed areas are: describe security, compliance, and identity concepts; describe the capabilities of Microsoft Entra; describe the capabilities of Microsoft security solutions; and describe the capabilities of Microsoft compliance solutions. Those four areas form a better study structure than memorizing isolated product names.
Think of the exam as a vocabulary-and-purpose assessment. You should be able to explain why an organization uses identity controls, how security responsibilities are divided in cloud services, what security tools protect different resources, and how compliance capabilities help manage data and regulatory obligations. You do not need to treat every service as an administration project.
Who should take this exam?
SC-900 is a sensible starting point for a business stakeholder, student, or IT professional who needs a broad Microsoft SCI foundation rather than a specialist credential. The main readiness question is whether you can follow basic Azure and Microsoft 365 concepts well enough to understand how security, compliance, and identity span both environments.
Microsoft identifies business stakeholders, new or existing IT professionals, and students as audiences for this certification. Candidates should be familiar with Microsoft Azure and Microsoft 365 and understand how Microsoft SCI solutions can span those solution areas to provide a holistic, end-to-end solution.
The official SC-900 course lists general networking and cloud computing concepts, general IT knowledge or experience in an IT environment, and general understanding of Azure and Microsoft 365 as preparation expectations. The Microsoft Learn concepts path lists no prerequisites, so these are best treated as useful background rather than a formal certification prerequisite.
For a business-facing learner, preparation should emphasize service purpose, risk reduction, governance, and the difference between identity, security, and compliance responsibilities. For an IT learner, add service relationships and scenario-based comparisons. If Azure and Microsoft 365 are entirely unfamiliar, begin with their basic terminology before attempting practice questions.
How are the skills weighted?
Allocate study time according to the official domain ranges, not according to the length of a product list. Microsoft’s study guide lists Describe the concepts of security, compliance, and identity at 10–15%, Describe the capabilities of Microsoft Entra at 25–30%, Describe the capabilities of Microsoft security solutions at 35–40%, and Describe the capabilities of Microsoft compliance solutions at 20–25%.
The largest domain is Describe the capabilities of Microsoft security solutions at 35–40%, so it should receive the largest share of review time. Describe the capabilities of Microsoft Entra accounts for 25–30%, while Describe the capabilities of Microsoft compliance solutions accounts for 20–25%. Describe the concepts of security, compliance, and identity accounts for 10–15%.
These ranges do not tell you the exact number of questions or guarantee an even distribution within a domain. Use them to sequence preparation: establish the concepts, then study Entra, spend substantial time on security solutions, and finish by consolidating compliance capabilities.
Microsoft says the skills-measured material is tied to a version of the exam and that exams are updated periodically to reflect role requirements. The study guide identifies skills measured as of July 28, 2026, so check the current official study guide before you finalize a long study plan, particularly if your exam date is well after that version.
What concepts should you master first?
Start with the ideas that explain why Microsoft services exist. The concepts domain includes security and compliance foundations such as shared responsibility, defense in depth, Zero Trust, encryption and hashing, data residency, data sovereignty, identity providers, authentication, authorization, single sign-on, directory services, and federation.
Do not learn these terms as interchangeable definitions. Authentication establishes who or what is requesting access; authorization concerns what that identity is allowed to do. Encryption protects data by transforming it so it cannot be readily read without the appropriate key, while hashing produces a different type of one-way representation used for comparison and integrity-related purposes.
Shared responsibility requires you to think about which security tasks belong to the cloud provider and which remain with the customer. Defense in depth describes layered controls rather than reliance on one safeguard. Zero Trust is a model that challenges implicit trust and requires continual consideration of identity, device, access, and resource conditions.
Data residency and data sovereignty are easy to confuse. Treat residency as where data is stored and sovereignty as the legal or jurisdictional authority affecting it. For revision, create a two-column glossary: one column for the term, and another for the decision it helps an organization make.
The concepts learning path covers shared responsibility, Zero Trust, data residency, the role of identity providers, and related foundations. It also separates security and compliance concepts from identity concepts, which is a useful order for first-pass study.
How should you study Microsoft Entra?
Study Microsoft Entra as the identity layer that helps organizations manage access, authentication, and trust across cloud services. Your goal is to distinguish identity concepts and capabilities, not to memorize screens in the portal. Connect each capability to a question such as who can sign in, how access is verified, or how trust is extended across organizations.
Review the relationships among authentication, authorization, identity providers, directory services, single sign-on, and federation. Then map those concepts to Microsoft Entra capabilities as presented in the official learning material. Explain each relationship aloud without looking at your notes; hesitation usually identifies a concept that needs another pass.
