Microsoft SC-900 Certification Guide: Exam, Cost & Prep
Updated August 2, 202625+ min read

Microsoft SC-900 Certification: Your Complete Decision & Prep Guide

Everything you need to decide if SC-900 is right for you—exam format, study plans, career value, costs, and what comes next.

What you’ll learn in this article…

  • SC-900 costs around $110 USD, never expires, and requires no prerequisites.
  • Most candidates need roughly 10 to 15 hours of focused study.
  • It validates Microsoft security and compliance concepts, not hands-on technical skills.

The SC-900 costs $99 and never expires, making it one of the most accessible Microsoft certifications, but that affordability creates a persistent question: does a fundamentals badge carry enough weight to justify the study time? You are probably weighing this against CompTIA Security+ or ISC2 CC, especially if you need a credential that hiring managers recognize outside Microsoft-centric roles. A realistic look at exam difficulty, what the SC-900 actually validates, and which career paths it supports can prevent overspending on training or missing a better-fitting alternative. The certification’s real value lies in its laser focus on Microsoft’s security, compliance, and identity stack, not as a broad cybersecurity credential.

SC-900 Credential Snapshot

What exactly does the SC-900 exam cover, and where can you find the most current details before registering?

Microsoft updates its certification exams periodically, so the smartest first step is going directly to the source. The official Microsoft Learn credentials page provides the authoritative, up-to-date information you need: current exam price, duration, passing score, domain breakdown, and delivery options.

Where to Find Official Exam Details

The SC-900 exam page on Microsoft Learn is your primary reference. Here you will find:

  • Exam code and full title: The official designation and what Microsoft calls the certification
  • Current price: Listed in USD with regional variations noted
  • Time allotment: How many minutes you have to complete the exam
  • Passing score: The minimum scaled score required
  • Scored domains: The topic areas and their approximate weight percentages
  • Delivery method: Whether Pearson VUE online proctoring or test center options are available
  • Prerequisites: Any formal requirements or recommended background

Microsoft also publishes a downloadable study guide PDF that breaks down each domain's objectives in detail. This document typically updates when Microsoft modifies exam content, so check the revision date before building your study plan.

Additional Authoritative Sources

For salary benchmarking and career trajectory research, the Bureau of Labor Statistics at bls.gov provides government data on related occupations like information security analysts. Professional associations such as ISACA and ISC2 publish industry standards that help contextualize where foundational Microsoft certifications fit within broader career pathways.

Bookmark the official Microsoft certification page and check it within a week of your planned exam date. Exam prices, domain weightings, and even question formats can shift with little advance notice. The credentials community forums on Microsoft Learn also surface recent candidate experiences that help calibrate your preparation timeline.

What Microsoft SC-900 Validates and Why It Exists

The SC-900 certification validates foundational knowledge of security, compliance, and identity concepts within the Microsoft ecosystem. It does not test hands-on technical skills or require candidates to configure systems, write scripts, or respond to security incidents. Instead, it confirms that the holder understands core terminology, recognizes how Microsoft services address common security challenges, and can articulate the value of tools like Microsoft Entra ID, Microsoft Defender, and Microsoft Purview to stakeholders.

A Fundamentals-Tier Credential

Microsoft positions SC-900 at the same level as AZ-900 (Azure Fundamentals) and MS-900 (Microsoft 365 Fundamentals). All three are explicitly designed for non-technical and early-career audiences who need conceptual grounding rather than practitioner-level depth. The SC-900 does not assume prior experience with security operations centers, identity management consoles, or compliance auditing workflows. It assumes curiosity and a willingness to study.

Is SC-900 a beginner certification? Yes. It is Microsoft's lowest barrier entry point for anyone interested in security, compliance, or identity topics within Azure and Microsoft 365 environments. That said, "beginner" does not mean "no preparation required." Candidates still need dedicated study time to learn Microsoft's frameworks, service names, and how different products fit together.

Who Benefits Most

The SC-900 serves audiences who interact with Microsoft security tooling without building or operating it directly:

  • Business stakeholders: Managers and executives who approve budgets for Microsoft security products benefit from understanding what those tools actually do.
  • Sales and pre-sales engineers: Professionals who position Microsoft solutions to clients need fluency in security, compliance, and identity terminology.
  • Compliance and governance staff: Auditors, policy analysts, and risk professionals who evaluate Microsoft environments gain context for their assessments.
  • IT generalists: Help desk technicians, system administrators, and junior analysts who support Microsoft 365 or Azure tenants can build a foundation before pursuing a security analyst certification path.

