Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
Everything you need to know about the Microsoft Certified: Security, Compliance, and Identity Fundamentals, the entry point to Microsoft security certifications, as of 2026. This guide covers the SC-900 exam on the outline that takes effect October 21, 2026, the four domains and their weights, the exam length and passing score, the no-expiry policy, DoD 8140 status, and the roles it supports.
The Microsoft Certified: Security, Compliance, and Identity Fundamentals, earned through exam SC-900, is Microsoft's entry-level certification for the security side of its cloud. It sits alongside AZ-900 and MS-900 in the fundamentals tier, and it is the one that covers Entra, Defender, Sentinel, and Purview.
A fundamentals exam tests what services do and when you would reach for them, not how to configure them. SC-900 asks you to recognize Zero Trust and defense in depth, tell authentication from authorization, know which Defender product protects which surface, and explain what a sensitivity label or a Conditional Access policy is for. The audience Microsoft names is business stakeholders, IT professionals new to security, and students, with a working familiarity with Azure and Microsoft 365 assumed.
SC-900 has no prerequisites and, like every Microsoft fundamentals certification, it does not expire. It is issued and maintained by Microsoft. The English exam updates on October 21, 2026, and this page describes that outline: the same four domains and weights, with small changes to the Entra identity types skill (workload identities are added) and to the Microsoft Defender XDR skill.
Shared responsibility, defense in depth, Zero Trust, encryption, GRC, and core identity concepts. 10 to 15%.
Entra ID, identity types, authentication and MFA, Conditional Access, roles, and ID Governance and Protection. 25 to 30%.
Azure network security, Key Vault, Defender for Cloud, Sentinel, and the Defender XDR family. The largest domain at 35 to 40%.
Service Trust Portal, Purview, Compliance Manager, classification, labels, DLP, retention, insider risk, eDiscovery, and audit. 20 to 25%.
Four things that make the Security, Compliance, and Identity Fundamentals the first security credential for people who work in Microsoft environments.
Most organizations that run Microsoft 365 already own Entra ID, Defender, and Purview, and many have Sentinel. SC-900 is the only exam that covers all of them in one sitting, so it gives a new hire or a non-security colleague the map of what the company has already bought and what each piece is for.
The exam is $99 in the US, runs 45 minutes, has no prerequisites, and the certification never expires. That combination makes SC-900 one of the cheapest ways to put a recognized security credential on a resume, and a common first exam for students and career changers.
SC-300 (Identity), SC-200 (Security Operations), SC-400 (Information Protection), and the new SC-500 all assume you know what the services are before they test you on configuring them. Our article on the AZ-500 to SC-500 change explains the current role-based ladder.
SC-900 is not a DoD 8140 credential. Microsoft does not appear on the Approved Qualifications Matrix, so it will not satisfy a cyber-coded position on its own. The current matrix is published at the DoD Cyber Exchange.
Its weight is market-driven instead. Microsoft partners, managed service providers, and enterprises standardized on Microsoft 365 and Azure ask for it because it maps to the products their staff touch every day.
Everything you need to know about the certification and the SC-900 exam as of the October 21, 2026 outline.
SC-900 is a starting point, not a destination. From here most people either move into a Microsoft role-based security exam, add a vendor-neutral security credential, or build the Azure administration skills that security work sits on top of.
The role-based next step on the Microsoft security track. AZ-500 retired on August 31, 2026, and SC-500 replaced it, covering the security of Microsoft cloud and AI workloads. The Entra, Defender, and Sentinel vocabulary from SC-900 is exactly what SC-500 assumes on day one.
The vendor-neutral counterpart. Security+ covers the same concepts SC-900 introduces, without the Microsoft product names, and it sits on the DoD 8140 matrix. If your goal is a government or contractor role, this is the credential that clears the HR filter. See our Security+ guide.
