Skip to content

sc-900Fundamentals

Microsoft Security, Compliance, and Identity Fundamentals

Microsoft Certified: Security, Compliance, and Identity Fundamentals

SC-900 wants the concepts and the product-to-problem mapping: which Defender does what, what Zero Trust means in Microsoft's framing, and how Purview's pieces divide up compliance. The explainers below are the fundamentals layer of the deeper SC-200, SC-300, and SC-401 paths.

For: Anyone who needs to talk about Entra, Defender, Sentinel, and Purview without running them — and admins starting the SC track.

21 guides in 3sections. The sections are this site's grouping, written to follow the shape of the published skills outline; weightings and the current outline live on the exam page above and change between exam versions.

01Security and identity concepts

  1. 1Zero trust in Microsoft 365What zero trust actually means in a Microsoft 365 context — and the concrete controls that get you there.
  2. 2Microsoft 365 security and complianceA practical tour of the Microsoft 365 security and compliance stack — Defender, Purview, Entra, and how they fit together.
  3. 3What is Microsoft Entra ID?What Microsoft Entra ID is: the identity service behind every Microsoft 365 sign-in, how it relates to Active Directory, and the licensing tiers that matter.
  4. 4Entra ID Conditional Access designDesigning a Conditional Access baseline: the policies, the principles, the order to write them in, and the habits that keep the estate healthy.
  5. 5Entra ID passwordless authenticationThe realistic options for going passwordless in Microsoft 365 — Authenticator, FIDO2, Windows Hello, and passkeys.
  6. 6Entra ID Privileged Identity ManagementPIM turns standing admin access into just-in-time, approval-gated activation. The model, what it covers, role settings that work, and a rollout that sticks.
  7. 7Entra ID Governance explainedEntra ID Governance explained: access reviews, entitlement management, lifecycle workflows, separation of duties, P2 vs Suite licensing, and rollout order.

02Microsoft security solutions

  1. 8Which Microsoft Defender is whichWhich Microsoft Defender is which: Endpoint, Office 365, Identity, Cloud Apps, Business, XDR, Cloud, Antivirus — what each does and which licence gets it.
  2. 9Microsoft Defender for Endpoint explainedDefender for Endpoint is Microsoft's EDR/XDR platform for laptops, servers, and mobile. Here's what it does.
  3. 10Microsoft Defender for Office 365 explainedWhat Defender for Office 365 adds on top of EOP — Safe Links, Safe Attachments, AIR, attack simulation — plus Plan 1 vs Plan 2 and the settings worth tuning.
  4. 11Microsoft Defender for Cloud Apps explainedDefender for Cloud Apps is Microsoft's CASB — discovering, monitoring, and controlling SaaS app usage.
  5. 12Microsoft Defender for Identity explainedDefender for Identity detects identity-based attacks against on-prem Active Directory and Entra ID. Here's how it works.
  6. 13Microsoft Sentinel for Microsoft 365How Microsoft Sentinel ingests Microsoft 365 signals and extends Defender XDR into a full SIEM.
  7. 14Microsoft Security CopilotMicrosoft's AI assistant for security analysts — what it does, where it's embedded, and how it's licensed.

03Microsoft compliance solutions

  1. 15What is Microsoft Purview?What Microsoft Purview is: labels, DLP, retention, eDiscovery, insider risk, and the data-governance catalogue — how the two halves differ and where to start.
  2. 16Microsoft Purview sensitivity labels — a deep diveHow Purview sensitivity labels classify and protect content, how to design a taxonomy that survives contact with users, and the rollout order that works.
  3. 17Microsoft Purview Data Loss Prevention — a deep diveDLP policies detect and prevent sensitive data from leaving Microsoft 365. Here's the architecture and how to roll them out.
  4. 18Purview retention policies explainedHow Microsoft Purview retention policies keep and delete content across Microsoft 365 — the model and the gotchas.
  5. 19Purview Insider Risk ManagementInsider Risk Management detects risky internal behaviour — data theft, IP leakage, policy violations — with built-in privacy controls.
  6. 20Microsoft Purview Compliance ManagerCompliance Manager scores your tenant against compliance frameworks and tracks improvements over time.
  7. 21Microsoft Service Trust Portal and compliance documentationWhere to find Microsoft's compliance certifications, audit reports, and data-handling commitments.

Independent site, not affiliated with Microsoft. Found a gap in this path? Send it through the contact form.