Microsoft Security, Compliance, and Identity FundamentalsStudy guide
The fundamentals certification for security, compliance, and identity (SC-900).
About Microsoft Security, Compliance, and Identity Fundamentals (SC-900)
Microsoft Security, Compliance, and Identity Fundamentals (SC-900) is a Fundamentals-level certification from Microsoft. This page organizes the exam scope into a 4-chapter, 10-section study guide and lets you check your understanding with exam-style practice questions. A good flow is to read the chapters below in order, then test yourself via "Practice questions."
Exam domains (approximate weighting)
- Concepts of security, compliance, and identity~13%
- Microsoft Entra and identity~28%
- Microsoft security solutions~30%
- Microsoft compliance solutions~29%
Weights are approximate guidance for the live exam. Each domain is covered in detail in the chapters and sections below.
Official exam information: https://learn.microsoft.com/en-us/credentials/certifications/resources/study-guides/sc-900
1Concepts of Security, Compliance, and Identity
- 1.1Zero Trust and Defense in Depth
Understand core security ideas—Zero Trust, defense in depth, the shared responsibility model, and confidentiality/integrity/availability (CIA). The starting point for SC-900.
- 1.2Authentication, Authorization, and Encryption
Understand the difference between authentication (AuthN) and authorization (AuthZ), and the basics of encryption and hashing.
2Microsoft Entra and Identity
- 2.1Microsoft Entra ID and Identity Types
Understand that identity is the "new security perimeter," the role of Microsoft Entra ID (formerly Azure AD), identity types (users, service principals, managed identities, devices), and SSO/federation.
- 2.2Authentication Methods and Conditional Access
Understand authentication methods like MFA and passwordless, and Conditional Access that controls access based on sign-in risk and conditions.
3Microsoft Security Solutions
- 3.1Defender for Cloud and Microsoft Sentinel
Understand Microsoft Defender for Cloud, which assesses and strengthens cloud security posture, and Microsoft Sentinel, a cloud SIEM/SOAR that detects and responds to threats.
- 3.2Microsoft Defender XDR
Understand the workloads of Microsoft Defender XDR, which detects and responds to threats across endpoints, email, identity, and SaaS apps.
- 3.3Azure Network and Infrastructure Security
Understand Azure’s foundational security features—network security groups (NSG), Azure Firewall, DDoS Protection, and Azure Key Vault.
4Microsoft Compliance Solutions
- 4.1Compliance Management Tools
Understand the Service Trust Portal for Microsoft’s compliance info, and Microsoft Purview (Compliance Manager and Compliance Score) for managing your own compliance.
- 4.2Information Protection and Data Lifecycle Management
Understand sensitivity labels, data loss prevention (DLP), and retention policies for classifying, protecting, and retaining/deleting sensitive data.
- 4.3Insider Risk, eDiscovery, and Audit
Understand insider risk management for internal risks, eDiscovery for legal investigations, and audit for recording activity.

