Microsoft · SC-900

SC-900 Exam: Complete Security Fundamentals Guide

Microsoft Certified: Security, Compliance, and Identity Fundamentals badge

Current SC-900 exam guide covering the $99 USD price, 45-minute duration, Microsoft Entra, Defender, Purview, domain weights, and how to prepare.

Last verified September 6, 2026

SC-900 exam at a glance

DetailInformation
Exam nameMicrosoft Security, Compliance, and Identity Fundamentals
Exam codeSC-900
Certification earnedMicrosoft Certified: Security, Compliance, and Identity Fundamentals
Cost$99
Duration45 min
QuestionsTypically 40–60; Microsoft does not publish a fixed count
Passing score700 / 1000 (scaled)
FormatProctored fundamentals exam; may include interactive components
DeliveryTest center or online proctored
PrerequisitesNone required
ValidityNo expiry
RenewalFundamentals certification does not expire

Facts last verified September 6, 2026

Domain breakdown

DomainWeight
Describe security, compliance, and identity concepts
Explain security controls, shared responsibility, defense in depth, Zero Trust, encryption, GRC, authentication, authorization, directories, and federation.
10–15%
Describe Microsoft Entra capabilities
Identify Entra identities, hybrid identity, authentication, Conditional Access, RBAC, identity protection, access reviews, and privileged identity management.
25–30%
Describe Microsoft security solution capabilities
Recognize Azure infrastructure protection, Defender for Cloud, Sentinel, and the threat-protection services integrated through Microsoft Defender XDR.
35–40%
Describe Microsoft compliance solution capabilities
Explain Service Trust Portal, privacy, Compliance Manager, information protection, data lifecycle, DLP, records management, insider risk, eDiscovery, and audit.
20–25%

Who should take the SC-900 exam?

SC-900 is for people who need a working map of Microsoft's security, compliance, and identity portfolio. That includes students, business stakeholders, sales and project staff, new IT professionals, and experienced administrators moving into security. It validates concepts and service capabilities rather than deep implementation skill.

The exam is especially useful when your work touches both Azure and Microsoft 365. You should understand why identity is a security perimeter, how Zero Trust changes access decisions, how Microsoft detects threats, and how organizations classify and govern information. You do not need to be a security operations analyst or compliance attorney.

There are no prerequisites. Basic cloud vocabulary helps, as does limited portal exposure. SC-900 can prepare you for role-based exams such as SC-300, SC-200, or SC-100, but Microsoft does not require it for those certifications.

Skills measured on SC-900

Microsoft's official SC-900 study guide lists objectives effective July 28, 2026. The verbs matter: most objectives ask you to describe, define, or identify a capability. Study what a service does, why it is used, and how it relates to neighboring services before learning configuration details.

Describe security, compliance, and identity concepts (10–15%)

Begin with types and categories of security controls and the shared responsibility model. Responsibility changes across on-premises systems, infrastructure as a service, platform as a service, and software as a service. The cloud provider never removes the customer's duty to protect identities, data, configuration, and access appropriate to the service model.

Defense in depth uses layers so one control failure is not catastrophic. Zero Trust assumes breach, verifies explicitly, and grants least-privileged access. Know how these principles relate to network segmentation, identity signals, device state, data protection, logging, and continuous evaluation rather than treating Zero Trust as a single Microsoft product.

Other foundations include encryption versus hashing and governance, risk, and compliance. For identity, distinguish an identity, account, identity provider, directory, authentication, authorization, and federation. A common exam pattern describes a need and asks which concept fits—not which portal button performs it.

Describe the capabilities of Microsoft Entra (25–30%)

Microsoft Entra ID is the cloud identity and access foundation. Know user, guest, service, device, workload, and agent identities and how hybrid identity connects on-premises directories with the cloud. Distinguish synchronization from federation and from authentication itself.

Authentication coverage includes passwords, multifactor authentication, passwordless methods, self-service password reset, and password protection. Access management adds Conditional Access, roles, and role-based access control. Understand that Conditional Access evaluates signals and enforces access controls; it is not simply an MFA switch.

Identity governance manages access over time. Access reviews help confirm continued need, Privileged Identity Management supports controlled elevation, and Identity Protection detects and responds to identity risk. Learn the outcome each capability provides and the problem it does not solve.

Describe Microsoft security solution capabilities (35–40%)

This largest domain begins with Azure infrastructure defenses. Azure DDoS Protection addresses volumetric network attacks; Azure Firewall is a managed network security service; Web Application Firewall filters web threats; virtual networks and network security groups segment and control traffic; Bastion supplies protected administrative connectivity; and Key Vault protects keys, secrets, and certificates.

Microsoft Defender for Cloud covers cloud security posture management and workload protection. Posture features use standards, policies, recommendations, and Secure Score-style prioritization to reduce risk. Workload protections add threat detection for supported resources. The exam may ask whether a requirement is preventive posture improvement or active threat protection.

Microsoft Sentinel is Microsoft's cloud-native SIEM and SOAR platform. SIEM collects and correlates security data; SOAR automates investigation and response workflows. Know the roles of connectors, analytics, incidents, hunting, automation rules, and playbooks at a conceptual level.

