Skip to main content
IAMRoadmapIAMRoadmap
General
9 min read

Getting Started with Microsoft SC-900 Security Fundamentals: A Guide for IAM Professionals

SC-900 is a fundamentals exam, not an implementation exam. This guide tells IAM practitioners what it covers, which parts they already know, which parts (Microsoft security and compliance products) they probably do not, and how to pass it in two weeks of evenings.

I

IAM Roadmap Team

IAM Security Expert

February 9, 2026

SC-900, "Microsoft Security, Compliance, and Identity Fundamentals", is an entry-level exam. It has no labs, no configuration questions and no prerequisites, and it costs about a third of an associate exam. So why would someone who already runs an identity platform take it?

Three reasons come up repeatedly. It is the fastest way to learn the vocabulary of a Microsoft security estate, which matters if your IAM work is about to touch Defender, Sentinel or Purview. It is often a stated requirement in job postings and partner programs, where "has an SC certification" is a checkbox. And it is a low-cost rehearsal for the Microsoft exam format before you sit SC-300, which is the exam that actually tests Entra ID administration.

This guide assumes you know identity. It spends little time on what you already know and more on the two domains that IAM people usually fail: Microsoft's security products and its compliance products.

The Exam in Numbers

  • About 45 minutes, roughly 40 to 60 questions, pass mark 700 on a 1000 scale.
  • Multiple choice, multiple select, drag and drop, and short yes/no sets. No case studies, no simulations.
  • Four domains. Microsoft revises the outline periodically; the names and approximate weights below were current when this was written, so check the exam page before booking.
DomainApproximate weightWhat it is really about
Concepts of security, compliance and identity10–15%Zero Trust, shared responsibility, defense in depth, encryption basics, what identity providers do
Capabilities of Microsoft Entra25–30%The product you already know, described in Microsoft's words
Capabilities of Microsoft security solutions35–40%Azure network security, Defender for Cloud, the Defender XDR family, Sentinel
Capabilities of Microsoft compliance solutions20–25%Microsoft Purview: labels, DLP, retention, insider risk, eDiscovery, Compliance Manager

Notice the weights. Identity is a quarter of the exam. More than half is products an identity engineer may never have opened.

Domain 1: Concepts

Short and mostly common sense, but the questions use Microsoft's definitions, so learn those rather than your own.

  • Zero Trust as Microsoft states it: verify explicitly, use least privilege, assume breach. The six pillars (identities, devices, applications, data, infrastructure, networks) appear in questions.
  • Shared responsibility: what the customer always owns (data, identities, devices) versus what shifts to Microsoft as you move from on-premises through IaaS, PaaS and SaaS.
  • Defense in depth layers, and the confidentiality, integrity, availability triad.
  • Encryption at rest versus in transit, symmetric versus asymmetric, hashing versus encryption, and signing. The question is usually "which protects integrity" or "which is reversible".
  • Compliance concepts: data residency, data sovereignty, the difference between privacy and security, and Microsoft's privacy principles.
  • Identity concepts: authentication versus authorization, the identity provider role, federation, directory services, and identity as the primary security perimeter.

Domain 2: Microsoft Entra

This is your home ground. The risk is answering from experience instead of from the current product names, so align your vocabulary:

  • Azure Active Directory is Microsoft Entra ID. Azure AD B2C still exists under that name for existing tenants, while new customer identity work points to Microsoft Entra External ID.
  • Identity types: users, groups (security and Microsoft 365), devices (registered, joined, hybrid joined), service principals and managed identities. Expect a question that asks which identity type a VM should use to reach a database (managed identity).
  • Hybrid identity: Entra Connect and Cloud Sync, with password hash sync, pass-through authentication and federation as the three sign-in methods.
  • Authentication: MFA methods, passwordless (Authenticator, FIDO2 keys, Windows Hello for Business), self-service password reset, password protection with banned password lists.
  • Access management: Conditional Access signals and controls, Entra roles versus Azure RBAC roles, and the idea of least privilege through built-in roles.
  • Protection and governance: Identity Protection (user risk and sign-in risk), Privileged Identity Management, access reviews, entitlement management, and the Entra ID Governance product. For fundamentals you need to know what each does, not how to configure it.
  • Microsoft Entra Verified ID (decentralized, verifiable credentials) may appear as a "which Entra product does X" item; one sentence is enough.

Domain 3: Microsoft Security Solutions

The largest domain and the one to spend most of your time on. It is a product catalogue, and the questions are "which product does this".

Azure infrastructure security: network security groups versus Azure Firewall (NSGs filter at the subnet or NIC; Firewall is a managed, stateful service with threat intelligence), DDoS Protection, Azure Bastion (RDP and SSH without public IPs), Web Application Firewall, and Azure Key Vault for secrets, keys and certificates.

Microsoft Defender for Cloud: cloud security posture management across Azure, AWS and GCP, the secure score, regulatory compliance dashboards, and the workload protection plans (servers, storage, databases, containers). Remember that posture management is free and the Defender plans are paid.

