SC-300: Microsoft Identity and Access Administrator
The exam measures the skills of a Microsoft identity and access administrator who designs, implements, and operates an organization’s identity and access management by using Microsoft Entra. Candidates configure and manage identities throughout their lifecycles for users, devices, Azure resources, and applications while applying Zero Trust principles. They plan and implement identity, authentication, authorization, identity governance, and hybrid identity solutions, and they monitor, troubleshoot, and report on identity and access environments.
What you get with membership
- The full SC-300 question bank with detailed explanations
- Readiness tracking by objective so you know when you're ready
- Access to every other exam in the Certavo library
- Content kept in step with the latest exam objectives
SC-300 exam objectives and study guide
The skills measured on the SC-300 exam, by objective domain. Percentages are the share of the exam each domain carries.
Implement authentication and access management
27.5% of the exam- Plan, implement, and manage Microsoft Entra user authentication
- Plan for authentication
- Implement and manage authentication methods, including certificate-based authentication, Temporary Access Pass, OAuth 2.0 tokens, Microsoft Authenticator, and passkeys (FIDO2)
- Implement and manage tenant-wide multifactor authentication (MFA) settings
- Configure and deploy self-service password reset (SSPR)
- Implement and manage Windows Hello for Business
- Disable accounts and revoke user sessions
- Implement and manage Microsoft Entra password protection
- Enable Microsoft Entra Kerberos authentication for hybrid identities
- Plan, implement, and manage Microsoft Entra Conditional Access
- Plan Conditional Access policies
- Implement Conditional Access policy assignments
- Implement Conditional Access policy controls
- Test and troubleshoot Conditional Access policies
- Implement session management
- Implement device-enforced restrictions
- Implement continuous access evaluation
- Configure authentication context
- Implement protected actions
- Create a Conditional Access policy from a template
- Manage risk by using Microsoft Entra ID Protection
- Implement and manage user risk by using Microsoft Entra ID Protection or Conditional Access policies
- Implement and manage sign-in risk by using Microsoft Entra ID Protection or Conditional Access policies
- Implement and manage multifactor authentication registration by using authentication methods and registration campaigns
- Monitor, investigate and remediate risky users and risky sign-ins
- Monitor, investigate, and remediate risky workload identities
- Implement Global Secure Access
- Deploy Global Secure Access clients
- Deploy and manage Private Access
- Deploy and manage Internet Access
- Deploy and manage Internet Access for Microsoft 365
Implement and manage user identities
22.5% of the exam- Configure and manage a Microsoft Entra tenant
- Configure and manage built-in and custom Microsoft Entra roles
- Recommend when to use administrative units
- Configure and manage administrative units
- Evaluate effective permissions for Microsoft Entra roles
- Configure and manage domains in Microsoft Entra ID and Microsoft 365
- Configure Company branding settings
- Configure tenant properties, user settings, group settings, and device settings
- Create, configure, and manage Microsoft Entra identities
- Create, configure, and manage users
- Create, configure, and manage groups
- Manage custom security attributes
- Automate bulk operations by using the Microsoft Entra admin center and PowerShell
- Manage device join and device registration in Microsoft Entra ID
- Assign, modify, and report on licenses
- Implement and manage identities for external users and tenants
- Manage External collaboration settings in Microsoft Entra ID
- Invite external users, individually or in bulk
- Manage external user accounts in Microsoft Entra ID
- Implement Cross-tenant access settings
- Implement and manage cross-tenant synchronization
- Configure external identity providers, including protocols such as SAML and WS-Fed
- Implement and manage hybrid identity
- Implement and manage Microsoft Entra Connect Sync
- Implement and manage Microsoft Entra Cloud Sync
- Implement and manage password hash synchronization
- Implement and manage pass-through authentication
- Implement and manage seamless single sign-on (SSO)
- Migrate from AD FS to other authentication and authorization mechanisms
- Implement and manage Microsoft Entra Connect Health
Plan and implement workload identities
22.5% of the exam- Plan and implement identities for applications and Azure workloads
- Select appropriate identities for applications and Azure workloads, including managed identities, service principals, user accounts, and managed service accounts
- Create managed identities
- Assign a managed identity to an Azure resource
- Use a managed identity assigned to an Azure resource to access other Azure resources
- Plan, implement, and monitor the integration of enterprise applications
- Plan and implement settings for enterprise applications, including application-level and tenant-level settings
- Assign appropriate Microsoft Entra roles to users to manage enterprise applications
- Design and implement integration for on-premises apps by using Microsoft Entra Application Proxy
