Skip to content

Azure SC-900: Microsoft Security, Compliance, and Identity Fundamentals - Fact Sheet

Exam Overview

The SC-900 certification validates foundational knowledge of security, compliance, and identity concepts across Microsoft cloud services. This exam is designed for business users, IT professionals, students, and those beginning their journey in Microsoft security solutions.

Exam Details: - πŸ“– Official SC-900 Exam Page - Complete exam information, registration, and requirements - πŸ“– SC-900 Study Guide - Official Microsoft study guide with exam objectives - πŸ“– SC-900 Skills Measured - Detailed breakdown of exam domains and weightings - πŸ“– Microsoft Learn SC-900 Learning Path - Free comprehensive training modules


Domain 1: Security, Compliance, and Identity Concepts (10-15%)

Shared Responsibility Model

Understanding how security responsibilities are distributed between cloud providers and customers is fundamental to cloud security.

Zero Trust Security Model

Zero Trust is a security framework that assumes breach and verifies each request as though it originates from an untrusted network.

Defense in Depth

A layered security approach that provides multiple levels of protection to prevent and detect security breaches.

Encryption and Hashing

Cryptographic methods for protecting data at rest, in transit, and in use.

Compliance Concepts

Understanding regulatory requirements, standards, and governance frameworks relevant to cloud services.


Domain 2: Identity and Access Management (25-30%)

Microsoft Entra ID (Azure Active Directory)

Microsoft's cloud-based identity and access management service, the foundation of Microsoft 365 and Azure security.

Authentication Methods

Various methods for verifying user identities in Microsoft cloud services.

Multi-Factor Authentication (MFA)

Requiring multiple forms of verification to significantly enhance security beyond passwords alone.

Conditional Access

Policy-based access control that evaluates signals to make intelligent access decisions.

Identity Protection

Automated detection and remediation of identity-based risks using machine learning.

Access Management

Controlling who can access what resources across Microsoft cloud services.

External Identities

Enabling secure collaboration with partners, suppliers, and customers outside your organization.


Domain 3: Microsoft Security Solutions (35-40%)

Microsoft Defender for Cloud

Unified security management and advanced threat protection for hybrid and multi-cloud workloads.

Microsoft Defender for Endpoint

Enterprise endpoint security platform for preventing, detecting, investigating, and responding to advanced threats.

Microsoft Defender for Office 365

Protection against threats in email, links, collaboration tools, and Office applications.

Microsoft Defender for Identity

Identity-based threat detection using on-premises Active Directory signals.

Microsoft Defender for Cloud Apps

Cloud Access Security Broker (CASB) providing visibility, data control, and threat protection for cloud applications.

Microsoft Sentinel

Cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution.

Microsoft 365 Defender

Unified pre- and post-breach enterprise defense suite coordinating protection across endpoints, identities, email, and applications.

Azure DDoS Protection

Safeguarding Azure resources against distributed denial-of-service attacks.

Azure Firewall

Cloud-native, intelligent network firewall security service providing best-in-class threat protection.


Domain 4: Microsoft Compliance Solutions (25-30%)

Microsoft Purview

Comprehensive data governance and compliance management platform.

Data Classification and Labeling

Discovering, classifying, and protecting sensitive information throughout its lifecycle.

Data Loss Prevention (DLP)

Preventing accidental or intentional sharing of sensitive information outside the organization.

Retention and Records Management

Ensuring data is retained according to business and regulatory requirements while disposing of unnecessary data.

eDiscovery and Audit

Identifying, preserving, and collecting electronic information for legal and investigative purposes.

Insider Risk Management

Detecting and acting on risky activities by employees and partners.

Communication Compliance

Monitoring organizational communications for policy violations and regulatory compliance.

Compliance Manager

Simplified compliance management with actionable insights and improvement actions.

Information Barriers

Preventing conflicts of interest by restricting communication and collaboration between specific groups.

Privacy Management

Managing personal data and meeting privacy regulations like GDPR.


Additional Microsoft Security Technologies

Microsoft Intune

Cloud-based endpoint management for mobile devices, desktops, and applications.

Microsoft Defender Vulnerability Management

Continuous visibility and risk-based prioritization of endpoint vulnerabilities.

