dc dotCreds
Reference guide

SC-900 Course Notes

Study SC-900 section notes, then jump straight into the guided course or related practice questions without losing your place.

Continue CourseStart PracticePDF downloads available in Pro.
Checking access

Checking Pro access...

Looking for your active Pro access before showing Course Notes. This usually takes just a moment.

Course Notes preview

Unlock Pro for the full per-exam reference guide.

Preview one piece from each section. Pro includes every Course Notes section, summary, key point, common mistake, exam tip, related-question review, and PDF export.

Includes full Course Mode and Course Notes.

Section 1Describe the concepts of security, compliance, and identityPreview
More in this section
  • 13 more key points in Pro version
  • 9 more common mistakes in Pro version
  • 9 more exam tips in Pro version
  • 22 more related questions in Pro version

Summary

Shared responsibility model in cloud computing: This objective covers defense-in-depth. Defense-in-depth combines controls at multiple layers so failure of one safeguard does not expose the entire system. This objective covers the core principles of the Zero Trust model, emphasizing a shift from implicit trust to continuous verification and limited access. This objective covers the core techniques of encryption and hashing, emphasizing their roles in protecting data integrity and confidentiality. This card focuses on the core concepts of security, compliance, and identity within a Governance, Risk, and Compliance (GRC) framework. It emphasizes accountability, risk prioritization, and the ongoing management of controls to achieve organizational objectives. This objective defines identity as the primary security perimeter, emphasizing that access control should be based on verifying the identity of users and non-human entities before granting access to resources, regardless of location. This objective covers understanding the fundamental distinction between authentication and authorization. Authentication confirms identity, while authorization determines access rights. Successful authentication precedes authorization; MFA utilizes multiple authentication factors. Authorization is the process of determining what actions a user or system is permitted to perform after successful authentication. It ensures access is granted only when necessary and aligned with the principle of least privilege. This objective covers understanding the role of identity providers (IdPs) in establishing consistent security and compliance across applications and resources. IdPs centralize identity management, enabling trust relationships and simplifying access control. This objective covers understanding directory services, specifically Active Directory and Microsoft Entra ID, and their role in managing identities and resources within an organization. Federation enables authentication trust between identity systems, distinct from directory synchronization or copying objects. It allows applications to accept trusted identity assertions or tokens without requiring password exchange.

Key Points

  • The shared responsibility model dictates that Microsoft secures the underlying infrastructure (physical, virtual, and platform), while the customer is responsible for securing their data, applications, identities, and configurations.

Common Mistakes

  • IaaS vs. PaaS: IaaS shifts responsibility to the customer for the operating system and runtime, while PaaS shifts responsibility to Microsoft.

Exam Tips

  • Carefully analyze the cloud service model (IaaS, PaaS, or SaaS) described in the scenario to determine which party is responsible for each component.
Section 2Describe the capabilities of Microsoft EntraPreview
More in this section
  • 13 more key points in Pro version
  • 9 more common mistakes in Pro version
  • 9 more exam tips in Pro version
  • 52 more related questions in Pro version

Summary

Microsoft Entra ID manages cloud identities, application access, single sign-on, and sign-in monitoring without replacing every AD DS capability. It focuses on cloud-based identity solutions. Microsoft Entra provides distinct identity constructs to manage various entities, including people, applications, devices, and AI agents. Understanding these distinctions is crucial for effective identity governance and security. This objective covers understanding how Microsoft Entra facilitates hybrid identity, enabling a single identity for users accessing both on-premises and cloud resources. It centers on leveraging synchronization tools to achieve this common identity. This card focuses on understanding the different authentication methods available within Microsoft Entra, specifically concentrating on the types of evidence used to verify user identities. This objective covers Microsoft Entra Multifactor Authentication (MFA) and its role in strengthening security by leveraging multiple authentication factors. MFA reduces the risk of unauthorized access even if a user's password is compromised. Microsoft Entra provides password protection capabilities to mitigate password-related risks. These capabilities include password protection with custom banned terms, SSPR with combined registration for MFA, and smart lockout to prevent malicious password guessing. Microsoft Entra Conditional Access operates as a Zero Trust policy engine, dynamically evaluating user, device, location, and risk signals to enforce access controls. This card focuses on Microsoft Entra Role-Based Access Control (RBAC), detailing how to effectively manage permissions within Entra using built-in and custom roles, aligning with the principle of least privilege. Microsoft Entra ID Governance automates identity changes (joiner, mover, leaver) and governs access throughout its lifecycle, from request to removal. It provides visibility and evidence that access controls operate as intended, supporting audit requirements and compliance. Access reviews validate whether users still require access to resources (groups, applications, roles, access packages). Microsoft Entra Privileged Identity Management (PIM) enables just-in-time activation of privileged roles, providing granular control and enhanced security. PIM manages Entra roles, Azure resource roles, and supported groups, recording assignments and activations for auditing and compliance. PIM leverages eligible assignments to allow users to activate privileged roles on an as-needed basis. These assignments are governed by configurable controls, including approval workflows, multi-factor authentication (MFA), justification requirements, and limited duration settings. PIM records all privileged assignments and activations, creating a comprehensive audit trail for security and compliance purposes. This includes tracking role assignments and activation history across both Entra roles and Azure resource roles. Microsoft Entra ID Protection leverages risk detections to assess authentication requests and user identities. Understanding the distinction between sign-in risk and user risk is crucial for security.

