Security, Compliance, and Identity Fundamentals (SC-900)
Foundational overview of security and identity concepts – Zero Trust principles, the CIA triad, multi-factor authentication (MFA), and Microsoft security tools.
Why did I take this certification?
I am genuinely interested in cybersecurity and enjoy studying it in my free time (such as practicing labs on TryHackMe). In my Service Desk role, I also deal with user accounts, passwords, and sign-in issues every single day.
I wanted to understand security fundamentals from Microsoft’s perspective – clarify core theory, understand why organizations enforce specific security policies, and build a structured theoretical baseline.
What did I actually learn?
The SC-900 exam is an entry-level foundational certification. It taught me essential security concepts:
1. Fundamental security principles
- The CIA Triad: The three foundational pillars of security:
- Confidentiality: ensuring data is only visible to authorized users.
- Integrity: ensuring data is not modified or tampered with by unauthorized parties.
- Availability: ensuring systems and data are available when users need them.
- Zero Trust Principle: The core guideline “never trust, always verify” – even when connecting from inside an office corporate network, identity and devices must be validated just as strictly as from anywhere else.
2. Identity and access concepts
- Authentication vs. Authorization:
- Authentication: identity verification – “Who are you?” (e.g. entering a password and confirming on a mobile device).
- Authorization: permission verification – “What are you allowed to do?” (which access rights and roles you hold).
- Importance of Multi-Factor Authentication (MFA): Why passwords alone are insufficient and how adding a second factor (e.g. the Microsoft Authenticator app) protects accounts against compromise.
- Microsoft Entra ID: High-level understanding of cloud identity and user management.
3. Overview of Microsoft security products
The exam introduced the theoretical purpose of Microsoft’s security ecosystem:
- Microsoft Defender: General understanding of endpoint antivirus and workstation protection.
- Microsoft Sentinel: Overview of what a SIEM is (a centralized tool for aggregating and evaluating security logs from different systems).
My reality and day-to-day use
In my day-to-day job, I don’t configure enterprise security policies or manage SOC incidents – I work on frontline user support on the Service Desk.
However, the knowledge from SC-900 provides a solid foundation:
- Troubleshooting sign-in issues: When users have trouble with passwords or the Authenticator app, I understand the underlying mechanics and can resolve tickets more effectively.
- Security awareness: I understand why security procedures must never be bypassed, even during urgent requests.
- Foundation for further study: It gives me a clean theoretical framework to build upon as I continue self-studying cybersecurity.