How SC-900 Differs from Practitioner Certifications

The SC-900 is a vendor-specific credential, not interchangeable with role-based certifications that test job-ready skills. The SC-200 (Security Operations Analyst) exam, for example, requires candidates to investigate threats, configure detection rules, and respond to incidents using Microsoft Sentinel and Microsoft Defender. The SC-300 (Identity and Access Administrator) exam tests the ability to implement and manage identity solutions in production environments. Both assume real-world experience and substantially longer preparation timelines.

SC-900 holders have demonstrated comprehension, not operational competence. Employers and hiring managers should understand this distinction: the credential signals readiness to learn, not readiness to perform security operations independently.

Who Should Pursue the SC-900, and Who Shouldn't

The SC-900 is purpose-built for two distinct audiences, and largely a detour for everyone else. Its design as a fundamentals exam means it introduces security, compliance, and identity concepts within the Microsoft cloud ecosystem rather than testing hands-on technical skills. Knowing which bucket you fall into can save you months of study time and several hundred dollars in exam fees.

Profile 1: Career Changer with No IT Background

  • Verdict: Strong fit. The SC-900 is the on-ramp you are looking for.
  • Why: The exam assumes no prior security knowledge and focuses on vocabulary, core principles, and Microsoft's specific toolset. For someone making a cybersecurity career change, this credential provides a structured, vendor-anchored introduction without the intimidating depth of CompTIA Security+. It also gives you a recognizable line item on a resume while you build toward more technical certifications. Within 30, 40 hours of study, you can walk into an entry-level IT interview and demonstrate that you understand concepts like Zero Trust, identity governance, and Microsoft’s compliance portfolio.

Profile 2: Early IT Professional (Helpdesk, Junior Admin)

  • Verdict: Good fit for building Microsoft security literacy and signaling specialization interest.
  • Why: If you are already working with Microsoft 365 or Azure in a support capacity, the SC-900 helps you connect daily tasks to broader security frameworks. It shows your manager that you are serious about moving into a security role and provides a low-risk credential that your employer might fund. The exam’s emphasis on Microsoft Sentinel, Defender, and Purview also gives you concrete talking points for internal job applications. However, if you already have Security+, the SC-900 adds only marginal depth; in that case, consider jumping to the SC-200 (Security Operations Analyst) instead.

Profile 3: Working Cybersecurity Practitioner (1, 3 Years)

  • Verdict: Marginal value unless employer-required.
  • Why: You likely already possess the conceptual knowledge tested here. Most employers looking for a security analyst or engineer will prioritize experience and intermediate certifications like Security+, CySA+, or Microsoft’s associate-level certs. The SC-900 does not demonstrate hands-on capability and may even be seen as a regression on a cybersecurity-focused resume. Pursue it only if your organization explicitly asks for it (common in Microsoft partner firms) or if you need a lightning-fast, low-cost way to check a compliance box. Otherwise, invest the same effort into the SC-200 or AZ-500.

Profile 4: Experienced Specialist or Manager (5+ Years)

  • Verdict: Skip unless mandated for partner requirements or compliance.
  • Why: At this stage, your time is better spent on strategic certifications like CISSP, CISM, or Microsoft’s expert-level credentials. The SC-900 will not elevate your credibility or open doors that are not already open. Exceptions include: you are transitioning into a new role that heavily relies on Microsoft compliance documentation (e.g., a GRC manager in a Microsoft-first shop) or your employer must maintain a certain number of certified staff for Microsoft Solution Partner designations. Even then, confirm with your organization before registering.

Exam Format, Domains, Scoring, and Testing Options

The SC-900 exam is a carefully constructed assessment of foundational knowledge, not a casual quiz that you can breeze through without preparation. Every detail of its format, from the balance of question types to the domain weighting, is designed to verify that you genuinely understand Microsoft's security, compliance, and identity fundamentals.

Question Types and Structure

You will face 40 to 60 questions in a single, timed session. The exam draws from a mix of question formats, including traditional multiple-choice, multiple-select, drag-and-drop, dropdown selection, scenario-based items, and true/false style prompts.[CITE:2] Microsoft does not include hands-on lab simulations on the SC-900, so you won't be asked to configure a tenant or run PowerShell commands. However, you should expect scenario-driven questions that ask you to identify the correct Microsoft solution for a given business need, which tests your practical understanding just as effectively.

