
An independent study guide for Microsoft Certified: Security, Compliance, and Identity Fundamentals · by Tony Rough
Know which Microsoft security, identity or compliance tool fits, and why.
Publishing soon on Amazon in Kindle and paperback editions.
This independent study guide for the Microsoft Certified: Security, Compliance, and Identity Fundamentals exam distils what SC-900 really expects you to understand into clear definitions, comparisons and the traps that catch newcomers. It assumes no previous security experience and is written to the skills measured as of 21 October 2026.
Ten chapters, each readable on its own and together covering all four SC-900 skill areas:
Microsoft's security products change quickly. This edition reflects Microsoft's documentation as of October 2026, including recent changes such as the retirement of Microsoft-provided SMS and voice sign-in codes, passkeys by default, Microsoft Sentinel's move to the Microsoft Defender portal and the single eDiscovery experience in the Microsoft Purview portal.
This book contains no exam questions. It explains the knowledge the exam expects, so you can answer questions you have never seen and carry the same understanding into SC-500 and real security work.
Written by Tony Rough, a cloud architect with more than twenty years in IT infrastructure who holds the Azure Solutions Architect Expert, Azure Administrator and Azure Security Engineer certifications.
Part of the Ultra Transcenders series from Distilled Press. An independent publication, not affiliated with, sponsored by or endorsed by Microsoft Corporation.
Every skill area in Microsoft's SC-900 outline (as of October 21, 2026), and the chapters that cover it.
| Skill area | Weight | Chapters |
|---|---|---|
| Describe the concepts of security, compliance, and identity | 10–15% | 1 |
| Describe the capabilities of Microsoft Entra | 25–30% | 2, 3, 4, 5 |
| Describe the capabilities of Microsoft security solutions | 35–40% | 6, 7, 8 |
| Describe the capabilities of Microsoft compliance solutions | 20–25% | 9, 10 |
Plus an appendix glossary of 300+ terms, each linked to Microsoft Learn, with the same terms explained free online for print readers.



Some sections of the book, free to read online:
How security duties move between customer and Microsoft across on-premises, IaaS, PaaS and SaaS, and the duties that never move.
Verify explicitly, use least privilege access and assume breach, and the areas a Zero Trust approach covers.
How Conditional Access combines signals into decisions after first-factor sign-in, and what it is not designed to stop.
The kinds of DDoS attack, what every public IP gets free, and what the paid tiers add.
What the free posture management tier includes and what the paid Defender CSPM plan adds.
What security information and event management and security orchestration, automation and response each do, and how they fit together.
The built-in mailbox protection every tenant has, and the protections each Defender for Office 365 plan adds.
The unified audit log, how long each audit tier keeps records, and what Audit (Premium) adds.