Back to blog
Study Tips13 min read

How to Pass the Microsoft SC-900 Exam in 2026: A 4-Week Study Plan for the New 28 July Objectives

Microsoft updated the SC-900 objectives on 28 July 2026, and most study material online still teaches the old list. Here is a realistic 4-week SC-900 study plan built on the current skills measured, including the new agent ID content.

Tom Ashford

Tom Ashford · Security Certifications Lead

11 August 2026

If you are searching for an SC-900 study plan right now, you have a timing problem that most candidates do not know about. Microsoft refreshed the skills measured for Exam SC-900 on 28 July 2026, and a large share of the study guides, video courses and question banks ranking on Google were written against the previous objectives. They are not wildly wrong, but they miss the new content, and the gaps sit in the two heaviest domains.

This guide fixes that. Below is a four-week plan built directly against the current SC-900 objectives, with the real domain weights, the specific changes Microsoft made in July, and a week-by-week schedule you can follow around a full-time job. SC-900 is a beginner exam, but it is broad, and broad exams punish unstructured revision more than hard ones do.

What SC-900 Actually Tests in 2026

SC-900 is Microsoft Security, Compliance, and Identity Fundamentals. It is a conceptual exam. You are not asked to configure anything, you are asked to explain what a Microsoft security product does and when you would reach for it. That distinction matters enormously for how you revise, and it is the single biggest reason candidates over-prepare in the wrong direction.

Here are the logistics, confirmed on Microsoft Learn:

DetailSC-900 in 2026
Full nameMicrosoft Security, Compliance, and Identity Fundamentals
Objectives versionSkills measured as of 28 July 2026
Time limit45 minutes
QuestionsTypically 40 to 60
Pass mark700 out of 1000, scaled
PriceUSD 99, varies by country or region
LevelBeginner, no prerequisites
DeliveryPearson VUE, test centre or online proctored
RenewalFundamentals certifications do not expire

Exam Tip: The 700 pass mark is a scaled score, not a percentage. It does not mean you need 70% of the questions correct. Microsoft weights questions by difficulty, so chasing an exact percentage on practice tests is a poor proxy for readiness. Consistent coverage across all four domains is the better signal.

The 45-minute limit is the detail that catches people out. That is roughly one minute per question with no meaningful buffer. There is no time to reason your way from first principles to an answer you never learned. You either recognise the product being described or you do not.

The four domains and their weights

DomainWeightWhat it really tests
Describe the concepts of security, compliance, and identity10 to 15%Shared responsibility, defence in depth, Zero Trust, encryption and hashing, GRC concepts, authentication versus authorisation
Describe the capabilities of Microsoft Entra25 to 30%Entra ID, identity types, hybrid identity, MFA, Conditional Access, RBAC, PIM, ID Protection, access reviews
Describe the capabilities of Microsoft security solutions35 to 40%Azure network security, Key Vault, Defender for Cloud, CSPM, Sentinel, the full Defender XDR family
Describe the capabilities of Microsoft compliance solutions20 to 25%Service Trust Portal, Purview portal, Compliance Manager, sensitivity labels, DLP, retention, insider risk, eDiscovery, audit

Domains 2 and 3 together account for 60 to 70% of the exam. If your revision time is limited, that is where it goes.

What Changed in the SC-900 Objectives on 28 July 2026

Microsoft's change log describes every change as minor, and no domain was added, removed or reweighted. That framing is fair but slightly misleading for a study plan, because "minor" changes to a fundamentals exam still translate into questions you cannot answer if your material predates them.

Five objectives were revised:

  • Describe function and identity types of Microsoft Entra ID. This is the important one. The objective now explicitly includes agent ID, covering identities assigned to AI agents rather than to humans or traditional workloads. Almost no pre-August study material covers this.
  • Describe access management capabilities of Microsoft Entra ID. Conditional Access and RBAC framing was refreshed.
  • Describe core infrastructure security services in Azure. Minor updates across the network security services.
  • Describe capabilities of Microsoft Sentinel. Updated SIEM and SOAR framing.
  • Describe Microsoft Service Trust Portal and privacy principles. Minor refresh.

The audience profile and all four domain groupings were left unchanged.

Exam Tip: If you are using a video course or PDF published before August 2026, treat identity types in Entra as a known gap and study agent ID separately. Microsoft has been adding agent and Copilot identity content across its security certifications throughout 2026, and SC-900 is now part of that pattern.

The practical consequence is good news. The exam did not get harder, and anything you already learned still counts. You just need to patch a handful of specific topics rather than start again.

Before You Start: What You Need for This SC-900 Study Plan

This plan assumes six to seven hours of study per week across four weeks, which is roughly one hour on weeknights plus a longer weekend session. That is around 26 hours in total, which is a realistic figure for someone with some IT exposure but no deep Microsoft security background.