Use short scenarios for active recall. For example, ask which concept is relevant when a user needs one sign-in across multiple services, when an organization must verify a sign-in more strongly, or when two organizations need to extend trust. The exercise is not to invent configuration steps but to select the underlying identity idea.
A common mistake is treating Microsoft Entra as only a user directory. That narrow view can obscure its relationship with authentication, authorization, identity governance, and access decisions. Another mistake is learning product labels without understanding the problem each capability addresses. Keep a service-purpose card for every Entra capability in your notes.
What belongs in the Microsoft security solutions domain?
The security solutions domain covers capabilities across Azure and Microsoft 365, including Azure infrastructure security, Azure security management, Microsoft Sentinel, Microsoft Defender XDR, Microsoft 365 security management, and Microsoft Security Copilot. Learn the role of each solution family and how the capabilities fit together before studying individual feature names.
The Microsoft security solutions learning path identifies core infrastructure security services in Azure, security management through Microsoft Defender for Cloud, security capabilities in Microsoft Sentinel, threat protection with Microsoft Defender XDR, and Microsoft Security Copilot. It describes Sentinel as a cloud-native security information and event management and security orchestration, automation, and response solution.
Build a protection map with four questions: what is being protected, where is it located, what kind of signal or risk is involved, and which service family addresses it? Azure network, virtual machine, and data protection concerns should not be collapsed into the same category as endpoint, identity, email, or application threat protection.
Study Defender for Cloud through its management purpose: security policies, standards, recommendations, secure score, workload protection plans, and related security management capabilities. Study Sentinel through collection and analysis of security information and event data, investigation, response, and its SIEM and SOAR role. The exam requires recognition of capabilities, not a claim that every organization deploys every service.
For Defender XDR, focus on its cross-domain threat protection role across endpoints, identities, email, and applications. For Security Copilot, focus on its introductory terminology, prompts, enablement, and relationship to security work as described in the learning path. Avoid assuming that an AI-assisted capability replaces security judgment or operational processes.
How should you approach compliance and Microsoft Purview?
Treat compliance as a governance and information-management problem rather than another name for threat detection. The compliance domain includes Microsoft compliance solutions, Microsoft Purview, and Microsoft’s privacy principles. Study how these capabilities help organizations understand, protect, retain, govern, and manage information in accordance with organizational or regulatory needs.
The official SC-900 learning structure places Microsoft Purview and Microsoft privacy principles after security concepts, Microsoft Entra, and Microsoft security solutions. That sequence is useful: first understand what data and identities are, then consider how an organization protects information and demonstrates responsible governance.
Create comparisons between security and compliance. Security solutions focus on preventing, detecting, investigating, and responding to threats. Compliance solutions address information governance, regulatory obligations, privacy, retention, and related organizational controls. The boundaries can interact, but the business question is different: one asks how to handle risk from threats, while the other asks how to manage information and obligations responsibly.
When revising Purview, avoid memorizing a catalogue of labels without a use case. For each capability named in the current study guide, write a sentence describing the information or governance decision it supports. Then test yourself with prompts such as identifying a compliance need, distinguishing privacy from threat protection, or selecting the type of control that supports data governance.
The Microsoft Learn security, compliance, and identity collection can provide wider context, but do not let optional material displace the current SC-900 study guide. Use the guide’s measured objectives as the boundary and wider documentation as clarification when a term remains unclear.
Which official preparation route fits your background?
Choose self-paced Microsoft Learn if you need flexibility and can maintain your own sequence; choose the official instructor-led course if you benefit from structured teaching and guided explanation. Both routes are supported by Microsoft resources, and the instructor-led SC-900 course content aligns with the exam objective domain.
The self-paced concepts learning path contains four parts in the broader SC-900 preparation structure: security, compliance, and identity concepts; Microsoft Entra; Microsoft security solutions; and Microsoft Purview and Microsoft privacy principles. The security solutions learning path provides five modules covering the security capability areas identified by Microsoft.
Microsoft Learn describes its online modules and tutorials as bite-sized, interactive skill builders that can be completed at your own pace and are available in multiple languages. That makes them useful for targeted remediation: you can return to a concept instead of repeating an entire course.
The official SC-900 instructor-led course is beginner-level and lasts one day. Its course page also lists instructor-led and self-paced study options and says the content aligns to the SC-900 exam objective domain. Select it when you want an organized overview, but still use the study guide to verify the version and close individual knowledge gaps.
A good decision rule is simple. If you already understand Azure, Microsoft 365, and basic cloud security, begin with the study guide and learning paths, then use practice assessment results to target weak areas. If those foundations are new, complete the concepts material first or choose structured training before scheduling.
What four-stage study roadmap should you follow?