Exam Domains and Weighting

Microsoft publishes a detailed skills outline, last updated on November 7, 2025[CITE:1], that breaks the exam into four domains. The weighting reflects the relative importance of each topic area:

  • Describe the concepts of security, compliance, and identity (10, 15%): This introductory domain covers core principles like Zero Trust, defense in depth, and regulatory compliance concepts.
  • Describe the capabilities of Microsoft security solutions (35, 40%): The largest domain focuses on Microsoft's security portfolio, including Microsoft Defender, Microsoft Sentinel, and security management features.
  • Describe the capabilities of Microsoft Entra (25, 30%): Questions here center on identity and access management, including Entra ID editions, hybrid identity, and Conditional Access, topics central to an IAM specialist career path.
  • Describe the capabilities of Microsoft compliance solutions (20, 25%): This domain covers Microsoft Purview, information protection, data lifecycle management, and insider risk capabilities, tools directly relevant to understanding different types of cybersecurity audits.

Knowing these weights allows you to allocate study time strategically. Since over a third of your score depends on security solutions, that domain deserves substantial focus.

Scoring and Time Management

You have 65 minutes of total seat time: up to 45 minutes to answer the questions, plus extra time for reading instructions, accepting the non-disclosure agreement, and providing feedback.[CITE:2] The exam uses a scaled score system ranging from 0 to 1,000. A passing score is 700,[CITE:2] which does not translate to a simple percentage of correct answers; Microsoft's statistical model adjusts for question difficulty. You won't receive a detailed breakdown by domain if you pass, but failing candidates get a summary to guide retakes.

Because you cannot skip and return to flagged questions, pacing is critical. Aim to spend no more than one minute per question on first pass, then review any uncertain answers if time permits. The absence of labs means every minute is question time, so don't let scenario-based items consume your entire clock.

Testing Delivery Options

You can take the SC-900 either at a Pearson VUE test center or through online proctoring via the OnVUE platform.[CITE:2] Both modes use the same exam and scoring, so the choice comes down to personal preference and environment.

For online proctoring, you'll need a quiet, private room with a clean desk and no interruptions. Pearson VUE strictly enforces workspace rules: no duplicate monitors, no headphones, no eating or smoking, and your phone must be out of reach. You'll complete a check-in process that includes photos of your ID, your face, and your surroundings. A live proctor monitors you throughout the exam via webcam and microphone, so test your system's compatibility ahead of time using the OnVUE system test.

At a test center, you receive a secure workstation, a locker for your belongings, and a proctor present on-site. Some candidates find the center environment less distracting and free from the technical risks of a home setup, such as internet drops or software conflicts.

Accessibility accommodations are available for both delivery modes. You must submit a request through Microsoft's exam accommodations portal with supporting documentation before scheduling your exam. Common accommodations include extra time, screen magnifiers, and separate testing rooms. Start this process at least two weeks early to avoid delays.

SC-900 Exam Domains at a Glance

The SC-900 exam covers four weighted domains. Understanding how Microsoft distributes questions across these areas helps you allocate study time proportionally. The percentages below reflect the published exam guide as of early 2026.

SC-900 exam domain weights: Security Concepts 10%, Identity Concepts 25%, Security Solutions 35%, Compliance Solutions 30%

Full Cost Breakdown: Exam, Training, Retakes, and Renewal Fees

Understanding the full financial picture before registering for the SC-900 is essential, especially if you are a career changer looking to compare cybersecurity certifications side by side. Rather than relying on secondhand sources, you should verify every cost directly through Microsoft's official channels, since pricing and policies do shift over time.

Exam Registration Fee

Microsoft publishes the current price for each certification exam on its credentials page at learn.microsoft.com. The SC-900 exam fee has historically been positioned at the lower end of Microsoft's certification pricing scale, consistent with its fundamentals-level designation. However, the exact amount can vary by country or region, and Microsoft periodically adjusts prices. Always confirm the price in your local currency on the official scheduling page before booking.

If you need to retake the exam, Microsoft's candidate handbook outlines specific waiting periods between attempts. Generally, there is a short mandatory wait after a first failed attempt, with progressively longer intervals for additional retakes within a given period. The retake fee is typically the same as the original exam fee, so plan your study timeline carefully to avoid unnecessary costs.

