arrow_backWróć do field notes
CLOUD Opublikowano 18 lip 2026

SC-900 Study Guide: What Actually Matters for the Exam

A practical breakdown of the SC-900 exam domains, what to actually study, and how to avoid wasting time on the wrong material.

SC-900 (Microsoft Security, Compliance, and Identity Fundamentals) gets treated as a throwaway exam by a lot of people chasing certifications, and that's a mistake. It's low-cost and entry-level, but the content maps directly to how Microsoft structures Entra ID, Defender, Purview, and Intune — which means the concepts show up again in AZ-500, SC-200, and SC-401. Treat it as foundation, not filler.

What the exam actually covers

Microsoft splits SC-900 into four rough domains: security and compliance concepts (5-10%), identity concepts and Microsoft Entra (25-30%), Microsoft security solutions (35-40%), and Microsoft compliance solutions (20-25%). The weighting tells you where to spend your hours. Identity and security solutions together make up roughly two-thirds of the exam, so if you're short on time, that's where you drill.

The identity section is really about Microsoft Entra ID (formerly Azure AD). You need to know the difference between authentication and authorization, what Conditional Access policies actually do, how Multi-Factor Authentication (MFA) fits into a Zero Trust model, and what Privileged Identity Management (PIM) is for versus Privileged Access Management (PAM). Don't just memorize definitions — understand the flow: a user signs in, Conditional Access evaluates signals like device compliance and location, and only then does access get granted or blocked.

The security solutions block is where people lose points

This is the biggest domain and also the one where candidates guess the most, because Microsoft has a lot of overlapping product names. Keep these separated in your head:

  • Microsoft Defender for Cloud — posture management and workload protection across Azure, AWS, and GCP resources
  • Microsoft Defender XDR (the suite) — includes Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps
  • Microsoft Sentinel — the SIEM/SOAR layer, built on Azure Monitor Log Analytics, used for detection and response across the whole environment

A common trick question setup: they'll describe a scenario (phishing email, suspicious sign-in, misconfigured storage account) and ask which tool handles it. If it's email-based, think Defender for Office 365. If it's identity behavior, Defender for Identity. If it's cross-tool correlation and hunting, that's Sentinel's job. Knowing which product owns which layer is worth more than memorizing feature lists.

Compliance is not the boring afterthought it looks like

The compliance domain leans heavily on Microsoft Purview. Know what Information Protection does (sensitivity labels, encryption), what Data Loss Prevention (DLP) policies enforce, and how eDiscovery and Insider Risk Management differ from each other. Also expect at least one or two questions on the Microsoft Purview Compliance Manager and how compliance scores get calculated — you don't need the math, just the concept that it's a percentage based on completed improvement actions.

Governance shows up too: Azure Policy, resource locks, and the Microsoft Cloud Adoption Framework's governance pillar. These get lumped into the compliance domain even though they're technically Azure-wide concepts, so don't assume compliance means

Napisane z pomocą AI, zweryfikowane i opublikowane przez Michal Pilch (CISSP), Korra Studio.

Gotowy na więcej?

To jedna notatka z bazy wiedzy Korra Studio — platforma łączy każdy temat z mentoringiem 1 na 1.

Zacznij za darmoarrow_forward