What you’ll learn in this article…
- SC-900 costs around $110 USD, never expires, and requires no prerequisites.
- Most candidates need roughly 10 to 15 hours of focused study.
- It validates Microsoft security and compliance concepts, not hands-on technical skills.
The SC-900 costs $99 and never expires, making it one of the most accessible Microsoft certifications, but that affordability creates a persistent question: does a fundamentals badge carry enough weight to justify the study time? You are probably weighing this against CompTIA Security+ or ISC2 CC, especially if you need a credential that hiring managers recognize outside Microsoft-centric roles. A realistic look at exam difficulty, what the SC-900 actually validates, and which career paths it supports can prevent overspending on training or missing a better-fitting alternative. The certification’s real value lies in its laser focus on Microsoft’s security, compliance, and identity stack, not as a broad cybersecurity credential.
SC-900 Credential Snapshot
What exactly does the SC-900 exam cover, and where can you find the most current details before registering?
Microsoft updates its certification exams periodically, so the smartest first step is going directly to the source. The official Microsoft Learn credentials page provides the authoritative, up-to-date information you need: current exam price, duration, passing score, domain breakdown, and delivery options.
Where to Find Official Exam Details
The SC-900 exam page on Microsoft Learn is your primary reference. Here you will find:
- Exam code and full title: The official designation and what Microsoft calls the certification
- Current price: Listed in USD with regional variations noted
- Time allotment: How many minutes you have to complete the exam
- Passing score: The minimum scaled score required
- Scored domains: The topic areas and their approximate weight percentages
- Delivery method: Whether Pearson VUE online proctoring or test center options are available
- Prerequisites: Any formal requirements or recommended background
Microsoft also publishes a downloadable study guide PDF that breaks down each domain's objectives in detail. This document typically updates when Microsoft modifies exam content, so check the revision date before building your study plan.
Additional Authoritative Sources
For salary benchmarking and career trajectory research, the Bureau of Labor Statistics at bls.gov provides government data on related occupations like information security analysts. Professional associations such as ISACA and ISC2 publish industry standards that help contextualize where foundational Microsoft certifications fit within broader career pathways.
Bookmark the official Microsoft certification page and check it within a week of your planned exam date. Exam prices, domain weightings, and even question formats can shift with little advance notice. The credentials community forums on Microsoft Learn also surface recent candidate experiences that help calibrate your preparation timeline.
What Microsoft SC-900 Validates and Why It Exists
The SC-900 certification validates foundational knowledge of security, compliance, and identity concepts within the Microsoft ecosystem. It does not test hands-on technical skills or require candidates to configure systems, write scripts, or respond to security incidents. Instead, it confirms that the holder understands core terminology, recognizes how Microsoft services address common security challenges, and can articulate the value of tools like Microsoft Entra ID, Microsoft Defender, and Microsoft Purview to stakeholders.
A Fundamentals-Tier Credential
Microsoft positions SC-900 at the same level as AZ-900 (Azure Fundamentals) and MS-900 (Microsoft 365 Fundamentals). All three are explicitly designed for non-technical and early-career audiences who need conceptual grounding rather than practitioner-level depth. The SC-900 does not assume prior experience with security operations centers, identity management consoles, or compliance auditing workflows. It assumes curiosity and a willingness to study.
Is SC-900 a beginner certification? Yes. It is Microsoft's lowest barrier entry point for anyone interested in security, compliance, or identity topics within Azure and Microsoft 365 environments. That said, "beginner" does not mean "no preparation required." Candidates still need dedicated study time to learn Microsoft's frameworks, service names, and how different products fit together.
Who Benefits Most
The SC-900 serves audiences who interact with Microsoft security tooling without building or operating it directly:
- Business stakeholders: Managers and executives who approve budgets for Microsoft security products benefit from understanding what those tools actually do.
- Sales and pre-sales engineers: Professionals who position Microsoft solutions to clients need fluency in security, compliance, and identity terminology.
- Compliance and governance staff: Auditors, policy analysts, and risk professionals who evaluate Microsoft environments gain context for their assessments.
- IT generalists: Help desk technicians, system administrators, and junior analysts who support Microsoft 365 or Azure tenants can build a foundation before pursuing a security analyst certification path.
How SC-900 Differs from Practitioner Certifications
The SC-900 is a vendor-specific credential, not interchangeable with role-based certifications that test job-ready skills. The SC-200 (Security Operations Analyst) exam, for example, requires candidates to investigate threats, configure detection rules, and respond to incidents using Microsoft Sentinel and Microsoft Defender. The SC-300 (Identity and Access Administrator) exam tests the ability to implement and manage identity solutions in production environments. Both assume real-world experience and substantially longer preparation timelines.
