CertVector

Exam updates

SC-900 July 2026 Update: Objective Changes and Study Checklist

A practical guide to Microsoft's July 28, 2026 SC-900 skills update, including what remains stable, which objectives changed, and how to adjust your study plan.

By CertVector Editorial TeamUpdated July 26, 20268 min read

Independent study guidanceEditorially reviewed July 26, 20262 sources
Sign in

What changes on July 28, 2026

Microsoft's current SC-900 study guide identifies a refreshed set of skills measured as of July 28, 2026. This is a targeted objective update rather than a new exam code or a complete restructuring of the certification.

The four top-level skill areas and their weight ranges remain the same: security, compliance, and identity concepts at 10–15%; Microsoft Entra at 25–30%; Microsoft security solutions at 35–40%; and Microsoft compliance solutions at 20–25%. A learner with a sound existing plan should update selected topics instead of restarting from zero.

Microsoft Entra receives the clearest identity update

The refreshed guide explicitly includes agent ID within Microsoft Entra identity types. Study agent identities beside workforce, external, workload, and hybrid identities: know why an autonomous agent needs a governed identity, how that differs from a human account, and why least privilege still applies.

Microsoft also marks access-management coverage as a minor change. Keep Conditional Access and Microsoft Entra roles and role-based access control in the same mental model, then review access reviews, Privileged Identity Management, and Identity Protection under identity governance. SC-900 usually tests what a capability is for, not the exact portal sequence used to configure it.

Free SC-900 checklist

Track the SC-900 objectives that actually changed.

Get a concise Microsoft Security, Compliance, and Identity checklist and material skills-update alerts.

Choose the emails you want

Security infrastructure and Sentinel need a terminology refresh

The change log marks core infrastructure security services and Microsoft Sentinel coverage as minor updates. Review the purpose of network controls, workload protection, posture management, secret and key protection, and the relationship between preventive and detective controls.

For Sentinel, keep SIEM and SOAR separate. SIEM centralizes and analyzes security data; SOAR coordinates automated response. Be ready to distinguish detection, investigation, orchestration, and remediation instead of treating one security dashboard as the answer to every scenario.

Purview and trust topics remain outcome focused

Microsoft marks the Service Trust Portal and privacy-principles objective as a minor change while leaving the top-level compliance skill area unchanged. The domain still covers Compliance Manager, compliance score, information protection, data lifecycle management, data loss prevention, records, retention, insider risk, eDiscovery, and audit.

Study the outcome each feature supports. Sensitivity labels classify and protect information, DLP helps prevent inappropriate sharing, retention controls how long information is kept, eDiscovery supports legal investigation, and audit records activity. That distinction is more reusable than memorizing product menus.

A focused seven-day update plan

Day one: compare your notes with Microsoft's current change log and mark only the changed or renamed objectives. Days two and three: refresh Entra identity types, agent ID, access management, and Zero Trust. Day four: review infrastructure security and Microsoft Defender relationships.

Day five: revisit Sentinel, SIEM, SOAR, and incident-response scenarios. Day six: review Purview and Service Trust Portal outcomes. Day seven: complete a mixed checkpoint and explain why each selected service fits the stated business or security requirement.

How to keep future updates from disrupting your plan

Use the Microsoft study guide as your scope baseline and keep one dated checklist. When Microsoft publishes another change log, update that document rather than mixing several undated video notes and blog summaries.

Treat CertVector articles as study interpretation and Microsoft Learn as the final authority. Exam providers can adjust wording, availability, and measured skills, so check the official guide again before scheduling and during your final review week.

FAQ

Does SC-900 get a new exam code in July 2026?

No. Microsoft's published change is an update to the skills measured for SC-900, effective July 28, 2026, rather than a new exam code.

Do the SC-900 domain weights change?

The current Microsoft study guide keeps the same four top-level skill areas and weight ranges. The changes are targeted within selected objectives.

Should an existing candidate restart studying?

Usually not. Preserve the stable security, identity, and compliance foundation, then refresh the objectives Microsoft labels as changed or minor.

Free SC-900 checklist

Track the SC-900 objectives that actually changed.

Get a concise Microsoft Security, Compliance, and Identity checklist and material skills-update alerts.

Choose the emails you want

Follow the SC-900 track

Request launch priority for the planned SC-900 practice bank. To receive material objective-change alerts, select that email option in the checklist form above.

Request SC-900 launch priority

Official sources

Use the certification provider's current guidance as the final authority for exam scope, policies, and dates.

Next steps

Related articles

Related tracks

Back to resources

Learner discussion

Ask clarifying questions or share study notes. Comments are not reviewed CertVector explanations.

0 comments

No discussion yet. Start with a specific question or clarification.