- Design and implement integration for software as a service (SaaS) apps
- Assign, classify, and manage users, groups, and app roles for enterprise applications
- Configure and manage user and admin consent
- Create and manage application collections
- Plan and implement app registrations
- Plan for app registrations
- Create app registrations
- Configure app authentication
- Configure API permissions
- Create app roles
- Manage and monitor app access by using Microsoft Defender for Cloud Apps
- Configure and analyze cloud discovery results by using Defender for Cloud Apps
- Configure connected apps
- Implement application-enforced restrictions
- Configure Conditional Access app control
- Create access and session policies in Defender for Cloud Apps
- Implement and manage policies for OAuth apps
- Manage the Cloud app catalog
Plan and automate identity governance
22.5% of the exam- Plan and implement entitlement management in Microsoft Entra
- Plan entitlements
- Create and configure catalogs
- Create and configure access packages
- Manage access requests
- Implement and manage terms of use (ToU)
- Manage the lifecycle of external users
- Configure and manage connected organizations
- Plan, implement, and manage access reviews in Microsoft Entra
- Plan for access reviews
- Create and configure access reviews
- Monitor access review activity
- Manually respond to access review activity
- Plan and implement privileged access
- Plan and manage Microsoft Entra roles in Microsoft Entra Privileged Identity Management (PIM), including settings and assignments
- Plan and manage Azure resources in PIM, including settings and assignments
- Plan and configure PIM for Groups
- Manage the PIM request and approval process
- Analyze PIM audit history and reports
- Create and manage break-glass accounts
- Monitor identity activity by using logs, workbooks, and reports
- Review and analyze sign-in, audit, and provisioning logs by using the Microsoft Entra admin center
- Configure diagnostic settings, including configuring destinations such as Log Analytics workspaces, storage accounts, and Azure Event Hubs
- Monitor Microsoft Entra ID by using KQL queries in Log Analytics
- Analyze Microsoft Entra ID by using workbooks and reporting
- Monitor and improve the security posture by using Identity Secure Score
SC-300 practice questions and answers
10 free sample questions from the SC-300 bank, with the correct answer and a full explanation for each. These are original questions written to the Microsoft objective domains — not real exam content.
- Question 1Implement and manage user identities
The tenant currently permits all users to invite external collaborators. The identity team wants employees to continue sending invitations, and help desk administrators will assist with partner onboarding. Existing B2B guests keep the default guest permissions and must not be able to invite other guests. Which guest invite setting should you select?
- AAnyone in the organization can invite guest users including guests and non-admins.
- BMember users and users assigned to specific admin roles can invite guest users including guests with member permissions.
- COnly users assigned to specific admin roles can invite guest users.
- DNo one in the organization can invite guest users including admins.
Show answer and explanation
Correct answer
- Member users and users assigned to specific admin roles can invite guest users including guests with member permissions.
Explanation
The correct setting is Member users and users assigned to specific admin roles can invite guest users including guests with member permissions. It permits normal member users and users in invitation-capable admin roles to invite guests, while guests that keep default guest permissions cannot invite.
- Anyone in the organization can invite guest users including guests and non-admins would still allow default guest users to invite other guests.
- Only users assigned to specific admin roles can invite guest users would prevent ordinary employee member users from inviting guests.
- No one in the organization can invite guest users including admins would disable invitations for both employees and administrators.
References:
- Question 2Implement and manage user identities
Emi, an identity governance analyst, must onboard auditors from a partner Microsoft Entra tenant. Only a specific partner group should access one internal enterprise application, and the security team wants to trust the partner tenant's MFA claims to reduce duplicate prompts. The partner can provide its tenant ID, the group object ID, and the application ID. Which configuration should Emi use?
- AAdd the partner in Cross-tenant access settings, customize inbound B2B collaboration for the partner group and application, and configure the trust settings.
- BAdd the partner email domain to collaboration restrictions and set guest user access to the most restrictive option.
- CCreate a tenant restrictions v2 policy scoped to the partner tenant and the internal enterprise application.
- DAssign the Guest Inviter role to the partner administrator and ask them to invite the audit users.
Show answer and explanation
Correct answer
- Add the partner in Cross-tenant access settings, customize inbound B2B collaboration for the partner group and application, and configure the trust settings.