Use a four-stage roadmap: establish the vocabulary, learn the service families, test retrieval, and verify readiness. This avoids the common pattern of watching training passively and scheduling before you can explain why a capability exists. Adjust the amount of time spent in each stage to your background and practice results rather than following an invented fixed timetable.
Stage one is orientation. Read the current SC-900 study guide and copy its four domains into a tracking sheet. Mark each objective as unfamiliar, partly understood, or explainable. Complete the security, compliance, and identity concepts path, paying particular attention to shared responsibility, Zero Trust, identity, encryption, and data-location terminology.
Stage two is service mapping. Work through the Microsoft Entra and Microsoft security solutions material, then the Purview and privacy material. For each service family, record its primary purpose, the problem it addresses, the adjacent services it may be confused with, and one short scenario in which it would be relevant. Keep the notes in your own words.
Stage three is retrieval practice. Use the official Practice Assessment when available, but treat it as a diagnostic rather than a promise of identical exam content. After each attempt, classify every missed or guessed item by domain and concept. Return to the relevant Microsoft Learn module or documentation, then answer a new question in your own words.
Stage four is readiness verification. Revisit every objective you marked as partly understood, explain the major service families without notes, and use the exam sandbox to become familiar with the interface and interactive question types. Schedule only after your preparation evidence shows consistent understanding across all four domains, not merely confidence in the largest product area.
How can you use practice assessments without overrelying on them?
Use a Practice Assessment to expose knowledge gaps and become familiar with question style, wording, and difficulty; do not use it as a substitute for the skills outline. Microsoft says Practice Assessments help candidates assess readiness and identify areas needing additional preparation, while the official exam can include interactive components.
Take an initial assessment before intensive revision if you can review the results calmly. Record whether each answer was correct because you knew the concept, correct by elimination, or a guess. A guessed correct answer is a study signal, not evidence that the topic is mastered.
For every missed question, write the reason for the error. Useful categories include confusing two services, reversing authentication and authorization, overlooking the scope of a capability, or answering from an outdated product description. Then locate the corresponding objective in the study guide and consult the official learning material.
Do not memorize the wording or infer that a practice item will reappear. The purpose is to improve recognition and explanation of the underlying skill. If your practice performance is strong in one domain but weak in another, direct the next study session to the weak domain even if the stronger one feels more comfortable.
Practice Assessments are available in multiple languages where offered, but Microsoft notes that an exam may not be available in the same languages as its Practice Assessment. Check language availability before treating a translated assessment as evidence about the language of your scheduled exam.
What delivery details should you confirm before scheduling?
SC-900 takes 45 minutes to complete, is proctored, and may include interactive components. Confirm the current delivery, language, and accommodation information on Microsoft’s certification page before booking, because scheduling conditions and available options are operational details that can change.
Microsoft lists SC-900 in English, Japanese, Chinese (Simplified), Korean, French, Spanish, Portuguese (Brazil), Russian, Arabic (Saudi Arabia), Indonesian (Indonesia), German, Chinese (Traditional), and Italian. The study guide says English is updated first and localized versions are updated approximately eight weeks after the English version, although Microsoft notes that the schedule can vary.
If the exam is unavailable in your preferred language, Microsoft says you can request an additional 30 minutes to complete it. Do not assume that this applies automatically; review the official accommodation or exam-language instructions and make the request through the stated process before the appointment.
Microsoft provides an exam sandbox so candidates can experience the look and feel of the exam and interact with different question types in the exam interface. Use it before exam day, especially if interactive components or unfamiliar navigation could distract you from reading the scenario carefully.
The certification page provides scheduling routes through Pearson VUE and, for students or educators, Certiport. Microsoft strongly recommends registering with a personal Microsoft account because exam records associated with an organizational work or school account may be lost if you leave that organization. Check the current certification page for the applicable scheduling and regional details.
How should you manage the 45-minute assessment?
Because Microsoft states that the assessment takes 45 minutes, use a calm, reading-first approach rather than trying to calculate an unsupported question pace. Read the requirement, identify the scope of the scenario, and eliminate options that describe a different security, identity, or compliance problem.
Interactive components may appear, so practice using the sandbox rather than assuming every item is a conventional multiple-choice question. If an item seems to combine several services, identify the requested outcome first: access control, threat detection, security management, information governance, privacy, or another stated objective.
Do not let one unfamiliar product label consume the assessment. Return to the domain and purpose behind the question, use the information in the scenario, and move forward according to the available exam controls. The important preparation is recognizing service families and their roles, not predicting live questions.
If you have an approved accommodation or need language support, confirm its effect on your appointment before scheduling. Microsoft’s study guide explains that an additional 30 minutes may be requested when the exam is not available in your preferred language, while other accommodations support assistive devices, read-aloud needs, fidgeting, or extra time.
