SC-900Free Study Guide

Microsoft Security, Compliance, and Identity Fundamentals SC-900The Complete Beginner's Guide

Complete SC-900 study guide — security, compliance, and identity fundamentals for Microsoft cloud services.

103 chapters
~43 hours total read
Free — no signup required

How to use this guide

This guide works best as a loop: read a chapter, test yourself with practice questions, look up unfamiliar terms in the glossary, then move to the next chapter.

① Read a chapter② Answer practice questions③ Review missed answers④ Repeat
Study Chapters

103 chapters covering every exam objective. Each chapter includes key concepts, exam tips, common traps, comparison tables, and a 5-question quiz at the end.

Start Chapter 1
Practice Questions

Free timed and untimed practice with instant feedback and full explanations. Pick 10–120 questions per session. Filter by domain to drill your weak areas.

Go to practice test
Glossary

Every SC-900term defined and searchable. Use it when a chapter mentions a concept you haven't seen before or want a quick refresher on.

Browse glossary
Exam Overview

Exam blueprint, domain weights, passing score, duration, cost, and registration links. Start here if you're new to this certification.

View exam guide

Security, Compliance, and Identity Concepts (10–15%)

15 chapters

Domain overview

Capabilities of Microsoft Entra (25–30%)

29 chapters

Domain overview
4

Microsoft Entra ID

Objective 2.1 · Identity Access

25m
5

Authentication and MFA in Entra

Objective 2.2 · Identity Access

25m
6

Conditional Access Policies

Objective 2.3 · Identity Access

25m
7

Entra ID Roles and RBAC

Objective 2.4 · Identity Access

25m
8

Microsoft Entra Identity Protection

Objective 2.5 · Identity Access

25m
21

Microsoft Entra External Identities: B2B and B2C

Objective 2.1 · Identity Access

25m
22

Privileged Identity Management (PIM)

Objective 2.2 · Identity Access

25m
23

Microsoft Entra Access Reviews

Objective 2.3 · Identity Access

25m
24

Microsoft Entra Permissions Management

Objective 2.4 · Identity Access

25m
25

Entra Workload Identities and Service Principals

Objective 2.5 · Identity Access

25m
26

Windows Hello for Business and FIDO2

Objective 2.2 · Identity Access

25m
41

Microsoft Authenticator and SSPR

Objective 2.2 · Identity Access

25m
47

OAuth 2.0 and OpenID Connect in Entra

Objective 2.1 · Identity Access

25m
48

SAML and Single Sign-On (SSO)

Objective 2.1 · Identity Access

25m
49

Microsoft Entra Password Protection

Objective 2.2 · Identity Access

25m
50

Self-Service Password Reset (SSPR)

Objective 2.2 · Identity Access

25m
51

Entra ID App Registrations

Objective 2.1 · Identity Access

25m
52

Entra ID Enterprise Applications

Objective 2.1 · Identity Access

25m
53

Microsoft Entra Verified ID

Objective 2.5 · Identity Access

25m
54

Security Defaults in Entra ID

Objective 2.2 · Identity Access

25m
55

Named Locations in Conditional Access

Objective 2.3 · Identity Access

25m
56

Terms of Use and Authentication Strengths

Objective 2.3 · Identity Access

25m
57

Cross-Tenant Access Settings

Objective 2.1 · Identity Access

25m
58

Hybrid Identity with Entra Connect

Objective 2.1 · Identity Access

25m
59

Microsoft Entra Domain Services

Objective 2.1 · Identity Access

25m
93

Lifecycle Workflows in Entra ID Governance

Objective 2.3 · Identity Access

25m
94

Microsoft Entra Global Secure Access

Objective 2.5 · Identity Access

25m
95

Entra Internet Access and Private Access

Objective 2.5 · Identity Access

25m
103

Identity Governance in Microsoft Entra

Objective 2.3 · Identity Access

25m

Capabilities of Microsoft Security Solutions (35–40%)

30 chapters

Domain overview
9

Microsoft Defender for Cloud

Objective 3.1 · Security Solutions

25m
10

Microsoft Sentinel

Objective 3.2 · Security Solutions

25m
11

Microsoft Defender XDR

Objective 3.3 · Security Solutions

25m
12

Azure DDoS Protection and Firewall

Objective 3.4 · Security Solutions

25m
27

Microsoft Defender for Office 365

Objective 3.1 · Security Solutions

25m
28

Microsoft Defender for Cloud Apps

Objective 3.2 · Security Solutions

25m
29

Microsoft Defender for Endpoint

Objective 3.3 · Security Solutions

25m
30

Microsoft Defender for Identity

Objective 3.3 · Security Solutions

25m
31

Microsoft Secure Score

Objective 3.4 · Security Solutions

25m
32

Microsoft Intune for Endpoint Security

Objective 3.4 · Security Solutions

25m
40

Microsoft Security Baselines

Objective 3.4 · Security Solutions

25m
60

Microsoft Defender Portal Overview

Objective 3.1 · Security Solutions

25m
61

Azure Network Security Groups and Firewalls

Objective 3.4 · Security Solutions

25m
62

Azure Private Link Basics

Objective 3.4 · Security Solutions

25m
63

Shadow IT Discovery in Defender for Cloud Apps

Objective 3.2 · Security Solutions

25m
64

Session and Access Policies in Defender for Cloud Apps

Objective 3.2 · Security Solutions

25m
71

Cloud Security Posture Management (CSPM)

