What changes on July 28, 2026
Microsoft's current SC-900 study guide identifies a refreshed set of skills measured as of July 28, 2026. This is a targeted objective update rather than a new exam code or a complete restructuring of the certification.
The four top-level skill areas and their weight ranges remain the same: security, compliance, and identity concepts at 10–15%; Microsoft Entra at 25–30%; Microsoft security solutions at 35–40%; and Microsoft compliance solutions at 20–25%. A learner with a sound existing plan should update selected topics instead of restarting from zero.
Microsoft Entra receives the clearest identity update
The refreshed guide explicitly includes agent ID within Microsoft Entra identity types. Study agent identities beside workforce, external, workload, and hybrid identities: know why an autonomous agent needs a governed identity, how that differs from a human account, and why least privilege still applies.
Microsoft also marks access-management coverage as a minor change. Keep Conditional Access and Microsoft Entra roles and role-based access control in the same mental model, then review access reviews, Privileged Identity Management, and Identity Protection under identity governance. SC-900 usually tests what a capability is for, not the exact portal sequence used to configure it.
Security infrastructure and Sentinel need a terminology refresh
The change log marks core infrastructure security services and Microsoft Sentinel coverage as minor updates. Review the purpose of network controls, workload protection, posture management, secret and key protection, and the relationship between preventive and detective controls.
For Sentinel, keep SIEM and SOAR separate. SIEM centralizes and analyzes security data; SOAR coordinates automated response. Be ready to distinguish detection, investigation, orchestration, and remediation instead of treating one security dashboard as the answer to every scenario.
Purview and trust topics remain outcome focused
Microsoft marks the Service Trust Portal and privacy-principles objective as a minor change while leaving the top-level compliance skill area unchanged. The domain still covers Compliance Manager, compliance score, information protection, data lifecycle management, data loss prevention, records, retention, insider risk, eDiscovery, and audit.
Study the outcome each feature supports. Sensitivity labels classify and protect information, DLP helps prevent inappropriate sharing, retention controls how long information is kept, eDiscovery supports legal investigation, and audit records activity. That distinction is more reusable than memorizing product menus.
A focused seven-day update plan
Day one: compare your notes with Microsoft's current change log and mark only the changed or renamed objectives. Days two and three: refresh Entra identity types, agent ID, access management, and Zero Trust. Day four: review infrastructure security and Microsoft Defender relationships.
Day five: revisit Sentinel, SIEM, SOAR, and incident-response scenarios. Day six: review Purview and Service Trust Portal outcomes. Day seven: complete a mixed checkpoint and explain why each selected service fits the stated business or security requirement.
How to keep future updates from disrupting your plan
Use the Microsoft study guide as your scope baseline and keep one dated checklist. When Microsoft publishes another change log, update that document rather than mixing several undated video notes and blog summaries.
Treat CertVector articles as study interpretation and Microsoft Learn as the final authority. Exam providers can adjust wording, availability, and measured skills, so check the official guide again before scheduling and during your final review week.
FAQ
Does SC-900 get a new exam code in July 2026?
No. Microsoft's published change is an update to the skills measured for SC-900, effective July 28, 2026, rather than a new exam code.
Do the SC-900 domain weights change?
The current Microsoft study guide keeps the same four top-level skill areas and weight ranges. The changes are targeted within selected objectives.
Should an existing candidate restart studying?
Usually not. Preserve the stable security, identity, and compliance foundation, then refresh the objectives Microsoft labels as changed or minor.
Follow the SC-900 track
Request launch priority for the planned SC-900 practice bank. To receive material objective-change alerts, select that email option in the checklist form above.
Request SC-900 launch priorityOfficial sources
Use the certification provider's current guidance as the final authority for exam scope, policies, and dates.
Next steps
Related articles
Related tracks
Back to resourcesLearner discussion
Ask clarifying questions or share study notes. Comments are not reviewed CertVector explanations.
No discussion yet. Start with a specific question or clarification.