Training and Preparation Costs

Preparation expenses range from zero to several hundred dollars depending on your cybersecurity certification study plan. Microsoft offers free, self-paced learning paths on Microsoft Learn that align directly with the SC-900 exam objectives, making it possible to prepare using free cybersecurity training. Microsoft has also periodically offered Virtual Training Days, instructor-led sessions that sometimes include a complimentary exam voucher upon completion. Check the Microsoft Events page to see whether a qualifying event is currently scheduled, as availability rotates and eligibility rules can change.

Beyond free options, independent training platforms and practice exam providers offer paid courses and question banks. Prices vary widely, so compare reviews and ensure any third-party resource maps to the current exam outline rather than an outdated version.

Renewal Costs

Microsoft fundamentals certifications do not expire in the same way that role-based certifications do, which means there is currently no renewal fee or continuing education requirement. This is a meaningful cost advantage over credentials that require annual or biennial renewal payments. Verify the latest renewal policy on Microsoft's certification renewal FAQ, since policies can evolve as the program matures.

How to Stay Current on Costs

To keep your cost estimates accurate, bookmark these resources:

  • Microsoft credentials page: Lists exam prices, objectives, and scheduling links.
  • Candidate handbook: Covers retake policies, accommodation requests, and exam-day rules.
  • Microsoft Events page: Shows upcoming Virtual Training Days and any voucher offers.
  • Professional associations and community forums: Groups like ISACA, (ISC)2, and CompTIA communities often share timely updates when pricing or voucher programs change.

By checking these sources directly, you avoid relying on outdated blog posts or unofficial estimates. A few minutes of verification can save you from surprise charges and help you budget realistically for the entire credential journey.

How Difficult Is the SC-900 and How to Prepare

The SC-900 occupies a unique spot in Microsoft's catalog: it is widely regarded as one of the easiest exams the company offers, yet people still fail it by underestimating the breadth of concepts. If you walk in cold without any exposure to cloud identity or compliance terminology, you'll struggle. But if you spend even a modest amount of structured time with the learning materials, you can clear the bar without breaking a sweat.

How Hard Is the SC-900, Really?

Against similar entry-level security exams, the difficulty is low to moderate. Compared to CompTIA Security+, which expects you to apply concepts and troubleshoot scenarios, the SC-900 stays firmly at the knowledge level. You need to recognize and describe principles, not configure a firewall or analyze a log file. Candidates coming from the SC-200 or AZ-500 world often call the SC-900 a "breeze." It is not a technical deep-dive, and Microsoft intentionally designed it as a first step for people new to security, compliance, and identity concepts on Microsoft platforms.

  • Exam style: Definitions, benefit statements, and identifying which Microsoft service does what. No hands-on labs or case studies.
  • Common pitfalls: Test-takers often brush off the compliance and privacy modules, but the exam frequently probes GDPR, Microsoft Purview capabilities, and the specifics of Azure Policy. Those sections can sink a test-taker who only studied identity and network security.

Study Time Estimates by Learner Profile

Your preparation time depends heavily on your starting point.

  • Already comfortable with Azure or M365 security basics: 10 to 15 hours. You will be reinforcing terminology and filling gaps around compliance and insider risk management.
  • General IT background but new to Microsoft cloud: 20 to 25 hours. You need extra time to map traditional security concepts onto Microsoft's service names and licensing tiers.
  • Complete beginner, no IT experience: 25 to 40 hours. You will learn foundational concepts and Microsoft's product landscape simultaneously. Break this into daily 60- to 90-minute sessions so the compliance terminology doesn't blur together.

Two Structured Study Plans

Both plans use the free Microsoft Learn learning path as the backbone, following the strategies outlined in our how to prepare for a cybersecurity certification exam article. Bookmark the official SC-900 exam page to pull the most current skills outline before you start.

2-Week Plan (for experienced IT or cloud learners)

  • Days 1-2: Complete the Microsoft Learn modules for "Describe the concepts of security, compliance, and identity" (approximately 4 hours). Take notes on shared responsibility, defense in depth, and Zero Trust.
  • Days 3-5: Work through "Describe the capabilities of Microsoft Entra" (identity). Pay attention to PIM, identity protection, and licensing differences.
  • Days 6-8: Tackle Microsoft Security solutions: Defender services, Sentinel, and Microsoft 365 security features.
  • Days 9-10: Finish with compliance capabilities: Microsoft Purview, eDiscovery, audit, and privacy.
  • Days 11-12: Take the official Microsoft practice assessment twice. Review every wrong answer using the linked documentation.
  • Days 13-14: Light review of weak areas plus one full-length timed practice exam from a third-party source.

