In early November the SC-900 exam will be updated with some minor changes. Most of the changes are focused on name changes, especially the removal of mentions of Azure AD, and shouldn’t have too much of an effect on your preparation at all.

If you work with Azure and Microsoft 365 security and compliance capabilities, this should be a straight forward exam for you. If you only focus on the security or compliance capabilities, or only Azure or Microsoft 365, make sure you focus your preparation on the areas that you are least familiar with.

There have also been some changes in the weighting of the domain objectives, but again, not something that should really have too much of an impact on your preparation.

After November 3

  • Describe the concepts of security, compliance, and identity (10–15%)
  • Describe the capabilities of Microsoft Entra (25–30%)
  • Describe the capabilities of Microsoft security solutions (35–40%)
  • Describe the capabilities of Microsoft compliance solutions (20–25%)

Before November 3

  • Describe the concepts of security, compliance, and identity (10–15%)
  • Describe the capabilities of Microsoft Entra ID (25–30%)
  • Describe the capabilities of Microsoft Security solutions (25–30%)
  • Describe the capabilities of Microsoft compliance solutions (25–30%)

The final note for this exam that I’ve received feedback on is that for many people who are familiar with Microsoft 365 and Azure, but not necessarily the security and compliance components, is that the wording/language used may not what they are used to. I guess you could view this is it being industry terminology that is being used, rather than Microsoft speak, so make sure that you don’t skip past any unusual wording in your preparation.

Describe the Concepts of Security, Compliance, and Identity (10-15%)

Describe security and compliance concepts

Describe identity concepts

Describe the capabilities of Microsoft Entra ID (25-30%)

Describe function and identity types of Microsoft Entra ID

Describe authentication capabilities of Microsoft Entra ID 

Describe access management capabilities of Microsoft Entra ID

Describe identity protection and governance capabilities of Microsoft Entra

Describe the capabilities of Microsoft Security Solutions (35-40%)

Describe core infrastructure security services in Azure

Describe security management capabilities of Azure

Describe capabilities of Microsoft Sentinel

Describe threat protection with Microsoft 365 Defender

Describe the Capabilities of Microsoft Compliance Solutions (20-25%)

Describe Microsoft Service Trust Portal and privacy principles

Describe compliance management capabilities of Microsoft Purview

Describe information protection, data lifecycle management, and data governance capabilities of Microsoft Purview

DDescribe insider risk, eDiscovery, and audit capabilities in Microsoft Purview

Check out my other exam reference guides here.