Azure SC-900: Microsoft Security, Compliance, and Identity Fundamentals - Fact Sheet¶
Exam Overview¶
The SC-900 certification validates foundational knowledge of security, compliance, and identity concepts across Microsoft cloud services. This exam is designed for business users, IT professionals, students, and those beginning their journey in Microsoft security solutions.
Exam Details: - π Official SC-900 Exam Page - Complete exam information, registration, and requirements - π SC-900 Study Guide - Official Microsoft study guide with exam objectives - π SC-900 Skills Measured - Detailed breakdown of exam domains and weightings - π Microsoft Learn SC-900 Learning Path - Free comprehensive training modules
Domain 1: Security, Compliance, and Identity Concepts (10-15%)¶
Shared Responsibility Model¶
Understanding how security responsibilities are distributed between cloud providers and customers is fundamental to cloud security.
- π Shared Responsibility Model Overview - Core concepts of shared security responsibilities in cloud computing
- π Shared Responsibility in the Cloud - How responsibilities shift across IaaS, PaaS, and SaaS models
- π Cloud Security Posture Management - Tools and practices for maintaining security responsibilities
Zero Trust Security Model¶
Zero Trust is a security framework that assumes breach and verifies each request as though it originates from an untrusted network.
- π Zero Trust Security Model - Comprehensive overview of Zero Trust principles and implementation
- π Zero Trust Deployment Guide - Step-by-step guidance for implementing Zero Trust architecture
- π Zero Trust Identity and Access - Identity-centric Zero Trust implementation strategies
- π Zero Trust Rapid Modernization Plan - Accelerated Zero Trust adoption framework
- π Guiding Principles of Zero Trust - Core tenets: verify explicitly, use least privilege access, assume breach
Defense in Depth¶
A layered security approach that provides multiple levels of protection to prevent and detect security breaches.
- π Defense in Depth Strategy - Multi-layered security approach from physical to application layers
- π Azure Defense in Depth - Implementing layered security in Azure environments
- π Security Layers Explained - Physical, identity, perimeter, network, compute, application, and data layers
Encryption and Hashing¶
Cryptographic methods for protecting data at rest, in transit, and in use.
- π Azure Encryption Overview - Comprehensive guide to encryption services in Azure
- π Data Encryption at Rest - Protecting stored data using Azure encryption services
- π Data Encryption in Transit - TLS/SSL and network-level encryption mechanisms
- π Azure Key Vault - Centralized secrets, keys, and certificate management service
Compliance Concepts¶
Understanding regulatory requirements, standards, and governance frameworks relevant to cloud services.
- π Microsoft Compliance Offerings - Comprehensive list of compliance certifications and attestations
- π Azure Compliance Documentation - Industry-specific and regional compliance resources
- π Data Residency in Azure - Understanding where data is stored and processed
Domain 2: Identity and Access Management (25-30%)¶
Microsoft Entra ID (Azure Active Directory)¶
Microsoft's cloud-based identity and access management service, the foundation of Microsoft 365 and Azure security.
- π Microsoft Entra ID Overview - Core identity service for authentication and authorization
- π Azure AD vs Active Directory - Key differences between cloud and on-premises identity services
- π Entra ID Licensing - Free, Premium P1, and Premium P2 feature comparisons
- π Entra ID Architecture - Understanding tenants, directories, and organizational structure
- π Hybrid Identity with Azure AD Connect - Synchronizing on-premises and cloud identities
Authentication Methods¶
Various methods for verifying user identities in Microsoft cloud services.
- π Authentication Methods in Entra ID - Passwords, passwordless, biometrics, and token-based authentication
- π Passwordless Authentication - Windows Hello, FIDO2 keys, and Microsoft Authenticator
- π Self-Service Password Reset - Enabling users to reset passwords without helpdesk intervention
- π Password Protection - Detecting and blocking weak passwords across the organization
Multi-Factor Authentication (MFA)¶
Requiring multiple forms of verification to significantly enhance security beyond passwords alone.
