- Overview: What the SC-900 Outline Actually Tests
- Domain 1: Security, Compliance, and Identity Concepts (10-15%)
- Domain 2: Microsoft Entra Capabilities (25-30%)
- Domain 3: Microsoft Security Solutions (35-40%)
- Domain 4: Microsoft Compliance Solutions (20-25%)
- Domain Weight Comparison Table
- Scheduling Your Prep Around the Four Domains
- Question Style and Exam Mechanics
- Who Actually Hires for This Fundamentals-Level Skillset
- Frequently Asked Questions
- Domain 3, Microsoft security solutions, is the largest area at 35-40% of the exam.
- Microsoft Entra capabilities (Domain 2) make up 25-30%, the second-heaviest domain.
- Passing requires a scaled score of 700 out of 1000, not a fixed percentage correct.
- The exam runs 45 minutes of testing time inside a 65-minute total appointment.
Overview: What the SC-900 Outline Actually Tests
Microsoft Certified: Security, Compliance, and Identity Fundamentals - the SC-900 - is organized around four scored content areas published directly by Microsoft. Each domain carries a percentage range that tells you roughly how many questions will draw from that area, though Microsoft does not disclose the exact scored-versus-unscored item count. Understanding these four domains, not just memorizing terms, is the difference between guessing on exam day and recognizing patterns in how Microsoft frames its questions.
This guide breaks down every domain in the current outline, explains what each one really asks you to know, and shows how the weighting should shape your study plan. If you want a broader walkthrough of the whole exam experience before diving into domain specifics, our SC-900 Study Guide 2026 is a good companion piece to this one.
Domain 1: Security, Compliance, and Identity Concepts (10-15%)
This is the foundational domain, and it's the smallest by weight, but it sets up vocabulary and mental models used everywhere else in the exam. Candidates who skip it often struggle later because Domains 2 through 4 all assume you already understand these baseline concepts.
Core Concepts You Must Know
This domain covers the language of modern security programs and how Microsoft frames security responsibility.
- Shared responsibility model and how it shifts across IaaS, PaaS, and SaaS
- Defense in depth and the layered security approach
- Zero Trust principles: verify explicitly, use least privilege, assume breach
- Encryption basics: at rest, in transit, and hashing concepts
- Governance, risk, and compliance (GRC) terminology at an introductory level
- Common compliance concepts used across Microsoft's broader ecosystem
Questions here tend to be scenario-light and definition-heavy. You'll be asked to match a description to a term - for example, distinguishing "defense in depth" from "zero trust" - rather than solving a multi-step configuration problem. That said, don't underestimate this domain just because its weight is lower; a shaky grasp of Zero Trust will hurt you again in Domain 2 when Entra Conditional Access questions build on the same logic.
Domain 2: Microsoft Entra Capabilities (25-30%)
Microsoft Entra is the identity and access management platform family, and this domain is where a meaningful chunk of your score lives. Expect it to test both conceptual understanding and recognition of specific feature names and what they do.
Identity and Access Fundamentals
You need to know what each Entra capability solves for, not just its name.
- Microsoft Entra ID core identity services and hybrid identity concepts
- Authentication methods, including multifactor authentication and passwordless options
- Conditional Access policies and how signals trigger access decisions
- Identity governance concepts: access reviews, entitlement management, privileged identity management
- External identities and business-to-business/business-to-consumer collaboration concepts
- Role-based access control (RBAC) fundamentals
A common mistake is treating this domain like a features list to memorize in isolation. Instead, connect each capability back to a problem it solves: Conditional Access answers "how do we let the right person in under the right conditions," while Privileged Identity Management answers "how do we limit standing access to sensitive roles." That problem-first framing sticks better under exam pressure than raw memorization.
Key Takeaway
Because Domain 2 is nearly a third of the exam, weak Entra knowledge alone can sink a passing attempt even if you're strong everywhere else. Prioritize it early in your prep.
Domain 3: Microsoft Security Solutions (35-40%)
This is the exam's center of gravity. At 35-40%, it's larger than any other single domain, and it's also the broadest in terms of product surface area covered.
Security Tooling and Platform Concepts
This domain spans multiple Microsoft security product families at a conceptual level.
- Microsoft Defender family capabilities across endpoints, identity, cloud apps, and email
- Microsoft Sentinel and security information and event management (SIEM) concepts
- Extended detection and response (XDR) concepts and how signals correlate
- Cloud security posture and workload protection basics
- Security management surfaces and how alerts, incidents, and recommendations are surfaced to admins
- Basic exposure management and attack surface reduction ideas
Because this domain covers so much ground, candidates often feel overwhelmed trying to memorize every product's full feature list. Resist that urge. The fundamentals-level exam rewards knowing what each solution is for and how it fits into a broader security posture, not deep configuration steps you'd only see in an administrator-level role. If you're unsure how deep to go, our breakdown on how hard the SC-900 exam actually is discusses exactly this kind of depth-versus-breadth tradeoff.
Domain 4: Microsoft Compliance Solutions (20-25%)
The final domain shifts from "how do we detect and stop threats" to "how do we manage data responsibly, meet regulatory obligations, and reduce organizational risk." It's the second-largest domain and often the one candidates underestimate because it feels less technical.
Compliance and Data Governance Concepts
This domain focuses on the tools and frameworks used to manage regulatory and organizational risk.
