🔷 Microsoft  ·  Security Fundamentals

Microsoft SC-900 Complete Course

Learn the fundamentals of Microsoft security, compliance, and identity. Covers everything on the SC-900 exam — from Zero Trust concepts to Microsoft Entra ID, Defender products, Sentinel, Azure Key Vault, and Microsoft Purview. Beginner-friendly.

7 modules ~20 hours beginner 60 practice questions free · no signup
SC-900Exam code
60Exam questions
700 / 1000Passing score
65 minExam duration
$165Exam fee (USD)
No prereqsRequirements
🎧
Study anywhere — CertQuests Podcast

Reinforce Zero Trust principles, Defender product differences, and Purview compliance tools while commuting or working out. Perfect supplement to this course.

▶ Listen on Spotify

Why get SC-900?

SC-900 is Microsoft's entry-level security certification — one of the fastest fundamentals certs to earn and highly valued in any cloud or IT role. It validates that you understand how Microsoft approaches security, compliance, and identity across its entire ecosystem.

Exam strategy: SC-900 is conceptual — it tests "what does X do" and "which Microsoft service handles Y scenario". You don't need to configure anything. Focus on understanding which product solves which problem (e.g., Sentinel = SIEM, Defender for Endpoint = EDR, Purview = compliance) and the three Zero Trust principles.

SC-900 exam domains

Four domains — the largest is Microsoft security solutions (Defender products, Sentinel, Firewall, Key Vault). Memorise the product-to-function mapping for that domain and you're most of the way there.

Domain 1 — Security, Compliance & Identity Concepts 10–15%
Domain 2 — Capabilities of Microsoft Entra 25–30%
Domain 3 — Capabilities of Microsoft Security Solutions 35–40%
Domain 4 — Capabilities of Microsoft Compliance Solutions 25–30%

3 concepts that underpin everything

Before diving into products, understand these foundational models. Multiple SC-900 questions directly test these definitions.

Zero Trust — Three Principles

1. Verify explicitly — Always authenticate and authorise based on all available signals (identity, location, device, service, data). Never trust just because a request comes from inside the network.

2. Use least privilege access — Grant only the minimum permissions needed, just-in-time. Limit standing access and use Just-In-Time / Just-Enough-Access (JIT/JEA).

3. Assume breach — Design as if the attacker is already inside. Segment access, encrypt end-to-end, use analytics to detect anomalies, minimise blast radius.

Defense in Depth — Layered Security

Defense in depth uses multiple security layers so a breach of one doesn't compromise everything. Layers include: physical security → identity → perimeter → network → compute → application → data. SC-900 expects you to identify which layer a given control belongs to.

Shared Responsibility Model

In the cloud, Microsoft and the customer share security responsibilities. Microsoft always handles physical infrastructure. Customers always handle their own identities and data. The boundary shifts by service model: in IaaS customers manage OS and up; in SaaS Microsoft manages almost everything except identity and data.

7 modules · ~20 hours

Organised by exam domain. Each module ends with a conceptual summary table — great for last-minute review.

01

Security, Compliance & Identity Concepts

Build the conceptual foundation for the entire exam. Learn the Zero Trust model (verify explicitly, use least privilege, assume breach), the CIA triad (confidentiality, integrity, availability), defense-in-depth layers, the shared responsibility model across IaaS/PaaS/SaaS, common threat types (phishing, ransomware, supply chain, DDoS, brute force, password spray), encryption at rest vs in transit, and the difference between authentication (who are you?) and authorisation (what can you do?).

zero-trust cia-triad defense-in-depth shared-responsibility threat-types encryption
~2h
02

Microsoft Entra ID — Authentication & Identity

Microsoft Entra ID (formerly Azure Active Directory) is the identity backbone of Microsoft 365 and Azure. This module covers what Entra ID is (cloud identity platform, not on-prem AD), the different identity types (users, service principals, managed identities, workload identities), authentication methods (password, MFA, passwordless with FIDO2/Windows Hello/Authenticator), Self-Service Password Reset (SSPR), Single Sign-On (SSO), and external identities (B2B for partners, B2C for consumers).

entra-id mfa passwordless sspr sso b2b-b2c managed-identity
~3h
🎧

Getting through the Entra ID module? The CertQuests podcast has a dedicated episode on Zero Trust + Entra ID — great for cementing these concepts while you're away from the screen.

▶ Open Spotify
03

Microsoft Entra ID — Access Management & Governance

The second Entra module covers access control and governance. Learn Conditional Access policies (the if-then engine: if user is in this location and this device, then require MFA or block), Entra ID roles vs Azure RBAC roles and why they're different, Privileged Identity Management (PIM) for Just-In-Time admin access, Microsoft Entra Identity Protection for detecting risky sign-ins and leaked credentials, Access Reviews for regularly certifying who still needs access, and the Microsoft Entra admin centre.

conditional-access pim identity-protection access-reviews entra-roles azure-rbac entra-connect
~3h
04

Microsoft Security Solutions — Defender & Azure

Domain 3 is the largest (35-40%) and covers Microsoft's security product portfolio. Master the Defender family: Defender for Cloud (CSPM + CWP, Secure Score, Just-In-Time VM access), Defender for Endpoint (EDR for devices), Defender for Office 365 (Safe Links, Safe Attachments, anti-phishing), Defender for Cloud Apps (CASB, shadow IT discovery), Defender for Identity (on-premises AD attack detection), and Microsoft Defender XDR (unified portal correlating all Defender signals). Also covers Azure network security: Azure Firewall, NSGs, WAF, DDoS Protection, and Azure Bastion.

defender-for-cloud secure-score defender-endpoint defender-office365 defender-cloud-apps defender-identity defender-xdr azure-firewall waf ddos
~5h
05