Explanation
The correct choice is to create organization-specific cross-tenant access settings for the partner and configure inbound B2B collaboration for selected external users and groups and selected applications. Cross-tenant access settings also include trust settings for MFA and device claims from other Microsoft Entra organizations.
- A domain allowlist controls which email domains can be invited; it does not scope access to a partner group and a specific application or trust partner MFA claims.
- Tenant restrictions v2 is used to control your users' access to external apps when using external accounts from your networks or devices.
- Assigning the Guest Inviter role delegates invitation capability; it does not configure inbound access scope or authentication trust between tenants.
References:
- Question 3Implement and manage user identities
A supplier user already has a B2B guest object with group memberships and enterprise app assignments. The user's email address is unchanged, but the supplier has moved authentication to its Microsoft Entra tenant, and the user must redeem the invitation again with the new home identity. The existing object ID and assignments must be preserved. What should you do?
- AReset the redemption status for the existing B2B collaboration user.
- BDelete the guest user object and send a new invitation to the same email address.
- CUpdate the existing account's `userType` property from `Guest` to `Member`.
- DRevoke the user's sessions and require the user to sign in again.
Show answer and explanation
Correct answer
- Reset the redemption status for the existing B2B collaboration user.
Explanation
The correct action is to reset the B2B guest user's redemption status. Resetting redemption lets the same guest user object be redeemed again, which preserves object-based assignments such as group memberships and app assignments.
- Deleting and reinviting the user creates a new object and can break assignments or application references that use the original object ID.
- Changing
userTypebetweenGuestandMemberchanges how the account is classified; it does not make the user redeem the invitation with a different home identity. - Revoking refresh tokens forces reauthentication but does not reset the B2B invitation redemption relationship.
References:
- Question 4Implement authentication and access management
The workforce uses unmanaged macOS, iOS, Android, and Linux devices from home networks. You need authentication-plane protection that limits sign-ins with external accounts to external Microsoft Entra applications. The design must work across browsers and platforms without deploying a corporate proxy. Which enforcement option should you use?
- AUniversal tenant restrictions in Microsoft Entra Global Secure Access.
- BWindows tenant restrictions v2 enforcement configured by Group Policy.
- CTenant restrictions v2 signaling inserted by an on-premises corporate proxy.
- DTenant restrictions v1 with a tenant allowlist configured on a proxy.
Show answer and explanation
Correct answer
- Universal tenant restrictions in Microsoft Entra Global Secure Access.
Explanation
Universal tenant restrictions in Microsoft Entra Global Secure Access are the best fit. They provide authentication-plane protection without a corporate proxy and can tag traffic across operating systems, browsers, and device form factors, including client and remote network connectivity scenarios.
- Windows device enforcement is intended for corporate-owned Windows devices, not unmanaged non-Windows platforms.
- A corporate proxy can inject tenant restrictions v2 signaling for authentication-plane protection, but the requirement explicitly excludes deploying a proxy.
- Tenant restrictions v1 uses a tenant allowlist on a corporate proxy and does not meet the no-proxy or tenant restrictions v2 requirements.
References:
- Question 5Implement authentication and access management
A security test plan must validate the data-plane and anonymous-access protections of Windows device-enforced tenant restrictions v2. Which two test cases should be included?
- AImport a copied access token on a managed Windows laptop and try to use it to access SharePoint Online.
- BOpen a Teams meeting link anonymously from a managed Windows laptop after the required federation controls are configured.
- CSign in interactively to a third-party SaaS application that uses Microsoft Entra ID by using an external account.
- DOpen a line-of-business web application that uses local forms authentication and does not use Microsoft Entra ID.
- ESign in to an external tenant from an unmanaged mobile phone that receives no tenant restrictions v2 signal.
Show answer and explanation
Correct answers
- Import a copied access token on a managed Windows laptop and try to use it to access SharePoint Online.
- Open a Teams meeting link anonymously from a managed Windows laptop after the required federation controls are configured.
Explanation
Windows device-enforced tenant restrictions v2 can provide data-plane protection for supported Microsoft 365 resources and anonymous-access protection for specific services.
- A copied access token used from a managed Windows device to access SharePoint Online validates token-infiltration protection on the data plane.
- Anonymous access to a Teams meeting link, when the required federation controls are configured, validates the anonymous-access protection scenario.
