🔒 Guided

Pre-launch preview. Authorised access only.

Incorrect code

Guided by A Guide to Cloud
Explore AB-900 AI-901
Guided SC-900 Domain 4
Domain 4 — Module 2 of 7 29%
23 of 28 overall

SC-900 Study Guide

Domain 1: Security, Compliance & Identity Concepts

  • Security Foundations: Shared Responsibility & Defence-in-Depth Free
  • Zero Trust: Never Trust, Always Verify Free
  • Encryption, Hashing & GRC Free
  • Identity: The New Security Perimeter Free

Domain 2: Microsoft Entra Capabilities

  • Microsoft Entra ID: Your Identity Hub Free
  • Hybrid & External Identities
  • Authentication: Passwords, MFA & Passwordless
  • Password Protection & Self-Service Reset
  • Conditional Access: Smart Access Decisions
  • Entra Roles and RBAC
  • Identity Governance: Entitlements and Access Reviews
  • PIM and Identity Protection

Domain 3: Microsoft Security Solutions

  • Azure Network Defence: DDoS, Firewall & WAF
  • Azure Infrastructure Security: VNets, NSGs, Bastion & Key Vault
  • Microsoft Defender for Cloud
  • Microsoft Sentinel: SIEM Meets SOAR
  • Defender XDR: The Unified Threat Platform
  • Microsoft Defender for Office 365
  • Microsoft Defender for Endpoint
  • Defender for Cloud Apps & Defender for Identity
  • Vulnerability Management & Threat Intelligence

Domain 4: Microsoft Compliance Solutions

  • Service Trust Portal, Privacy Principles & Microsoft Priva
  • The Purview Portal & Compliance Manager
  • Data Classification & Sensitivity Labels
  • Data Loss Prevention (DLP)
  • Records Management & Retention
  • Insider Risk Management
  • eDiscovery & Audit

SC-900 Study Guide

Domain 1: Security, Compliance & Identity Concepts

  • Security Foundations: Shared Responsibility & Defence-in-Depth Free
  • Zero Trust: Never Trust, Always Verify Free
  • Encryption, Hashing & GRC Free
  • Identity: The New Security Perimeter Free

Domain 2: Microsoft Entra Capabilities

  • Microsoft Entra ID: Your Identity Hub Free
  • Hybrid & External Identities
  • Authentication: Passwords, MFA & Passwordless
  • Password Protection & Self-Service Reset
  • Conditional Access: Smart Access Decisions
  • Entra Roles and RBAC
  • Identity Governance: Entitlements and Access Reviews
  • PIM and Identity Protection

Domain 3: Microsoft Security Solutions

  • Azure Network Defence: DDoS, Firewall & WAF
  • Azure Infrastructure Security: VNets, NSGs, Bastion & Key Vault
  • Microsoft Defender for Cloud
  • Microsoft Sentinel: SIEM Meets SOAR
  • Defender XDR: The Unified Threat Platform
  • Microsoft Defender for Office 365
  • Microsoft Defender for Endpoint
  • Defender for Cloud Apps & Defender for Identity
  • Vulnerability Management & Threat Intelligence

Domain 4: Microsoft Compliance Solutions

  • Service Trust Portal, Privacy Principles & Microsoft Priva
  • The Purview Portal & Compliance Manager
  • Data Classification & Sensitivity Labels
  • Data Loss Prevention (DLP)
  • Records Management & Retention
  • Insider Risk Management
  • eDiscovery & Audit
Domain 4: Microsoft Compliance Solutions Premium ⏱ ~11 min read

The Purview Portal & Compliance Manager

Your organisation's compliance command centre — how the Purview portal, Compliance Manager, and compliance score help you track and improve your regulatory posture.

One portal to rule compliance

☕ Simple explanation

Think of a car’s dashboard.

Your car has one dashboard that shows your speed, fuel, engine temperature, and warning lights — all in one place. You don’t open the bonnet to check the engine every time you drive.