Adjust honestly:

  • Complete beginner, no IT background. Stretch this to six weeks by splitting weeks 2 and 3 in half. Do not compress it.
  • Working IT professional already using Microsoft 365 or Azure. Three weeks is achievable. Fold week 1 into week 2.
  • Already hold AZ-900. You have a genuine head start on domain 1 and the Azure portions of domain 3. Our AZ-900 study plan covers ground that overlaps directly.

Three things to set up before day one:

  1. A free Microsoft 365 developer tenant or Azure free account. You are not tested on configuration, but clicking through the Entra admin centre and the Defender portal makes the product names stick in a way that reading never does.
  2. The official skills measured list, downloaded on the day you start so you know you have the post-28 July version.
  3. A practice question bank you can run repeatedly. Recognition speed is the skill SC-900 actually rewards, and that is built through repetition, not through re-reading notes.

The 4-Week SC-900 Study Plan

Each week ends with a checkpoint. Do not move forward until you can pass it, because every domain in SC-900 builds vocabulary the later domains assume you already have.

WeekFocusDomain coverageTime
1SCI concepts and identity foundationsDomain 1, start Domain 25 to 6 hours
2Microsoft Entra in depthDomain 26 to 7 hours
3Microsoft security solutionsDomain 37 to 8 hours
4Purview compliance and full revisionDomain 4 and revision6 to 7 hours

Week 1: Concepts and identity foundations

Domain 1 is only 10 to 15% of the exam, but it is the vocabulary layer for everything else. Rush it and domains 2 to 4 become memorisation instead of understanding.

Cover this week:

  • The shared responsibility model, and specifically which responsibilities shift between IaaS, PaaS and SaaS
  • Defence in depth as a layered model
  • The Zero Trust model and its guiding principles
  • Encryption versus hashing, symmetric versus asymmetric
  • Governance, risk and compliance concepts
  • Identity as the primary security perimeter
  • Authentication versus authorisation, stated precisely
  • Identity providers, directory services and Active Directory, federation

Checkpoint: explain the difference between authentication and authorisation, and between encryption and hashing, out loud in one sentence each without notes. These two pairs appear in some form on almost every sitting.

Week 2: Microsoft Entra in depth

Domain 2 is 25 to 30% of the exam and contains the newly updated identity types objective. This is your highest-value week per hour spent.

Cover this week:

  • Microsoft Entra ID: what it is and how it differs from on-premises Active Directory
  • Identity types, including agent ID, plus user, device, service principal and managed identity
  • Hybrid identity and why organisations run it
  • Authentication methods, MFA, and password protection and management
  • Conditional Access: signals, decisions and enforcement
  • Entra roles and role-based access control
  • Entra ID Governance, access reviews, Privileged Identity Management, and ID Protection

The four governance and protection features are the most commonly confused set on the entire exam. Learn them by the question each answers:

  • ID Governance asks: who should have access, and is that still appropriate?
  • Access reviews ask: does this person still need this access today?
  • PIM asks: can this privileged role be temporary and approved rather than permanent?
  • ID Protection asks: does this sign-in look risky right now?

Checkpoint: given a one-line scenario, name the correct Entra feature in under ten seconds. That is the actual exam task.

Week 3: Microsoft security solutions

Domain 3 is the largest at 35 to 40%. It is also the widest, covering Azure infrastructure security, posture management, SIEM and the Defender XDR family.

Cover this week:

  • Azure DDoS Protection, Azure Firewall, Web Application Firewall
  • Network segmentation with virtual networks, network security groups, Azure Bastion
  • Azure Key Vault
  • Microsoft Defender for Cloud, Cloud Security Posture Management, and how policies and recommendations improve posture
  • Microsoft Sentinel, and the definitions of SIEM and SOAR
  • Defender XDR: Defender for Office 365, for Endpoint, for Cloud Apps, for Identity, Vulnerability Management, Threat Intelligence, and the Defender portal

The Defender family is where most SC-900 failures happen, because the names are similar and the distinctions are one word wide. Build a single table mapping each Defender product to the one asset it protects: Office 365 to email and collaboration, Endpoint to devices, Cloud Apps to SaaS applications, Identity to on-premises Active Directory signals, Cloud to Azure and multicloud resources.

Exam Tip: Defender for Identity protects on-premises Active Directory, while Entra ID Protection covers cloud identity risk. Swapping these two is one of the most reliably punished mistakes on SC-900. If you learn one distinction perfectly this week, make it this one.

Checkpoint: write the Defender mapping table from memory, then define SIEM and SOAR in one sentence each.

Week 4: Purview compliance and full revision

Domain 4 is 20 to 25%, and it is almost entirely Microsoft Purview. Split the week: four days new material, three days revision.