SC-900 holders have demonstrated comprehension, not operational competence. Employers and hiring managers should understand this distinction: the credential signals readiness to learn, not readiness to perform security operations independently.
Who Should Pursue the SC-900, and Who Shouldn't
The SC-900 is purpose-built for two distinct audiences, and largely a detour for everyone else. Its design as a fundamentals exam means it introduces security, compliance, and identity concepts within the Microsoft cloud ecosystem rather than testing hands-on technical skills. Knowing which bucket you fall into can save you months of study time and several hundred dollars in exam fees.
Profile 1: Career Changer with No IT Background
- Verdict: Strong fit. The SC-900 is the on-ramp you are looking for.
- Why: The exam assumes no prior security knowledge and focuses on vocabulary, core principles, and Microsoft's specific toolset. For someone making a cybersecurity career change, this credential provides a structured, vendor-anchored introduction without the intimidating depth of CompTIA Security+. It also gives you a recognizable line item on a resume while you build toward more technical certifications. Within 30, 40 hours of study, you can walk into an entry-level IT interview and demonstrate that you understand concepts like Zero Trust, identity governance, and Microsoft’s compliance portfolio.
Profile 2: Early IT Professional (Helpdesk, Junior Admin)
- Verdict: Good fit for building Microsoft security literacy and signaling specialization interest.
- Why: If you are already working with Microsoft 365 or Azure in a support capacity, the SC-900 helps you connect daily tasks to broader security frameworks. It shows your manager that you are serious about moving into a security role and provides a low-risk credential that your employer might fund. The exam’s emphasis on Microsoft Sentinel, Defender, and Purview also gives you concrete talking points for internal job applications. However, if you already have Security+, the SC-900 adds only marginal depth; in that case, consider jumping to the SC-200 (Security Operations Analyst) instead.
Profile 3: Working Cybersecurity Practitioner (1, 3 Years)
- Verdict: Marginal value unless employer-required.
- Why: You likely already possess the conceptual knowledge tested here. Most employers looking for a security analyst or engineer will prioritize experience and intermediate certifications like Security+, CySA+, or Microsoft’s associate-level certs. The SC-900 does not demonstrate hands-on capability and may even be seen as a regression on a cybersecurity-focused resume. Pursue it only if your organization explicitly asks for it (common in Microsoft partner firms) or if you need a lightning-fast, low-cost way to check a compliance box. Otherwise, invest the same effort into the SC-200 or AZ-500.
Profile 4: Experienced Specialist or Manager (5+ Years)
- Verdict: Skip unless mandated for partner requirements or compliance.
- Why: At this stage, your time is better spent on strategic certifications like CISSP, CISM, or Microsoft’s expert-level credentials. The SC-900 will not elevate your credibility or open doors that are not already open. Exceptions include: you are transitioning into a new role that heavily relies on Microsoft compliance documentation (e.g., a GRC manager in a Microsoft-first shop) or your employer must maintain a certain number of certified staff for Microsoft Solution Partner designations. Even then, confirm with your organization before registering.
Related Articles
Exam Format, Domains, Scoring, and Testing Options
The SC-900 exam is a carefully constructed assessment of foundational knowledge, not a casual quiz that you can breeze through without preparation. Every detail of its format, from the balance of question types to the domain weighting, is designed to verify that you genuinely understand Microsoft's security, compliance, and identity fundamentals.
Question Types and Structure
You will face 40 to 60 questions in a single, timed session. The exam draws from a mix of question formats, including traditional multiple-choice, multiple-select, drag-and-drop, dropdown selection, scenario-based items, and true/false style prompts.[CITE:2] Microsoft does not include hands-on lab simulations on the SC-900, so you won't be asked to configure a tenant or run PowerShell commands. However, you should expect scenario-driven questions that ask you to identify the correct Microsoft solution for a given business need, which tests your practical understanding just as effectively.
Exam Domains and Weighting
Microsoft publishes a detailed skills outline, last updated on November 7, 2025[CITE:1], that breaks the exam into four domains. The weighting reflects the relative importance of each topic area:
- Describe the concepts of security, compliance, and identity (10, 15%): This introductory domain covers core principles like Zero Trust, defense in depth, and regulatory compliance concepts.
