
Explore the four-part course flow for the Microsoft security, compliance and identity fundamentals, detailing parts, modules, lectures, quizzes, and the beta exam aligned with the SC-900 framework.
embrace zero trust by treating everything as untrusted and verifying every user, device, and resource inside or outside the network.
Zero trust rests on three principles: authenticate and authorize users based on identity and context, enforce least privileged access with risk-based policies, and assume breach with segmentation and encryption.
Understand the six foundational pillars of zero trust—infrastructure, network, devices, applications, data, and identities—and how to enforce monitoring, encryption, access controls, and least-privilege access.
Explore the cloud shared responsibility model across IaaS, PaaS, and SaaS, clarifying what security and governance duties belong to the CSP and what the customer owns, including data security.
Adopt the responsibility model where customers own data, devices, endpoints, and compliance, while Microsoft and cloud providers are not responsible for these protections. Emphasize aligning with certifications and security controls.
Explore the information security basics through the CIA triad—confidentiality, integrity, and availability—explaining how access controls, encryption, signatures, and data availability protect information.
explore defense in depth as a layered security approach that slows attackers and protects data across physical, identity and access management, perimeter, network, computer, application, and data layers.
Explore common threats that compromise data and operations, including data breaches, phishing and spearfishing, ransomware, and self-spreading malware.
Explore encryption for data at rest and in transit, explain symmetric and asymmetric schemes, and examine hashing methods and digital signatures to verify message integrity and origin.
Explore Microsoft's six privacy principles for safeguarding data, including control, transparency, security, legal protection, no advertising, and data use aimed at improving services.
Access the service trust portal to view audit reports and privacy documentation in one place. Explore security blueprints and ISO 27001 resources to understand how Microsoft implements controls in cloud.
This module covers common identity attacks, including brute force, dictionary attacks, phishing, and spear phishing, showing how attackers steal credentials and enable identity theft.
Explore how identity becomes the primary security perimeter across on-prem and cloud resources, guiding administration, authentication, authorization, and audit to protect digital identities.
Understand identity federation and the trusted identity provider model, where authentication is delegated to IDPs like Google or Facebook and services receive tokens to grant access.
Understand single sign-on (SSO) and its pain-point solution, as an identity provider authenticates a user once to grant access across multiple applications using common SSO protocols.
Explore directory services and active directory as hierarchical systems that store and manage network objects, acting as a central on-premises component with cloud-based identity as a service.
Azure directory is a global cloud-based identity service. It manages users, groups, devices, and access to internal and external apps, with flexible licensing from free to premium.
Explore Azure AD identity types and managed identities, including system and user managed, and learn how they enable secure authentication and a service principal without hard-coded credentials.
Explore Azure AD users, including cloud-based, on-premises, and B2B guest accounts. Create and manage them via the Azure portal, PowerShell, and Azure CLI, with MFA for extra security.
Explore Azure AD groups and security groups, including assigned static membership and dynamic rules for either users or devices (not both), Office 365 groups for access to calendar and OneDrive.
Azure AD Connect links on-premises and cloud identities to enable hybrid identity management, providing synchronization and single sign on for seamless access.
Explore Azure AD Connect authentication types, including password hash synchronization, pass through authentication, and federation integration, and learn how to choose methods for on-premises and cloud apps.
discover how Azure conditional access enforces zero trust by using signals like user, location, device, and apps to apply policies, prompt for multi-factor authentication, and control access.
Understand how Azure conditional access works when multiple policies apply, with all applicable policies needing satisfaction, two-phase evaluation, and a hierarchy of controls including MFA and compliant or joined devices.
Explore azure rbac: learn how roles, scope, and security principles grant fine-grained access to resources such as virtual machines, storage accounts, or databases, based on day-to-day duties.
Learn how to configure a conditional access policy with MFA in Azure, create a test user, apply conditions (devices, location, apps), and verify access prompts via the what-if tool.
Describe identity governance in Azure by outlining the identity lifecycle, provisioning, and privileged access management; automate access across systems like SAP, CRM, and PeopleSoft while auditors verify controls.