- π Multi-Factor Authentication Overview - How MFA provides additional security layers
- π Enabling Azure MFA - Step-by-step MFA deployment guide
- π MFA Registration Policies - Combined security information registration experience
- π Microsoft Authenticator App - Mobile app for push notifications and OTP codes
Conditional Access¶
Policy-based access control that evaluates signals to make intelligent access decisions.
- π Conditional Access Overview - If-then policy engine for automated access control decisions
- π Conditional Access Policies - Building blocks: assignments, cloud apps, conditions, and access controls
- π Common Conditional Access Policies - Best practice policy templates for typical scenarios
- π Conditional Access Signals - User location, device state, application, and risk-based signals
- π What-If Tool - Testing and validating Conditional Access policies before enforcement
Identity Protection¶
Automated detection and remediation of identity-based risks using machine learning.
- π Identity Protection Overview - Risk-based Conditional Access using AI and machine learning
- π Risk Detections - Anonymous IP, atypical travel, malware-linked IP, and leaked credentials
- π Risk Policies - User risk and sign-in risk remediation policies
- π Investigating Risk Events - Analyzing and responding to detected identity risks
Access Management¶
Controlling who can access what resources across Microsoft cloud services.
- π Azure Role-Based Access Control (RBAC) - Fine-grained access management for Azure resources
- π Built-in Azure Roles - Owner, Contributor, Reader, and specialized role definitions
- π Entra ID Roles - Administrative roles for managing identity and access
- π Privileged Identity Management (PIM) - Just-in-time privileged access with approval workflows
- π Access Reviews - Periodic certification of user access rights and group memberships
External Identities¶
Enabling secure collaboration with partners, suppliers, and customers outside your organization.
- π External Identities Overview - B2B and B2C identity scenarios
- π B2B Collaboration - Inviting external users to access your applications and resources
- π Azure AD B2C - Customer identity and access management for consumer-facing applications
Domain 3: Microsoft Security Solutions (35-40%)¶
Microsoft Defender for Cloud¶
Unified security management and advanced threat protection for hybrid and multi-cloud workloads.
- π Defender for Cloud Overview - Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP)
- π Security Posture Management - Continuous assessment and security recommendations
- π Secure Score - Quantifying security posture with actionable improvement metrics
- π Defender for Cloud Plans - Workload-specific protection for servers, storage, databases, and containers
- π Security Recommendations - Prioritized guidance for improving security posture
- π Defender for Servers - Advanced threat protection for virtual machines and servers
- π Defender for Storage - Protection against malicious file uploads and sensitive data exposure
Microsoft Defender for Endpoint¶
Enterprise endpoint security platform for preventing, detecting, investigating, and responding to advanced threats.
- π Defender for Endpoint Overview - Next-generation endpoint protection, detection, and response
- π Threat and Vulnerability Management - Continuous vulnerability discovery, prioritization, and remediation
- π Attack Surface Reduction - Rules and policies to reduce organizational exposure
- π Next-Generation Protection - Real-time antivirus and anti-malware protection
- π Endpoint Detection and Response - Advanced threat detection and automated investigation
- π Automated Investigation and Remediation - AI-driven threat analysis and response automation
Microsoft Defender for Office 365¶
Protection against threats in email, links, collaboration tools, and Office applications.
- π Defender for Office 365 Overview - Safeguarding against phishing, malware, and business email compromise
- π Safe Attachments - Sandboxing and detonating email attachments in virtual environments
- π Safe Links - Time-of-click URL scanning and rewriting
- π Anti-Phishing Protection - Machine learning models to detect impersonation and spoofing
- π Threat Explorer - Real-time reporting and analysis of email threats
Microsoft Defender for Identity¶
Identity-based threat detection using on-premises Active Directory signals.