- Describe the capabilities of Microsoft security solutions (35, 40%): The largest domain focuses on Microsoft's security portfolio, including Microsoft Defender, Microsoft Sentinel, and security management features.
- Describe the capabilities of Microsoft Entra (25, 30%): Questions here center on identity and access management, including Entra ID editions, hybrid identity, and Conditional Access, topics central to an IAM specialist career path.
- Describe the capabilities of Microsoft compliance solutions (20, 25%): This domain covers Microsoft Purview, information protection, data lifecycle management, and insider risk capabilities, tools directly relevant to understanding different types of cybersecurity audits.
Knowing these weights allows you to allocate study time strategically. Since over a third of your score depends on security solutions, that domain deserves substantial focus.
Scoring and Time Management
You have 65 minutes of total seat time: up to 45 minutes to answer the questions, plus extra time for reading instructions, accepting the non-disclosure agreement, and providing feedback.[CITE:2] The exam uses a scaled score system ranging from 0 to 1,000. A passing score is 700,[CITE:2] which does not translate to a simple percentage of correct answers; Microsoft's statistical model adjusts for question difficulty. You won't receive a detailed breakdown by domain if you pass, but failing candidates get a summary to guide retakes.
Because you cannot skip and return to flagged questions, pacing is critical. Aim to spend no more than one minute per question on first pass, then review any uncertain answers if time permits. The absence of labs means every minute is question time, so don't let scenario-based items consume your entire clock.
Testing Delivery Options
You can take the SC-900 either at a Pearson VUE test center or through online proctoring via the OnVUE platform.[CITE:2] Both modes use the same exam and scoring, so the choice comes down to personal preference and environment.
For online proctoring, you'll need a quiet, private room with a clean desk and no interruptions. Pearson VUE strictly enforces workspace rules: no duplicate monitors, no headphones, no eating or smoking, and your phone must be out of reach. You'll complete a check-in process that includes photos of your ID, your face, and your surroundings. A live proctor monitors you throughout the exam via webcam and microphone, so test your system's compatibility ahead of time using the OnVUE system test.
At a test center, you receive a secure workstation, a locker for your belongings, and a proctor present on-site. Some candidates find the center environment less distracting and free from the technical risks of a home setup, such as internet drops or software conflicts.
Accessibility accommodations are available for both delivery modes. You must submit a request through Microsoft's exam accommodations portal with supporting documentation before scheduling your exam. Common accommodations include extra time, screen magnifiers, and separate testing rooms. Start this process at least two weeks early to avoid delays.
SC-900 Exam Domains at a Glance
The SC-900 exam covers four weighted domains. Understanding how Microsoft distributes questions across these areas helps you allocate study time proportionally. The percentages below reflect the published exam guide as of early 2026.

Full Cost Breakdown: Exam, Training, Retakes, and Renewal Fees
Understanding the full financial picture before registering for the SC-900 is essential, especially if you are a career changer looking to compare cybersecurity certifications side by side. Rather than relying on secondhand sources, you should verify every cost directly through Microsoft's official channels, since pricing and policies do shift over time.
Exam Registration Fee
Microsoft publishes the current price for each certification exam on its credentials page at learn.microsoft.com. The SC-900 exam fee has historically been positioned at the lower end of Microsoft's certification pricing scale, consistent with its fundamentals-level designation. However, the exact amount can vary by country or region, and Microsoft periodically adjusts prices. Always confirm the price in your local currency on the official scheduling page before booking.
If you need to retake the exam, Microsoft's candidate handbook outlines specific waiting periods between attempts. Generally, there is a short mandatory wait after a first failed attempt, with progressively longer intervals for additional retakes within a given period. The retake fee is typically the same as the original exam fee, so plan your study timeline carefully to avoid unnecessary costs.
Training and Preparation Costs
Preparation expenses range from zero to several hundred dollars depending on your cybersecurity certification study plan. Microsoft offers free, self-paced learning paths on Microsoft Learn that align directly with the SC-900 exam objectives, making it possible to prepare using free cybersecurity training. Microsoft has also periodically offered Virtual Training Days, instructor-led sessions that sometimes include a complimentary exam voucher upon completion. Check the Microsoft Events page to see whether a qualifying event is currently scheduled, as availability rotates and eligibility rules can change.
Beyond free options, independent training platforms and practice exam providers offer paid courses and question banks. Prices vary widely, so compare reviews and ensure any third-party resource maps to the current exam outline rather than an outdated version.
