Microsoft SC-900: Skills and Scope
SC-900 is Microsoft’s fundamentals exam for security, compliance, and identity across Azure and Microsoft 365. It is designed for learners who need to understand what the major controls do, how Microsoft’s services fit together, and which type of capability addresses a given business or security requirement.
As of October 3, 2026, the SC-900 exam uses objectives effective July 28, 2026. Candidates should be familiar with security, compliance, and identity concepts, Microsoft Entra capabilities, Microsoft security solutions, and Microsoft Purview. The exam remains conceptual, but the scenarios still reward people who understand how the pieces interact.
The most efficient way to study is to organize the platform around questions: Who is the user or workload? What are they trying to access? What risk exists? Which signal detects it? Which policy can reduce it? Which compliance requirement governs the data?
Microsoft Entra ID provides identities, authentication, access controls, application identities, and the foundation for many conditional decisions across Microsoft cloud services. Candidates should understand users, groups, external identities, workloads, and why identity has become a primary security boundary.
The concepts in Microsoft Entra ID help connect authentication with authorization. Signing in proves or establishes identity; permissions and policy determine what that identity can do afterward. Mixing those ideas is a common source of confusion.
Create a simple mental model with one employee, one guest, one managed device, and one application identity. Ask how each is authenticated and which controls can influence access.
Zero Trust assumes that network location alone is not sufficient evidence of trust. Access decisions should consider identity, device condition, risk, application sensitivity, and other context while minimizing unnecessary privilege.
The shift toward zero-trust access explains why endpoint state and identity work together. A valid password from an unmanaged or risky device may need a different response than the same identity on a compliant corporate device.
For SC-900, you do not need to design every policy. You should be able to recognize why multifactor authentication, Conditional Access, least privilege, device compliance, and continuous risk evaluation support the same security model.
Passwords are familiar but vulnerable to reuse, phishing, guessing, and theft. Multifactor authentication raises the bar by requiring additional evidence. Passwordless methods can reduce reliance on shared secrets and improve both security and user experience when implemented correctly.
Be careful not to treat every second factor as equally strong. The security benefit depends on how the method resists phishing and replay, how recovery is handled, and whether users can be socially engineered into approving a request.
Study authentication methods by asking what attack each one is intended to reduce and what new operational dependency it creates. That approach is more durable than memorizing a list of sign-in options.
Organizations need a way to decide who receives access, who approves it, how long it lasts, and when it should be reviewed or removed. This is where identity governance extends ordinary group and role administration.
The deeper material in Microsoft identity governance is useful because it shows the lifecycle behind concepts such as entitlement management, access reviews, and privileged identity. SC-900 only requires foundational understanding, but the business purpose is the same.
Imagine a contractor who needs temporary access to a project. Compare permanent group membership with an approved, time-limited entitlement that is reviewed automatically. The difference explains why governance matters.
Microsoft Defender is not one product. The security stack includes capabilities for endpoints, identities, cloud resources, email and collaboration, and other attack surfaces. Candidates should understand what each category protects and how consolidated security operations can correlate signals.
The distinction between Microsoft Defender for Cloud and Microsoft Sentinel is particularly useful. Defender products generate and act on security findings in their domains, while Sentinel is a SIEM and security-operations platform for collecting, analyzing, and responding to signals across sources.
When studying a scenario, first identify the asset or signal. Endpoint malware, suspicious identity activity, cloud configuration risk, and cross-system incident investigation naturally point to different capabilities.
Microsoft Sentinel collects and analyzes security data, detects suspicious patterns, supports investigation, and can automate response. For SC-900, focus on why a SIEM exists: organizations need centralized visibility across many systems rather than treating each alert as an isolated event.
The operating concepts in Microsoft Sentinel show how logs become detections, incidents, hunting data, and automation opportunities. More data is not automatically better; useful security operations depend on collecting relevant telemetry with enough context to investigate.
Think through a compromised account scenario. Identity logs, endpoint signals, cloud activity, and application events may each tell part of the story. Sentinel’s value is in helping analysts connect that evidence.
Microsoft Purview addresses data governance and compliance concerns such as classification, information protection, data loss prevention, retention, audit, eDiscovery, and insider risk. These capabilities answer different questions about how sensitive information should be discovered, protected, retained, and investigated.
A useful study method is to separate prevention from investigation. Data loss prevention can stop or warn about inappropriate sharing. Retention controls how long content must be kept or deleted. Audit provides evidence of activity. eDiscovery supports legal or investigative collection.
Take one sensitive-data example, such as customer financial information, and ask how it is classified, protected, prevented from leaving approved channels, retained, audited, and produced during an investigation.
Cloud security responsibilities are divided between the provider and the customer, but the split changes depending on whether the organization consumes infrastructure, a managed platform, or SaaS. Microsoft secures the underlying cloud, while customers remain responsible for identities, data, configuration, devices, and many access decisions.
This concept matters because “the cloud provider handles security” is never a complete answer. A compromised account with excessive permissions remains the customer’s problem even if the physical datacenter is perfectly protected.
For each Microsoft service you study, identify at least one security responsibility that stays with the customer. This builds the habit of reading cloud-security questions through ownership rather than brand names.
Conditional Access is worth treating as a policy engine rather than another authentication feature. A policy evaluates signals such as user, application, device state, location, and risk, then applies a control such as MFA or blocking access. This helps explain why Conditional Access belongs at the intersection of identity and Zero Trust rather than inside a simple password discussion.
Microsoft Purview concepts become clearer when you follow one file through its lifecycle. A document can be classified, labeled, restricted, monitored for inappropriate sharing, retained according to policy, searched during an investigation, and audited for activity. The same data object can therefore touch several compliance capabilities for different reasons.
Understand the difference between security posture and active threat response. Defender for Cloud can identify configuration weaknesses and security recommendations while also producing workload protections, whereas Sentinel concentrates security data into detections and incidents. Fundamentals questions often become straightforward once you identify whether the scenario is asking about posture, protection, investigation, or governance.
Do one final review using plain-language requirements instead of product names: “Require stronger authentication for risky sign-ins,” “discover sensitive data,” “investigate activity across multiple sources,” “retain records for a policy period,” and “review privileged access.” Then map each requirement back to the Microsoft capability that fits it.
Service Trust Portal belongs in the compliance picture because customers often need evidence about Microsoft cloud controls, audit reports, and regulatory commitments. You do not need to memorize every document, but you should understand why a customer might consult Microsoft-provided compliance evidence rather than trying to validate the provider’s datacenter controls independently.
Privacy and compliance are related but not identical. A control may satisfy a retention or auditing requirement while still creating privacy concerns if data is collected or retained unnecessarily. Fundamentals-level questions become easier when you ask both what the organization is required to do and what data handling is actually justified.
Finally, separate preventive, detective, and corrective controls when you review scenarios. MFA can reduce the chance of account takeover, monitoring can reveal suspicious activity, and remediation can contain or reverse harm after detection. Microsoft products often combine these functions, but the security objective behind each one is different.
The exam contains many product names, but the underlying problems are familiar: prove identity, limit access, detect threats, investigate events, protect data, meet compliance obligations, and demonstrate what happened. Product knowledge is easier to retain when attached to one of those jobs.
A dedicated SC-900 foundation can help organize the vocabulary, but your final review should be scenario-driven. For each scenario, identify the problem before looking at the Microsoft product choices.
If you can explain how Entra establishes and governs access, how Defender and Sentinel handle threats and signals, and how Purview protects and governs information, you have the conceptual map SC-900 is designed to validate.