- π Defender for Identity Overview - Detecting advanced threats, compromised identities, and malicious insider actions
- π Identity Security Posture - Assessments for Active Directory misconfigurations and vulnerabilities
- π Lateral Movement Detection - Identifying potential attack paths through the network
- π Identity Threat Investigation - Analyzing suspicious activities and entity behaviors
Microsoft Defender for Cloud Apps¶
Cloud Access Security Broker (CASB) providing visibility, data control, and threat protection for cloud applications.
- π Defender for Cloud Apps Overview - Comprehensive CASB for SaaS security and compliance
- π Cloud Discovery - Identifying shadow IT and unsanctioned cloud application usage
- π App Connectors - API-based connections for deep visibility and control
- π Conditional Access App Control - Real-time session monitoring and control for cloud applications
- π Information Protection Policies - DLP and classification for cloud-stored sensitive data
Microsoft Sentinel¶
Cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution.
- π Microsoft Sentinel Overview - Intelligent security analytics and threat intelligence across the enterprise
- π Sentinel Architecture - Workspace design and data collection strategies
- π Data Connectors - Ingesting security data from Microsoft and third-party sources
- π Analytics Rules - Built-in and custom detection rules for security threats
- π Incident Management - Investigating and triaging security incidents
- π Workbooks and Visualization - Creating dashboards for security monitoring and reporting
- π Threat Hunting - Proactive searching for security threats using KQL queries
- π Automation and Playbooks - Logic Apps-based automated response workflows
- π User and Entity Behavior Analytics (UEBA) - Machine learning to detect anomalous user and entity behavior
Microsoft 365 Defender¶
Unified pre- and post-breach enterprise defense suite coordinating protection across endpoints, identities, email, and applications.
- π Microsoft 365 Defender Overview - Extended detection and response (XDR) platform
- π Incidents and Alerts - Unified incident queue across all Defender products
- π Advanced Hunting - Query-based threat hunting across 30 days of raw data
- π Threat Analytics - Intelligence reports on emerging threats and attack campaigns
- π Secure Score - Measurement and improvement of security posture across Microsoft 365
Azure DDoS Protection¶
Safeguarding Azure resources against distributed denial-of-service attacks.
- π DDoS Protection Overview - Always-on traffic monitoring and automatic attack mitigation
- π DDoS Protection Tiers - Network Protection and IP Protection service levels
Azure Firewall¶
Cloud-native, intelligent network firewall security service providing best-in-class threat protection.
- π Azure Firewall Overview - Managed, stateful firewall with built-in high availability
- π Azure Firewall Manager - Centralized security policy and route management
Domain 4: Microsoft Compliance Solutions (25-30%)¶
Microsoft Purview¶
Comprehensive data governance and compliance management platform.
- π Microsoft Purview Overview - Unified data governance and risk management solutions
- π Purview Compliance Portal - Centralized hub for managing compliance across Microsoft 365
Data Classification and Labeling¶
Discovering, classifying, and protecting sensitive information throughout its lifecycle.
- π Know Your Data - Understanding data classification and sensitive information types
- π Sensitive Information Types - Pre-built patterns for identifying sensitive data like credit cards, SSNs, and passport numbers
- π Trainable Classifiers - Machine learning models for identifying content types
- π Sensitivity Labels - Classifying and protecting documents and emails with persistent labels
- π Auto-Labeling Policies - Automatically applying labels based on content inspection
- π Label Analytics - Monitoring and reporting on label usage and data access
Data Loss Prevention (DLP)¶
Preventing accidental or intentional sharing of sensitive information outside the organization.
- π Data Loss Prevention Overview - Protecting sensitive data across devices, services, and on-premises locations
- π DLP Policies - Creating rules to detect and protect sensitive information
- π Endpoint DLP - Monitoring and protecting sensitive data on Windows and macOS devices
- π DLP Alerts and Reports - Investigating and responding to data loss prevention incidents
Retention and Records Management¶
Ensuring data is retained according to business and regulatory requirements while disposing of unnecessary data.
