SC-900 remains Microsoft’s entry-level Security, Compliance, and Identity Fundamentals exam. As of October 4, 2026, the live English blueprint is the version measured from July 28, 2026, although Microsoft has already announced another English-language update for October 21. Candidates testing before that date should therefore use the current July objectives rather than studying a future version prematurely.
The current SC-900 weighting is 10–15% security, compliance, and identity concepts; 25–30% Microsoft Entra; 35–40% Microsoft security solutions; and 20–25% Microsoft compliance solutions. Microsoft requires a score of 700 or greater to pass. The exam remains fundamentals-level: explain capabilities, purposes, and relationships rather than configure production security architecture.
Security, compliance, and identity concepts make up 10–15%
The first domain covers the shared responsibility model, defense in depth, Zero Trust, encryption, hashing, and Governance, Risk, and Compliance concepts. It also covers identity as a primary security perimeter, authentication, authorization, identity providers, directory services, Active Directory, and federation.
A Zero Trust foundation is useful because the exam expects candidates to understand explicit verification, least privilege, and assumption of breach as principles that influence Microsoft identity and security services.
Identity concepts are foundational, not product trivia
Authentication answers who or what is proving an identity; authorization determines what that identity can do. Federation lets identity trust cross organizational or service boundaries. Directory services organize identity information and relationships.
These distinctions make later Entra topics easier because features such as Conditional Access, roles, PIM, and Identity Protection all act at different points in the identity and access lifecycle.
Microsoft Entra represents 25–30%
The current blueprint includes Microsoft Entra ID, identity types including agent ID, hybrid identity, authentication methods, MFA, password protection/management, Conditional Access, Entra roles and RBAC, ID Governance, access reviews, PIM, and Identity Protection.
The appearance of agent identities in the July 2026 guide is a useful freshness marker. SC-900 now treats human, workload, and emerging agent identities as part of a broader identity platform rather than focusing only on employee accounts.
Conditional Access connects authentication with context
Conditional Access is not simply an MFA switch. It can evaluate user, resource, risk, device, location, and other signals before applying access controls. Conditional Access belongs beside authentication methods because policy decides when stronger assurance or blocking is appropriate.
At fundamentals depth, know the purpose and relationship—not every portal setting.
Microsoft security solutions is the largest domain at 35–40%
This section begins with Azure infrastructure security: DDoS Protection, Azure Firewall, Web Application Firewall, virtual-network segmentation, network security groups, Azure Bastion, and Key Vault. These services operate at different layers, so “security” should not be treated as one product category.
A Defender for Cloud perspective then adds security posture management and cloud workload protection to the Azure layer.
Defender for Cloud, Sentinel, and Defender XDR solve different problems
Defender for Cloud focuses on cloud security posture and workload protection. Microsoft Sentinel is a SIEM/SOAR platform for detection, investigation, and automated response. Defender XDR correlates threat signals across Microsoft security products and provides integrated investigation.
The current guide explicitly names Defender for Office 365, Defender for Endpoint, Defender for Cloud Apps, Defender for Identity, Defender Vulnerability Management, Defender Threat Intelligence, and the Microsoft Defender portal.
Microsoft compliance solutions account for 20–25%
The final domain covers Service Trust Portal and Microsoft’s privacy principles, Microsoft Purview, Compliance Manager, compliance score, data classification, Content explorer, Activity explorer, sensitivity labels, DLP, records management, retention, Insider Risk Management, eDiscovery, and Audit.
A Purview compliance model helps separate information protection, data lifecycle, investigation, and compliance-management capabilities.
Compliance score is evidence and prioritization, not certification
Compliance Manager and compliance score help organizations assess improvement actions and posture against selected requirements. A score can support prioritization, but it does not automatically prove legal compliance. Organizations still need to interpret applicable laws, contracts, risks, and evidence.
This distinction is important at fundamentals level because Microsoft tools support compliance work; they do not replace governance or legal responsibility.
The October 21 update should be treated as a date boundary
Microsoft’s certification page already warns that the English exam will update on October 21, 2026. The current July guide remains authoritative for an October 4 exam appointment. If your appointment is on or after October 21, review the updated study guide and change log immediately before final revision.
A SC-900 preparation plan should therefore keep exam-date versioning visible instead of mixing present and future objective wording.
SC-900 is a relationship exam
The strongest candidate can explain how identity, infrastructure security, threat protection, governance, and compliance fit together across Azure and Microsoft 365. You do not need specialist-level configuration depth, but you should know which service family addresses the requirement and which nearby service solves a different problem.