- Interactive sign-in to a third-party Microsoft Entra-integrated SaaS app is an authentication-plane scenario, not a data-plane validation.
- A line-of-business application using only local forms authentication is outside Microsoft Entra tenant restrictions v2 enforcement.
- An unmanaged phone with no tenant restrictions v2 signal does not validate Windows device-enforced restrictions.
References:
- Question 6Plan and automate identity governance
Litware's application governance meeting needs a portal report that summarizes Microsoft Entra application activity and AD FS application activity so owners can identify low-use apps. The team does not need to inspect individual sign-in events. Which report area should be used?
- AMicrosoft Entra ID > Monitoring & health > Usage & insights
- BMicrosoft Entra ID > Monitoring & health > Sign-in logs
- CMicrosoft Entra ID > Monitoring & health > Audit logs
- DMicrosoft Entra ID > Enterprise applications > Provisioning logs
Show answer and explanation
Correct answer
- Microsoft Entra ID > Monitoring & health > Usage & insights
Explanation
Microsoft Entra Usage & insights provides application-focused reports, including Microsoft Entra application activity and AD FS application activity. It is intended for reviewing application-specific sign-in activity trends without starting from individual raw sign-in events.
The sign-in logs are the detailed event records and are useful when an analyst needs individual authentication details. Audit logs are for tenant changes, such as user, group, and resource updates. Provisioning logs are for synchronization and provisioning service operations, not application usage summaries.
References:
- Question 7Plan and automate identity governance
Failed sign-ins must be summarized before the Monday stand-up. Complete the KQL query that lists Microsoft Entra apps with failed interactive user sign-ins from a Log Analytics workspace.
kql 1 | where ResultType != "0" | summarize FailedSignIns = count() by AppDisplayName | order by FailedSignIns descBlank 1
- ASigninLogs
- BAuditLogs
- CAADServicePrincipalSignInLogs
- DAADProvisioningLogs
Show answer and explanation
Correct answer
- Blank 1: SigninLogs
Explanation
SigninLogsis the Azure Monitor Logs table for Microsoft Entra interactive user sign-in records. In that table, a successful sign-in hasResultTypeof0, so filtering for values not equal to0returns failed sign-ins and then summarizes them byAppDisplayName.AuditLogscontains tenant change events, not sign-in attempts.AADServicePrincipalSignInLogsis for service principal sign-ins rather than interactive user sign-ins.AADProvisioningLogscontains provisioning service activity, not authentication events.References:
- Question 8Plan and implement workload identities
A quarterly governance review requires a quick explanation of how Defender for Cloud Apps can populate Cloud Discovery reports from firewall and proxy traffic logs before the team chooses a deployment method. Which two ingestion methods are supported for that log-based discovery?
- AUpload supported firewall or proxy traffic logs manually to create a snapshot report.
- BConfigure automatic log upload, such as by using a Defender for Cloud Apps log collector, to create continuous reports.
- CConnect each SaaS application by using a Defender for Cloud Apps app connector.
- DExport Microsoft Entra audit logs through diagnostic settings to a Log Analytics workspace.
- EEnable DNS proxy on Azure Firewall for the virtual networks that host the users' workloads.
Show answer and explanation
Correct answers
- Upload supported firewall or proxy traffic logs manually to create a snapshot report.
- Configure automatic log upload, such as by using a Defender for Cloud Apps log collector, to create continuous reports.
Explanation
The correct answers are manual snapshot upload and automatic log upload.
- A snapshot report can be created by manually uploading supported firewall or proxy traffic logs for point-in-time analysis.
- Automatic log upload, including a Defender for Cloud Apps log collector, supports continuous reports from network appliances.
- App connectors provide API-based visibility and governance for connected SaaS applications; they are not the log ingestion method for firewall or proxy Cloud Discovery reports.
- Microsoft Entra diagnostic settings can export Entra audit and sign-in logs, but they are not firewall or proxy traffic logs for Cloud Discovery.
- Azure Firewall DNS proxy changes DNS behavior for Azure Firewall clients; it does not upload secure web gateway logs to Defender for Cloud Apps.
References:
- Question 9Plan and implement workload identities
You are configuring custom real-time controls for a cloud app that appears as an enterprise application in Microsoft Entra ID. Which two configurations are required before Defender for Cloud Apps can enforce the controls during user browser sessions?