Microsoft Sentinel & Azure Key Vault

Microsoft Sentinel is Microsoft's cloud-native SIEM and SOAR platform. This module covers how Sentinel ingests data (data connectors from Azure, Microsoft 365, and third-party sources), detects threats (analytics rules running KQL queries on a schedule), automates responses (playbooks = Logic Apps workflows), enables proactive investigation (hunting queries), and visualises data (workbooks = dashboards). Azure Key Vault completes this module: storing secrets (API keys, passwords), cryptographic keys (HSM-backed), and certificates, with access controlled via RBAC and audited via Key Vault diagnostic logs.

sentinel-siem sentinel-soar data-connectors playbooks analytics-rules threat-hunting key-vault secrets-keys-certs
~3h
06

Microsoft Purview — Information Protection & DLP

Microsoft Purview (formerly Microsoft 365 Compliance Centre + Azure Purview) is the compliance umbrella. This module covers the information protection stack: sensitivity labels (classify documents and emails, apply encryption and markings), Data Loss Prevention (DLP) policies (detect and block sharing of sensitive content like credit card numbers, SSNs, health data), retention policies and labels (govern how long content is kept and what happens when it expires), and Insider Risk Management (detect users leaking IP, violating policies, or behaving anomalously). Learn the key differences between these tools and when to use each.

sensitivity-labels dlp-policies retention-policies insider-risk information-protection purview
~2h
07

Microsoft Purview — Compliance Management & eDiscovery

Completing the compliance picture: Compliance Manager (assess posture against GDPR, ISO 27001, NIST, HIPAA — generates a compliance score and recommended actions), Microsoft Purview Audit Standard vs Premium (immutable log of user and admin activity; Premium extends retention to 1 year), eDiscovery Standard vs Premium (legal hold, content search, review sets, export for legal proceedings), Communication Compliance (supervise messages for harassment or regulatory violations), Information Barriers (block communication between user segments), and Microsoft Priva (Subject Rights Requests for GDPR data subject access/deletion requests).

compliance-manager compliance-score purview-audit ediscovery legal-hold communication-compliance information-barriers priva
~2h

Product → Function cheat sheet

SC-900 heavily tests "which product does X". Memorise this mapping before your exam.

Identity & Access: Entra ID = cloud identity platform. Conditional Access = if-then access policies. PIM = just-in-time admin access. Identity Protection = risk-based sign-in detection. SSPR = users reset their own passwords. B2B = partner access. B2C = consumer app auth.
Endpoint & Email Security: Defender for Endpoint = EDR for Windows/Mac/Linux devices. Defender for Office 365 = Safe Links, Safe Attachments, anti-phishing for email. Intune = MDM/MAM for device compliance.
Cloud & Network Security: Defender for Cloud = CSPM (posture / Secure Score) + CWP (threat detection on workloads). Azure Firewall = layer 4/7 managed firewall. NSG = network-layer IP/port filter. WAF = layer 7 OWASP protection. DDoS Protection = volumetric attack mitigation. Azure Bastion = browser-based RDP/SSH without open ports.
SIEM / SOAR / CASB: Microsoft Sentinel = SIEM (log collection + analytics) + SOAR (playbooks). Defender for Cloud Apps = CASB (shadow IT, SaaS visibility). Defender for Identity = on-prem AD attack detection (pass-the-hash, Kerberoasting).
Secrets & Crypto: Azure Key Vault = store secrets (passwords/keys/certs). Keys = used BY Key Vault for crypto operations. Secrets = arbitrary values you retrieve. Managed Identity = no-credential app auth to Azure services.
Compliance: Purview = compliance umbrella. Sensitivity labels = classify + protect documents. DLP = block sharing sensitive data. Retention = lifecycle (keep / delete). Insider Risk = detect anomalous data exfiltration. Compliance Manager = score vs GDPR/ISO/NIST. Audit = immutable activity log. eDiscovery = legal hold + content search. Information Barriers = block communication between segments. Priva = GDPR subject rights requests.

Ready to test your SC-900 knowledge?

60 scenario-based questions across all 4 exam domains. Track your progress, review explanations, and identify gaps. No signup required.

Pass SC-900 in 2 weeks

SC-900 is a beginner exam — 10–12 hours of focused study is enough for most candidates. Here's a realistic plan.

Top 3 common mistakes on SC-900:
1. Confusing Compliance Manager (tracks your compliance posture score) with Audit (immutable activity log).
2. Mixing up Defender for Cloud (CSPM for Azure resources) with Microsoft Sentinel (SIEM for security events).
3. Forgetting that Insider Risk Management detects patterns of risky behaviour while DLP blocks specific data transfers — they solve different problems.
🎧
Study smarter, not just harder

The CertQuests podcast covers Microsoft Defender product comparisons, Zero Trust use cases, and Purview compliance scenarios — all mapped to SC-900 objectives. Perfect for revision on the go.

▶ Listen on Spotify

Continue the Microsoft path

SC-900 opens the door to Microsoft's security and cloud certification tracks.

BEGINNER
Azure AZ-900
Azure Fundamentals — perfect companion to SC-900
INTERMEDIATE
Azure AZ-104
Azure Administrator — next step for cloud ops roles
INTERMEDIATE
CompTIA Security+
Vendor-neutral security cert — great alongside SC-900
ADVANCED
CompTIA CySA+
Cybersecurity Analyst — deeper SIEM & threat analysis
CertQuests is an independent study tool and is not affiliated with or endorsed by Microsoft. "Azure", "Microsoft Entra", "Microsoft Defender", "Microsoft Purview", and "SC-900" are trademarks of Microsoft Corporation.