The identity move. SC-300 is the role-based Microsoft Entra exam, covering the configuration of users, authentication, Conditional Access, and identity governance that SC-900 only asks you to describe. Since Entra is the second-largest SC-900 domain, this is the most direct step up for anyone drawn to identity work.
SC-900 sits at the fundamentals tier of Microsoft's certification path. It is the first step, and from there the path branches into role-based Microsoft security exams or vendor-neutral security credentials.
The security vocabulary
Operate and secure
Pick your path
Two questions to answer before you commit: can you sit it, and should you pursue SC-900 specifically. Here's a straight answer to both.
No prerequisites and no required experience.
SC-900 has no prerequisites at all. You register through Pearson VUE, or through Certiport if you are a student, pay the $99 US fee, and sit a 45-minute exam. Microsoft writes it for business stakeholders and people new to IT security as much as for technical staff, so it is a realistic first certification with no IT background required.
Short exam, long list of product names.
Microsoft recommends familiarity with Azure and Microsoft 365, and the exam rewards it. You will be asked to pick the right Defender product, Purview feature, or Entra capability for a scenario, which means knowing what several dozen services do. Work through the Microsoft Learn path, click around a trial tenant, and use our SC-900 practice test to find the domains where the names have not stuck yet.
A fundamentals certification supports a hire rather than qualifying one on its own. These are the roles where SC-900 shows up in job postings and where the knowledge it tests is used every day.
The first rung of a security operations career. Watches alerts, triages incidents, and works inside tools like Microsoft Sentinel and the Defender portal. SC-900 gives a new analyst the product vocabulary the job posting assumes.
Manages users, groups, roles, MFA, and Conditional Access in Microsoft Entra ID. The Entra domain of SC-900 is the direct on-ramp, and the role-based SC-300 exam is the natural next credential.
Works with sensitivity labels, retention, data loss prevention, eDiscovery, and Compliance Manager in Microsoft Purview. The compliance domain of SC-900 covers exactly the tools this role uses day to day.
Runs a tenant and inherits its security settings. Many M365 admins take SC-900 to understand Defender for Office 365, Entra ID protections, and Purview policies they are already responsible for.
The help desk technician who wants to move toward security. SC-900 shows a hiring manager you understand Zero Trust, identity, and the Microsoft security stack before you have a security title.
Explains Microsoft security, compliance, and identity products to customers and maps them to business needs. SC-900 is a common ask for account and presales staff at Microsoft partners.
SC-900 is most often weighed against its Azure sibling, the vendor-neutral Security+, and the role-based exam that follows it. Here is how the four line up.
| SC-900 | Azure Fundamentals (AZ-900) | CompTIA Security+ (SY0-701) | Cloud and AI Security Engineer (SC-500) | |
|---|---|---|---|---|
| Issuer | Microsoft | Microsoft | CompTIA | Microsoft |
| Level | Fundamentals | Fundamentals | Entry to intermediate, vendor-neutral | Role-based |
| Focus | Microsoft security, compliance, and identity concepts | Cloud concepts and Azure basics | General security concepts and operations | Securing Microsoft cloud and AI workloads |
| Domains | 4 | 3 | 5 | See Microsoft Learn |
| Prerequisites | None | None | None (Network+ and 2 years recommended) | See Microsoft Learn |
| Exam | 45 min, count not published | 45 min, count not published | Up to 90 questions, 90 min | See Microsoft Learn |
| Passing Score | 700 of 1000 | 700 of 1000 | 750 of 900 | See Microsoft Learn |
| Cost (US) | $99 | $99 | About $439 | See Microsoft Learn |
| Validity | Does not expire | Does not expire | 3 years, renews with CEUs | See Microsoft Learn |
| DoD 8140 | Not listed | Not listed | Listed | Not listed |
| Best For | First security credential in a Microsoft shop | Cloud literacy for beginners and non-technical roles | Vendor-neutral security and government roles | Security engineers on Microsoft cloud |
Pricing varies by region and taxes. No Microsoft certification appears on the DoD 8140 Approved Qualifications Matrix; their recognition is market-driven. SC-500 replaced AZ-500 when that exam retired on August 31, 2026, and its exam details are published on Microsoft Learn. Security+ facts are from our Security+ guide.