Renewal Costs
Microsoft fundamentals certifications do not expire in the same way that role-based certifications do, which means there is currently no renewal fee or continuing education requirement. This is a meaningful cost advantage over credentials that require annual or biennial renewal payments. Verify the latest renewal policy on Microsoft's certification renewal FAQ, since policies can evolve as the program matures.
How to Stay Current on Costs
To keep your cost estimates accurate, bookmark these resources:
- Microsoft credentials page: Lists exam prices, objectives, and scheduling links.
- Candidate handbook: Covers retake policies, accommodation requests, and exam-day rules.
- Microsoft Events page: Shows upcoming Virtual Training Days and any voucher offers.
- Professional associations and community forums: Groups like ISACA, (ISC)2, and CompTIA communities often share timely updates when pricing or voucher programs change.
By checking these sources directly, you avoid relying on outdated blog posts or unofficial estimates. A few minutes of verification can save you from surprise charges and help you budget realistically for the entire credential journey.
How Difficult Is the SC-900 and How to Prepare
The SC-900 occupies a unique spot in Microsoft's catalog: it is widely regarded as one of the easiest exams the company offers, yet people still fail it by underestimating the breadth of concepts. If you walk in cold without any exposure to cloud identity or compliance terminology, you'll struggle. But if you spend even a modest amount of structured time with the learning materials, you can clear the bar without breaking a sweat.
How Hard Is the SC-900, Really?
Against similar entry-level security exams, the difficulty is low to moderate. Compared to CompTIA Security+, which expects you to apply concepts and troubleshoot scenarios, the SC-900 stays firmly at the knowledge level. You need to recognize and describe principles, not configure a firewall or analyze a log file. Candidates coming from the SC-200 or AZ-500 world often call the SC-900 a "breeze." It is not a technical deep-dive, and Microsoft intentionally designed it as a first step for people new to security, compliance, and identity concepts on Microsoft platforms.
- Exam style: Definitions, benefit statements, and identifying which Microsoft service does what. No hands-on labs or case studies.
- Common pitfalls: Test-takers often brush off the compliance and privacy modules, but the exam frequently probes GDPR, Microsoft Purview capabilities, and the specifics of Azure Policy. Those sections can sink a test-taker who only studied identity and network security.
Study Time Estimates by Learner Profile
Your preparation time depends heavily on your starting point.
- Already comfortable with Azure or M365 security basics: 10 to 15 hours. You will be reinforcing terminology and filling gaps around compliance and insider risk management.
- General IT background but new to Microsoft cloud: 20 to 25 hours. You need extra time to map traditional security concepts onto Microsoft's service names and licensing tiers.
- Complete beginner, no IT experience: 25 to 40 hours. You will learn foundational concepts and Microsoft's product landscape simultaneously. Break this into daily 60- to 90-minute sessions so the compliance terminology doesn't blur together.
Two Structured Study Plans
Both plans use the free Microsoft Learn learning path as the backbone, following the strategies outlined in our how to prepare for a cybersecurity certification exam article. Bookmark the official SC-900 exam page to pull the most current skills outline before you start.
2-Week Plan (for experienced IT or cloud learners)
- Days 1-2: Complete the Microsoft Learn modules for "Describe the concepts of security, compliance, and identity" (approximately 4 hours). Take notes on shared responsibility, defense in depth, and Zero Trust.
- Days 3-5: Work through "Describe the capabilities of Microsoft Entra" (identity). Pay attention to PIM, identity protection, and licensing differences.
- Days 6-8: Tackle Microsoft Security solutions: Defender services, Sentinel, and Microsoft 365 security features.
- Days 9-10: Finish with compliance capabilities: Microsoft Purview, eDiscovery, audit, and privacy.
- Days 11-12: Take the official Microsoft practice assessment twice. Review every wrong answer using the linked documentation.
- Days 13-14: Light review of weak areas plus one full-length timed practice exam from a third-party source.
4-Week Plan (for beginners)
- Week 1: Same as above but slower, aiming for about 5 hours per week on the concepts domain. Supplement with YouTube overviews from John Savill or Microsoft Mechanics for visual reinforcement.
- Week 2: Identity domain, with hands-on clicking around in a free Microsoft 365 E5 trial tenant. Seeing the portals makes the menu names stick.
- Week 3: Security and compliance domains, alternating days. Use the Microsoft Learn sandbox to explore Purview and Defender interfaces.
- Week 4: two practice exam rounds per week, each followed by deep review. In the final days, narrow in on the lowest-scoring domain.
Practice Test Sources: Which Ones Mirror the Real Exam?
