Guide

How to pass SC-900 Security Fundamentals

A beginner-friendly route through Microsoft's Security, Compliance, and Identity Fundamentals exam: what it actually tests, the four skills domains and their weights, a realistic four-week study plan, the concepts that trip people up, and how to walk into exam day settled.

Updated July 2026 · ~9 min read

The exam

What is SC-900, and is it for you?

SC-900 earns the Microsoft Certified: Security, Compliance, and Identity Fundamentals credential. It is the entry-level exam for Microsoft's whole security stack across Azure and Microsoft 365, and it is deliberately written for a wide audience: business stakeholders evaluating security procurement, IT generalists moving toward a security role, and students who want a credible foundation before committing to a specialism.

You do not need a technical background to sit SC-900. The exam does not ask you to configure a Conditional Access policy or write a Sentinel query. It asks you to recognise the right concept or product for a described scenario: which control enforces Zero Trust, which Defender product covers this surface, which Purview tool meets this requirement. That makes it a genuine Fundamentals exam rather than a scaled-down Associate one.

Microsoft updated the SC-900 skills outline on 7 November 2025, and the exam is refreshed periodically as Microsoft's security products evolve, so anchor your study to the live objectives rather than an old syllabus. It sits alongside AZ-900 and AI-901 as one of Microsoft's three main Fundamentals exams, and it is the recommended (though not required) on-ramp to the Security Operations, Identity, and Cybersecurity Architect role-based tracks.

Format & domains

Exam format and skills domains

SC-900 is entirely multiple choice — no drag-and-drop ordering, no hotspot screenshots, no case studies. What it lacks in question variety it makes up for in breadth: four domains cover everything from abstract security concepts to five distinct Microsoft Defender products.

The exam fee changes from country to country, so check Microsoft's certification page for the price where you live. The four skills domains and their weights, from the official November 2025 outline, are below.

SC-900 skills measured (November 2025 outline)
DomainWeight
Describe the concepts of security, compliance, and identity10–15%
Describe the capabilities of Microsoft Entra25–30%
Describe the capabilities of Microsoft security solutions35–40%
Describe the capabilities of Microsoft compliance solutions20–25%

Microsoft security solutions and Microsoft Entra together account for roughly two-thirds of the exam, so give them the largest share of your revision time. The concepts domain is smallest, but skipping it is a mistake — Zero Trust and shared responsibility are the vocabulary the other three domains assume you already have.

Four-week study plan

A realistic four-week study plan

If you already work in IT, one to two weeks of focused revision is often enough. If security and cloud concepts are new to you, four weeks gives each domain proper room. Compress it if terms like Conditional Access and Zero Trust already feel familiar; stretch it if this is your first Microsoft exam. Each week below maps onto the domains in order of weight.

  1. Security, compliance, and identity concepts

    Start with the shared vocabulary: the shared responsibility model, defence-in-depth, the Zero Trust model, and encryption versus hashing. Then move into identity fundamentals — identity as the security perimeter, authentication versus authorisation, identity providers, directory services and Active Directory, and federation. This is the smallest domain, but it underpins everything that follows.

  2. Microsoft Entra

    The biggest domain and the most scenario-heavy. Cover Microsoft Entra ID identity types — member, guest, and hybrid — and authentication methods including multi-factor authentication, passwordless sign-in, and password protection. Then access management with Conditional Access and Microsoft Entra role-based access control, and identity governance through Identity Protection, Privileged Identity Management, and entitlement management.

  3. Microsoft security solutions

    The largest domain by weight. Start with core Azure security services: network security groups, Azure Firewall, Azure DDoS Protection, and Web Application Firewall. Then learn to distinguish the Microsoft Defender product family — Defender for Cloud, Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender XDR — alongside Microsoft Sentinel for SIEM and SOAR, and Microsoft Defender Threat Intelligence.

  4. Microsoft compliance solutions and simulation

    Cover Microsoft Purview's compliance portal, Compliance Manager, and compliance score; information protection and data lifecycle management through sensitivity labels, retention policies, records management, and data loss prevention; insider risk capabilities; and Microsoft Priva for privacy management. Then switch to sharpening: drill your weakest domain daily and sit two full-length timed simulations before you book.

Where people lose marks

The hardest SC-900 topics

SC-900's questions are conceptual rather than technical, but a handful of areas consistently cost newcomers marks. They reward precise definitions over general familiarity. Give these extra attention.

Authentication versus authorisation

These two terms are used almost interchangeably in everyday speech, and the exam relies on you keeping them apart. Authentication proves who you are; authorisation determines what you are allowed to do once proven. Questions describe a scenario and ask which of the two just happened. Practise labelling every identity scenario you read as one or the other before checking your answer.

Zero Trust

Zero Trust is not a single product, it is a model built on three principles: verify explicitly, use least-privilege access, and assume breach. Candidates who memorise the phrase but not the principles struggle when a question describes a control and asks which principle it demonstrates. Learn the three by name and practise matching real controls, such as Conditional Access, to the one each supports.

The shared responsibility model

Responsibility shifts with the service model: on-premises, you own everything; in infrastructure as a service, Microsoft takes over the physical layers; in software as a service, Microsoft owns almost everything except your data and identities. Questions describe a control, such as patching an operating system, and ask whose responsibility it is under a given model. Sketch the SaaS/PaaS/IaaS split yourself until the split is automatic.

