Certification guide
SC-900Microsoft Security, Compliance, and Identity Fundamentals: the honest guide
SC-900 teaches you what Microsoft calls things. Security, Compliance and Identity Fundamentals covers Zero Trust and the shared responsibility model, what Entra ID does, which Defender product guards which asset, and what Microsoft Purview is for. It asks what a capability is, never how to configure it, and that shapes everything about how you should study.
The exam is 40 to 60 questions in 45 minutes, scored 700 out of 1000 to pass, with multiple choice, drag-and-drop and hot area items. There are no prerequisites and no assumption of hands-on experience, which is unusual and is the reason people outside engineering roles pass it.
The four skill areas are weighted unevenly and it matters: security, compliance and identity concepts is about 12 percent, Entra capabilities about 28 percent, Microsoft security solutions about 38 percent, and Microsoft compliance solutions about 22 percent. Two thirds of the exam is product knowledge.
Who Security, Compliance, and Identity Fundamentals is for
A good fit if
- You work in a Microsoft 365 shop in a non-engineering role: compliance, legal, procurement, HR systems, project management.
- You are on a help desk or in general IT support and want to move toward security or identity work.
- You sell, buy or audit Microsoft security licensing and keep losing track of what each product actually does.
- You are heading for SC-300, SC-200 or AZ-500 and want the product map before you start on the deep material.
- You need a credential that never expires, costs $99, and can be finished in a fortnight of evenings.
Probably not, if
- You already administer Entra ID, Defender or Purview. You will pass on existing knowledge and learn nothing. Go to SC-300 or SC-200.
- You need to prove hands-on ability. SC-900 asks what a service is for and hiring managers read it exactly that way.
- You want vendor-neutral security foundations for a mixed environment. Security+ covers the concepts without tying them to one stack.
- You are already certified at role level in Microsoft security. There is no path where SC-900 adds anything on top of SC-200 or AZ-500.
Is Security, Compliance, and Identity Fundamentals worth it?
For someone in a non-engineering role inside a Microsoft tenant, yes, and for a specific reason. The gap that costs organisations money is not technical, it is that the compliance officer, the procurement lead and the security engineer use the same words for different things. SC-900 gives all three the same map for $99 and about twenty hours.
For someone in IT support aiming at a security or identity role, it is worth it as a first step and nothing more. It gets you the vocabulary and it signals direction on a CV. It does not signal capability, and treating it as though it does is how people end up disappointed after passing.
For a working Microsoft administrator, no. The content is a subset of what you already do, and the hour is better spent on SC-300 or SC-200 where the questions actually test decisions.
As a hiring signal on its own, SC-900 is weak, and it should be judged on what it costs rather than what it opens. At $99 with no expiry, it clears its own bar easily. It just is not the thing that gets an interview.
What the exam actually asks you to do
Multiple choice and multiple response, plus drag-and-drop ordering and hot area items where you click a region of a screenshot.
Item formats
- Multiple choice
- Multiple response
- Drag and drop
- Hot area
The highlighted formats are the ones you cannot answer from memory alone. Microsoft Learn, exam duration and question types ↗
Domain breakdown and official weightings
From the official Microsoft Learn study guides. Describe capabilities of Microsoft security solutions is the heaviest domain at 38 percent, followed by Describe capabilities of Microsoft Entra at 28 percent.
- Describe concepts of security, compliance, and identity12%
- Describe capabilities of Microsoft Entra28%
- Describe capabilities of Microsoft security solutions38%
- Describe capabilities of Microsoft compliance solutions22%
Study plans by experience level
Non-technical, working near a Microsoft 365 tenant
4 to 5 weeksat 4 hours
- 1Week 1: the security, compliance and identity concepts module on Microsoft Learn. Zero Trust, defence in depth, the shared responsibility model, and the difference between authentication and authorization. Everything later assumes this and it is only 12 percent of the exam, so learn it for comprehension rather than marks.
- 2Week 2: Microsoft Entra. Identity types (user, service principal, managed identity, device), authentication methods, Conditional Access as a concept, and what identity governance means. This is 28 percent of the exam.
- 3Week 3: the Microsoft security solutions area, which is the largest at roughly 38 percent. Build one page mapping each Defender product to the asset it protects, and add Microsoft Sentinel as the thing that collects from all of them.
- 4Week 4: Microsoft Purview. Sensitivity labels, data lifecycle management, insider risk, eDiscovery and audit. Ask a colleague to show you your own tenant's compliance portal if you have access, because the names make far more sense on screen.
- 5Week 5: practice questions, reading each wrong answer until you can say which product it belongs to instead. Book when you are consistently above 85 percent.
IT support or M365 administration, some hands-on already
1 to 2 weeksat 6 to 8 hours
- 1Read the current skills outline first and mark only the lines you could not explain to a colleague. For most people in this group that is Purview and Sentinel, not Entra.
- 2Skim the Entra modules quickly. If you reset passwords and manage groups for a living, this area is already yours.
- 3Spend the bulk of your time on the Defender family and Microsoft Sentinel. Knowing that a SIEM correlates signals is not enough here: the exam wants you to pick between Defender for Cloud and Defender for Cloud Apps in a specific scenario.
- 4Give one full session to Purview and one to the Service Trust Portal and privacy principles, which people in technical roles routinely skip and then lose marks on.
- 5Take one timed practice set, fix what it exposes, and book.
Security background, new to the Microsoft stack
2 to 3 weeksat 5 hours
- 1Skip the concepts area almost entirely. Zero Trust and defence in depth are the same ideas you already work with, and Microsoft's phrasing of them is not exotic.