Entitlement management, an identity governance feature, automates the access lifecycle and built-in approvals, and manages access for internal and external users through access packages, catalogs, and policies.
Explore azure ad access reviews to efficiently manage group memberships, enterprise app access, and role assignments, ensuring the right people have the right access and auditing is maintained.
Explore how Azure privileged identity management secures elevated access to critical resources with just-in-time access, multi-factor authentication, access reviews, approvals, and audit trails.
Describe Azure identity protection's three reports—risky users, risky sign-ins, and risk detection—and how they help identify risks, block and remediate at-risk identities, and assess policy effectiveness.
Describe how Azure network security groups control inbound and outbound traffic with rules, priorities, sources, destinations, ports, and protocols, applied to a subnet or a single virtual machine.
Explore distributed denial of service attacks and how Azure DDoS protection defends web servers, applications, and endpoints with always-on detection, automatic mitigation, and real-time metrics under basic and standard offerings.
Discover how Azure DDoS Protection works by monitoring normal traffic with machine learning-based profiling and standard policies, auto-tuning, mitigating attacks, and redirecting traffic to protect public IPs and resources.
Manage Azure firewall centrally to enforce stateful, high-availability network security across hub-and-spoke networks, with threat intelligence, traffic filtering, and integrated logging.
Azure Bastion provides secure connectivity to virtual machines in a virtual network without exposing public IPs, using a private IP and SSL-protected access.
A web application firewall provides centralized protection for web applications against SQL injection, cross-site scripting, misconfigurations, and vulnerabilities, with integration to cloud and on-premises services.
Learn how Azure Key Vault acts as a managed secret solution to store secrets, encryption keys, and certificates with hardware security modules and management plane and data plane access controls.
Explore Azure Key Vault objects, including encryption keys, unstructured secrets, and certificates for data in transit, and discover how keys can be stored as secrets.
Explain how cloud security posture management helps govern vast cloud environments by identifying misconfigurations, unauthorized access, and lack of visibility, and automates alerts for security and compliance teams.
Discover Azure Security Center overview and how policy-based recommendations, threat analytics, and just-in-time access help secure VMs, databases, networks, and identities.
Explore Azure Security Center's overview of subscriptions, policy and compliance, and security hygiene. Learn how threat detection, alerts, and workflow automation integrate with SIEM tools like Splunk to secure environments.
Azure Defender protects workloads across cloud, on-prem, and multi-cloud environments, integrates with Azure Security Center, enforces built-in and custom policies and initiatives, and enables alerting and automation via logic apps.
Explore how to implement the Azure security benchmark to establish a cloud security baseline with best practices for network, identity, data protection, vulnerability and endpoint security, and meet regulatory requirements.
Learn how Azure Defender pricing works, including hourly and monthly options, a free 30-day trial, region and currency settings, and a calculator to estimate monthly costs.
Explore Azure Sentinel as a cloud-native SIEM that collects logs from on-premises sources. Leverage machine learning and threat intelligence to correlate alerts and automate responses with playbooks and ServiceNow.
Azure Sentinel provides a proactive, cloud-native SIEM that gathers data from cloud, on-prem, and multi-cloud sources to detect risks early with machine learning, addressing escalating alerts and insider threats.
This module explains Azure Sentinel pricing options, including pay-as-you-go and capacity reservations, emphasizes data ingestion and log analytics workspace storage, and demonstrates using the pricing calculator and regional variations.
Explore the Azure Sentinel portal, focusing on the workspace overview, incidents, analytics, log analytics queries, data connectors, workbooks, and playbooks, with automation for incident response.
Explore Azure Sentinel connectors to feed data from native Microsoft services and third-party sources, including AWS, Citrix, Barracuda, and Cisco, into Log Analytics for alerts and investigations.
Develop proactive threat hunting with Azure Sentinel by using built-in queries, notebooks, and bookmarks to investigate suspicious activity across networks, logs, and data sources.
Explore threat hunting with Microsoft Sentinel by running built-in and custom queries across data sources like cloud trail and office activity, then view results and bookmark findings for investigation.