The current fundamentals blueprint is deliberately broad because Microsoft wants candidates to understand how security, identity, and compliance reinforce one another. A user identity can be protected by Entra, access a workload protected by Defender, generate signals in Sentinel or XDR, and interact with data governed by Purview. Seeing that chain is more valuable than memorizing every product logo.
Shared responsibility should be learned comparatively. In SaaS, Microsoft manages more of the underlying stack; in IaaS, the customer manages more configuration and workload layers. Yet customer responsibility for identities, data, and correct access policies remains important across models. This concept prevents the mistaken belief that cloud adoption transfers all security accountability to the provider.
Defense in depth should also be studied by control purpose. An NSG can filter network traffic, Key Vault protects secrets and keys, Entra controls identity, WAF inspects web requests, and Defender services detect or respond to threats. These controls can coexist because an attacker may cross several layers during one incident.
Encryption and hashing often appear together in fundamentals materials, but their goals differ. Encryption is reversible with the appropriate key and protects confidentiality; hashing is one-way and commonly supports integrity or password-verification designs. Knowing the purpose is more important for SC-900 than knowing mathematical implementation details.
Governance, Risk, and Compliance should be treated as organizational disciplines around technology. Governance sets direction and accountability, risk management evaluates uncertainty and business impact, and compliance maps obligations to controls and evidence. Microsoft tools can support all three, but the organization still decides what risk is acceptable and which obligations apply.
Hybrid identity remains relevant because many organizations still use Active Directory on-premises while extending identity into Microsoft Entra. The exam does not require deep synchronization configuration, but candidates should recognize that cloud and on-premises identity can coexist and that governance must account for both sources.
Agent identities are a newer objective because AI agents or automated actors may need permissions to data and tools. At fundamentals level, the key insight is that non-human identities require the same principles as human identities: least privilege, lifecycle management, authentication, authorization, and monitoring.
Microsoft Entra roles and Azure RBAC are related but should not be collapsed into one concept. Entra roles manage identity/directory capabilities, while Azure RBAC controls access to Azure resources. SC-900 questions can test whether the requested permission belongs to identity administration or resource authorization.
Access reviews and PIM represent identity governance rather than ordinary sign-in. Access reviews help organizations periodically validate whether users still need access; PIM reduces standing privileged access by making selected roles eligible or time-bound. Both support least privilege over time, not just at account creation.
Identity Protection contributes risk signals about users or sign-ins. Conditional Access can then use risk as one input to access decisions. That relationship matters because a correct password does not necessarily mean a sign-in should be trusted when the surrounding behavior is suspicious.
Azure Bastion is best understood as an administrative-access service. It lets administrators reach supported VMs without exposing ordinary RDP/SSH management ports directly to the public internet. It does not replace network segmentation, identity controls, or endpoint protection; it reduces one specific administration exposure.
Key Vault belongs in the infrastructure-security branch because secrets, keys, and certificates are security dependencies. Applications should avoid embedding credentials in source code or configuration files when they can retrieve protected secrets through controlled identities and permissions.
Microsoft Sentinel’s SIEM/SOAR role should be differentiated from Defender XDR. Sentinel can ingest and analyze broad security data across sources, while Defender XDR focuses on correlated detections across Microsoft protection products. Organizations may use both, with incident context and automation flowing between them.
Defender Vulnerability Management is another useful distinction. It is about exposure and remediation of weaknesses rather than necessarily detecting an active attack. A device can be vulnerable without being compromised, and a mature security program should reduce exposure before attackers exploit it.
Service Trust Portal is often overlooked because it is not a threat-control product. It provides Microsoft audit reports, compliance documentation, and trust-related materials that customers can use in due diligence and assurance. This is provider evidence supporting the customer’s own governance process.
Content explorer and Activity explorer belong to the compliance-information layer. Content explorer helps understand where sensitive or labeled information exists; Activity explorer shows related user or system actions. These tools support visibility into whether information-protection policies match real data use.
Insider Risk Management, eDiscovery, and Audit should be learned by investigative purpose. Insider Risk looks for risky internal behavior patterns, eDiscovery supports legal/investigative collection and review, and Audit provides records of activity. They can overlap in an investigation while answering different questions.
For final revision, use one fictional incident that touches every domain: a risky user signs in, accesses an Azure workload, downloads sensitive information, and triggers security alerts. Then identify the relevant Entra, Defender/Sentinel, and Purview capabilities. If you can explain the role of each without over-configuring the scenario, your scope understanding is aligned with SC-900.
Within the broader Microsoft certification path, SC-900 is the vocabulary-and-architecture foundation for later identity, security-operations, compliance, and cybersecurity-architect roles.