Key Points

  • Entra ID provides cloud IAM but does not replace every AD DS protocol or domain-service capability.

Common Mistakes

  • Unlike traditional AD DS, Entra ID is a cloud-based service and does not replicate every AD DS protocol or domain-service capability. It's designed to complement, not replace, existing on-premises AD infrastructure.

Exam Tips

  • Focus on the core purpose of Entra ID: cloud identity and access management. Avoid assuming it's a direct replacement for all AD DS functionality.
Section 3Describe the capabilities of Microsoft security solutionsPreview
More in this section
  • 13 more key points in Pro version
  • 9 more common mistakes in Pro version
  • 9 more exam tips in Pro version
  • 67 more related questions in Pro version

Summary

Azure DDoS Protection provides DDoS mitigation capabilities, offering two tiers: DDoS IP Protection and DDoS Network Protection. Understanding the differences between these tiers and their respective attack mitigation layers is crucial for effective protection. Azure Firewall is a managed firewall service that centrally enforces network and application policies and inspects east-west and north-south traffic. It utilizes network and application rules, and integrates threat intelligence for comprehensive protection. Azure Web Application Firewall (WAF) protects web applications from common layer 7 attacks like SQL injection and cross-site scripting. It's deployed with Azure Front Door and Application Gateway, providing centralized policy enforcement at the application layer. This objective covers establishing secure network boundaries within Azure using virtual networks, subnets, and peering, enabling isolation and controlled traffic flow between environments. Network security groups (NSGs) provide network-level security controls for Azure virtual networks. They operate at the subnet or network interface level, filtering inbound and outbound traffic based on source, destination, port, and protocol. NSGs are associated with subnets or network interfaces to enforce traffic policies. Azure Bastion provides a managed platform service for secure administrative connectivity to virtual machines within a virtual network. It enables RDP and SSH access over TLS without requiring public IP addresses or direct exposure of management ports on the VMs. Azure Key Vault provides a secure location to store and manage cryptographic keys, secrets, and certificates. This centralized management reduces the risk of hardcoding sensitive information within applications and infrastructure. Microsoft Defender for Cloud is a CNAPP that spans posture and workload protection across supported Azure, AWS, and Google Cloud environments. It combines CSPM capabilities with cloud workload protection for deployed resources. Cloud Security Posture Management (CSPM) continuously assesses cloud configurations, prioritizes recommendations to reduce exposure risk, and can surface attack paths. CSPM focuses on proactive posture management and remediation, unlike cloud workload protection which addresses threats to running workloads. This objective covers leveraging Microsoft security solutions to improve cloud security posture through the strategic application of policies, standards, and recommendations. Enhance cloud security by leveraging runtime threat protection for workloads. Cloud workload protection detects active threats using workload telemetry and threat intelligence, generating alerts for investigation and response. This objective covers capabilities providing runtime protection, complementing posture assessments performed by CSPM. This objective defines Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) concepts, focusing on their combined use within Microsoft Sentinel. SIEM ingests and analyzes security data, while SOAR coordinates response; Sentinel automation rules and playbooks provide response workflows. Microsoft Sentinel utilizes data connectors to ingest telemetry from various sources. Analytics rules trigger alerts based on defined conditions, while threat-hunting queries enable proactive investigation. Sentinel incidents consolidate alerts and entities for comprehensive attack scope assessment. Microsoft Defender XDR provides a unified view of security events across multiple domains – email, identities, endpoints, and services – by correlating related signals into incidents. Defender for Office 365 provides capabilities to detect and mitigate various threats, including malware in attachments and phishing attacks. Microsoft Defender for Endpoint provides endpoint detection and response (EDR) capabilities, enabling the detection and investigation of endpoint behavior. It supports automated response workflows and integrates with Defender XDR for broader threat intelligence and correlation. The service focuses on reducing attack surfaces and responding to detected threats. Microsoft Defender for Cloud Apps provides capabilities for Cloud Access Security Broker (CASB), Shadow IT discovery, and real-time session controls. Defender for Identity monitors supported identity signals to detect suspicious authentication, privilege escalation, and lateral movement. It leverages behavioral analytics and known attack patterns to identify these threats, and correlates with XDR for comprehensive threat detection. Microsoft Defender Vulnerability Management continuously discovers assets and identifies vulnerabilities. It provides prioritization, remediation recommendations, and tracks fixes. Microsoft Defender Threat Intelligence provides curated information about threats, including reputation, infrastructure relationships, and actor profiles, to enhance investigations and proactively defend against attacks. It complements vulnerability scanning by focusing on adversary tactics and techniques. The Microsoft Defender portal consolidates supported security signals, incidents, hunting, investigation, and response in one location.