Microsoft Defender XDR, the family and what each member watches:

ProductWatches
Defender for EndpointDevices: endpoint detection and response, attack surface reduction
Defender for Office 365Email and collaboration: Safe Links, Safe Attachments, anti-phishing
Defender for IdentityOn-premises Active Directory signals, lateral movement, compromised credentials
Defender for Cloud AppsSaaS usage: shadow IT discovery, app governance, session controls
Defender Vulnerability ManagementSoftware weaknesses on managed devices

The Defender portal correlates these into incidents; Microsoft Sentinel is the SIEM and SOAR that ingests from them and from anything else. The exam likes "Defender XDR versus Sentinel" questions: XDR is pre-integrated detection and response across Microsoft products; Sentinel is the cloud SIEM with connectors, analytics rules, workbooks, hunting and automation playbooks.

Microsoft Security Copilot appears in newer versions of the outline as an assistant embedded across these products; know that it exists and what it is attached to.

Domain 4: Microsoft Compliance Solutions

Almost entirely Microsoft Purview, plus a little Azure governance. IAM people tend to underestimate this domain; it is a fifth of the score.

  • Service Trust Portal and Compliance Manager: where Microsoft publishes audit reports, and where you track your own controls with a compliance score.
  • Information protection: sensitivity labels, label policies, auto-labelling, and encryption through labels. Know the difference between a sensitivity label (classifies and protects) and a retention label (keeps or deletes).
  • Data loss prevention: policies that detect sensitive information types in email, files, Teams and endpoints.
  • Data lifecycle management and records management: retention policies versus retention labels, and what makes an item a record.
  • Insider Risk Management, Communication Compliance, and Information Barriers: three products that are easy to confuse; learn one defining sentence for each.
  • eDiscovery (standard versus premium) and audit (standard versus premium, with longer retention).
  • Azure governance: Azure Policy, resource locks, and Microsoft Purview's data governance (catalog, lineage) as distinct from its compliance features.

A Two-Week Plan for an IAM Professional

DaysDo
1–2Microsoft Learn SC-900 learning path, concepts and Entra modules, at reading speed. Note every product name you do not recognize.
3–7Security solutions modules, slowly. For each product write one line: what it watches, where it lives, what it is not. Open the Defender portal and Defender for Cloud in a trial tenant so the names attach to screens.
8–11Compliance modules. Open the Purview portal in the trial and find labels, DLP, retention, insider risk and eDiscovery.
12Microsoft's free practice assessment. Review every miss against the Learn page it links.
13Reread your one-line product notes; take the practice assessment again.
14Exam.

If you only have a weekend, do days 3 to 7 and 12. Identity will carry itself.

Common Mistakes

Reading too much into the questions. Fundamentals questions are literal. "Which service provides SIEM capabilities" wants Sentinel, not a discussion of Defender XDR's incident correlation.

Mixing up the two Purviews. Purview compliance (labels, DLP, retention) and Purview data governance (data catalog, lineage) share a name and a portal and are tested as different things.

Mixing up the retention objects. Retention policies apply to locations; retention labels apply to items and can be published for users to apply. Only labels can declare records.

Expecting configuration questions. There are none. If you find yourself remembering PowerShell, you have over-prepared for this exam and under-prepared for the catalogue.

Using old courseware. The Entra rename, the Defender rename, and the move of compliance features under the Purview name all happened after much of the free material was recorded. Microsoft Learn is current.

Quick Reference

Question saysAnswer is usually
"Verify explicitly, least privilege, assume breach"Zero Trust principles
"Secure score for Azure, AWS and GCP resources"Microsoft Defender for Cloud
"Detect lateral movement in on-premises Active Directory"Microsoft Defender for Identity
"Discover shadow IT SaaS usage"Microsoft Defender for Cloud Apps
"Collect logs from many sources, run analytics rules, automate response"Microsoft Sentinel
"RDP to a VM without a public IP"Azure Bastion
"Classify and encrypt a document"Sensitivity label
"Keep emails for seven years then delete"Retention policy or label
"Detect employees sending data to personal accounts before resigning"Insider risk management
"Prevent two departments from communicating in Teams"Information barriers
"Track compliance with a regulation using a score"Compliance Manager
"VM needs to read a secret without storing credentials"Managed identity with Key Vault

Key Takeaways

  • SC-900 is a vocabulary exam. Identity is a quarter of it; Microsoft security and compliance products are more than half.
  • Learn one defining sentence per product, especially the Defender family, Sentinel and the Purview features.
  • Use Microsoft Learn and the free practice assessment; older material uses product names the exam no longer uses.
  • Two weeks of evenings is enough for someone who already does IAM. Then go sit SC-300, which is the exam that tests what you actually do.

Related Topics

microsoft sc-900iam security fundamentalsazure active directoryidentity management best practicessecurity certificationsmicrosoft security trainingcloud identity fundamentals

Found this helpful?

Share it with your network