Explore Microsoft 365 Defender, an enterprise defense suite that aggregates threat signals from apps and emails, identifies attacks, assesses their scope and impact on endpoints, and automates responses with playbooks.
Microsoft Defender for Endpoint is a unified endpoint protection platform with sensors that collect signals for threat intelligence, automated investigations, endpoint detection and response, playbooks, and risk-based vulnerability management.
Explore Microsoft Defender for Identity, a cloud-based solution that monitors user behavior, protects credentials, reduces attack surface, and detects advanced threats to safeguard high-value assets.
Explore Casb and its framework, revealing cloud access security broker capabilities to detect shadow IT, enforce policies, protect sensitive data, assess risk, and ensure cloud app compliance.
Explore cloud app security architecture to gain visibility and discovery of apps, dynamically analyze traffic, and enforce sanctioned app policies with app connectors and conditional access.
Learn how Microsoft Intune enables mobile device management and mobile application management, enforcing device and app policies for corporate data on both business-owned and bring your own devices.
Explore endpoint security with Intune, learning how admins assess device risk, manage security policies, and enforce compliance through malware scans and conditional access for Windows devices.
Explore how data protection meets regulatory requests across borders, with Microsoft 365 compliance supporting HIPAA, FERPA, and '7 seven deal one' regulations, and offering downloadable reports for your organization.
Explore the Microsoft 365 compliance center to view your organization's compliance posture, monitor active alerts and policies, access reports, and quickly discover, investigate, and respond to compliance issues.
Office 365 compliance manager guides organizations through their compliance journey with data inventory, risk assessment, and controls to meet regulations and certifications, plus actionable reports and workflows.
Explore the compliance manager features to centralize compliance actions, assign improvement actions, and run assessments against standards and regulations with Microsoft templates, custom templates, and detailed reporting.
Learn how the compliance score is calculated in the compliance center, with encryption and data protection boosting scores, and mandatory versus discretionary controls guiding preventive, detective, and corrective actions.
Learn data classification capabilities in the Office 365 Compliance Center, including sensitive information types and custom classifiers, plus Content Explorer and Activity Explorer for monitoring across OneDrive, Exchange, and SharePoint.
Describe data loss prevention in Office 365, outlining DLP policies across Exchange Online, SharePoint Online, OneDrive for Business, and endpoint data loss prevention to detect and automatically protect sensitive information.
Explain how retention policies and labels help organizations comply with regulations, manage content, and enforce automatic or manual labeling in Office 365 across SharePoint and OneDrive.
Describe records management for regulatory and military records in Office 365, highlighting labeling, migration, and admin controls that prevent changing or deleting a record once labeled.
Secure elevated access to critical resources with Azure privileged identity management, enabling just-in-time access, MFA enforcement, approvals, justifications, access reviews, and audit history.
Discover how e-discovery supports litigation by locating electronic information to serve as admissible court evidence. Explore how content search tools across exchange online and SharePoint Online identify data for discovery.
Explore the content search tool in Office 365 security and compliance center, build queries to narrow searches across emails, documents, mailboxes, and sites, and export or preserve results for e-discovery.
Describe the Gaudí discovery workflow in Office 365, showing how to create a discovery hold, search content with keywords and properties, and export results for e-discovery cases.
Explore advanced e-discovery workflows in Microsoft 365, from adding custodians and searching data sources to review, analyze, and export relevant content using the edrm framework.
Explore how Office 365 audit capabilities use a unified audit log to monitor user and admin activity across services, IP address data, and how to search, filter, and export results.
Explore the purpose and value of Office 365 advance auditing for long-term log storage, crucial events, and investigations, including mailbox, search, and SharePoint activity.
Discover how Azure resource lock prevents accidental deletions and changes by applying cannot delete or read-only locks at the resource group or resource level, protecting critical resources such as VMs.
Enable locks on Azure resources to prevent accidental deletion and enforce read-only and cannot delete modes on critical storage accounts.
Explore how Azure policy enables governance by defining and enforcing resource rules, ensuring encryption at rest, regional constraints, and compliance with organizational standards through policy definitions.
Azure blueprints provide reusable packages that bundle policy definitions, access controls, and ARM templates to enforce compliance standards across subscriptions, enabling consistent and scalable deployments.