4-Week Plan (for beginners)

  • Week 1: Same as above but slower, aiming for about 5 hours per week on the concepts domain. Supplement with YouTube overviews from John Savill or Microsoft Mechanics for visual reinforcement.
  • Week 2: Identity domain, with hands-on clicking around in a free Microsoft 365 E5 trial tenant. Seeing the portals makes the menu names stick.
  • Week 3: Security and compliance domains, alternating days. Use the Microsoft Learn sandbox to explore Purview and Defender interfaces.
  • Week 4: two practice exam rounds per week, each followed by deep review. In the final days, narrow in on the lowest-scoring domain.

Practice Test Sources: Which Ones Mirror the Real Exam?

  • Microsoft Official Practice Assessment (free): Available on Microsoft Learn. The question style and difficulty are the closest match to the live exam. Use this first and last.
  • MeasureUp: Officially endorsed by Microsoft. Their question bank is larger and often more difficult than the actual test, so if you pass MeasureUp consistently, you are ready.
  • Whizlabs: Moderate difficulty. Good for drilling term recognition, but some questions feel more like memorization puzzles than the real exam's scenario-lite paragraphs.
  • Free quiz platforms (like Quizlet or random YouTube "SC-900 practice questions"): Useful for quick recall on the go. Do not rely on them as your only measure of readiness because answer explanations and accuracy vary widely.

What to Do If You Fail

A failing score is not the end and does not go on a permanent record anyone else sees. Your score report breaks down performance by domain, so you will know exactly where you fell short, whether identity, compliance, or security operations.

  • Interpret weak areas: If one domain scored below 60 percent, that becomes your full-time focus for the next attempt. Re-read the Microsoft Learn modules and take the official practice assessment by filtering questions to that domain only.
  • Retake waiting period: Microsoft enforces a 24-hour wait before a second attempt, in line with their Online Cybersecurity Exams: Proctoring and Retakes policies. For third and subsequent attempts, the waiting period extends to 14 days between exam sittings. Use that time to fix knowledge gaps, not to cram the same way again.
  • Action plan: Create a short log of the concepts that tripped you up during the exam while the memory is fresh. Then find a study buddy or post in the Microsoft Learn community to talk through those points aloud. Explaining a concept to someone else often locks it in faster than re-reading slides.

Jobs, Salary Impact, and Employer Use Cases

What jobs can you actually get with the SC-900 certification, and how much does it help your salary?

This is where expectations need to align with reality. The SC-900 is a fundamentals certification, and fundamentals certifications rarely unlock jobs on their own. What SC-900 does well is signal Microsoft security literacy to employers already invested in the Microsoft ecosystem, and it positions you for roles where that baseline knowledge matters.

Roles Where SC-900 Adds Value

The SC-900 maps best to entry-level and adjacent positions where Microsoft cloud security concepts are relevant but not the primary technical requirement. Many of these roles, like the entry level cybersecurity jobs we cover, include:

  • SOC Analyst (Tier 1): Entry-level security operations roles increasingly involve Microsoft Sentinel, Defender, and Azure AD. SC-900 demonstrates you understand how these tools fit together conceptually.
  • Junior Security Administrator: Organizations running Microsoft 365 and Azure environments value candidates who grasp identity management and compliance frameworks before diving into hands-on configuration.
  • GRC Analyst: Governance, risk, and compliance roles benefit from SC-900’s coverage of Microsoft Purview and compliance portal capabilities.
  • IT Compliance Coordinator: Roles focused on regulatory alignment and audit support gain context from SC-900’s compliance and data governance modules.
  • Cloud Support Engineer: Help desk and support roles in Microsoft partner organizations often require familiarity with security and identity concepts across Azure and Microsoft 365.

Why SC-900 Alone Is Not Enough

Hiring managers rarely filter candidates specifically for SC-900. Instead, they use it as a checkbox confirming you understand the Microsoft security stack at a conceptual level. The certification becomes most valuable when stacked with either relevant experience or practitioner-level credentials like SC-200 (Security Operations Analyst), SC-300 (Identity and Access Administrator), or AZ-500 (Azure Security Engineer), as outlined in Cybersecurity Certification Roadmaps.

Microsoft partner organizations frequently use SC-900 for internal staff baseline credentialing, particularly for sales, pre-sales, and customer success teams who need security fluency without deep technical responsibilities. HR departments at these organizations sometimes filter for SC-900 as a signal of Microsoft ecosystem familiarity, especially when hiring for roles that touch security without being security-focused.