Key Points

  • DDoS IP Protection: Designed for smaller deployments with a single protected IP address.

Common Mistakes

  • DDoS IP Protection vs. DDoS Network Protection: IP Protection is per-IP, while Network Protection is a virtual-network plan with automatic tuning.

Exam Tips

  • Focus on the attack layers: Understand the distinction between layer 3/4 and layer 7 attacks and the corresponding mitigation services.
Section 4Describe the capabilities of Microsoft compliance solutionsPreview
More in this section
  • 13 more key points in Pro version
  • 9 more common mistakes in Pro version
  • 9 more exam tips in Pro version
  • 47 more related questions in Pro version

Summary

The Service Trust Portal is the central location for accessing Microsoft cloud audit reports and compliance information, including reports produced by external auditors. Authenticated customers can download these reports. Microsoft-authored whitepapers provide guidance on cloud data protection and compliance practices, but are distinct from independent audit reports. Microsoft's privacy principles center on customer control, transparency, purpose limitation, and robust data protection. The Microsoft Purview portal is a single entry point for data security, governance, risk, and compliance solutions. Compliance Manager provides prebuilt and custom assessments for regulations, standards, and policies. Suggested improvement actions provide guidance for reducing compliance risk and implementing controls. Compliance Manager supports assigning, testing, documenting, and monitoring compliance activities in one solution. Compliance Manager distinguishes customer-managed, Microsoft-managed, and shared controls. The Compliance Manager calculates a score reflecting progress on improvement actions. This score does not certify legal or regulatory compliance but provides a metric for prioritizing remediation efforts. This objective covers selecting the appropriate Microsoft Purview classification techniques to identify and categorize sensitive data based on its characteristics and the available context. Content Explorer and Activity Explorer are key tools for managing and investigating sensitive and labeled content. Understanding their distinct roles is crucial for effective compliance. This objective covers Microsoft compliance solutions, specifically the use of sensitivity labels to classify content and enforce protection. It covers how labels persist across locations and how policies are used to manage labeling behavior and automated application. This objective covers how Microsoft Purview Data Loss Prevention (DLP) protects sensitive information by identifying, classifying, and controlling its use and sharing across various locations. DLP policy conditions use sensitive information types, labels, and context to determine when rules apply and enforce appropriate responses. Microsoft Purview Records Management enables organizations to manage records according to regulatory requirements. This includes declaring records as regulatory, restricting editing/deletion, and routing content for disposition review before final deletion. This objective covers Microsoft compliance solutions using retention policies and retention labels to manage content lifecycles. Retention policies apply retain or delete settings broadly at a container or location level. Retention labels apply item-level settings, and retention label policies publish or automatically apply labels. Microsoft Purview Insider Risk Management identifies and mitigates insider risk by correlating multiple signals to detect potential malicious or inadvertent actions. This capability leverages policy-defined scenarios, pseudonymization, and role-based access controls to protect sensitive data and intellectual property. This objective covers utilizing Microsoft Purview eDiscovery to manage electronically stored information (ESI) for legal and compliance purposes. This objective covers utilizing Microsoft Purview Audit Standard to investigate user and administrator activities, specifically searching for events based on workload, activity, user, and time.

Key Points

  • Service Trust Portal: Repository for external audit reports and compliance information.

Common Mistakes

  • External audit reports provide independent assurance evidence, while Microsoft-authored whitepapers offer guidance.

Exam Tips

  • Understand the access requirements for restricted documents.