Microsoft Security, Compliance, and Identity Fundamentals (SC-900) Exam Blueprint

SC-900

700 (1-1000)Passing Score
Practice Microsoft Security, Compliance, and Identity Fundamentals on QuizForge

Credential type: certification examination · verified on the issuer's site September 20, 2026 issuer page

Exam Domains

1.0 Describe the concepts of security, compliance, and identity 10-15%
  • 1.1Describe security and compliance concepts
    Describe the shared responsibility model; Describe defense-in-depth; Describe the Zero Trust model; Describe encryption and hashing; Describe Governance, Risk, and Compliance (GRC) concepts
  • 1.2Define identity concepts
    Define identity as the primary security perimeter; Define authentication; Define authorization; Describe identity providers; Describe the concept of directory services and Active Directory; Describe the concept of federation
2.0 Describe the capabilities of Microsoft Entra 25-30%
  • 2.1Describe function and identity types of Microsoft Entra ID
    Describe Microsoft Entra ID; Describe types of identities, including agent ID; Describe hybrid identity
  • 2.2Describe authentication capabilities of Microsoft Entra ID
    Describe the authentication methods; Describe multifactor authentication (MFA); Describe password protection and management capabilities
  • 2.3Describe access management capabilities of Microsoft Entra ID
    Describe Microsoft Entra Conditional Access; Describe Microsoft Entra roles and role-based access control (RBAC)
  • 2.4Describe identity protection and governance capabilities of Microsoft Entra
    Describe Microsoft Entra ID Governance; Describe access reviews; Describe the capabilities of Microsoft Entra Privileged Identity Management; Describe Microsoft Entra ID Protection
3.0 Describe the capabilities of Microsoft security solutions 35-40%
  • 3.1Describe core infrastructure security services in Azure
    Describe Azure DDoS Protection; Describe Azure Firewall; Describe Azure Web Application Firewall (WAF); Describe network segmentation with Azure virtual networks; Describe network security groups (NSGs); Describe Azure Bastion; Describe Azure Key Vault
  • 3.2Describe security management capabilities of Azure
    Describe Microsoft Defender for Cloud; Describe Cloud Security Posture Management (CSPM); Describe how security policies, standards, and recommendations improve the cloud security posture; Describe enhanced security features provided by cloud workload protection
  • 3.3Describe capabilities of Microsoft Sentinel
    Define the concepts of security information and event management (SIEM) and security orchestration automated response (SOAR); Describe threat detection and mitigation capabilities in Microsoft Sentinel
  • 3.4Describe threat protection with Microsoft Defender XDR
    Describe Microsoft Defender XDR services; Describe Microsoft Defender for Office 365; Describe Microsoft Defender for Endpoint; Describe Microsoft Defender for Cloud Apps; Describe Microsoft Defender for Identity; Describe Microsoft Defender Vulnerability Management; Describe Microsoft Defender Threat Intelligence (Defender TI); Describe the Microsoft Defender portal
4.0 Describe the capabilities of Microsoft compliance solutions 20-25%
  • 4.1Describe Microsoft Service Trust Portal and privacy principles
    Describe the Service Trust Portal offerings; Describe the privacy principles of Microsoft
  • 4.2Describe compliance management capabilities of Microsoft Purview
    Describe the Microsoft Purview portal; Describe Compliance Manager; Describe the uses and benefits of compliance score
  • 4.3Describe information protection, data lifecycle management, and data governance capabilities of Microsoft Purview
    Describe the data classification capabilities; Describe the benefits of Content explorer and Activity explorer; Describe sensitivity labels and sensitivity label policies; Describe data loss prevention (DLP); Describe records management; Describe retention policies, retention labels, and retention label policies
  • 4.4Describe insider risk, eDiscovery, and audit capabilities in Microsoft Purview
    Describe insider risk management; Describe eDiscovery solutions in Microsoft Purview; Describe audit solutions in Microsoft Purview

Exam Details

Online ProctoringAvailable
RenewalNot required -- Microsoft Fundamentals certifications do not expire and do not require renewal.
Retake PolicyAfter the first failure, wait 24 hours. Wait 14 days between later attempts. At most five attempts in the 12 months starting with the first attempt; after five failures, wait until that period ends. Retake fees apply. See Microsoft's policy for exceptions.

Official Study Resources

Source review and study planning

Source checked 2026-09-04. Objectives effective 2026-07-28.

Official-source reconciliation with automated hierarchy checks; not an endorsement by Microsoft.

Official objectives | Official retake policy

Plan against this version