As a Microsoft training partner, our Security, Compliance, and Identity Fundamentals boot camp covers all four SC-900 domains with official Microsoft courseware, an instructor who works in Entra, Defender, and Purview, your exam voucher, and a free retake included, so you leave exam-ready.
Where to start, how the Microsoft security ladder changed in 2026, and how to study a vocabulary-heavy exam.
Where SC-900 sits among the first certifications a beginner should consider, what each one proves to an employer, and how to sequence them without paying for exams you do not need.
Zero Trust is the first concept SC-900 tests. This piece explains the model in plain terms and lists the certifications, Microsoft and vendor-neutral, that cover it in depth.
The Microsoft credentials employers ask for most this year, where the fundamentals exams fit, and which role-based exams candidates are moving toward after SC-900.
What changed when Microsoft retired the Azure Security Engineer exam and what the new Cloud and AI Security Engineer credential covers. Required reading before you plan the step after SC-900.
The full Microsoft map, from the fundamentals tier through role-based associate and expert exams, showing how SC-900 connects to the security, identity, and compliance tracks.
The same fundamentals-or-skip question applied to the Azure side. Useful if you are deciding whether SC-900, AZ-900, or both belong at the start of your Microsoft path.
A study method for the terminology-heavy exams. SC-900 is mostly definitions and product capabilities, so the way you learn vocabulary matters more than it does for hands-on exams.
The SC-900 exam is organized into four domains, each carrying its own weight. Microsoft security solutions is the heaviest at 35 to 40 percent, followed by Entra at 25 to 30 percent. Click any domain for what it covers.
The vocabulary the rest of the exam assumes: the shared responsibility model, defense in depth, Zero Trust, encryption and hashing, and governance, risk, and compliance. It also covers identity as the security perimeter, authentication versus authorization, identity providers, directory services, and federation.
What Microsoft Entra ID is and the identity types it manages, including workload identities and hybrid identity, plus authentication methods, multifactor authentication, password protection, and Conditional Access. The domain closes with Entra roles and role-based access control, ID Governance, access reviews, Privileged Identity Management, and ID Protection.
The heaviest domain. Core Azure security services such as DDoS Protection, Azure Firewall, Web Application Firewall, network segmentation, network security groups, Azure Bastion, and Key Vault, then Microsoft Defender for Cloud and cloud security posture management. It finishes with Microsoft Sentinel as SIEM and SOAR, and the Microsoft Defender XDR family including Defender for Office 365, Endpoint, Cloud Apps, Identity, Vulnerability Management, Threat Intelligence, and the Defender portal.
The Service Trust Portal and Microsoft privacy principles, then the Microsoft Purview portal with Compliance Manager and compliance score. It also covers data classification, Content explorer and Activity explorer, sensitivity labels, data loss prevention, records management and retention, insider risk management, eDiscovery, and audit.
Domains and weights reflect the Microsoft SC-900 skills-measured outline that takes effect October 21, 2026 for the English exam. The update keeps the same domains and weights and makes minor changes to the Entra identity types and Microsoft Defender XDR skill areas. Microsoft refreshes exams periodically, so confirm the current outline on Microsoft Learn before scheduling.
The questions candidates ask most often when researching the Microsoft Security, Compliance, and Identity Fundamentals certification.
The Microsoft Certified: Security, Compliance, and Identity Fundamentals, earned by passing exam SC-900, is Microsoft's entry-level certification for the security side of its cloud. It covers core security and identity concepts and the capabilities of Microsoft Entra, Microsoft's security solutions such as Defender and Sentinel, and its compliance solutions in Microsoft Purview. It's a fundamentals exam, so it tests what these services do, not how to configure them.