- AConfigure app access through Microsoft Entra SSO, such as SAML or OpenID Connect, for the users in scope.
- BCreate a Conditional Access policy that targets the app and users, and set Session to Use Conditional Access App Control with a custom policy.
- CAssign Microsoft Graph application permissions to the enterprise application so Defender for Cloud Apps can inspect the session.
- DConfigure Application enforced restrictions as the Conditional Access session control for the app.
- ECreate an Intune app protection policy for the SaaS web app and assign it to the same users.
Show answer and explanation
Correct answers
- Configure app access through Microsoft Entra SSO, such as SAML or OpenID Connect, for the users in scope.
- Create a Conditional Access policy that targets the app and users, and set Session to Use Conditional Access App Control with a custom policy.
Explanation
The two required pieces are Microsoft Entra sign-in for the app and a Conditional Access policy that routes the targeted browser sessions to Defender for Cloud Apps. For custom access and session policies in Defender for Cloud Apps, the Conditional Access session control should use Conditional Access App Control with a custom policy.
- Microsoft Graph application permissions don't route user browser sessions to Defender for Cloud Apps.
- Application enforced restrictions is a different Conditional Access session control where the cloud app applies a limited experience; it doesn't invoke custom Defender for Cloud Apps access and session policies.
- Intune app protection policies are useful for managed app data protection, but they aren't the prerequisite that enables Conditional Access App Control for a SaaS browser session.
References:
- Question 10Plan and implement workload identities
Users report that downloads from a protected SaaS app are not being intercepted. A Defender for Cloud Apps session policy exists and includes the correct app, users, and download criteria. The Microsoft Entra sign-in logs show that the Conditional Access policy for the same users and app only requires multifactor authentication and has no session control configured. What should you change first?
- AEdit the Conditional Access policy and add the Use Conditional Access App Control session control with the custom policy option for the same users and app.
- BEdit the Conditional Access policy and change the target resource from the SaaS enterprise app to Microsoft Graph.
- CEdit the Conditional Access policy and add Application enforced restrictions for the same users and app.
- DEdit the Conditional Access policy and configure Sign-in frequency for the same users and app.
Show answer and explanation
Correct answer
- Edit the Conditional Access policy and add the Use Conditional Access App Control session control with the custom policy option for the same users and app.
Explanation
You must route the session to Defender for Cloud Apps by configuring the Conditional Access session control.
- Correct: Defender for Cloud Apps access and session policies for Conditional Access App Control require a Conditional Access policy that sends the app session through Use Conditional Access App Control. For custom Defender policies, use the custom policy option.
- Targeting Microsoft Graph is not correct. Microsoft Graph is an umbrella resource and is not the target resource used to route this SaaS application session.
- Application enforced restrictions is a different Conditional Access session control. It passes device information to supported apps and does not enforce custom Defender for Cloud Apps session policies.
- Sign-in frequency can force reauthentication after a time period, but it does not proxy or inspect file downloads.
References:
Membership includes 186 questions and explanations aligned to the SC-300 curriculum, including 9 case studies.
Other Microsoft certifications
Every one of these is included with the same membership as SC-300.
Microsoft 365 Copilot and Agent Administration Fundamentals
This exam is intended for candidates who are familiar with Microsoft 365, including core services, security, identity and access, data…
Microsoft Azure AI Fundamentals
This exam measures knowledge of machine learning and AI concepts and related Microsoft Azure services. It is intended for candidates…
Microsoft Azure Fundamentals
This exam is intended for technology professionals who want to demonstrate foundational knowledge of cloud concepts and Microsoft Azure.…
SC-300 exam FAQ
How many questions are on the SC-300 exam?+
The SC-300 (Microsoft Identity and Access Administrator) exam has around 50 questions. Question counts vary slightly between exam forms, so treat this as the typical number rather than a guarantee.
How long is the SC-300 exam?+
You get 100 minutes for the SC-300 exam itself. Allow extra time at the test centre or for the online check-in process before the timer starts.
What level is SC-300?+
SC-300 is a Microsoft associate-level certification.
Are there free SC-300 practice questions?+
Yes. 10 free SC-300 practice questions are on this page, each with the correct answer and a full explanation. The complete bank of 186 questions is included with membership.
Are these real SC-300 exam questions?+
No. Every question is original, written to match the published SC-300 objective domains and question styles. Real exam content is confidential, and reusing it would breach Microsoft's exam policies.