Cover this week:

  • Service Trust Portal offerings and Microsoft's privacy principles
  • The Microsoft Purview portal, Compliance Manager, and compliance score
  • Data classification, Content explorer and Activity explorer
  • Sensitivity labels and label policies
  • Data loss prevention
  • Records management, retention policies, retention labels and label policies
  • Insider risk management, eDiscovery, and audit solutions

Then revise. Spend the final three days on timed practice questions across all four domains rather than on notes. You are training recall speed for a 45-minute exam, and passive re-reading does not build that.

Checkpoint: two full timed practice runs at 45 minutes, scoring consistently across every domain rather than carrying one weak area. A lopsided score is the clearest sign you are not ready.

Common Mistakes That Fail SC-900 Candidates

  • Studying like it is a technical exam. SC-900 asks what a product does, not how to configure it. Deep-diving Conditional Access policy syntax is wasted time.
  • Using pre-August 2026 material without patching it. The 28 July update is recent enough that most search results have not caught up. Agent ID is the clearest gap.
  • Ignoring the clock. At roughly a minute per question, hesitation is expensive. Flag and move on rather than stalling.
  • Skipping domain 1 as "just theory". Zero Trust, shared responsibility and the auth pair are woven through the scenario wording in every other domain.
  • Confusing the Defender products. This is the highest-frequency failure point on the exam. Fix it with a mapping table, not with more reading.
  • Treating practice scores as percentages. The pass mark is scaled. Even coverage beats a high average with one weak domain.

Where SC-900 Fits in Your Certification Path

SC-900 is a genuine entry point. It has no prerequisites, it does not expire, and it is designed for business stakeholders and students as well as IT professionals. It is worth being clear-eyed about what it is: a fluency credential, not a role-ready one. It proves you can hold a sensible conversation about Microsoft's security stack.

The usual next steps after SC-900 are SC-200 for security operations or SC-300 for identity and access administration. If you are unsure which suits your role, our SC-200 versus SC-300 comparison breaks down the day-to-day work each one maps to. For a fuller look at cost, domains and career value before you commit, see Microsoft SC-900 Explained.

Frequently Asked Questions

What is SC-900 certification?

SC-900 is the exam for Microsoft Certified: Security, Compliance, and Identity Fundamentals. It validates foundational knowledge of security, compliance and identity concepts and how Microsoft services such as Entra, Defender, Sentinel and Purview address them. It is a beginner-level certification with no prerequisites, and it does not expire.

Is SC-900 a difficult exam?

SC-900 is one of Microsoft's easier certifications, but it is broad rather than deep. Most candidates who fail do so because they underestimated the breadth of product names in the Entra and Defender families, or ran out of time in the 45-minute window. With four weeks of structured study and consistent practice questions, a first-time pass is a realistic target.

Which is better, SC-200 or SC-900?

They serve different purposes, so neither is strictly better. SC-900 is a fundamentals exam that explains what Microsoft security products do, while SC-200 is a role-based associate exam that tests whether you can actually operate Microsoft Sentinel and Defender XDR as a security operations analyst. Take SC-900 first if you are new to Microsoft security, and go to SC-200 when you need a credential that maps to a SOC analyst job.

Is SC-900 a beginner certification?

Yes. Microsoft classifies SC-900 as beginner level, it carries no prerequisites, and its stated audience includes business stakeholders and students alongside IT professionals. Some familiarity with Azure and Microsoft 365 helps, but it is not required.

How much does the SC-900 exam cost?

The SC-900 exam is USD 99 in the United States, with pricing varying by the country or region in which it is proctored. It is booked through Pearson VUE and can be taken at a test centre or online with a proctor. Students and educators can also schedule through Certiport.

Ready to Start Practising?

Reading about Conditional Access, Purview and the Defender family will get you partway. Recognising them instantly under a 45-minute clock is what actually passes SC-900, and that only comes from working through questions until the product names stop blurring together.

CertCrush has an SC-900 course built around the current objectives, with practice questions that mirror the real exam's scenario wording and pacing. Work through them domain by domain alongside this plan, and use your scores to find the weak area before the exam does.

Create a free CertCrush account and start your first SC-900 practice session today, or browse the full course catalogue to plan what comes after it.

SC-900MicrosoftAzureStudy PlanSecurity Compliance and IdentityMicrosoft EntraExam Prep
Tom Ashford

Written by

Tom Ashford · Security Certifications Lead

Tom spent over a decade in security operations and consulting before turning to full-time exam-prep writing. He covers the big security certifications — CISSP, CISM, CISA, Security+ and the rest of the alphabet — with a soft spot for the questions everyone gets wrong. His rule for every article: if it doesn’t help you score marks, it doesn’t go in.

All articles by Tom

Practise for Microsoft SC-900free

10 real exam-style questions with full explanations, no account needed. Then unlock the complete bank with an exam-readiness score and a daily plan built around your exam date.