Microsoft Defender XDR unifies signals and incidents across Defender services. Be able to associate Office 365 with email and collaboration, Endpoint with devices, Cloud Apps with SaaS usage, Identity with on-premises identity signals, Vulnerability Management with exposure, and Threat Intelligence with adversary context. The Microsoft Defender portal provides the combined investigation experience.

Describe Microsoft compliance solution capabilities (20–25%)

The Service Trust Portal publishes Microsoft audit, compliance, and trust documentation. Microsoft privacy principles describe how the company approaches data protection. Compliance Manager helps organizations assess controls and improvement actions, while its compliance score is a risk-management aid—not a legal guarantee that an organization complies with every law.

Microsoft Purview provides information protection and governance. Learn data classification, sensitive information types, sensitivity labels, Content explorer, Activity explorer, data loss prevention, retention, and records management. Distinguish a sensitivity label that describes and may protect content from a retention control that governs how long content is kept or deleted.

Insider Risk Management looks for potentially risky internal activity under configured policies. eDiscovery supports identification, preservation, collection, review, and export for legal cases. Audit records activities for investigation. These tools can share signals but address different business and regulatory needs.

How to prepare for SC-900

Use Microsoft's free learning paths in blueprint order. After each module, write one sentence for the problem, capability, and nearest confusing alternative. For example: Sentinel correlates security events; Defender XDR unifies incidents across Defender products; Defender for Cloud improves cloud posture and protects workloads.

Build a small service map. Put Entra under identity, Azure security services under infrastructure, Defender and Sentinel under security operations, and Purview under compliance and information governance. Add arrows where products integrate, but retain each product's primary job.

Portal tours are enough at this level. Inspect an Entra user and Conditional Access policy, Defender's incident experience, Sentinel concepts, and Purview's solution catalog. Do not spend most of your time scripting advanced deployments that the describe-level objectives do not test.

Finally, take the free Microsoft Practice Assessment. Review every explanation and return to the exact objective for each missed item. Practice answering promptly because 45 minutes is shorter than Microsoft role-based exams.

SC-900 practice questions

Good SC-900 practice asks you to match a requirement to a concept or service. It may ask which tool reviews privileged access, which control limits data sharing, or which platform correlates events. Explain the service boundary in your answer; recognition alone is fragile.

Use objective-aligned material and Microsoft's exam sandbox to learn the interface. Avoid dumps or claims of live questions. Besides violating exam rules, memorized answers age quickly when Microsoft renames products or changes integrations.

SC-900 compared with other fundamentals exams

AZ-900 surveys cloud concepts, Azure architecture, services, management, and governance. SC-900 goes deeper on identity, security operations, and compliance across Azure and Microsoft 365. They overlap on shared responsibility, governance, and security basics, but neither replaces the other.

For a security career, SC-900 is the more direct foundation. Follow it with a role-based exam only after choosing a target: SC-300 for identity, SC-200 for security operations, or SC-100 for architecture after substantial implementation experience.

Career value of SC-900

SC-900 supports entry-level security conversations and cross-functional work. It can strengthen a support, sales, audit, project, or junior administration profile by showing that you understand Microsoft's security and compliance vocabulary. It does not by itself prove that you can operate a SOC or design an enterprise security architecture.

Its best value comes when paired with a small portfolio: document a Zero Trust access design, classify sample information, or diagram how an alert becomes an incident and response. Because the fundamentals credential does not expire, it remains on your transcript without annual renewal.

Exam-day notes

  • The exam duration is 45 minutes; the booking includes additional seat time for instructions.
  • The US list price is $99, with regional pricing and taxes determined during scheduling.
  • Microsoft does not publish a fixed question count; most certification exams contain 40–60.
  • A scaled score of 700 or higher passes.
  • Register with a personal Microsoft account to keep the record when changing employers.

SC-900 FAQ

Is the SC-900 exam hard?

SC-900 is a beginner certification, but its product vocabulary is broad. Candidates usually struggle when they memorize names without understanding whether Entra, Defender, Sentinel, or Purview owns a particular capability.

How long is the SC-900 exam?

Microsoft currently provides 45 minutes for the assessment. The full seat duration is longer because it includes instructions, the candidate agreement, and comments.

Does SC-900 expire?

No. Microsoft fundamentals certifications do not expire, so SC-900 has no annual renewal assessment. Role-based associate, expert, and specialty credentials follow different renewal rules.

Do I need Azure experience for SC-900?

There is no formal prerequisite. Familiarity with Azure and Microsoft 365 is helpful, and brief hands-on exploration of Entra, Defender, Sentinel, and Purview makes the service boundaries easier to remember.

What score is required to pass SC-900?

You need a scaled score of at least 700. That value is not a simple percentage because Microsoft scales scores across exam forms that may differ in difficulty.

Prep resources

ResourceTypeProvider
SC-900 certification and exam page official Official guideMicrosoft Learn
Official SC-900 study guide official Official guideMicrosoft Learn
Introduction to Microsoft security, compliance, and identity official CourseMicrosoft Learn
Microsoft SC-900 Practice Assessment official Practice labMicrosoft Learn

← More Microsoft exams