Salary Context and Career Ceiling

The SC-900 itself does not command a salary premium. However, the career path it supports can lead to well-compensated roles, as reflected in broader cybersecurity salary data. According to BLS data, information security analysts earn a median annual wage of $124,910, with the 25th percentile at $92,160 and the 75th percentile reaching $159,600.2 These figures represent the career ceiling for practitioners who stack experience with advanced certifications, not the starting point for someone holding only SC-900.

Long-Term Career Trajectory

The broader field offers strong momentum. The Bureau of Labor Statistics projects 29 percent job growth for information security analysts between 2024 and 2034, characterized as much faster than average. This translates to roughly 53,000 to 55,000 new positions over the projection period, with approximately 16,000 annual openings.1

These numbers frame the opportunity, but the salary and career upside comes from progression. SC-900 validates foundational knowledge. The real advancement happens when you stack it with practitioner certifications, hands-on project experience, and demonstrated expertise in Microsoft security tooling.

Information Security Analyst Salary by State

The SC-900 is a foundational credential, so it is most relevant to professionals entering or supporting the information security field rather than senior analysts. Still, understanding the salary landscape for information security analysts helps frame where this certification fits into longer career plans. The figures below reflect annual wages for information security analysts across all 50 states, the District of Columbia, and Puerto Rico, based on data from the Occupational Employment and Wage Statistics program (2024) published by the U.S. Bureau of Labor Statistics.

StateTotal EmploymentMedian Annual Salary25th Percentile75th PercentileMean Annual Salary
Washington6,830$142,920$117,040$169,350$144,140
California15,800$140,660$105,150$178,090$152,640
Maryland8,770$140,480$105,230$175,390$145,450
New Jersey4,730$135,390$108,320$168,240$141,130
Delaware630$134,050$105,310$154,060$130,860
New Mexico1,760$133,780$101,940$166,300$131,220
Virginia18,670$132,460$101,610$166,510$136,680
New York8,860$131,100$98,320$170,220$139,540
Colorado5,840$130,570$102,350$164,010$135,980
Connecticut1,160$130,500$95,260$152,410$127,740
New Hampshire730$129,690$98,540$158,360$128,040
Minnesota2,550$128,830$99,300$145,860$126,150
District of Columbia2,010$127,760$109,680$150,920$132,790
Massachusetts5,780$127,610$101,730$161,940$129,350
Hawaii580$125,790$99,730$154,340$128,310
Arizona4,170$125,320$88,520$161,250$123,780
Texas14,730$124,970$96,020$149,780$126,800
Georgia6,480$124,270$92,620$156,390$126,380
Idaho870$121,970$87,980$157,060$145,880
WyomingN/A$121,290$82,350$161,650$122,570
North Carolina6,850$121,070$88,560$147,030$122,310
Oregon1,370$119,000$93,650$152,880$132,430
Illinois4,560$114,300$83,960$138,130$119,540
Iowa1,180$112,950$82,990$133,830$116,710
North Dakota340$112,330$89,520$112,330$101,200
Alabama3,290$111,110$79,870$138,270$112,800
Pennsylvania4,420$110,230$79,670$137,900$114,870
Rhode Island880$109,410$85,790$141,690$117,010
West Virginia270$107,820$79,870$123,770$103,770
Ohio5,070$107,570$83,480$137,430$115,600
Nevada1,570$106,530$80,380$136,710$111,340
Florida13,770$105,990$86,250$139,150$117,500
Michigan3,120$104,540$79,920$129,150$107,630
South Dakota430$103,310$86,360$115,300$104,120
Missouri2,560$102,440$78,210$130,810$107,250
Alaska210$102,170$96,320$121,060$111,900
Kansas1,380$99,420$71,960$129,080$100,850
Wisconsin1,760$99,210$79,640$128,770$106,260
Kentucky1,790$98,210$67,650$128,910$102,820
Utah1,720$97,180$72,800$127,980$101,430
Nebraska1,120$95,470$85,120$122,360$103,310
Maine270$93,710$73,890$129,560$99,420
Arkansas1,010$93,560$66,800$125,550$96,080
Louisiana580$88,200$73,830$107,250$101,280
MontanaN/A$87,100$87,100$102,650$99,560
Vermont80$86,810$67,080$108,940$95,800
Oklahoma1,270$86,500$57,490$117,500$92,390
Mississippi560$84,640$60,240$105,830$89,910
Indiana2,540$78,290$64,500$115,650$91,740
Puerto Rico470$59,520$44,780$81,330$62,190

Renewal, Expiration, and Continuing Education

SC-900 is a Microsoft fundamentals certification, and it comes with a significant perk: it never expires.1 Unlike associate, expert, or specialty role-based Microsoft certifications that require annual renewal, the SC-900 badge is valid for life once you pass. There is no renewal window, no recurring exam, and no continuing education mandate to keep the certification active.