The Microsoft Purview portal is the dashboard for your organisation’s compliance. It shows everything — what regulations you need to meet, how far along you are, and what’s still red.

The Microsoft Purview portal (purview.microsoft.com) is the centralised hub for managing compliance, data governance, and risk across your Microsoft 365 environment.

For the SC-900 exam, the focus is on the compliance side of Purview — data classification, sensitivity labels, DLP, and Compliance Manager. Purview also has a data governance side (data cataloguing, data estate mapping), but that’s outside the SC-900 scope.

Microsoft Purview portal

The Purview portal at purview.microsoft.com brings together all compliance tools under one roof:

AreaWhat It Covers
Compliance ManagerTrack compliance posture across regulations with assessments and improvement actions
Data classificationDiscover and classify sensitive data using SITs, trainable classifiers, and labels
Data Loss PreventionPolicies to prevent sensitive data from being shared inappropriately
Information protectionSensitivity labels, encryption, rights management
Data lifecycle managementRetention policies and labels to keep or delete data based on rules
Audit & eDiscoverySearch and investigate content for legal or compliance purposes
💡 Exam tip: Purview compliance vs Purview governance

Microsoft Purview has two sides:

  1. Purview compliance — managing regulations, protecting data, preventing leaks (this is what SC-900 tests)
  2. Purview governance — cataloguing data estates, mapping data lineage, scanning data sources (this is NOT on SC-900)

If an exam question mentions “data catalogue” or “data lineage,” that’s the governance side. If it mentions “DLP,” “sensitivity labels,” or “Compliance Manager,” that’s the compliance side.

Compliance Manager

Compliance Manager is the tool inside the Purview portal that helps you assess, track, and improve your compliance posture. Think of it as a project management tool for regulations.

The three building blocks

Assessments contain controls, which map to improvement actions
Building BlockWhat It DoesExample
AssessmentsPre-built templates that map your actions to specific regulationsA GDPR assessment shows every control you need and whether you've done it
Improvement actionsRecommended steps to improve compliance — each one can be assigned to a team memberEnable MFA for all users (reduces identity risk, improves GDPR and ISO 27001 scores)
ControlsThe specific requirements from a regulation that your actions map toGDPR Article 32: 'Implement appropriate technical measures' — mapped to encryption and access controls

Assessments in detail

Compliance Manager comes with hundreds of pre-built assessment templates for common regulations:

  • GDPR (EU General Data Protection Regulation)
  • HIPAA (US Health Insurance Portability and Accountability Act)
  • ISO 27001 (International information security standard)
  • NIST 800-53 (US federal security framework)
  • And many more — regional, industry-specific, and custom templates

Each assessment shows which controls are satisfied, which need work, and who is responsible.

💡 Scenario: Nadia sets up a HIPAA assessment

MedGuard Health needs to demonstrate HIPAA compliance for an upcoming audit. Nadia opens Compliance Manager and adds the HIPAA assessment template.

Immediately, she sees:

  • 120 improvement actions needed for HIPAA
  • 40 are already marked complete (things Microsoft handles, like data centre security)
  • 80 are customer-managed actions that MedGuard needs to address

Nadia assigns actions to the right people: Liam (IT Director) gets encryption and access control tasks, Dr. Torres gets data handling policy reviews. Each person sees their tasks in Compliance Manager and marks them as they complete.

Improvement actions: who does what?

Every improvement action falls into one of two ownership categories:

Microsoft handles infrastructure-level controls; you handle configuration and policy
FeatureMicrosoft-managedCustomer-managed
Who does it?MicrosoftYour organisation
ExamplePhysical data centre security, host OS patching, network encryptionEnabling MFA, configuring DLP policies, writing data handling policies
Can you change it?No — these are auto-completed by MicrosoftYes — you mark these as complete, in progress, or assign them to people
Impact on scoreIncluded in your total score automaticallyOnly counted when you mark the action as implemented and tested

Compliance score

The compliance score is a numeric value (0 to maximum) that measures your overall compliance posture. It works like Microsoft Secure Score, but for compliance instead of security.