Objective 3.1 · Security Solutions

25m
72

Defender for Cloud Workload Protections

Objective 3.1 · Security Solutions

25m
73

Sentinel Incidents and Alerts Overview

Objective 3.2 · Security Solutions

25m
74

Logic Apps Playbooks in Sentinel

Objective 3.2 · Security Solutions

25m
75

Defender for Endpoint Onboarding

Objective 3.3 · Security Solutions

25m
76

Attack Surface Reduction Rules

Objective 3.3 · Security Solutions

25m
77

Cloud App Governance and App Consent

Objective 3.2 · Security Solutions

25m
78

Microsoft 365 Defender Portal Overview

Objective 3.3 · Security Solutions

25m
79

Azure Key Vault Basics

Objective 3.4 · Security Solutions

25m
80

Azure NSG and Application Security Groups

Objective 3.4 · Security Solutions

25m
81

Azure Web Application Firewall (WAF)

Objective 3.4 · Security Solutions

25m
92

Defender Vulnerability Management Basics

Objective 3.3 · Security Solutions

25m
99

Threat and Vulnerability Management

Objective 3.3 · Security Solutions

25m
101

Basic KQL Queries in Sentinel

Objective 3.2 · Security Solutions

25m

Capabilities of Microsoft Compliance Solutions (20–25%)

29 chapters

Domain overview
13

Microsoft Purview

Objective 4.1 · Compliance Solutions

25m
14

Compliance Manager

Objective 4.2 · Compliance Solutions

25m
15

Information Protection and DLP

Objective 4.3 · Compliance Solutions

25m
16

eDiscovery and Audit

Objective 4.4 · Compliance Solutions

25m
33

Azure Policy for Compliance

Objective 4.1 · Compliance Solutions

25m
34

Sensitivity Labels and Information Protection

Objective 4.2 · Compliance Solutions

25m
35

Retention Policies and Labels

Objective 4.2 · Compliance Solutions

25m
36

Insider Risk Management

Objective 4.3 · Compliance Solutions

25m
37

Communication Compliance

Objective 4.3 · Compliance Solutions

25m
38

Data Residency, Sovereignty, and Privacy

Objective 4.4 · Compliance Solutions

25m
39

GDPR and Global Privacy Regulations Overview

Objective 4.4 · Compliance Solutions

25m
65

Azure Policy and Initiatives

Objective 4.1 · Compliance Solutions

25m
66

Management Groups and Subscription Governance

Objective 4.1 · Compliance Solutions

25m
67

Records Management in Microsoft Purview

Objective 4.2 · Compliance Solutions

25m
68

Data Classification in Microsoft Purview

Objective 4.2 · Compliance Solutions

25m
69

Microsoft Compliance Manager Score

Objective 4.2 · Compliance Solutions

25m
70

Azure Blueprints for Compliance

Objective 4.1 · Compliance Solutions

25m
82

Microsoft Purview Compliance Portal

Objective 4.1 · Compliance Solutions

25m
83

Content Explorer for Data Discovery

Objective 4.2 · Compliance Solutions

25m
84

Exact Data Match for Sensitive Info Types

Objective 4.3 · Compliance Solutions

25m
85

DLP Policies for Microsoft Teams

Objective 4.3 · Compliance Solutions

25m
86

eDiscovery Standard vs Premium

Objective 4.4 · Compliance Solutions

25m
87

Audit Log Retention Policies

Objective 4.4 · Compliance Solutions

25m
88

Microsoft Privacy Principles

Objective 4.4 · Compliance Solutions

25m
89

Service Trust Portal

Objective 4.4 · Compliance Solutions

25m
90

Azure Policy Effects: Audit, Deny, Modify

Objective 4.1 · Compliance Solutions

25m
91

Azure Resource Locks: ReadOnly and Delete

Objective 4.1 · Compliance Solutions

25m
100

Advanced Audit in Microsoft 365

Objective 4.4 · Compliance Solutions

25m
102

Trainable Classifiers for Content Classification

Objective 4.2 · Compliance Solutions

25m

Ready to test your knowledge?

Free SC-900 practice questions with full explanations. Test what you learn chapter by chapter.

SC-900 Practice Questions