Microsoft updates the English version of SC-900 on October 21, 2026. The four domains and their weights stay the same. The changes are minor and land in two skill areas: identity types in Microsoft Entra ID, which now includes workload identities, and threat protection with Microsoft Defender XDR. This page describes the October 21, 2026 outline.
No. SC-900 has no prerequisites and no required experience, so anyone can register and sit the exam. Microsoft aims it at business stakeholders, new and existing IT professionals, and students, and recommends that you be familiar with Azure and Microsoft 365 before you take it. That familiarity is a suggestion, not a gate.
The four domains are Describe the concepts of security, compliance, and identity (10 to 15 percent), Describe the capabilities of Microsoft Entra (25 to 30 percent), Describe the capabilities of Microsoft security solutions (35 to 40 percent), and Describe the capabilities of Microsoft compliance solutions (20 to 25 percent). Security solutions is the heaviest domain by a wide margin.
Microsoft does not publish the question count or a fixed mix of formats for SC-900. Fundamentals exams are shorter than the role-based exams, and you have 45 minutes to complete it. The exam sandbox on Microsoft Learn shows the question types in the same interface you will use on exam day, so run through it before you sit the exam.
You need 700 on a scale of 100 to 1000 to pass. Microsoft uses scaled scoring, so 700 does not mean 70 percent correct. Some items count for more than others and unscored pilot items may appear, so treat the passing line as an overall performance mark rather than a straight percentage.
The SC-900 exam costs $99 USD in the United States, with pricing that varies by country and local taxes. It's delivered through Pearson VUE, or through Certiport for students. Training Camp's Security, Compliance, and Identity Fundamentals boot camp includes the exam voucher in the program fee, along with a free retake.
No. Microsoft certifications don't appear on the DoD 8140 Approved Qualifications Matrix, so SC-900 on its own won't satisfy a cyber-coded position requirement. Its value is with employers and Microsoft partners who run on Entra ID, Microsoft 365, and Azure and want staff who understand the security stack they have already bought. If you need an 8140-approved entry credential, CompTIA Security+ is the usual choice. See the full DoD 8140 work role paths.
No. Microsoft fundamentals certifications do not expire and have no renewal requirement. Once you pass SC-900 the credential stays active on your Microsoft Learn transcript. That is different from Microsoft's role-based certifications, which are valid for one year and renew through a free online assessment.
SC-900 by itself is rarely the qualifying credential for a job, but it supports entry into roles such as junior security analyst, identity and access administrator, compliance analyst, Microsoft 365 administrator, and security presales engineer, and it helps IT support staff move toward security. Employers read it as proof you know what Entra, Defender, Sentinel, and Purview do, which is the baseline for working around them.
They answer different questions. SC-900 is a 45-minute, $99 fundamentals exam about Microsoft's security, identity, and compliance products, and it never expires. CompTIA Security+ is a vendor-neutral, 90-minute exam of up to 90 questions that is on the DoD 8140 matrix and renews every three years. If you work in a Microsoft shop and want a fast start, SC-900 first. If you need a credential that HR filters and government roles recognize, Security+. Many people end up with both.
SC-900 is an entry-level exam, but it is not a giveaway. The difficulty is breadth: you're expected to know what several dozen Microsoft services do and which one solves a given problem, and the security solutions domain alone covers Azure network security, Defender for Cloud, Sentinel, and the whole Defender XDR family. Plan on a few weeks of preparation with the Microsoft Learn path and a practice test, and the ones who struggle are usually the ones who skipped the compliance domain.
For people who work in or sell into Microsoft environments and don't yet have a security credential, yes. It costs $99, takes a few weeks to prepare for, never expires, and gives you the vocabulary for Entra, Defender, Sentinel, and Purview that role-based exams like SC-500 and SC-300 assume. It's a weaker fit if you already hold Security+ or a role-based Microsoft security certification, or if you need a credential that appears on the DoD 8140 matrix.
If you're weighing the certification, planning the Microsoft security path, or arranging training for a team, tell us where you are and we'll help you map out the right path.