- Microsoft Purview capabilities for data governance, protection, and risk management
- Compliance Manager and compliance score concepts
- Information protection: sensitivity labels and data classification basics
- Data lifecycle management: retention and records management concepts
- Insider risk management and communication compliance fundamentals
- eDiscovery and audit concepts at an introductory level
A lot of test-takers coming from a purely technical background find this domain the least intuitive because it borrows vocabulary from legal, risk, and records-management disciplines rather than IT operations. Spend extra time making sure you can distinguish related-but-different concepts, like retention policies versus sensitivity labels, since the exam frequently tests these distinctions directly.
Domain Weight Comparison Table
Here's the full picture side by side, useful for quickly checking where your study time should be concentrated.
| Domain | Weight | Relative Size |
|---|---|---|
| 1. Security, compliance, and identity concepts | 10-15% | Smallest |
| 2. Microsoft Entra capabilities | 25-30% | Second-largest |
| 3. Microsoft security solutions | 35-40% | Largest |
| 4. Microsoft compliance solutions | 20-25% | Third-largest |
Notice that Domains 2 and 3 together account for 60-70% of the exam. That means Entra and security solutions content should collectively dominate your study calendar, with Domains 1 and 4 filling in the remainder. For a deeper dive into how these weights translate into a passing score strategy, see our article on the SC-900 passing score.
Scheduling Your Prep Around the Four Domains
Rather than studying the domains in numerical order out of habit, structure your calendar around their weight. A simple four-week model built around the outline looks like this.
Domain 1 Foundations
- Learn shared responsibility, defense in depth, and Zero Trust vocabulary
- Build a glossary of GRC and encryption terms you can recall instantly
Domain 2 Deep Dive
- Study Entra ID, Conditional Access, and identity governance concepts
- Practice distinguishing authentication methods from access-control features
Domain 3 Deep Dive
- Work through Defender family products and Sentinel/SIEM concepts
- Map each tool to the security problem it solves rather than memorizing menus
Domain 4 and Full Review
- Cover Purview, Compliance Manager, and data lifecycle concepts
- Run mixed practice questions across all four domains before scheduling
This isn't a generic spaced-repetition template - it's specifically weighted so that the two heaviest domains, Entra and security solutions, each get a dedicated week, while the lighter Domain 1 and moderately weighted Domain 4 get proportionally less but not zero attention. For a more detailed week-by-week walkthrough with resource recommendations, check the full SC-900 study guide.
Question Style and Exam Mechanics
Knowing the domains is only half the picture - understanding how questions are delivered matters just as much. The SC-900 is a proctored, computer-based exam, and interactive item types are possible, though Microsoft doesn't publish the exact mix of question formats. Testing time is 45 minutes, with a standard appointment length of 65 minutes to account for check-in and instructions.
There is no in-exam access to Microsoft Learn documentation, so everything you need has to already be in your head or reasoned out from concepts you've studied. Passing requires a scaled score of 700 out of 1000 - importantly, that scaled number does not map directly to "70% of questions correct," since item difficulty is factored into scoring. You can read a full explanation of how that scaled scoring works in our dedicated piece on the SC-900 passing score.
On logistics: the exam is delivered through Pearson VUE, with Certiport also listed as an option for students and educators. A commonly cited third-party reference for exam cost is around $99 USD, though the current official checkout total isn't independently verified here and regional taxes or discounts can change what you actually pay - see our SC-900 certification cost breakdown for more on pricing mechanics. There's also no formal degree, prior certification, or mandatory training-hour requirement to sit the exam, though familiarity with Azure and Microsoft 365 is recommended; our SC-900 requirements guide covers this in detail. Once earned, this Fundamentals-level credential does not expire and requires no renewal assessment or continuing-education credits.
Who Actually Hires for This Fundamentals-Level Skillset
Because the SC-900 is positioned as an entry point rather than a role-based credential, it tends to appeal to a wider range of professionals than administrator or expert-level exams. People pursuing it include early-career IT staff who want structured exposure to security, compliance, and identity concepts before specializing; non-technical roles like compliance officers, auditors, or project managers who work alongside security teams and need shared vocabulary; and sales, presales, or customer success professionals at partners who need to speak credibly about Microsoft's security portfolio.
It also functions well as a stepping stone. Many candidates use it to validate baseline knowledge before attempting Entra-focused, security operations, or compliance administrator certifications later. If you're weighing whether this investment makes sense for your specific career stage, our ROI analysis on whether the SC-900 is worth it walks through that decision in more depth, and our SC-900 jobs overview looks at how the credential tends to show up on résumés and job postings.
Whatever your starting point, testing your domain knowledge against realistic practice questions before exam day is one of the most reliable ways to confirm readiness. You can work through full-length domain-weighted practice sets on our practice test platform to see how your preparation holds up under exam-style conditions.
Frequently Asked Questions
Start with Domain 1's foundational concepts, since terms like Zero Trust and defense in depth reappear throughout the Entra and security solutions domains. Then move to Domains 2 and 3, which carry the most weight.
Yes. At 35-40%, Microsoft security solutions is the single largest domain, meaning it can influence your overall scaled score more than any other content area on the exam.
No formal hands-on requirement exists for the SC-900. Microsoft recommends general familiarity with Azure and Microsoft 365, but the exam tests conceptual understanding rather than step-by-step configuration skill.
Microsoft publishes percentage ranges for each domain but does not disclose the exact scored or unscored question counts, so treat the ranges as proportional guides rather than fixed numbers.
Our SC-900 cheat sheet compiles must-know facts across all four domains into a single quick-reference page for last-minute review.