- Microsoft Official Practice Assessment (free): Available on Microsoft Learn. The question style and difficulty are the closest match to the live exam. Use this first and last.
- MeasureUp: Officially endorsed by Microsoft. Their question bank is larger and often more difficult than the actual test, so if you pass MeasureUp consistently, you are ready.
- Whizlabs: Moderate difficulty. Good for drilling term recognition, but some questions feel more like memorization puzzles than the real exam's scenario-lite paragraphs.
- Free quiz platforms (like Quizlet or random YouTube "SC-900 practice questions"): Useful for quick recall on the go. Do not rely on them as your only measure of readiness because answer explanations and accuracy vary widely.
What to Do If You Fail
A failing score is not the end and does not go on a permanent record anyone else sees. Your score report breaks down performance by domain, so you will know exactly where you fell short, whether identity, compliance, or security operations.
- Interpret weak areas: If one domain scored below 60 percent, that becomes your full-time focus for the next attempt. Re-read the Microsoft Learn modules and take the official practice assessment by filtering questions to that domain only.
- Retake waiting period: Microsoft enforces a 24-hour wait before a second attempt, in line with their Online Cybersecurity Exams: Proctoring and Retakes policies. For third and subsequent attempts, the waiting period extends to 14 days between exam sittings. Use that time to fix knowledge gaps, not to cram the same way again.
- Action plan: Create a short log of the concepts that tripped you up during the exam while the memory is fresh. Then find a study buddy or post in the Microsoft Learn community to talk through those points aloud. Explaining a concept to someone else often locks it in faster than re-reading slides.
Jobs, Salary Impact, and Employer Use Cases
What jobs can you actually get with the SC-900 certification, and how much does it help your salary?
This is where expectations need to align with reality. The SC-900 is a fundamentals certification, and fundamentals certifications rarely unlock jobs on their own. What SC-900 does well is signal Microsoft security literacy to employers already invested in the Microsoft ecosystem, and it positions you for roles where that baseline knowledge matters.
Roles Where SC-900 Adds Value
The SC-900 maps best to entry-level and adjacent positions where Microsoft cloud security concepts are relevant but not the primary technical requirement. Many of these roles, like the entry level cybersecurity jobs we cover, include:
- SOC Analyst (Tier 1): Entry-level security operations roles increasingly involve Microsoft Sentinel, Defender, and Azure AD. SC-900 demonstrates you understand how these tools fit together conceptually.
- Junior Security Administrator: Organizations running Microsoft 365 and Azure environments value candidates who grasp identity management and compliance frameworks before diving into hands-on configuration.
- GRC Analyst: Governance, risk, and compliance roles benefit from SC-900’s coverage of Microsoft Purview and compliance portal capabilities.
- IT Compliance Coordinator: Roles focused on regulatory alignment and audit support gain context from SC-900’s compliance and data governance modules.
- Cloud Support Engineer: Help desk and support roles in Microsoft partner organizations often require familiarity with security and identity concepts across Azure and Microsoft 365.
Why SC-900 Alone Is Not Enough
Hiring managers rarely filter candidates specifically for SC-900. Instead, they use it as a checkbox confirming you understand the Microsoft security stack at a conceptual level. The certification becomes most valuable when stacked with either relevant experience or practitioner-level credentials like SC-200 (Security Operations Analyst), SC-300 (Identity and Access Administrator), or AZ-500 (Azure Security Engineer), as outlined in Cybersecurity Certification Roadmaps.
Microsoft partner organizations frequently use SC-900 for internal staff baseline credentialing, particularly for sales, pre-sales, and customer success teams who need security fluency without deep technical responsibilities. HR departments at these organizations sometimes filter for SC-900 as a signal of Microsoft ecosystem familiarity, especially when hiring for roles that touch security without being security-focused.
Salary Context and Career Ceiling
The SC-900 itself does not command a salary premium. However, the career path it supports can lead to well-compensated roles, as reflected in broader cybersecurity salary data. According to BLS data, information security analysts earn a median annual wage of $124,910, with the 25th percentile at $92,160 and the 75th percentile reaching $159,600.2 These figures represent the career ceiling for practitioners who stack experience with advanced certifications, not the starting point for someone holding only SC-900.