Telling the Defender products apart

Microsoft security solutions is the largest domain, and the Defender family is where it bites. Defender for Cloud protects cloud workloads, Defender for Endpoint protects devices, Defender for Office 365 protects email and collaboration, Defender for Identity protects on-premises Active Directory signals, and Defender XDR ties their detections together. Write a one-line description of each product in your own words rather than relying on the name alone.

How to practise

Practise the way the exam works

Watching videos and reading Microsoft Learn modules builds recognition, but SC-900 tests recall of specific product names under time pressure, and recognition alone will not get you there. Two habits close that gap. First, retrieval practice: answer from memory before you read the explanation, because pulling the answer out of your own head is what makes it stick. Second, spaced repetition: come back to a domain a few days after you first studied it, so the Defender product you learned in week three has not faded by exam day.

Third, full-length simulation. A timed, mixed-domain run is the only way to find out whether you can hold four domains' worth of vocabulary in your head at once across 40 to 60 questions in 45 minutes. Sit at least two before you book, and review every wrong answer rather than just noting the score.

Build all three habits in one app

Azure Mastery is built around exactly this loop for SC-900. Practise with over 300 exam-style questions mapped to the four November 2025 domains, get an on-device readiness score from the Exam IQ engine, follow an adaptive study plan that targets your weak spots, and let knowledge-decay alerts tell you what to revise before you forget it. When you want a dress rehearsal, the Practice tab serves a timed mock matched to the exam's own length and question count, and every feature runs offline without a sign-in.

Download Azure Mastery — free

Exam day

Tactics for exam day

If you are sitting online, run the system check the day before and clear everything off your desk, because the proctor will have you sweep the webcam across the room and stow anything within arm's reach. Arrive early either way, whether that means logging in ahead of time or reaching the test centre with room to settle.

With 45 minutes for 40 to 60 questions, you have roughly 45 to 65 seconds each, which is workable if you keep moving and do not stall on any single definition. Use the mark-for-review flag on anything that makes you hesitate and come back to it once you have banked the easy marks, rather than losing a minute early on a question you are unsure of.

Read scenario questions carefully. SC-900 likes to embed the answer in a subtle word choice — "hybrid" versus "guest" identity, "detect" versus "prevent" — so a slower second pass on anything ambiguous pays off. Finally, remember the score is scaled: you need 700 out of 1000, not a perfect run, so an unfamiliar term is not a disaster.

Frequently asked

SC-900 FAQs

How hard is the SC-900 exam?

SC-900 is a conceptual exam, not a hands-on one. You are not asked to configure a Conditional Access policy or write a KQL query; you are asked to recognise which Microsoft service or concept fits a described scenario. That makes it approachable for beginners, but the breadth catches people out — four domains span identity, several Defender products, Sentinel, and the whole Purview compliance surface. Most newcomers to security pass after two to four weeks of focused study.

How long should I study for SC-900?

If you already work in IT, one to two weeks of focused revision is usually enough. If security and cloud concepts are genuinely new to you, plan for three to four weeks, because the exam expects you to hold several unfamiliar product families in your head at once. The four-week plan on this page is a comfortable pace for a first Fundamentals exam; compress it if terms like Zero Trust and Conditional Access already feel familiar.

Do I need any other certification before SC-900?

No. SC-900 has no formal prerequisites and is designed as an entry point — Microsoft pitches it at business stakeholders, IT professionals moving toward security, and students, not just existing administrators. If cloud concepts alongside security concepts feel unfamiliar, pairing it with AZ-900 (Azure Fundamentals) rounds out the picture, but you can sit SC-900 on its own.

What is the passing score for SC-900?

You need 700 out of 1000 to pass. The score is scaled rather than a raw percentage, so it does not map to a fixed number of correct answers, and question difficulty is weighted. Treat 700 as a comfortable target to clear rather than a line to scrape over, especially since the exam gives no partial credit on multi-select questions.

Does the SC-900 certification expire?

No. Microsoft Fundamentals certifications, including SC-900, AZ-900, DP-900, and AI-901, do not expire once earned. That is different from Associate and Expert certifications such as SC-200 or SC-300, which require a free annual renewal assessment on Microsoft Learn to stay current.

What should I take after SC-900 — SC-200 or SC-500?

It depends on the role you want. SC-200 (Security Operations Analyst Associate) is the day-to-day defender path: investigating incidents in Microsoft Sentinel, triaging alerts, and working inside Defender XDR. SC-500 is Microsoft's newer cloud and AI security engineering credential, replacing AZ-500 when it retires on 2026-08-31, and suits engineers who build and secure the platform rather than monitor it. Read both exam pages and the comparison guide linked below before committing to a direction.

After SC-900

What's next after SC-900

SC-900 does not lock you into one path. It is the shared on-ramp for two different Associate-level directions, and which one fits depends on whether you want to defend against attacks or build and secure the platform itself.

For day-to-day security operations — investigating alerts, hunting threats in Microsoft Sentinel, working inside Defender XDR — SC-200 (Security Operations Analyst Associate) is the natural next step. For engineering and securing cloud and AI workloads rather than monitoring them, look at SC-500, Microsoft's newer credential replacing AZ-500 when it retires on 2026-08-31. Both expect hands-on configuration in a way SC-900 deliberately does not.

Not sure which track to commit to, or whether to pair SC-900 with a cloud-fundamentals exam first? The guides below walk through the decision.

Browse the full library on the Azure certification guides index.

Ready to start on SC-900?

Practise with over 300 exam-style SC-900 questions across all four domains, with an on-device readiness score, an adaptive study plan, and a full-length simulator. Free to start, works offline.

Download Azure Mastery — free iPhone & iPad · Free to start · No account required