Explore the cloud adoption framework, guiding organizations through strategy definition, planning, landing zones, migration, and governance with best practices and implementation guidance for cloud success.
Congratulations on completing SC-900: security, compliance & identity fundamentals and for your dedication to the exercises and quizzes; please share the course and rate it five stars on Udemy.
SC-900 Certification: Microsoft Security, Compliance, and Identity Fundamentals
The SC-900 certification is designed for professionals and individuals aiming to build a career in cybersecurity and compliance. Created by Microsoft, this exam covers essential security, compliance, and identity concepts, focusing on Microsoft’s cloud-based security services.
Course Overview: The SC-900 course is structured into four main sections, each featuring multiple modules to ensure a thorough understanding of key concepts:
1. Security, Compliance, and Identity Fundamentals
Module 1: Security Concepts and Methodologies
Explore the Zero Trust model, focusing on principles like verify explicitly, least privilege access, and assume breach.
Understand security pillars including identity, devices, applications, data, and networks.
Learn about the shared responsibility model, crucial for organizations moving to the cloud, and the principles of confidentiality, integrity, and availability.
Module 2: Microsoft Security and Compliance Principles
Study Microsoft’s six privacy principles and their impact on security strategies.
Navigate the Service Trust Portal to access compliance and regulatory documentation for Azure.
2. Microsoft Identity and Access Management Solutions
Module 1: Identity Principles and Concepts
Delve into identity basics such as identity as a security perimeter, authentication, authorization, and the role of Active Directory.
Understand federated services and their role in modern identity management.
Module 2: Azure AD Services and Identity Types
Learn the advantages of a cloud-based identity provider, including single sign-on (SSO).
Explore Azure AD’s pricing models and support for various identity types, including external users.
Module 3: Azure AD Authentication Capabilities
Understand multi-factor authentication (MFA) and how it enhances security.
Explore password protection and management features within Azure AD.
Module 4: Azure AD Access Management
Learn about Conditional Access and how it secures organizational assets.
Study Azure AD roles and their use in managing access to resources.
Module 5: Identity Protection and Governance in Azure AD
Explore Azure AD’s identity protection and governance features, including risk-based policies.
3. Microsoft Security Solutions
Module 1: Basic Security Capabilities in Azure
Discover services like network security groups (NSGs), Azure Firewall, and Azure DDoS Protection.
Learn about encryption techniques for data protection.
Module 2: Security Management with Azure Security Center
Understand how Azure Security Center provides a unified security management system.
Explore Azure secure score and Azure Defender for monitoring security posture and compliance readiness.
Module 3: Security with Azure Sentinel
Study Azure Sentinel and its role in SIEM (Security Information and Event Management).
Learn about threat detection, proactive hunting, and response capabilities.
Module 4: Microsoft 365 Defender for Threat Protection
Explore how Microsoft Defender protects against threats across identities, endpoints, Office 365, and cloud apps.
Module 5: Security Management in Microsoft 365
Dive into the Microsoft 365 security center, Secure Score, and security reports.
Learn about incident management capabilities in Microsoft 365.
Module 6: Endpoint Security with Microsoft Intune
Understand how Microsoft Intune manages and secures endpoints through Microsoft Endpoint Manager.
4. Microsoft Compliance Solutions
Module 1: Compliance Management in Microsoft 365
Learn about tools like the Microsoft 365 compliance center and Compliance Manager.
Understand how these tools simplify compliance processes for organizations.
Module 2: Information Protection and Governance
Study features like data classification, records management, and data loss prevention (DLP).
Module 3: Insider Risk Management
Explore insider risk management, communication compliance, and privileged access management (PAM).
Module 4: E-Discovery in Microsoft 365
Understand the purpose of eDiscovery, its core workflows, and advanced eDiscovery capabilities.
Module 5: Audit Capabilities in Microsoft 365
Learn about core auditing and the benefits of Advanced Auditing in Microsoft 365.
Module 6: Resource Governance in Azure
Explore Azure’s resource governance capabilities, including the Cloud Adoption Framework.