Long-Term Career Trajectory
The broader field offers strong momentum. The Bureau of Labor Statistics projects 29 percent job growth for information security analysts between 2024 and 2034, characterized as much faster than average. This translates to roughly 53,000 to 55,000 new positions over the projection period, with approximately 16,000 annual openings.1
These numbers frame the opportunity, but the salary and career upside comes from progression. SC-900 validates foundational knowledge. The real advancement happens when you stack it with practitioner certifications, hands-on project experience, and demonstrated expertise in Microsoft security tooling.
Information Security Analyst Salary by State
The SC-900 is a foundational credential, so it is most relevant to professionals entering or supporting the information security field rather than senior analysts. Still, understanding the salary landscape for information security analysts helps frame where this certification fits into longer career plans. The figures below reflect annual wages for information security analysts across all 50 states, the District of Columbia, and Puerto Rico, based on data from the Occupational Employment and Wage Statistics program (2024) published by the U.S. Bureau of Labor Statistics.
| State | Total Employment | Median Annual Salary | 25th Percentile | 75th Percentile | Mean Annual Salary |
|---|---|---|---|---|---|
| Washington | 6,830 | $142,920 | $117,040 | $169,350 | $144,140 |
| California | 15,800 | $140,660 | $105,150 | $178,090 | $152,640 |
| Maryland | 8,770 | $140,480 | $105,230 | $175,390 | $145,450 |
| New Jersey | 4,730 | $135,390 | $108,320 | $168,240 | $141,130 |
| Delaware | 630 | $134,050 | $105,310 | $154,060 | $130,860 |
| New Mexico | 1,760 | $133,780 | $101,940 | $166,300 | $131,220 |
| Virginia | 18,670 | $132,460 | $101,610 | $166,510 | $136,680 |
| New York | 8,860 | $131,100 | $98,320 | $170,220 | $139,540 |
| Colorado | 5,840 | $130,570 | $102,350 | $164,010 | $135,980 |
| Connecticut | 1,160 | $130,500 | $95,260 | $152,410 | $127,740 |
| New Hampshire | 730 | $129,690 | $98,540 | $158,360 | $128,040 |
| Minnesota | 2,550 | $128,830 | $99,300 | $145,860 | $126,150 |
| District of Columbia | 2,010 | $127,760 | $109,680 | $150,920 | $132,790 |
| Massachusetts | 5,780 | $127,610 | $101,730 | $161,940 | $129,350 |
| Hawaii | 580 | $125,790 | $99,730 | $154,340 | $128,310 |
| Arizona | 4,170 | $125,320 | $88,520 | $161,250 | $123,780 |
| Texas | 14,730 | $124,970 | $96,020 | $149,780 | $126,800 |
| Georgia | 6,480 | $124,270 | $92,620 | $156,390 | $126,380 |
| Idaho | 870 | $121,970 | $87,980 | $157,060 | $145,880 |
| Wyoming | N/A | $121,290 | $82,350 | $161,650 | $122,570 |
| North Carolina | 6,850 | $121,070 | $88,560 | $147,030 | $122,310 |
| Oregon | 1,370 | $119,000 | $93,650 | $152,880 | $132,430 |
| Illinois | 4,560 | $114,300 | $83,960 | $138,130 | $119,540 |
| Iowa | 1,180 | $112,950 | $82,990 | $133,830 | $116,710 |
| North Dakota | 340 | $112,330 | $89,520 | $112,330 | $101,200 |
| Alabama | 3,290 | $111,110 | $79,870 | $138,270 | $112,800 |
| Pennsylvania | 4,420 | $110,230 | $79,670 | $137,900 | $114,870 |
| Rhode Island | 880 | $109,410 | $85,790 | $141,690 | $117,010 |
| West Virginia | 270 | $107,820 | $79,870 | $123,770 | $103,770 |
| Ohio | 5,070 | $107,570 | $83,480 | $137,430 | $115,600 |
| Nevada | 1,570 | $106,530 | $80,380 | $136,710 | $111,340 |
| Florida | 13,770 | $105,990 | $86,250 | $139,150 | $117,500 |
| Michigan | 3,120 | $104,540 | $79,920 | $129,150 | $107,630 |
| South Dakota | 430 | $103,310 | $86,360 | $115,300 | $104,120 |
| Missouri | 2,560 | $102,440 | $78,210 | $130,810 | $107,250 |
| Alaska | 210 | $102,170 | $96,320 | $121,060 | $111,900 |
| Kansas | 1,380 | $99,420 | $71,960 | $129,080 | $100,850 |
| Wisconsin | 1,760 | $99,210 | $79,640 | $128,770 | $106,260 |
| Kentucky | 1,790 | $98,210 | $67,650 | $128,910 | $102,820 |
| Utah | 1,720 | $97,180 | $72,800 | $127,980 | $101,430 |
| Nebraska | 1,120 | $95,470 | $85,120 | $122,360 | $103,310 |
| Maine | 270 | $93,710 | $73,890 | $129,560 | $99,420 |
| Arkansas | 1,010 | $93,560 | $66,800 | $125,550 | $96,080 |
| Louisiana | 580 | $88,200 | $73,830 | $107,250 | $101,280 |
| Montana | N/A | $87,100 | $87,100 | $102,650 | $99,560 |