- π Retention Policies - Proactively retaining or deleting content based on organizational policies
- π Retention Labels - Item-level retention settings with manual or automatic application
- π Records Management - Declaring items as regulatory or business records with deletion restrictions
- π Disposition Review - Reviewing content before permanent deletion at retention period end
eDiscovery and Audit¶
Identifying, preserving, and collecting electronic information for legal and investigative purposes.
- π eDiscovery Solutions - Content search, eDiscovery Standard, and eDiscovery Premium capabilities
- π Content Search - Searching mailboxes, SharePoint sites, and Teams locations
- π eDiscovery Cases - Managing legal holds, searches, and exports for investigations
- π Audit Logging - Recording user and administrator activities across Microsoft 365
- π Advanced Audit - Extended retention, forensically relevant events, and higher bandwidth access
Insider Risk Management¶
Detecting and acting on risky activities by employees and partners.
- π Insider Risk Management - Identifying potential malicious or inadvertent insider threats
- π Insider Risk Policies - Templates for data theft, leaks, and security violations
- π Insider Risk Alerts - Investigating and escalating risky user activities
Communication Compliance¶
Monitoring organizational communications for policy violations and regulatory compliance.
- π Communication Compliance - Detecting inappropriate messages, harassment, and sensitive information sharing
- π Communication Policies - Creating rules to monitor email, Teams, and third-party communications
Compliance Manager¶
Simplified compliance management with actionable insights and improvement actions.
- π Compliance Manager Overview - Centralized tool for managing compliance across regulations and standards
- π Compliance Score - Risk-based score measuring progress in completing recommended actions
- π Compliance Assessments - Pre-built and custom templates for regulatory frameworks
- π Improvement Actions - Technical and non-technical recommendations for compliance improvement
- π Compliance Manager Templates - GDPR, ISO 27001, NIST, HIPAA, and other regulatory templates
Information Barriers¶
Preventing conflicts of interest by restricting communication and collaboration between specific groups.
- π Information Barriers - Policies to segment users and control collaboration in regulated industries
Privacy Management¶
Managing personal data and meeting privacy regulations like GDPR.
- π Privacy Management - Subject rights requests, data minimization, and consent management
- π Subject Rights Requests - Automating responses to data subject access requests
Additional Microsoft Security Technologies¶
Microsoft Intune¶
Cloud-based endpoint management for mobile devices, desktops, and applications.
- π Microsoft Intune Overview - Mobile Device Management (MDM) and Mobile Application Management (MAM)
- π Device Enrollment - Bringing devices under Intune management
- π Compliance Policies - Defining security requirements for managed devices
- π Configuration Profiles - Deploying settings and features to devices
- π App Protection Policies - Protecting corporate data in mobile applications without device enrollment
- π Conditional Access Integration - Device compliance as a Conditional Access signal
Microsoft Defender Vulnerability Management¶
Continuous visibility and risk-based prioritization of endpoint vulnerabilities.
- π Defender Vulnerability Management - Asset discovery, vulnerability assessment, and remediation tracking
- π Exposure Score - Quantifying organizational exposure to cybersecurity threats
Azure Information Protection (AIP)¶
Classifying and protecting documents and emails by applying labels (now integrated into Microsoft Purview Information Protection).