SC-900 Is a Lifetime Credential

When you earn the SC-900, your transcript shows the certification indefinitely. Microsoft does not impose a renewal cadence for any fundamentals exam, including SC-900. This means you can list it on your resume without worrying about a ticking clock. The only way the credential could lose relevance is if you choose not to stay current with the security, compliance, and identity landscape, but that is a personal decision, not a Microsoft requirement.

No Renewal Assessment, No Fee, No Expiration

Because SC-900 is a fundamentals certification, there is no open-book renewal assessment, no 30- to 45-minute online quiz, and no 24-hour wait after a failed attempt that you see with higher-level Microsoft certs. You will not receive email reminders about an upcoming expiration because there simply is no expiration date. Those processes apply only to role-based certifications like SC-200, SC-300, or SC-400, which do require annual renewal through the Microsoft Learn platform.2

If you hold or plan to pursue those associate-level certifications later, remember that each of them will have its own one-year renewal cycle. But the SC-900 remains untouched by that policy. It serves as a permanent foundational marker on your Microsoft certification transcript.

Optional Continuing Learning Paths

While formal continuing education is not required, Microsoft encourages credential holders to keep learning. The security ecosystem changes often, and Microsoft regularly updates its SC-900 learning paths on Microsoft Learn with new modules, case studies, and updated features. You can revisit those modules anytime at no cost. This is purely voluntary and has no impact on your certification status.

If you plan to move into an IT or cybersecurity career, using the SC-900 as a permanent anchor while exploring other credentials, like those in the All Cybersecurity Certifications Directory, is a common approach. The lack of expiration also means you won't need to budget for renewal fees or schedule a proctored retake years later. Your initial effort pays off for the duration of your career.

SC-900 Vs. Security+ Vs. ISC2 CC

Entry-level cybersecurity certifications now serve distinct purposes, and choosing between the SC-900, CompTIA Security+, and ISC2 Certified in Cybersecurity (CC) comes down to your career goals, budget, and how deeply you work within the Microsoft ecosystem. Here's how they compare on the dimensions that matter most when deciding where to invest your time and money.

Scope and Vendor Alignment

The SC-900 is a vendor-specific credential. It validates your understanding of Microsoft security, compliance, and identity services, including Azure AD, Microsoft Defender, Purview, and related cloud tools. If your target employer runs a Microsoft-centric environment, this credential signals relevant product literacy.

Security+ and the ISC2 CC are both vendor-neutral. Security+ covers a broad swath of cybersecurity domains, from threat analysis and risk management to cryptography and network security. The ISC2 CC similarly addresses foundational concepts across security principles, incident response, access controls, and network security, though its scope is somewhat narrower than Security+.

Exam Structure and Difficulty

  • SC-900: 40 to 60 questions, 60 to 90 minutes, passing score of 700. This is the lightest exam of the three and serves as a baseline orientation rather than a practitioner-level test.
  • ISC2 CC: 100 questions, 120 minutes, passing score of 700. Moderately harder than the SC-900, with broader conceptual coverage and a longer test window.
  • Security+: 90 questions (including performance-based items), 90 minutes, passing score of 750 on a 100 to 900 scale. CompTIA recommends at least two years of hands-on IT experience before attempting it. This is the hardest of the three2 and the only one that routinely appears on DoD 8570 approved lists.

Cost Comparison

  • SC-900: $99 exam fee. Renewal is free through a Microsoft Learn assessment before expiration.
  • ISC2 CC: The exam itself is currently offered at no cost, but you pay a $50 annual maintenance fee once certified.
  • Security+: $404 to $425 for the exam voucher. You also need 50 continuing education units every three years, along with a renewal fee,1 making it the most expensive option over time.