| Vermont | 80 | $86,810 | $67,080 | $108,940 | $95,800 |
| Oklahoma | 1,270 | $86,500 | $57,490 | $117,500 | $92,390 |
| Mississippi | 560 | $84,640 | $60,240 | $105,830 | $89,910 |
| Indiana | 2,540 | $78,290 | $64,500 | $115,650 | $91,740 |
| Puerto Rico | 470 | $59,520 | $44,780 | $81,330 | $62,190 |
Renewal, Expiration, and Continuing Education
SC-900 is a Microsoft fundamentals certification, and it comes with a significant perk: it never expires.1 Unlike associate, expert, or specialty role-based Microsoft certifications that require annual renewal, the SC-900 badge is valid for life once you pass. There is no renewal window, no recurring exam, and no continuing education mandate to keep the certification active.
SC-900 Is a Lifetime Credential
When you earn the SC-900, your transcript shows the certification indefinitely. Microsoft does not impose a renewal cadence for any fundamentals exam, including SC-900. This means you can list it on your resume without worrying about a ticking clock. The only way the credential could lose relevance is if you choose not to stay current with the security, compliance, and identity landscape, but that is a personal decision, not a Microsoft requirement.
No Renewal Assessment, No Fee, No Expiration
Because SC-900 is a fundamentals certification, there is no open-book renewal assessment, no 30- to 45-minute online quiz, and no 24-hour wait after a failed attempt that you see with higher-level Microsoft certs. You will not receive email reminders about an upcoming expiration because there simply is no expiration date. Those processes apply only to role-based certifications like SC-200, SC-300, or SC-400, which do require annual renewal through the Microsoft Learn platform.2
If you hold or plan to pursue those associate-level certifications later, remember that each of them will have its own one-year renewal cycle. But the SC-900 remains untouched by that policy. It serves as a permanent foundational marker on your Microsoft certification transcript.
Optional Continuing Learning Paths
While formal continuing education is not required, Microsoft encourages credential holders to keep learning. The security ecosystem changes often, and Microsoft regularly updates its SC-900 learning paths on Microsoft Learn with new modules, case studies, and updated features. You can revisit those modules anytime at no cost. This is purely voluntary and has no impact on your certification status.
If you plan to move into an IT or cybersecurity career, using the SC-900 as a permanent anchor while exploring other credentials, like those in the All Cybersecurity Certifications Directory, is a common approach. The lack of expiration also means you won't need to budget for renewal fees or schedule a proctored retake years later. Your initial effort pays off for the duration of your career.
SC-900 Vs. Security+ Vs. ISC2 CC
Entry-level cybersecurity certifications now serve distinct purposes, and choosing between the SC-900, CompTIA Security+, and ISC2 Certified in Cybersecurity (CC) comes down to your career goals, budget, and how deeply you work within the Microsoft ecosystem. Here's how they compare on the dimensions that matter most when deciding where to invest your time and money.
Scope and Vendor Alignment
The SC-900 is a vendor-specific credential. It validates your understanding of Microsoft security, compliance, and identity services, including Azure AD, Microsoft Defender, Purview, and related cloud tools. If your target employer runs a Microsoft-centric environment, this credential signals relevant product literacy.
Security+ and the ISC2 CC are both vendor-neutral. Security+ covers a broad swath of cybersecurity domains, from threat analysis and risk management to cryptography and network security. The ISC2 CC similarly addresses foundational concepts across security principles, incident response, access controls, and network security, though its scope is somewhat narrower than Security+.
Exam Structure and Difficulty
- SC-900: 40 to 60 questions, 60 to 90 minutes, passing score of 700. This is the lightest exam of the three and serves as a baseline orientation rather than a practitioner-level test.
- ISC2 CC: 100 questions, 120 minutes, passing score of 700. Moderately harder than the SC-900, with broader conceptual coverage and a longer test window.