- π Azure Information Protection - Label-based classification and protection for documents and emails
- π AIP Unified Labeling Client - Client software for applying sensitivity labels in Office apps
Exam Preparation Resources¶
Official Learning Paths and Documentation¶
- π SC-900 Certification Page - Official certification landing page with all resources
- π Microsoft Learn Training - Free hands-on learning modules
- π Microsoft Security Documentation - Comprehensive technical documentation
- π Microsoft 365 Security Center - Production portal for managing security across Microsoft 365
Practice and Assessment¶
- π SC-900 Practice Assessment - Official Microsoft practice questions
- π Microsoft Learn Sandbox - Free Azure subscription for hands-on practice within learning modules
- π Microsoft Security YouTube Channel - Video content on security features and best practices
Community Resources¶
- π Microsoft Security Community - Forums, blogs, and discussions with Microsoft engineers and community experts
- π Microsoft Security Blog - Latest security news, threat intelligence, and product announcements
Key Concepts Summary¶
Zero Trust Principles¶
- Verify explicitly - Always authenticate and authorize based on all available data points
- Use least privilege access - Limit user access with Just-In-Time and Just-Enough-Access
- Assume breach - Minimize blast radius and segment access, verify end-to-end encryption
Defense in Depth Layers¶
- Physical security - Datacenter access controls
- Identity & access - Authentication, SSO, MFA
- Perimeter - DDoS protection, firewalls
- Network - Segmentation, access controls, deny by default
- Compute - Secure VM access, endpoint protection, patching
- Application - Secure development, no credentials in code
- Data - Encryption at rest and in transit, classification
Identity Types in Entra ID¶
- User identities - Employees and internal users
- Workload identities - Applications and services (service principals, managed identities)
- Device identities - Registered, joined, and hybrid-joined devices
- External identities - Guest users and B2B collaboration partners
Microsoft Defender Suite¶
- Defender for Endpoint - Device/endpoint protection
- Defender for Office 365 - Email and collaboration security
- Defender for Identity - On-premises AD threat detection
- Defender for Cloud Apps - CASB for SaaS applications
- Defender for Cloud - CSPM and CWPP for Azure and multi-cloud
- Microsoft 365 Defender - XDR coordinating all Defender products
- Microsoft Sentinel - SIEM and SOAR platform
Compliance Solution Categories¶
- Information Protection - Classification, labeling, encryption
- Data Lifecycle Management - Retention, deletion, records management
- Insider Risk Management - Detecting malicious or negligent insider actions
- eDiscovery and Audit - Legal holds, content search, activity logging
- Compliance Management - Assessments, scores, improvement actions
Exam Tips¶
- Understand concepts over memorization - Focus on when and why to use each service rather than memorizing every feature
- Know the differences - Be clear on distinctions between similar services (e.g., Defender for Cloud vs. Defender for Endpoint)
- Licensing awareness - Understand which features require Premium licenses (especially for Entra ID P1/P2)
- Scenario-based thinking - Practice identifying appropriate solutions for given business requirements
- Hands-on experience - Use Microsoft Learn sandboxes and free trials to explore the services
- Service relationships - Understand how services integrate (e.g., Intune + Conditional Access, Sentinel + Defender)
- Compliance frameworks - Familiarize yourself with common regulations (GDPR, HIPAA, ISO 27001)
- Zero Trust mindset - Many questions relate to implementing Zero Trust principles
Glossary of Key Terms¶
- CASB - Cloud Access Security Broker
- CWPP - Cloud Workload Protection Platform
- CSPM - Cloud Security Posture Management
- DLP - Data Loss Prevention
- EDR - Endpoint Detection and Response
- IAM - Identity and Access Management
- IaaS - Infrastructure as a Service
- MDM - Mobile Device Management
- MFA - Multi-Factor Authentication
- PaaS - Platform as a Service
- PIM - Privileged Identity Management
- RBAC - Role-Based Access Control
- SaaS - Software as a Service
- SIEM - Security Information and Event Management
- SOAR - Security Orchestration, Automation, and Response
- SSO - Single Sign-On
- UEBA - User and Entity Behavior Analytics
- XDR - Extended Detection and Response
Last Updated: 2025-10-13 Exam Version: This fact sheet covers the current SC-900 exam objectives Total Documentation Links: 80+
Next Steps¶
- Complete the official Microsoft Learn learning paths for SC-900
- Take the practice assessment to identify knowledge gaps
- Explore each service in the Azure and Microsoft 365 portals
- Review security and compliance documentation for your areas of weakness
- Schedule and pass the SC-900 exam
- Consider advanced certifications: SC-200, SC-300, AZ-500, or SC-400
Good luck with your SC-900 certification journey!