Microsoft SC-900: Identity, Security and Compliance Basics

A business adopts cloud collaboration, then discovers that every department uses “security” to mean something different. Operations wants service availability, legal wants retention, HR wants identity governance and finance wants evidence of control. A fundamentals learner becomes effective by identifying which security, compliance or identity problem is actually being described before choosing a product name.

Microsoft SC-900, Security, Compliance, and Identity Fundamentals , is a foundation-level view of concepts and Microsoft capabilities. Learn what a service is meant to solve, which responsibilities remain with the customer and how each control would be recognized in practice.

Separate authentication from authorization

A successful sign-in proves that an identity has met an authentication requirement; it does not automatically authorize access to a payroll folder. Users, groups, roles, devices and application identities each participate differently in access decisions. Multifactor authentication raises confidence in sign-in, while least privilege determines what an authenticated principal is allowed to do. These controls are related but not interchangeable.

Imagine a contractor who passes multifactor authentication yet downloads material outside a contracted project. Changing the password policy does not correct the access boundary. Practice naming the control that should have been scoped more narrowly and identifying how an identity platform, conditional access and governance reviews play different roles in a secure access process.

Understand responsibility across cloud service models

Cloud providers secure significant portions of their infrastructure, but customers retain responsibilities for identities, data, configuration and application use. The balance varies across infrastructure, platform and software services. A company cannot assume that selecting a managed cloud service will classify records, assign acceptable permissions or meet a sector-specific retention obligation without deliberate configuration.

Compare a virtual machine, a hosted database service and a SaaS collaboration application. For each, identify who patches the underlying platform, who controls accounts and who defines how information is retained. A good fundamentals question asks for the boundary of responsibility in a situation, not a declaration that the provider or the customer owns every security task.

Distinguish defense in depth from product duplication

Encryption, network segmentation, identity policy, threat detection and recovery provide different kinds of protection. Multiple tools that all report malicious sign-ins do not necessarily compensate for unrestricted data access. The defense-in-depth principle is that compromise or failure of one layer should not automatically expose everything behind it. Zero Trust adds continuous verification and limited assumed trust.

Take a fictional remote employee connecting to a sensitive application. Trace identity verification, device signals, access decisions, the application network, data controls and monitoring. Then ask which layer would still prevent damage if the device became infected. The answer depends on the asset and threat, making this a stronger exercise than memorizing a diagram without its context.

Map Defender, Entra and Purview to different outcomes

Microsoft Entra focuses on identity and access, Defender offerings address threat protection and security operations, and Purview provides capabilities for information protection, governance and compliance. Product boundaries can overlap in real workflows, but their central purposes remain distinguishable. An alert about suspicious activity is a different artifact from a retention policy or the classification of a document.

Write ten workplace requests, such as investigating a malicious attachment, reviewing privileged roles or keeping regulated records for an approved period. Choose the family that is most directly responsible, then explain why another similarly named product would not be the first solution. This method trains reasoning from the problem toward a capability instead of guessing from branding.

Read compliance and risk claims carefully

Compliance is not a synonym for technical security. An organization may protect systems against intrusion and still mishandle retention, discovery requests or personal information. Similarly, a regulatory framework can demand evidence about people, processes and controls rather than merely the presence of software. Audits require knowing the scope of a policy and whether it actually operated over the relevant period.

Create a miniature example involving customer communications with sensitive details. Decide what requires classification, who should access it, how long it must be retained and what would be needed to answer a legal request. Use the result to explain how risk management, audit evidence and incident response connect without collapsing into one indistinct security feature.

  • img