- Security+: 90 questions (including performance-based items), 90 minutes, passing score of 750 on a 100 to 900 scale. CompTIA recommends at least two years of hands-on IT experience before attempting it. This is the hardest of the three2 and the only one that routinely appears on DoD 8570 approved lists.
Cost Comparison
- SC-900: $99 exam fee. Renewal is free through a Microsoft Learn assessment before expiration.
- ISC2 CC: The exam itself is currently offered at no cost, but you pay a $50 annual maintenance fee once certified.
- Security+: $404 to $425 for the exam voucher. You also need 50 continuing education units every three years, along with a renewal fee,1 making it the most expensive option over time.
Which One Fits Your Path
If you're exploring cybersecurity for the first time and want a low-risk, low-cost introduction that doubles as a stepping stone toward Microsoft's more advanced security certifications (SC-200, SC-300, SC-400), the SC-900 is the practical starting point. If you need a broadly recognized, vendor-neutral credential that satisfies government and enterprise hiring requirements, Security+ carries the most weight, though it demands real preparation and a larger financial commitment. The ISC2 CC sits in the middle: vendor-neutral and affordable, with a difficulty level that stretches you beyond pure fundamentals without requiring professional experience.
Many career changers find it effective to earn the SC-900 first for quick confidence and Microsoft familiarity, then pursue Security+ or the ISC2 CC to build vendor-neutral credibility. The credentials are complementary rather than competing; using a How to Choose a Cybersecurity Certification framework will help you decide which doors to open next.
SC-900 Cross-Certification Pathways and Next Steps
The SC-900 is designed as a launchpad into Microsoft's role-based security certification ecosystem. While it does not serve as a formal prerequisite for any associate-level exam, the foundational knowledge it builds maps directly to four key progression paths. Note that AZ-500 retires on August 31, 2026, and is being replaced by the SC-500 (Cloud and AI Security Engineer Associate). All role-based certifications below are valid for 12 months and renewed through a free online assessment.

Frequently Asked Questions
Below are some of the most common questions prospective candidates ask about the SC-900. Where specific details like pricing or exam domains may shift over time, we point you to the authoritative sources so you can verify the latest information before registering.
Explore More
- AAISM Certification Guide
- Are Cybersecurity Certifications Worth It? ROI Guide
- AWS Certified Security Specialty Guide
- Brain Dumps & Exam Ethics in Cybersecurity Certifications
- BTL1 Certification Guide
- CCSP Certification Guide
- CEH Certification Guide
- CISA Certification Guide
- Cisco CCNA Cybersecurity Certification Guide
- Cisco CCST Cybersecurity Certification Guide
- CISM Certification Guide
- CISSP Certification Guide
- Compare Cybersecurity Certifications Side by Side
- CompTIA CySA+ Certification Guide
- CompTIA PenTest+ Certification Guide (PT0-003)
- CompTIA SecAI+ Certification Guide
- CompTIA Security+ Certification Guide
- CompTIA SecurityX Certification Guide
- CRISC Certification Guide
- Cybersecurity Certification Finder
- Cybersecurity Certification Methodology
- Cybersecurity Certification Prerequisites Explained
- Cybersecurity Certification Roadmaps by Role & Level
- Cybersecurity Certification Study Plan for Working Adults
- Cybersecurity Certification vs. Certificate vs. Bootcamp
- Cybersecurity Certifications Without a Degree
- Cybersecurity Degree vs. Certification vs. Bootcamp
- eJPT Certification Guide
- GIAC AI Platform Security (GAIPS)
- GIAC GICSP Certification Guide
- GIAC GPEN Certification Guide
- GIAC GSEC Certification Guide
- GIAC GWAPT Certification Guide
- Google Cybersecurity Certificate Guide
- Google Professional Cloud Security Engineer Guide
- How to Choose a Cybersecurity Certification
- How to Prepare for a Cybersecurity Certification Exam
- HTB CPTS Certification Guide
- ISACA CCOA Certification Guide
- ISC2 Certified in Cybersecurity (CC) Guide
- ISC2 CGRC Certification Guide
- ISC2 CSSLP Certification Guide
- ISC2 SSCP Certification Guide
- Microsoft SC-100 Certification Guide
- Microsoft SC-200 Certification Guide
- Online Cybersecurity Exams
- OSCP & OSCP+ Certification Guide
- OSWE Certification Guide
- PNPT Certification Guide
- Self-Study vs. Instructor-Led vs. Bootcamp Cyber Training
- Vendor-Neutral vs. Vendor-Specific Cybersecurity Certs