Azure Information Protection (AIP)

Classifying and protecting documents and emails by applying labels (now integrated into Microsoft Purview Information Protection).


Exam Preparation Resources

Official Learning Paths and Documentation

Practice and Assessment

Community Resources


Key Concepts Summary

Zero Trust Principles

  1. Verify explicitly - Always authenticate and authorize based on all available data points
  2. Use least privilege access - Limit user access with Just-In-Time and Just-Enough-Access
  3. Assume breach - Minimize blast radius and segment access, verify end-to-end encryption

Defense in Depth Layers

  1. Physical security - Datacenter access controls
  2. Identity & access - Authentication, SSO, MFA
  3. Perimeter - DDoS protection, firewalls
  4. Network - Segmentation, access controls, deny by default
  5. Compute - Secure VM access, endpoint protection, patching
  6. Application - Secure development, no credentials in code
  7. Data - Encryption at rest and in transit, classification

Identity Types in Entra ID

  • User identities - Employees and internal users
  • Workload identities - Applications and services (service principals, managed identities)
  • Device identities - Registered, joined, and hybrid-joined devices
  • External identities - Guest users and B2B collaboration partners

Microsoft Defender Suite

  • Defender for Endpoint - Device/endpoint protection
  • Defender for Office 365 - Email and collaboration security
  • Defender for Identity - On-premises AD threat detection
  • Defender for Cloud Apps - CASB for SaaS applications
  • Defender for Cloud - CSPM and CWPP for Azure and multi-cloud
  • Microsoft 365 Defender - XDR coordinating all Defender products
  • Microsoft Sentinel - SIEM and SOAR platform

Compliance Solution Categories

  • Information Protection - Classification, labeling, encryption
  • Data Lifecycle Management - Retention, deletion, records management
  • Insider Risk Management - Detecting malicious or negligent insider actions
  • eDiscovery and Audit - Legal holds, content search, activity logging
  • Compliance Management - Assessments, scores, improvement actions

Exam Tips

  1. Understand concepts over memorization - Focus on when and why to use each service rather than memorizing every feature
  2. Know the differences - Be clear on distinctions between similar services (e.g., Defender for Cloud vs. Defender for Endpoint)
  3. Licensing awareness - Understand which features require Premium licenses (especially for Entra ID P1/P2)
  4. Scenario-based thinking - Practice identifying appropriate solutions for given business requirements
  5. Hands-on experience - Use Microsoft Learn sandboxes and free trials to explore the services
  6. Service relationships - Understand how services integrate (e.g., Intune + Conditional Access, Sentinel + Defender)
  7. Compliance frameworks - Familiarize yourself with common regulations (GDPR, HIPAA, ISO 27001)
  8. Zero Trust mindset - Many questions relate to implementing Zero Trust principles

Glossary of Key Terms

  • CASB - Cloud Access Security Broker
  • CWPP - Cloud Workload Protection Platform
  • CSPM - Cloud Security Posture Management
  • DLP - Data Loss Prevention
  • EDR - Endpoint Detection and Response
  • IAM - Identity and Access Management
  • IaaS - Infrastructure as a Service
  • MDM - Mobile Device Management
  • MFA - Multi-Factor Authentication
  • PaaS - Platform as a Service
  • PIM - Privileged Identity Management
  • RBAC - Role-Based Access Control
  • SaaS - Software as a Service
  • SIEM - Security Information and Event Management
  • SOAR - Security Orchestration, Automation, and Response
  • SSO - Single Sign-On
  • UEBA - User and Entity Behavior Analytics
  • XDR - Extended Detection and Response

Last Updated: 2025-10-13 Exam Version: This fact sheet covers the current SC-900 exam objectives Total Documentation Links: 80+


Next Steps

  1. Complete the official Microsoft Learn learning paths for SC-900
  2. Take the practice assessment to identify knowledge gaps
  3. Explore each service in the Azure and Microsoft 365 portals
  4. Review security and compliance documentation for your areas of weakness
  5. Schedule and pass the SC-900 exam
  6. Consider advanced certifications: SC-200, SC-300, AZ-500, or SC-400

Good luck with your SC-900 certification journey!