Exam Details
Microsoft · SC-900
Master foundational security, compliance, and identity concepts across Microsoft Azure and Microsoft 365 environments.
Practice with ExamOS for Microsoft Security, Compliance, and Identity Fundamentals. Learn daily with scenario-based questions, timed quizzes, detailed explanations, and exam-style difficulty.
Try a sample quiz for free : 10 questions, 10 mins.
Who is this for?
Level: Beginner. This foundational exam introduces critical security, compliance, and identity concepts. There are absolutely no formal prerequisites, making it the perfect entry point for non-technical business leaders, students, and junior IT professionals. Microsoft officially recommends having a basic familiarity with networking concepts, cloud computing principles, and general Microsoft Azure or Microsoft 365 environments. Are you ready? You are fully prepared to pass if you can confidently define Zero Trust principles, explain the shared responsibility model, and identify the core functions of Microsoft Entra and Microsoft Purview without needing to configure them technically. Jumpstart your security career with a fast-paced practice sprint today!
Overview
Launch your cybersecurity career with the definitive starting point for understanding enterprise defense. The Microsoft Security, Compliance, and Identity Fundamentals (SC-900) certification validates your core knowledge of how organizations protect their data, manage identities, and ensure regulatory compliance within the Microsoft ecosystem. In today's landscape, where cyber threats and strict privacy regulations constantly make headlines, businesses require all professionals—from IT helpdesk staff to non-technical business leaders—to speak the language of cybersecurity. This foundational credential is meticulously designed for students, business stakeholders, and emerging IT professionals who want to grasp the concepts of Zero Trust architecture, shared responsibility models, and the comprehensive capabilities of Microsoft Entra, Microsoft Defender, and Microsoft Purview. By earning the SC-900 credential, you demonstrate to employers that you understand how comprehensive security solutions are structured, making you a highly attractive candidate for entry-level security roles or strategic business positions. This certification acts as the perfect springboard, providing immediate job readiness, boosting your resume, and laying a rock-solid foundation for advanced, role-based certifications like the SC-200 or SC-300. Start your journey into the highly lucrative cybersecurity sector today.
FAQ
The SC-900 exam typically consists of 40–60 questions. You are given 45–60 minutes for the exam itself, with a total seat time of 85 minutes to allow for instructions and the non-disclosure agreement. The format includes multiple-choice, drag-and-drop, and matching scenarios. Note that Fundamentals exams generally do not include complex case studies or labs.
The passing score is a scaled score of 700 out of 1000. Microsoft uses a scaled scoring system to ensure consistency across different versions of the exam. To build the confidence needed to clear this threshold, ExamOS offers scenario-based practice quizzes that focus on "Service Matching"—helping you perfectly identify which Microsoft tool solves a specific security or compliance problem.
The exam is balanced across four functional pillars. The current weightings are:
The AZ-900 is about general cloud infrastructure (VMs, VNets, Storage). The SC-900 is a "horizontal" certification—it focuses specifically on the security and compliance layer that sits on top of both Azure and Microsoft 365. If you want to specialize in cybersecurity, SC-900 is the better starting point.
No. Microsoft’s "Open Book" feature is only available for Associate, Expert, and Specialty exams. Because SC-900 is a Fundamentals level exam, you must rely entirely on your memory for service names and conceptual definitions. You will not have access to any external documentation during the test.
The standard registration fee is $99 USD in the United States. Prices vary by region and local taxes. If you are a student or a teacher, you may be eligible for a significant discount or even a free voucher through the "Microsoft Learn for Educators" program or by attending a "Microsoft Virtual Training Day."
If you do not pass on your first attempt, you must wait 24 hours before rescheduling. For any subsequent attempts, a 14-day waiting period is required. You are allowed a maximum of five attempts within a 12-month period. Each retake attempt requires a new registration fee.
No. Microsoft Fundamentals certifications do not expire. Once you earn the SC-900 badge, it remains on your transcript permanently. You do not need to take annual renewal assessments. However, it is highly recommended to move on to an Associate-level certification (like SC-200 or SC-300) to keep your skills current as the technology evolves.
There are no formal prerequisites. This exam is ideal for:
After mastering the fundamentals, you should choose a role-based path: