Training course
This is a free, self-paced reading course for SC-900: Microsoft Security, Compliance, and Identity Fundamentals — the entry point to Microsoft’s security certification stack, and an exam that asks you to describe capabilities rather than configure them. That verb matters. SC-900 is won and lost on vocabulary: knowing that Defender for Cloud and Defender for Cloud Apps are different products solving different problems, that a sensitivity label and a retention label answer different questions about the same document, that Secure Score and Compliance Score measure different things. This course is written to build that vocabulary in order, so the distinctions land before you start drilling questions.
The course is organized as one module per official exam domain, in the order Microsoft publishes them, and each module carries the domain’s published weight. That structure keeps your effort proportional to the exam’s: the Microsoft security solutions domain alone is 35–40% of SC-900, and it is the largest module here. Every module ends with its key terms and suggested further reading, which matters more on a concept exam than on a hands-on one — the terms are the material. The course works as a glossary you come back to as well as a syllabus you read through once.
What the course covers
Describe the concepts of security, compliance, and identity
Module 1 · 10–15%The foundations the rest of the exam leans on: security methodologies including Zero Trust and defense in depth, the shared responsibility model, encryption and hashing, and the basics of governance, risk, and compliance. Then the identity groundwork — authentication versus authorization, identity providers, directory services, federation, and why the perimeter moved from the network to the identity.
Describe the capabilities of Microsoft Entra
Module 2 · 25–30%The identity control plane. Microsoft Entra ID as an identity provider; hybrid identity through password hash synchronization, pass-through authentication, and AD FS; authentication methods including MFA, FIDO2, Windows Hello for Business, and Temporary Access Pass; Conditional Access; Entra ID Protection and its sign-in and user risk signals; Privileged Identity Management, entitlement management, and access reviews; External ID for B2B collaboration; lifecycle workflows; and which capabilities sit in the Free, P1, and P2 licensing tiers.
Describe the capabilities of Microsoft security solutions
Module 3 · 35–40%The largest domain, covered in four passes. Azure network security — DDoS Protection, Azure Firewall, Web Application Firewall, Bastion, network security groups, VNet segmentation, and Key Vault. Defender for Cloud — cloud security posture management, workload protection, Secure Score, the regulatory compliance dashboard, and multi-cloud connectors. Microsoft Sentinel as combined SIEM and SOAR, with data connectors, analytics rules, workbooks, playbooks, and KQL. And Microsoft Defender XDR — Defender for Endpoint, Office 365, Identity, and Cloud Apps, plus Defender Threat Intelligence and Vulnerability Management.
Describe the capabilities of Microsoft compliance solutions
Module 4 · 20–25%Microsoft Purview and the wider trust posture: the Service Trust Portal, Microsoft’s privacy principles, and Compliance Manager with its Compliance Score. Then the data-governance toolkit — sensitive information types and trainable classifiers, Content explorer and Activity explorer, sensitivity labels set against retention labels, data loss prevention, records management, insider risk management, eDiscovery in its Standard and Premium forms, and Audit Standard versus Audit Premium retention.
How to use it
Read a module, then test that domain immediately rather than saving all the questions for the end. On a concept exam the gap between “I have read this” and “I can pick this out of four plausible options” is wide, and only questions expose it. The free SC-900 sample is the quickest way to see what that feels like; the full SC-900 practice exam is where you work until you are clearing every domain rather than carrying a weak one on the back of a strong one. Pay particular attention to items where two Microsoft products could both plausibly be the answer — that is where SC-900 does most of its discriminating.
You do not need an Azure subscription to pass this exam, but a free tenant helps the names stick: seeing Conditional Access and a sensitivity label in the portal once turns an abstraction into an object. For exam logistics — length, question count, the 700 out of 1000 pass mark, pricing, and the renewal policy for fundamentals credentials — see the SC-900 certification guide.
Course not found.
Frequently asked questions about the SC-900 training course
Is the SC-900 training course free?
Yes. The course is free to read and requires no signup or account. It is funded by the same practice-exam catalogue it sits alongside.
How is the course structured?
One module per official SC-900 exam domain, in Microsoft’s published order, with each module weighted to the domain’s published percentage range. Within each module the material is broken into short lessons, followed by key terms and further reading. Because SC-900 is a vocabulary exam, the key-term sections carry more of the load here than they would on a hands-on course.
Does this replace Microsoft’s official training?
No. Microsoft Learn publishes free official learning paths for SC-900, and they are the authoritative source. This course is an independent study companion — written to be read quickly and to slot alongside practice questions — not a substitute for the official study guide.
Do I need security or Azure experience before starting?
No. SC-900 requires no hands-on administration experience, and the course assumes none. It is written for people entering the field — aspiring security analysts, IT staff moving into security-adjacent work, compliance and audit professionals learning the Microsoft cloud, and decision-makers who need shared vocabulary with a security team. AZ-900 is a peer fundamentals exam, not a prerequisite, though the AZ-900 course gives useful context for the Azure networking topics in module 3.
What should I do after finishing the course?
Move to the SC-900 practice exam and work until your weakest domain is comfortable, not just your average. After the exam, the usual next step is a role-based security credential — SC-500 for security operations work, or an associate-tier Azure credential if you are heading toward administration.
Is the course current with the latest SC-900 outline?
The course is built against the four-domain outline and weightings published on the SC-900 credential page, including the Microsoft Entra naming that replaced Azure Active Directory. Microsoft can revise the outline at any time; verify the current study guide on Microsoft Learn before you sit the exam.
Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by Microsoft Corporation. Microsoft®, Microsoft Certified®, Microsoft Entra™, Microsoft Defender™, Microsoft Purview™, Microsoft Sentinel™, and SC-900 are trademarks or registered trademarks of Microsoft Corporation. Use of these marks is solely to identify the certification for which these study materials are intended. The SC-900 exam objectives and skill outline are the property of Microsoft Corporation; candidates should review the official, current study guide directly on Microsoft Learn.
All course content, questions, answers, and explanations on Certifym are original content created for study purposes. They are not actual Microsoft training materials or examination questions and are not represented as such. Studying with these materials does not guarantee a passing result on any live certification exam. Exam requirements, format, domain weights, pricing, and renewal policies are set by Microsoft and may change; always verify current details on Microsoft Learn before scheduling your exam.
