The Complete Azure SC-900 Exam Guide

Covers the SC-900 exam format, its four domains, who should take it, and a study order for beginners.

Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900) is the only entry point in Microsoft's security certification lineup that requires no hands-on console experience — just an understanding of the concepts. IT staff outside a security team, legal and compliance professionals handling regulatory work, and junior engineers just getting curious about security all end up taking it. Like an intern walking into a hospital for the first time and learning what each department actually does, SC-900 checks whether you understand the roles security, compliance, and identity play inside the Microsoft ecosystem and how they connect to each other.

Who Actually Needs This Exam

An ER intake clerk doesn't need medical training to know which department a patient belongs in, and SC-900 works the same way — it checks whether you can judge which Microsoft security tool fits a given situation, not deep technical mastery of any one of them. It's especially useful for IT staff considering a move into security, developers or administrators who need to collaborate with a security team, and compliance staff responsible for regulatory audits. There are no prerequisites, and true to its Fundamentals level, it never needs to be renewed once earned.

 

Exam Format: Checking Concepts Within 60 Minutes

Much like a routine physical runs through several systems quickly, SC-900 spends 60 minutes covering roughly 40 to 60 questions across security, compliance, and identity. The passing score is 700 out of 1000, and the exam fee is 99 USD. Question formats mix single-choice, multiple-choice, and drag-and-drop, and the exam frequently tests whether you can correctly pair a product family name — Microsoft Entra, Purview — with the exact problem it solves.

 

Domain 1: Describe the Concepts of Security, Compliance, and Identity (10-15%)

Just as you sketch a blueprint before building a house, this domain covers the shared vocabulary needed to understand the other three domains. The essentials are defense in depth, the CIA triad of confidentiality, integrity, and availability, the shared responsibility model, and the three principles of Zero Trust — verify explicitly, use least privilege, and assume breach. The related post Security, Compliance, and Identity Concepts covers these foundational ideas in depth.

 

Domain 2: Describe the Capabilities of Microsoft Entra (25-30%)

Like a security officer issuing and managing building access cards, this domain covers Microsoft Entra's capabilities for managing who can access what. The essentials are the difference between authentication and authorization, multi-factor authentication (MFA) and Conditional Access, risk-based policies through Microsoft Entra ID Protection, and Microsoft Entra Connect for hybrid identity. Two related posts cover this domain: Microsoft Entra ID and Authentication and Access Management and Identity Governance.

 

Domain 3: Describe the Capabilities of Microsoft Security Solutions (35-40%)

This is the highest-weighted domain, and just as different diagnostic machines in a hospital each catch different symptoms, each Microsoft security product detects a different category of threat. The essentials are the Microsoft Defender XDR family covering endpoints, identity, email, and cloud apps, SIEM and SOAR capabilities through Microsoft Sentinel, and Azure network security tools like NSGs, Azure Firewall, and DDoS Protection. Two related posts cover this domain: Azure Security Services and Microsoft Sentinel and Defender XDR.

 

Domain 4: Describe the Capabilities of Microsoft Compliance Solutions (20-25%)

Just as a company organizes its paperwork ahead of an audit, this domain covers the tools an organization uses to prove it's meeting its regulatory obligations. The essentials are information protection and data loss prevention (DLP) through Microsoft Purview, insider risk management and eDiscovery, tracking a compliance score with Compliance Manager, and reviewing audit reports through the Service Trust Portal. Three related posts cover this domain: Purview Compliance and Information Protection, Insider Risk, eDiscovery, and Audit, and Service Trust Portal and Privacy.

 

A Study Order for Beginners, and Common Mistakes

Walking an unfamiliar city without a map means retracing the same streets twice. If you're new to security, start with Domain 1 (core concepts) to lock down terms like Zero Trust and the shared responsibility model, then move into Domain 2 (Entra) and practice telling authentication apart from authorization. From there, sort out what each Defender product and Sentinel actually do in Domain 3 (security solutions), and finish by layering in Purview and Compliance Manager in Domain 4 (compliance). The most common mistake is confusing the similarly-named Defender products; organizing them by what each one protects — endpoints with Defender for Endpoint, email with Defender for Office 365, cloud apps with Defender for Cloud Apps — clears that up fast. A second common mistake is treating authentication and authorization as the same idea; keeping the distinction as "confirms who you are" versus "decides what you're allowed to do" prevents that mix-up on exam day.

 

Exam Key Takeaways

"The process of confirming an identity" -- Authentication "The process of granting permissions to a confirmed identity" -- Authorization "Verify every request, grant only minimum access" -- Zero Trust model "Security responsibilities split between provider and customer" -- shared responsibility model "Threat protection spanning endpoints, identity, email, and cloud apps" -- Microsoft Defender XDR "Cloud SIEM that collects and analyzes security events" -- Microsoft Sentinel "Applies access conditions dynamically based on risk signals" -- Conditional Access "Blocks sensitive data from leaving the organization" -- Data Loss Prevention (DLP) "Detects risky behavior from people inside the organization" -- insider risk management "Searches and preserves relevant data for litigation or investigation" -- eDiscovery "Tracks an organization's compliance posture as a score" -- Compliance Manager "Publishes Microsoft's audit reports and certification status" -- Service Trust Portal

SC-900 asks which tool fits a given situation rather than how to operate any single tool, so pairing each product name with the exact problem it blocks makes even the most confusing question on exam day much easier to answer.

Back to blog list