- 2Start with Entra ID as a rename exercise, mapping what you know from other identity providers onto Microsoft's terms. Conditional Access, Identity Protection, Privileged Identity Management and entitlement management are the four names to fix.
- 3Week 2: the Defender products and Sentinel. Your instinct will be to read them as one platform. The exam treats them as separate products with separate scopes, so learn the boundaries rather than the marketing.
- 4Week 3: Purview and the compliance area, which is where an experienced engineer is most likely to be genuinely unfamiliar. Data classification, retention and eDiscovery are 22 percent of the exam between them and the rest of the compliance content.
- 5Practice questions until product names come back without hesitation, then book.
Common mistakes
- Studying it as a technical exam
- Building things in a portal is enjoyable and is not what SC-900 tests. The questions ask which product solves a described problem. Recognition beats configuration here, which is the opposite of how you should study SC-300.
- Treating the Defender products as one thing
- Defender for Endpoint, Defender for Office 365, Defender for Cloud, Defender for Cloud Apps and Defender XDR are five distinct answers, and a question will often offer you several of them. Learn each one by the asset it protects.
- Skipping the compliance area because it sounds dull
- Microsoft compliance solutions is roughly 22 percent of the exam. Purview, retention, eDiscovery and insider risk are worth about a fifth of your score, and technical candidates lose more marks here than anywhere else.
- Studying from outdated material
- Content written before the renames still calls Entra ID by its old name and Defender XDR by its old name. The exam uses current terms. Check the publication date on anything you read that is not on Microsoft Learn.
- Buying a course for a $99 exam
- The Microsoft Learn path is free, current and written by the people who publish the skills outline. Paid SC-900 courses mostly restate it, and the money is better held as your retake reserve.
- Expecting it to produce a security job
- SC-900 is a fundamentals credential and it reads as one. It gets a conversation started and it gets a screening filter satisfied. The role-based exams are what change how a CV is read.
What comes after passing
Nothing expires and nothing renews, so there is no maintenance to plan. That is specific to the fundamentals level and it does not carry over to whatever you take next.
The natural next step depends on which part held your attention. If it was Entra ID, Conditional Access and governance, that is SC-300. If it was Defender and Sentinel, that is SC-200. If it was Azure infrastructure security, that is AZ-500. All three are role-based, all three assume hands-on experience, and all three renew free each year through an online assessment on Microsoft Learn.
If you sat it for vocabulary rather than a career move, you are finished, and that is a legitimate place to stop. The most useful thing you can do next is get read access to your own tenant's Entra and Purview portals so the names attach to your own organisation's data.
Where people go next
Costs across the full renewal cycle are on the Security, Compliance, and Identity Fundamentals cost page.
Frequently asked questions
Is SC-900 worth it?
For non-engineers working inside a Microsoft tenant, yes: $99 for a shared vocabulary with the security team, and it never expires. For people already administering Entra or Defender, no, because the content is a subset of what they already do.
How hard is SC-900?
It is a recall exam with no prerequisites, 40 to 60 questions in 45 minutes and a passing score of 700 out of 1000. The difficulty is not conceptual, it is the number of Microsoft product names that sound alike.
How long does SC-900 take to study for?
One to two weeks at 6 to 8 hours for someone doing M365 support, two to three weeks for an experienced engineer new to the Microsoft stack, four to five weeks at a lighter pace for a non-technical reader.
Do I need IT experience to take SC-900?
No. There are no prerequisites and the exam does not test configuration. Compliance, procurement and project staff pass it regularly using the free Microsoft Learn path and a trial tenant.
Does SC-900 expire?
No. Microsoft fundamentals certifications do not expire, so there is no renewal fee and no continuing education requirement. Role-based certifications such as SC-300 expire after one year and renew free online.
Should I take SC-900 or AZ-900 first?
Take the one that matches your work. AZ-900 covers Azure infrastructure and billing, SC-900 covers security, compliance and identity across Microsoft 365 and Azure. Neither is a prerequisite for the other and they overlap only lightly on Entra basics.
Is SC-900 enough to get a security job?
On its own, no. It signals direction and vocabulary rather than capability. It works as a first step alongside help desk or administration experience, and as a primer before SC-300, SC-200 or AZ-500.
Do I need SC-900 before SC-300?
No, it is not a formal prerequisite. It is a useful primer if the Microsoft security product family is new to you, and skippable if you already administer Entra ID day to day.
Keep reading
- Security, Compliance, and Identity Fundamentals practice questions
Free sample questions with the full explanation on every answer.
- Free Security, Compliance, and Identity Fundamentals practice test
Ten real questions, playable now. No account, no card.
- Security, Compliance, and Identity Fundamentals exam objectives
The full official blueprint, with practice pages on covered objectives.
- Security, Compliance, and Identity Fundamentals passing score
The exact cut score, what kind of number it is, and the retake terms.
- How hard is Security, Compliance, and Identity Fundamentals?
An honest difficulty read from the format, the clock and the weights.
- What Security, Compliance, and Identity Fundamentals costs
The voucher price, the retake, and what renewal costs across the cycle.
Cheat sheets
Printable reference tables, free.
Compared with
Side by side on cost, difficulty, and which one to take first.
Practise Security, Compliance, and Identity Fundamentals for free while you decide
Original questions written from the published objectives, with the concept, the reasoning, and a note on every wrong option. No account needed to start.
Start free Security, Compliance, and Identity Fundamentals questions