SC-900, "Microsoft Security, Compliance, and Identity Fundamentals", is an entry-level exam. It has no labs, no configuration questions and no prerequisites, and it costs about a third of an associate exam. So why would someone who already runs an identity platform take it?
Three reasons come up repeatedly. It is the fastest way to learn the vocabulary of a Microsoft security estate, which matters if your IAM work is about to touch Defender, Sentinel or Purview. It is often a stated requirement in job postings and partner programs, where "has an SC certification" is a checkbox. And it is a low-cost rehearsal for the Microsoft exam format before you sit SC-300, which is the exam that actually tests Entra ID administration.
This guide assumes you know identity. It spends little time on what you already know and more on the two domains that IAM people usually fail: Microsoft's security products and its compliance products.
01The Exam in Numbers
- About 45 minutes, roughly 40 to 60 questions, pass mark 700 on a 1000 scale.
- Multiple choice, multiple select, drag and drop, and short yes/no sets. No case studies, no simulations.
- Four domains. Microsoft revises the outline periodically; the names and approximate weights below were current when this was written, so check the exam page before booking.
| Domain | Approximate weight | What it is really about |
|---|---|---|
| Concepts of security, compliance and identity | 10–15% | Zero Trust, shared responsibility, defense in depth, encryption basics, what identity providers do |
| Capabilities of Microsoft Entra | 25–30% | The product you already know, described in Microsoft's words |
| Capabilities of Microsoft security solutions | 35–40% | Azure network security, Defender for Cloud, the Defender XDR family, Sentinel |
| Capabilities of Microsoft compliance solutions | 20–25% | Microsoft Purview: labels, DLP, retention, insider risk, eDiscovery, Compliance Manager |
Notice the weights. Identity is a quarter of the exam. More than half is products an identity engineer may never have opened.
02Domain 1: Concepts
Short and mostly common sense, but the questions use Microsoft's definitions, so learn those rather than your own.
- Zero Trust as Microsoft states it: verify explicitly, use least privilege, assume breach. The six pillars (identities, devices, applications, data, infrastructure, networks) appear in questions.
- Shared responsibility: what the customer always owns (data, identities, devices) versus what shifts to Microsoft as you move from on-premises through IaaS, PaaS and SaaS.
- Defense in depth layers, and the confidentiality, integrity, availability triad.
- Encryption at rest versus in transit, symmetric versus asymmetric, hashing versus encryption, and signing. The question is usually "which protects integrity" or "which is reversible".
- Compliance concepts: data residency, data sovereignty, the difference between privacy and security, and Microsoft's privacy principles.
- Identity concepts: authentication versus authorization, the identity provider role, federation, directory services, and identity as the primary security perimeter.
03Domain 2: Microsoft Entra
This is your home ground. The risk is answering from experience instead of from the current product names, so align your vocabulary:
- Azure Active Directory is Microsoft Entra ID. Azure AD B2C still exists under that name for existing tenants, while new customer identity work points to Microsoft Entra External ID.
- Identity types: users, groups (security and Microsoft 365), devices (registered, joined, hybrid joined), service principals and managed identities. Expect a question that asks which identity type a VM should use to reach a database (managed identity).
- Hybrid identity: Entra Connect and Cloud Sync, with password hash sync, pass-through authentication and federation as the three sign-in methods.
- Authentication: MFA methods, passwordless (Authenticator, FIDO2 keys, Windows Hello for Business), self-service password reset, password protection with banned password lists.
- Access management: Conditional Access signals and controls, Entra roles versus Azure RBAC roles, and the idea of least privilege through built-in roles.
- Protection and governance: Identity Protection (user risk and sign-in risk), Privileged Identity Management, access reviews, entitlement management, and the Entra ID Governance product. For fundamentals you need to know what each does, not how to configure it.
- Microsoft Entra Verified ID (decentralized, verifiable credentials) may appear as a "which Entra product does X" item; one sentence is enough.
04Domain 3: Microsoft Security Solutions
The largest domain and the one to spend most of your time on. It is a product catalogue, and the questions are "which product does this".
Azure infrastructure security: network security groups versus Azure Firewall (NSGs filter at the subnet or NIC; Firewall is a managed, stateful service with threat intelligence), DDoS Protection, Azure Bastion (RDP and SSH without public IPs), Web Application Firewall, and Azure Key Vault for secrets, keys and certificates.
Microsoft Defender for Cloud: cloud security posture management across Azure, AWS and GCP, the secure score, regulatory compliance dashboards, and the workload protection plans (servers, storage, databases, containers). Remember that posture management is free and the Defender plans are paid.
