SC-900 Study Guide
A curated learning path for the SC-900 exam: the best documentation, videos, blog posts and tutorials for every exam objective.A curated learning path for the SC-900 exam: the best documentation, videos, blog posts and tutorials for every exam objective, in the order worth studying them.
Microsoft Certified: Security, Compliance, and Identity Fundamentals
Exam at a Glance
SC-900 measures whether you understand how security, compliance, and identity work across Microsoft cloud services: the core concepts (Zero Trust, shared responsibility, encryption), what Microsoft Entra does for identity, which Microsoft security service solves which problem, and how Microsoft Purview handles compliance. It is a concepts exam — you describe and identify, you do not configure.
| SC-900 | Microsoft Security, Compliance, and Identity Fundamentals |
|---|---|
| Certification | Microsoft Certified: Security, Compliance, and Identity Fundamentals |
| Level | Beginner (fundamentals exam) |
| Exam length | 45 minutes |
| Questions | Typically 40 to 60 |
| Passing score | 700 out of 1000 |
| Question formats | Multiple choice, multiple select, drag and drop, build list, hot area |
| Open book | No: Microsoft Learn access during the exam is not available on fundamentals exams |
| Skills measured version | July 28, 2026 |
| Renewal | Not needed — fundamentals certifications do not expire |
| Cost | Depends on your country or region; shown when you schedule |
What the Exam Covers
The exam has four domains with very different weights. Microsoft security solutions is the heavyweight — the Defender family, Sentinel, and Azure network security together carry more than a third of the exam — and Microsoft Entra is close behind. Plan your study time accordingly.
Concepts of security, compliance, and identity — 10-15%
Shared responsibility model, defense-in-depth, the Zero Trust model, encryption and hashing, Governance Risk and Compliance (GRC) concepts, identity as the primary security perimeter, authentication vs authorization, identity providers, directory services and Active Directory, federation.
Capabilities of Microsoft Entra — 25-30%
Microsoft Entra ID and identity types (including the new agent ID for AI agents), hybrid identity, authentication methods, MFA, password protection, Conditional Access, Entra roles and RBAC, ID Governance, access reviews, Privileged Identity Management, Entra ID Protection.
Capabilities of Microsoft security solutions — 35-40%
Azure DDoS Protection, Azure Firewall, Web Application Firewall, network segmentation and NSGs, Azure Bastion, Azure Key Vault, Microsoft Defender for Cloud and cloud security posture management, Microsoft Sentinel (SIEM and SOAR), the Microsoft Defender XDR services and portal.
Capabilities of Microsoft compliance solutions — 20-25%
Service Trust Portal and Microsoft's privacy principles, the Microsoft Purview portal, Compliance Manager and compliance score, data classification, sensitivity labels, data loss prevention, records management, retention, insider risk management, eDiscovery, audit.
The full bullet-level list lives in the official study guide. Treat it as your checklist:
The Official SC-900 Study Guide
How This Maps to CertiAce Practice Modules
The CertiAce question bank mirrors the four exam domains, so you can drill each area in isolation and see exactly where you are weak:
| CertiAce practice module | What you will drill there |
|---|---|
| Introduction to security, compliance, and identity concepts | Zero Trust, shared responsibility, defense-in-depth, encryption and hashing, GRC, identity concepts and federation |
| Introduction to Microsoft Entra | Identity types incl. agent ID, authentication methods and MFA, Conditional Access, RBAC, PIM, access reviews, ID Protection |
| Introduction to Microsoft security solutions | Azure network security services, Key Vault, Defender for Cloud, Sentinel, the Defender XDR family |
| Introduction to Microsoft Purview and Microsoft's privacy principles | Service Trust Portal, privacy principles, Compliance Manager, classification, labels, DLP, retention, insider risk, eDiscovery, audit |
Where SC-900 Fits
| Certification | What it validates | When to take it |
|---|---|---|
| AZ-900: Azure Fundamentals | General cloud and Azure concepts | Optional companion — take it before or after SC-900 if you are new to cloud |
| SC-900: Security, Compliance, and Identity Fundamentals (this exam) | Foundational knowledge of Microsoft security, compliance, and identity solutions | You are here |
| SC-300: Identity and Access Administrator Associate | Implementing Microsoft Entra identity solutions hands-on | A natural next step if identity is your direction |
| SC-200: Security Operations Analyst Associate | Threat detection and response with Sentinel and Defender XDR | The next step toward security operations |
SC-900 has no prerequisites. It is designed for business stakeholders, students, and IT professionals alike — you should have a general idea of what Microsoft Azure and Microsoft 365 are, but you do not need hands-on security experience.
