EXAM COVERAGE · SC-900

SC-900 exam objectives and where the book covers them

Microsoft's skills measured for SC-900 as of October 21, 2026, mapped to the chapters of Ultra Transcenders SC-900: Microsoft Security, Compliance, and Identity Fundamentals.

ObjectiveChapters
Describe the concepts of security, compliance, and identity (10–15%)
Describe security and compliance concepts1. Security, compliance and identity concepts
Define identity concepts1. Security, compliance and identity concepts
Describe the capabilities of Microsoft Entra (25–30%)
Describe function and identity types of Microsoft Entra ID2. Microsoft Entra ID, identity types and hybrid identity
Describe authentication capabilities of Microsoft Entra ID3. Authentication: methods, MFA and passwords
Describe access management capabilities of Microsoft Entra ID4. Access management: Conditional Access and roles
Describe identity protection and governance capabilities of Microsoft Entra5. Identity governance and protection
Describe the capabilities of Microsoft security solutions (35–40%)
Describe core infrastructure security services in Azure6. Core infrastructure security in Azure
Describe security management capabilities of Azure7. Security management: Microsoft Defender for Cloud and Microsoft Sentinel
Describe capabilities of Microsoft Sentinel7. Security management: Microsoft Defender for Cloud and Microsoft Sentinel
Describe threat protection with Microsoft Defender XDR8. Threat protection with Microsoft Defender XDR
Describe the capabilities of Microsoft compliance solutions (20–25%)
Describe Microsoft Service Trust Portal and privacy principles9. Compliance management and information protection
Describe compliance management capabilities of Microsoft Purview9. Compliance management and information protection
Describe information protection, data lifecycle management, and data governance capabilities of Microsoft Purview9. Compliance management and information protection; 10. Data lifecycle, records, insider risk, eDiscovery and audit
Describe insider risk, eDiscovery, and audit capabilities in Microsoft Purview10. Data lifecycle, records, insider risk, eDiscovery and audit

The full list of tasks under each objective is in the official SC-900 study guide and practice assessment. The book is organised by technology, so one chapter often serves several objectives.

About the book · Free study notes · Certification paths