Microsoft Defender XDR, the family and what each member watches:
| Product | Watches |
|---|---|
| Defender for Endpoint | Devices: endpoint detection and response, attack surface reduction |
| Defender for Office 365 | Email and collaboration: Safe Links, Safe Attachments, anti-phishing |
| Defender for Identity | On-premises Active Directory signals, lateral movement, compromised credentials |
| Defender for Cloud Apps | SaaS usage: shadow IT discovery, app governance, session controls |
| Defender Vulnerability Management | Software weaknesses on managed devices |
The Defender portal correlates these into incidents; Microsoft Sentinel is the SIEM and SOAR that ingests from them and from anything else. The exam likes "Defender XDR versus Sentinel" questions: XDR is pre-integrated detection and response across Microsoft products; Sentinel is the cloud SIEM with connectors, analytics rules, workbooks, hunting and automation playbooks.
Microsoft Security Copilot appears in newer versions of the outline as an assistant embedded across these products; know that it exists and what it is attached to.
05Domain 4: Microsoft Compliance Solutions
Almost entirely Microsoft Purview, plus a little Azure governance. IAM people tend to underestimate this domain; it is a fifth of the score.
- Service Trust Portal and Compliance Manager: where Microsoft publishes audit reports, and where you track your own controls with a compliance score.
- Information protection: sensitivity labels, label policies, auto-labelling, and encryption through labels. Know the difference between a sensitivity label (classifies and protects) and a retention label (keeps or deletes).
- Data loss prevention: policies that detect sensitive information types in email, files, Teams and endpoints.
- Data lifecycle management and records management: retention policies versus retention labels, and what makes an item a record.
- Insider Risk Management, Communication Compliance, and Information Barriers: three products that are easy to confuse; learn one defining sentence for each.
- eDiscovery (standard versus premium) and audit (standard versus premium, with longer retention).
- Azure governance: Azure Policy, resource locks, and Microsoft Purview's data governance (catalog, lineage) as distinct from its compliance features.
06A Two-Week Plan for an IAM Professional
| Days | Do |
|---|---|
| 1–2 | Microsoft Learn SC-900 learning path, concepts and Entra modules, at reading speed. Note every product name you do not recognize. |
| 3–7 | Security solutions modules, slowly. For each product write one line: what it watches, where it lives, what it is not. Open the Defender portal and Defender for Cloud in a trial tenant so the names attach to screens. |
| 8–11 | Compliance modules. Open the Purview portal in the trial and find labels, DLP, retention, insider risk and eDiscovery. |
| 12 | Microsoft's free practice assessment. Review every miss against the Learn page it links. |
| 13 | Reread your one-line product notes; take the practice assessment again. |
| 14 | Exam. |
If you only have a weekend, do days 3 to 7 and 12. Identity will carry itself.
07Common Mistakes
Reading too much into the questions. Fundamentals questions are literal. "Which service provides SIEM capabilities" wants Sentinel, not a discussion of Defender XDR's incident correlation.
Mixing up the two Purviews. Purview compliance (labels, DLP, retention) and Purview data governance (data catalog, lineage) share a name and a portal and are tested as different things.
Mixing up the retention objects. Retention policies apply to locations; retention labels apply to items and can be published for users to apply. Only labels can declare records.
Expecting configuration questions. There are none. If you find yourself remembering PowerShell, you have over-prepared for this exam and under-prepared for the catalogue.
Using old courseware. The Entra rename, the Defender rename, and the move of compliance features under the Purview name all happened after much of the free material was recorded. Microsoft Learn is current.
08Quick Reference
| Question says | Answer is usually |
|---|---|
| "Verify explicitly, least privilege, assume breach" | Zero Trust principles |
| "Secure score for Azure, AWS and GCP resources" | Microsoft Defender for Cloud |
| "Detect lateral movement in on-premises Active Directory" | Microsoft Defender for Identity |
| "Discover shadow IT SaaS usage" | Microsoft Defender for Cloud Apps |
| "Collect logs from many sources, run analytics rules, automate response" | Microsoft Sentinel |
| "RDP to a VM without a public IP" | Azure Bastion |
| "Classify and encrypt a document" | Sensitivity label |
| "Keep emails for seven years then delete" | Retention policy or label |
| "Detect employees sending data to personal accounts before resigning" | Insider risk management |
| "Prevent two departments from communicating in Teams" | Information barriers |
| "Track compliance with a regulation using a score" | Compliance Manager |
| "VM needs to read a secret without storing credentials" | Managed identity with Key Vault |
09Key Takeaways
- SC-900 is a vocabulary exam. Identity is a quarter of it; Microsoft security and compliance products are more than half.
- Learn one defining sentence per product, especially the Defender family, Sentinel and the Purview features.
- Use Microsoft Learn and the free practice assessment; older material uses product names the exam no longer uses.
- Two weeks of evenings is enough for someone who already does IAM. Then go sit SC-300, which is the exam that tests what you actually do.
