Guide

How to pass SC-900 Security Fundamentals

A four-week route through security, Entra, Microsoft security and compliance solutions, plus exam-day tactics.

· ~9 min read

Aura presents a four-step visual study cycle: learn, connect, practise, and prove readiness.
Your study loop

The exam

What is SC-900, and is it for you?

SC-900 earns the Microsoft Certified: Security, Compliance, and Identity Fundamentals credential, the entry-level exam for Microsoft's whole security stack across Azure and Microsoft 365.

Format & domains

Exam format and skills domains

SC-900 is entirely multiple choice — no drag-and-drop ordering, no hotspot screenshots, no case studies. What it lacks in question variety it makes up for in breadth: four domains cover everything from abstract security concepts to five distinct Microsoft Defender products.

The exam fee changes from country to country, so check Microsoft's certification page for the price where you live. The four skills domains and their weights, from the official November 2025 outline, are below.

SC-900 skills measured (November 2025 outline)
DomainWeight
Describe the concepts of security, compliance, and identity10–15%
Describe the capabilities of Microsoft Entra25–30%
Describe the capabilities of Microsoft security solutions35–40%
Describe the capabilities of Microsoft compliance solutions20–25%

Microsoft security solutions and Microsoft Entra together account for roughly two-thirds of the exam, so give them the largest share of your revision time. The concepts domain is smallest, but skipping it is a mistake — Zero Trust and shared responsibility are the vocabulary the other three domains assume you already have.

Four-week study plan

A realistic four-week study plan

If you already work in IT, one to two weeks of focused revision is enough. If security and cloud concepts are new, four weeks gives each domain proper room. Compress it if Conditional Access and Zero Trust feel familiar; stretch it if this is your first Microsoft exam. Each week below maps onto the domains by weight.

  1. Security, compliance, and identity concepts

    The smallest domain, but it underpins everything that follows.

    • Shared responsibility model, defence-in-depth, Zero Trust, encryption versus hashing.
    • Identity as the security perimeter; authentication versus authorisation.
    • Identity providers, directory services and Active Directory, federation.
  2. Microsoft Entra

    The biggest domain, and the most scenario-heavy.

    • Entra ID identity types: member, guest, hybrid.
    • Authentication: MFA, passwordless sign-in, password protection.
    • Access management with Conditional Access and Entra RBAC; governance through Identity Protection, PIM, and entitlement management.
  3. Microsoft security solutions

    The largest domain by weight, and where the product names pile up.

    • Core Azure security: NSGs, Azure Firewall, DDoS Protection, Web Application Firewall.
    • The Defender family: Cloud, Endpoint, Office 365, Identity, and XDR.
    • Microsoft Sentinel for SIEM and SOAR, plus Defender Threat Intelligence.
  4. Microsoft compliance solutions and simulation

    Cover the last domain, then spend the closing days under exam conditions.

    • Purview's compliance portal, Compliance Manager, compliance score.
    • Sensitivity labels, retention policies, records management, data loss prevention; insider risk; Microsoft Priva.
    • Drill your weakest domain daily, then sit two full-length timed simulations before you book.

Where people lose marks

The hardest SC-900 topics

SC-900 tests concepts and precise definitions. Give the areas below extra attention, especially when similar terms are easy to confuse.

Authentication versus authorisation

  • These two terms are used almost interchangeably in everyday speech, and the exam relies on you keeping them apart.
  • Authentication proves who you are; authorisation decides what you're allowed to do once proven — label every scenario as one or the other before you check the answer.

Zero Trust

  • Candidates memorise the phrase "Zero Trust" but not the three principles behind it, and stall when a question asks which principle a control demonstrates.
  • Learn verify explicitly, use least-privilege access, and assume breach by name, then practise matching real controls like Conditional Access to the one each supports.

The shared responsibility model

  • Responsibility shifts with the service model, and questions describe one control and ask whose job it is under a given model.
  • On-premises: you own everything. IaaS: Microsoft takes the physical layers. SaaS: Microsoft owns almost everything except your data and identities.