Which One Fits Your Path

If you're exploring cybersecurity for the first time and want a low-risk, low-cost introduction that doubles as a stepping stone toward Microsoft's more advanced security certifications (SC-200, SC-300, SC-400), the SC-900 is the practical starting point. If you need a broadly recognized, vendor-neutral credential that satisfies government and enterprise hiring requirements, Security+ carries the most weight, though it demands real preparation and a larger financial commitment. The ISC2 CC sits in the middle: vendor-neutral and affordable, with a difficulty level that stretches you beyond pure fundamentals without requiring professional experience.

Many career changers find it effective to earn the SC-900 first for quick confidence and Microsoft familiarity, then pursue Security+ or the ISC2 CC to build vendor-neutral credibility. The credentials are complementary rather than competing; using a How to Choose a Cybersecurity Certification framework will help you decide which doors to open next.

SC-900 Cross-Certification Pathways and Next Steps

The SC-900 is designed as a launchpad into Microsoft's role-based security certification ecosystem. While it does not serve as a formal prerequisite for any associate-level exam, the foundational knowledge it builds maps directly to four key progression paths. Note that AZ-500 retires on August 31, 2026, and is being replaced by the SC-500 (Cloud and AI Security Engineer Associate). All role-based certifications below are valid for 12 months and renewed through a free online assessment.

Microsoft security certification pathway from SC-900 fundamentals through four associate-level role-based certifications in 2026

Frequently Asked Questions

Below are some of the most common questions prospective candidates ask about the SC-900. Where specific details like pricing or exam domains may shift over time, we point you to the authoritative sources so you can verify the latest information before registering.

Yes. Microsoft designed the SC-900 (Security, Compliance, and Identity Fundamentals) as a foundational credential in the broader catalog of cybersecurity certifications. It does not require prior IT experience or prerequisite certifications. That said, candidates with at least a basic understanding of cloud computing concepts and general IT terminology will find the material easier to absorb. If you are completely new to technology, spending a few weeks with introductory cloud literacy content before diving into SC-900 study materials can smooth the learning curve considerably.

Most candidates with some IT familiarity report preparing in roughly two to four weeks of focused study. If you are brand new to Microsoft Azure, identity concepts, or compliance frameworks, plan for closer to four to six weeks. Microsoft Learn offers a free, self-paced learning path mapped directly to the exam objectives, which is the best starting point. Supplementing that with practice questions and short video walkthroughs can help reinforce weaker areas.

Compared to associate or expert level Microsoft certifications, the SC-900 is on the easier end of the spectrum. It tests conceptual understanding rather than deep technical configuration skills. The biggest challenge for most test takers is the breadth of topics: you need to be comfortable with security principles, compliance concepts, and identity services across the Microsoft ecosystem. Candidates who rely solely on memorization without understanding how these services relate to each other tend to struggle more.

The SC-900 is a fundamentals credential, so it is best understood as a knowledge validator rather than a standalone hiring qualification. It is most useful for roles adjacent to security, such as IT support, help desk, cloud administration, or compliance coordination, where demonstrating baseline security literacy adds value. For dedicated cybersecurity analyst or engineer positions, employers typically look for associate or professional level certifications alongside hands-on experience. You can explore role-specific career roadmaps in our cybersecurity career guide to see where SC-900 fits within broader progression paths.

The two serve different purposes. SC-900 is vendor specific and foundational: it validates your understanding of Microsoft security, compliance, and identity services. Security+ is vendor neutral and covers a broader set of cybersecurity domains at a more applied level, serving as the starting point for the CompTIA cybersecurity career path. Security+ also carries more weight with employers hiring for dedicated security roles, particularly in government and defense sectors where it meets certain baseline requirements. Many career changers find value in earning SC-900 first as a confidence builder, then pursuing Security+ or a Microsoft associate level certification next.

Microsoft fundamentals certifications, including SC-900, do not expire and do not require renewal. Once you pass the exam, the credential remains valid indefinitely. However, because the underlying technologies and services evolve, it is wise to stay current through continuing education. Microsoft periodically updates exam content, and reviewing the latest exam skills outline on the official Microsoft Learn site is a good habit even after you have earned the badge.

Always check the official Microsoft Learn credentials page for the SC-900. That page lists the current exam code, registration fee, skills measured, and any recent updates to the exam outline. For broader salary benchmarks related to security roles, the Bureau of Labor Statistics (bls.gov) publishes occupational data for information security analysts. Professional associations and our Cybersecurity Certification Finder can help you compare training options and map out next steps after the SC-900.

Recent Articles

In this article

Follow us