Before You Start
The official course lists only light prerequisites. Check yourself against this table — anything unfamiliar is where your preparation should start:
| Area | You should be comfortable with |
|---|---|
| Cloud basics | What the cloud is, general networking and cloud computing concepts (what AZ-900 teaches) |
| Microsoft Azure awareness | What Azure is and roughly what kinds of services it offers |
| Microsoft 365 awareness | What Microsoft 365 is (email, Teams, SharePoint) — several compliance topics live there |
| General IT vocabulary | Users, groups, permissions, servers, and what an IT admin does day to day |
Step-by-Step Study Plan
How long you need depends on where you start:
| Your starting point | Suggested prep time |
|---|---|
| You work in IT or already know Azure basics | 1 to 2 weeks |
| New to Microsoft cloud and security topics | 2 to 4 weeks |
Step 1: Read the Official Study Guide
Skim the full skills-measured list once, and mark every bullet you could not explain to a colleague. That marked-up list is your personal syllabus — everything else in this plan exists to clear it. Note the July 28, 2026 update added two topics older materials miss entirely: agent ID (identities for AI agents) and GRC concepts.
Step 2: Schedule Your Exam
Book the exam before you feel ready. A real date on the calendar turns studying from "someday" into a countdown — pick one using the prep-time table above and plan backwards from it.
Certification and Exam Details Page
Step 3: Work Through the Official Learning Path
Complete the SC-900 course modules on Microsoft Learn. They map one-to-one to the exam domains, and the recently rewritten units are unusually close to how the exam words things. Take notes on every concept you cannot explain in one sentence.
Official Learning Path Course Page
Step 4: Watch a Full Video Course
John Savill's SC-900 Study Cram V2 compresses the whole syllabus into one focused session with whiteboard explanations — ideal as a second pass after the learning path, and again as a final refresher in your last days. Make sure you use the V2 — the original cram predates the current exam content.
John Savill's SC-900 Study Cram V2
Step 5: See the Services for Yourself
SC-900 is a concepts exam, but the concepts stick much faster when you have seen the real thing. With a free Azure account you can open the Microsoft Entra admin center and look at users, groups, and Conditional Access; the Service Trust Portal is publicly accessible, so you can browse Microsoft's audit reports and compliance offerings exactly as the exam describes them. Focus on recognizing what each service is for — configuration is not tested.
Step 6: Benchmark Your Knowledge
Use CertiAce to benchmark your readiness module by module — the practice modules map to the exam domains as shown above, so a weak module tells you exactly which skills-measured area to revisit. Microsoft also offers a free official practice assessment. Aim for consistent performance across every module, not one lucky high score.
Free Official Practice Assessment
Step 7: Take the Exam
The day before, review only your weak topics — no brand-new material. On exam day, read each question for what it is truly asking: most SC-900 questions come down to matching the right service or concept to a one-line scenario, so eliminate the options from the wrong product family first.
Worth knowing before you sit down:
- This is a closed-book exam — unlike the role-based exams, Microsoft Learn is NOT available during fundamentals exams. What you know is what you have.
- You can take unscheduled breaks, but the clock keeps running and you cannot return to questions you already saw.
- Watch the naming: the exam uses current product names — Microsoft Entra ID (not Azure AD), Microsoft Defender XDR, Microsoft Purview, Microsoft Defender for Cloud. Older study materials with legacy names will actively mislead you.
- Try the exam sandbox beforehand so the question formats and interface hold no surprises: Exam Sandbox
Additional Learning Resources
| Resource | Type | Why it is useful |
|---|---|---|
| Exam Readiness Zone | Video series | Microsoft Certified Trainer prep videos — search for the SC-900 episodes covering each domain |
| Microsoft security documentation | Docs hub | The entry point to every security product doc the exam draws from |
| Microsoft Purview documentation | Docs hub | The compliance domain's source of truth — skim the overview pages for each solution |
| Microsoft Sentinel documentation | Docs hub | SIEM and SOAR concepts straight from the product docs |
| Security, compliance, and identity community hub | Community | Microsoft's official SCI community — announcements and discussions |
| Free Official Practice Assessment | Practice | Microsoft's own question-style preview, free |
Realistic SC-900 exam-style questions with instant feedback and detailed explanations.
Practice SC-900 now