Telling the Defender products apart

  • Microsoft security solutions is the largest domain, and the five-strong Defender family is where most marks are lost.
  • Write a one-line description of each in your own words: Cloud protects workloads, Endpoint protects devices, Office 365 protects email, Identity protects on-premises AD signals, XDR ties detections together.

How to practise

Practise the way the exam works

SC-900 tests recall of specific product names under time pressure, a skill videos alone don't build.

Keep the Defender family straight

Azure Mastery drills every SC-900 domain with a rationale on every option, so mixing up Defender for Cloud and Defender for Identity teaches you the distinction, not just costs a mark. Exam IQ adds an on-device readiness score, the plan re-targets your weak domain, and the simulator runs at blueprint weight. Free to start, works offline.

Download Azure Mastery — free

Exam day

Tactics for exam day

A few habits keep 45 minutes from feeling rushed.

  1. Sitting online? Run the system check the day before and clear your desk — the proctor sweeps the webcam across the room before you start.
  2. Arrive early either way, whether that's logging in ahead of time or reaching the test centre with room to settle.
  3. Budget 45 to 65 seconds per question, and flag anything you hesitate on with mark-for-review instead of losing a minute on it early.
  4. Read scenario questions twice. SC-900 hides the answer in a subtle word choice — "hybrid" versus "guest" identity, "detect" versus "prevent".
  5. Remember the pass mark is 700 out of 1000, scaled. An unfamiliar term isn't a disaster: make your call and move on.
Five Defender products, one memory test. Drill SC-900 questions with a rationale on every option and watch your Exam IQ score climb — free to start. Download free

Frequently asked

SC-900 FAQs

How hard is the SC-900 exam?

Conceptual, not hands-on — you recognise which Microsoft service fits a scenario, rather than configuring anything. That's approachable, but the breadth catches people out: four domains span identity, several Defender products, Sentinel, and the Purview compliance surface. Most newcomers to security pass after two to four weeks.

How long should I study for SC-900?

One to two weeks if you already work in IT. Three to four weeks if security and cloud concepts are new — the exam expects several unfamiliar product families held in your head at once. The four-week plan above is a comfortable pace; compress it if Zero Trust and Conditional Access already feel familiar.

Do I need any other certification before SC-900?

No formal prerequisites — it's designed as an entry point for business stakeholders and IT generalists, not just administrators. If cloud concepts feel unfamiliar too, pairing it with AZ-900 (Azure Fundamentals) rounds out the picture, but SC-900 stands on its own.

What is the passing score for SC-900?

700 out of 1000. The score is scaled rather than a raw percentage, so it doesn't map to a fixed number of correct answers. Multi-part items usually award one point for each correctly answered component unless the question states otherwise, so treat 700 as a comfortable target, not a line to scrape over.

Does the SC-900 certification expire?

No. Fundamentals certifications, SC-900 included, don't expire once earned. That's different from Associate and Expert certifications such as SC-200 or SC-300, which need a free annual renewal assessment on Microsoft Learn.

What should I take after SC-900 — SC-200 or SC-500?

It depends on the role you want. SC-200 (Security Operations Analyst Associate) is the day-to-day defender path — investigating incidents in Sentinel, triaging alerts, working inside Defender XDR. SC-500 replaces AZ-500, retired 2026-08-31, and suits engineers who build and secure the platform rather than monitor it.

After SC-900

What's next after SC-900

SC-900 does not lock you into one path. It is the shared on-ramp for two different Associate-level directions, and which one fits depends on whether you want to defend against attacks or build and secure the platform itself.

Not sure which track to commit to, or whether to pair SC-900 with a cloud-fundamentals exam first? The guides below walk through the decision.

Every other exam's guide lives at Azure certification guides.

Ready to start on SC-900?

Four domains, one habit: answer, then read why every option was right or wrong. Exam IQ adds an on-device score with a confidence range. Free to start, works offline.

Download Azure Mastery — free iPhone & iPad · Free to start · No account required