How the score is calculated

Every improvement action has points. Those points are weighted by two dimensions:

1. Mandatory vs Discretionary

  • Mandatory: Actions required by the regulation (higher points)
  • Discretionary: Recommended best practices but not strictly required (lower points)

2. Preventive vs Detective vs Corrective

  • Preventive: Actions that stop issues before they happen (highest points) — e.g., encryption
  • Detective: Actions that find issues after they occur (medium points) — e.g., audit logs
  • Corrective: Actions that fix issues after detection (lowest points) — e.g., incident response plans

Key exam concept: Mandatory preventive actions score the highest because they both satisfy a regulation AND stop problems before they start. The exam may ask which type of action gives the most points.

💡 Scenario: Nadia prioritises by compliance score impact

Nadia has limited time before the audit. She opens Compliance Manager and sorts improvement actions by point value (highest first).

The top items:

  1. Enable encryption for data at rest — mandatory + preventive = 10 points
  2. Configure DLP policies for patient data — mandatory + preventive = 10 points
  3. Set up audit logging — mandatory + detective = 6 points
  4. Create an incident response plan — mandatory + corrective = 4 points

Nadia tackles encryption and DLP first — maximum compliance improvement for the effort spent.

💡 Exam tip: Compliance score vs Secure Score

These are easy to confuse:

  • Compliance score (in Compliance Manager) measures how well you meet regulatory requirements
  • Secure Score (in Microsoft Defender portal) measures how well you’ve configured security settings

Both give numeric scores and recommend improvement actions. But compliance score is about regulations, and Secure Score is about security posture. An action can appear in both (like enabling MFA).

🎬 Video walkthrough

🎬 Video coming soon

Purview Portal & Compliance Manager — SC-900 Domain 4.2

Purview Portal & Compliance Manager — SC-900 Domain 4.2

~9 min

Flashcards

Question

What is the Microsoft Purview portal used for in SC-900?

Click or press Enter to reveal answer

Answer

The centralised hub for compliance management — data classification, DLP, sensitivity labels, Compliance Manager, audit, and eDiscovery. The SC-900 focuses on the compliance side, not the data governance side.

Click to flip back

Question

What are the three building blocks of Compliance Manager?

Click or press Enter to reveal answer

Answer

1. Assessments — pre-built templates mapped to regulations (GDPR, HIPAA, ISO 27001). 2. Improvement actions — recommended steps assigned to team members. 3. Controls — specific regulation requirements that actions map to.

Click to flip back

Question

Which type of improvement action scores the most compliance points?

Click or press Enter to reveal answer

Answer

Mandatory preventive actions — they satisfy a regulation requirement AND stop problems before they happen. The scoring order: mandatory > discretionary, and preventive > detective > corrective.

Click to flip back

Question

What's the difference between Microsoft-managed and customer-managed actions?

Click or press Enter to reveal answer

Answer

Microsoft-managed actions are handled by Microsoft (like data centre security) and auto-complete. Customer-managed actions are your responsibility (like enabling MFA or configuring DLP). Both contribute to your compliance score.

Click to flip back

Knowledge Check

Knowledge Check

Nadia wants to track MedGuard's progress towards HIPAA compliance. She needs a dashboard that shows which controls are met and which need work. Which tool should she use?

Knowledge Check

In Compliance Manager, which type of improvement action earns the MOST compliance score points?

Knowledge Check

Nadia notices that 40 improvement actions in MedGuard's HIPAA assessment are already marked complete, even though her team hasn't done anything yet. What explains this?

← Previous

Service Trust Portal, Privacy Principles & Microsoft Priva

Next →

Data Classification & Sensitivity Labels

Guided

I learn, I simplify, I share.

A Guide to Cloud YouTube Feedback

© 2026 Sutheesh. All rights reserved.

Guided is an independent study resource and is not affiliated with, endorsed by, or officially connected to Microsoft. Microsoft, Azure, and related trademarks are property of Microsoft Corporation. Always verify information against Microsoft Learn.