Which mistakes most often weaken preparation?
The most damaging preparation mistakes are studying product names without purposes, ignoring the domain ranges, relying on unofficial recalled questions, and failing to check the current study guide. Correct these by using objective-based notes, scenario explanations, diagnostic practice, and an official-source check immediately before scheduling.
Mistake one is treating SC-900 as a list of definitions. A definition may be technically correct but still fail to distinguish two capabilities in a scenario. Add a “when would I choose this?” sentence to every important term.
Mistake two is spending all your time on a familiar Azure or Microsoft 365 area. The official ranges show that all four domains matter. Give the 10–15% concepts domain enough attention to support the rest, and do not neglect the 20–25% compliance domain simply because security products feel more concrete.
Mistake three is confusing adjacent services. Defender for Cloud, Microsoft Sentinel, Defender XDR, Entra, and Purview can appear in the same organizational security story, but they do not have identical purposes. Build a comparison table with columns for primary concern, scope, and example decision.
Mistake four is treating a practice score as a guarantee. Practice assessments are readiness aids, not live exam content. Review why an answer is right and why the alternatives are wrong, then confirm the explanation against Microsoft Learn.
Mistake five is using exam dumps or leaked-question claims. Memorization of unauthorized or recalled content does not establish the foundational knowledge the certification is designed to validate and does not guarantee a passing result. Prepare from the current official objectives and learning resources instead.
What should you do after a failed attempt?
A failed attempt should produce a narrower second plan, not a complete restart. Use the score report and your preparation notes to identify the weakest domain, revisit its official objectives and learning material, and then retest the concepts you missed. Microsoft states that a first retake is available after 24 hours; later retake intervals vary.
Separate a knowledge gap from an exam-process problem. If you misunderstood identity terminology, study the concepts and Entra material. If you rushed interactive items or misread the requested outcome, repeat the sandbox and practice careful scenario extraction. If language or accommodation issues affected the attempt, resolve those before another appointment.
Do not infer that a score below the passing threshold maps directly to a percentage of questions. Microsoft’s study guide states that a score of 700 or greater is required to pass, but the score report should guide your remediation rather than a simple arithmetic target.
Before rebooking, write a short explanation for each domain in your own words and complete targeted practice after the review. The goal is changed understanding: you should be able to identify the service family, explain its role, and distinguish it from nearby capabilities without relying on remembered answer patterns.
What is the final scheduling checklist?
Schedule when you can explain the four domains, have checked the current official study guide, and understand the appointment conditions. Your final checklist should cover the skills version, language, account, delivery route, accommodations, sandbox familiarity, and a targeted review of weak objectives.
Confirm that you are preparing against the current SC-900 study guide. Microsoft updates exams periodically, and the study guide provides different skills-measured versions when an update is in progress. The supplied study guide identifies a version effective July 28, 2026; verify the applicable version for your appointment.
Check the language offered for the exam itself rather than relying only on the language of a Practice Assessment or learning module. Review whether you need to request an accommodation or additional time, and complete that process before the appointment rather than treating it as a last-minute option.
Use a personal Microsoft account when registering, as Microsoft recommends, so your exam history remains connected to you if you change employers or schools. Select the appropriate Pearson VUE or Certiport route shown on the certification page and verify regional details there.
Finally, run the exam sandbox, review your domain tracker, and stop adding unrelated technologies. A focused final review of concepts, Entra, security solutions, and compliance solutions is more useful than collecting another broad list of products.
Where should your next study session begin?
Begin with the official SC-900 study guide, then use Microsoft Learn to fill the first clearly marked gap. If the concepts are unfamiliar, start with the security, compliance, and identity concepts path. If the foundations are sound, move to Microsoft Entra and the security solutions path, giving the largest domain the most deliberate review.
A practical first session has three outputs: a four-domain tracker, a short glossary of concepts you cannot yet explain, and a service-purpose map for the Microsoft capabilities named in the learning paths. Finish by identifying one objective for the next session rather than attempting to study the entire certification at once.
Keep the official certification page open when making delivery or scheduling decisions. It is the appropriate place to verify the assessment duration, proctored status, language list, scheduling routes, practice assessment access, sandbox, and current certification information.
Once your tracker shows explainable knowledge across every domain, take the official Practice Assessment if available, review the results, and remediate before scheduling. That sequence turns preparation into a decision based on evidence rather than optimism.
Conclusion
SC-900 is best approached as a foundation in how Microsoft organizes security, compliance, and identity across Azure and Microsoft 365. Start with the concepts, map Microsoft Entra and the security and compliance solution families to real decisions, then use practice results and the exam sandbox to verify readiness. Before booking, recheck the current study guide, language, accommodation, account, and delivery details on Microsoft’s official pages.