DEV Community

Cover image for SC-900 in 2026: The Complete Study Series (4 Domains, Free Labs, 60+ Practice Questions)
CyberTTopic
CyberTTopic

Posted on

SC-900 in 2026: The Complete Study Series (4 Domains, Free Labs, 60+ Practice Questions)

I passed the SC-900: Microsoft Security, Compliance, and Identity Fundamentals exam, and while studying I noticed something: almost every free guide out there is the same list of definitions copied from the learning path. Very few of them let you do anything.

So I wrote the series I wish I had found — five posts that cover the four exam domains, each one with:

  • Diagrams instead of walls of text
  • Hands-on labs you can complete in 10–20 minutes in a free tenant
  • 10–12 practice questions per domain with the reasoning behind each answer, not just the letter
  • An "exam trap" section with the confusions that actually cost people points

SC-900 study series cover

⚠️ Read this before you start. Microsoft updated the SC-900 skills measured on July 28, 2026. Always open the official study guide and check the "Skills measured as of" date before your exam. This series follows the current four-domain structure, but Microsoft renames products often (Azure AD → Microsoft Entra ID, Azure AD B2C → Microsoft Entra External ID, and so on).


What SC-900 actually is

It's a fundamentals certification. There is no lab in the exam, no PowerShell, no configuration. What it measures is whether you can look at a business problem and say "that's a job for Conditional Access" or "that's a Purview retention policy."

Typical exam facts:

Item Detail
Level Fundamentals (entry level)
Questions Around 40–60, multiple choice and multi-select
Passing score 700 out of 1000
Prerequisites None
Good for Support, helpdesk, sales, compliance, and anyone entering cloud security

Always confirm duration and pricing on the official exam page, since those change by region.

The four domains and their weight

SC-900 exam domains and weight

# Domain Weight Post
1 Security, compliance and identity concepts 10–15% Part 1
2 Capabilities of Microsoft Entra 25–30% Part 2
3 Capabilities of Microsoft security solutions 35–40% Part 3
4 Capabilities of Microsoft compliance solutions 15–20% Part 4

Two thirds of the exam is domains 2 and 3. If you are short on time, that is where you spend it. Domain 1 is short but it is the vocabulary everything else is built on — skipping it makes the other three harder, not faster.


Build your free lab (what still works in 2026)

Here is the part most guides get wrong. A lot of them still tell you to join the Microsoft 365 Developer Program and get an instant sandbox. That program no longer accepts personal accounts: it now requires a qualifying subscription such as Visual Studio Enterprise/Professional, or partner/support program membership. If you don't qualify, you need another path.

Free SC-900 lab setup

The path that works

  1. Create an Azure free account with a personal email. Creating a directory costs nothing; you only pay for resources you deploy, and you get starting credit.
  2. Create a new Microsoft Entra tenant. Azure portal → Microsoft Entra IDManage tenantsCreate. This gives you the Entra ID Free tier: users, groups, security defaults, basic reports.
  3. Start the Entra ID P2 trial (30 days) only when you're ready to touch Conditional Access, Identity Protection and PIM. Starting it on day one wastes half of it.
  4. Start a Microsoft 365 E5 trial (30 days) when you reach domains 3 and 4 — that's what unlocks the Defender and Purview portals.
  5. Set a calendar reminder for day 25 of each trial so nothing surprises you.

💡 Use a naming convention from the start: svc-, usr-, grp- prefixes. It costs nothing and it makes the labs (and the screenshots you'll take) much easier to read.

If you can't build a tenant

Every post in this series includes a paper version of the lab: a table to complete or a diagram to fill in. You will still get most of the learning value, and you can do it on a phone during a commute.


How to use this series

I recommend two passes:

Pass 1 — understand (4 days). Read one post per day. Do the lab. Don't worry about memorizing product names yet.

Pass 2 — drill (2 days). Redo only the practice questions and the "exam traps" boxes. Anything you get wrong twice goes on an index card.

Then take the official practice assessment linked from the study guide. If you're scoring above 80% consistently, book the exam.

The three mistakes I see most

  1. Memorizing without a mental model. There are dozens of Microsoft product names in this exam. If you learn them as a flat list, you will mix them up. If you learn them as "this one protects devices, this one protects mailboxes, this one protects on-prem AD," you won't.
  2. Ignoring licensing. A surprising number of questions hinge on which tier gives you a feature. Conditional Access is P1. Identity Protection and PIM are P2. That single fact is worth points.
  3. Skipping domain 4. Compliance feels boring next to threat detection, but it's 15–20% of the exam and the content is very memorizable — labels, DLP, retention, eDiscovery. It's the cheapest score in the whole exam.

Series index

  • Part 0 — this post: how the exam works and how to build the lab
  • Part 1: Security, compliance and identity concepts (Zero Trust, shared responsibility, CIA, encryption, AuthN vs AuthZ)
  • Part 2: Microsoft Entra capabilities (tenant objects, authentication methods, Conditional Access, governance)
  • Part 3: Microsoft security solutions (Defender XDR family, Defender for Cloud, Sentinel, Azure network security)
  • Part 4: Microsoft compliance solutions (Purview, labels, DLP, retention, insider risk, eDiscovery)
  • Part 5: Final mock exam — 30 questions with full explanations + glossary

If this series helps you pass, leave a comment with your score. And if you spot something that changed in a newer exam update, tell me and I'll edit the post — that's the whole point of publishing it here instead of a PDF.


I work in IT support and identity administration, and I hold SC-900 and ISC2 CC. Everything here is my own study material; always validate against Microsoft Learn before your exam.


Part 1 — Security, Compliance and Identity Concepts drops in 48 hours: Zero Trust, shared responsibility, encryption vs hashing, and 12 practice questions + A 15-minute self-assessment exercise with full explanations.

Follow me so it shows up in your feed, and bookmark this post — it's the index for all six parts.

Quick one for the comments: in a SaaS model, who owns the responsibility for user identities? 👇

Top comments (1)

Collapse
 
topstar_ai profile image
Luis Cruz

I appreciate your approach to incorporating hands-on labs and practical exam strategies into your SC-900 study series. This real-world application can significantly enhance retention and understanding, especially in a field that evolves so rapidly. It might be beneficial to include video walkthroughs for the labs, as that can cater to various learning styles and provide a more comprehensive understanding of the concepts. If you're looking for help in expanding the lab content or any other part of the project, I'd be glad to collaborate on a paid basis. What challenges have you faced in creating these labs?