Microsoft Identity & Access Administrator (SC-300) — Practice Exam | Oluma Digital Cert Zone · Identity & Access Management Microsoft Identity & Access Administrator SC-300 Microsoft Certified: Identity and Access Administrator Associate The SC-300 validates your ability to design, implement, and operate an organization’s identity and access management using Microsoft Entra ID — managing users and groups, securing authentication with MFA and Conditional Access, protecting workload identities, and governing access with PIM, access reviews, and entitlement management. Managed byMicrosoftExam codeSC-300LevelAssociate (role-based)DeliveryPearson VUE — online proctored or test centerLength~100 minutesExam fee~US$165 (varies by region)RenewalAnnually — free online renewalQuestions here100 practice itemsFormatMultiple choice 🔗 Official exam page — learn.microsoft.com → SC-300 What the exam covers The official skills are grouped into these domains. 01Implement and manage user identitiesTenants, users & groups, external (B2B) identities, hybrid identity and device join.02Implement authentication & access managementMFA, passwordless, Conditional Access, SSPR, and Entra ID Protection.03Plan and implement workload identitiesApp registrations, service principals, managed identities, and permissions/consent.04Plan and implement identity governanceEntitlement management, access reviews, PIM, terms of use and lifecycle workflows. Domain weightings shift slightly between exam refreshes — always confirm the current skills outline on the official exam page above. Practice questions Number of questions: 10 25 50 All 100 Pick a length, then choose an answer for instant feedback. Your score tracks below and counts only the questions you can see. User identitiesWhat is a Microsoft Entra tenant?A single user accountA dedicated, isolated instance of Entra ID for an organizationAn on-prem domain controllerA virtual network✓ Access granted. A tenant is an organization's own isolated Entra ID directory instance.✗ Access denied. Correct answer: A dedicated, isolated instance of Entra ID for an organization. A tenant is an organization's own isolated Entra ID directory instance.User identitiesWhich group membership type adds and removes users automatically based on attribute rules?Assigned groupDynamic groupDistribution listMail-enabled group✓ Authenticated. Dynamic groups use membership rules to update membership automatically (requires Entra ID P1).✗ Access denied. Correct answer: Dynamic group. Dynamic groups use membership rules to update membership automatically (requires Entra ID P1).User identitiesAn 'Assigned' group differs from a dynamic group because it:Uses attribute rulesRequires members to be added manuallyCannot hold usersIs read-only✓ Identity verified. Assigned (static) groups have members added/removed manually by an admin.✗ Access denied. Correct answer: Requires members to be added manually. Assigned (static) groups have members added/removed manually by an admin.User identitiesTo let an external partner collaborate using their own organization's credentials, you use:B2B collaboration (guest invitation)A shared passwordA new full member licenseA service principal✓ Trust established. B2B collaboration invites external users as guests who sign in with their home credentials.✗ Access denied. Correct answer: B2B collaboration (guest invitation). B2B collaboration invites external users as guests who sign in with their home credentials.User identitiesWhich solution is designed for customer-facing sign-up/sign-in (consumer identity)?Entra ID P2Azure AD B2C / Entra External IDGroup-based licensingAdministrative units✓ Privilege confirmed. B2C / Microsoft Entra External ID handles consumer (CIAM) identities separate from workforce users.✗ Access denied. Correct answer: Azure AD B2C / Entra External ID. B2C / Microsoft Entra External ID handles consumer (CIAM) identities separate from workforce users.User identitiesSelf-Service Password Reset (SSPR) allows users to:Bypass MFAReset or unlock their own account after verifying identityDelete other usersAssign licenses✓ Token validated. SSPR reduces helpdesk load by letting users securely reset/unlock their own passwords.✗ Access denied. Correct answer: Reset or unlock their own account after verifying identity. SSPR reduces helpdesk load by letting users securely reset/unlock their own passwords.User identitiesWhich license tier is required for dynamic groups and Conditional Access?FreeEntra ID P1Windows Server CALOffice E1✓ Session secured. Dynamic membership and Conditional Access require at least Microsoft Entra ID P1.✗ Access denied. Correct answer: Entra ID P1. Dynamic membership and Conditional Access require at least Microsoft Entra ID P1.User identitiesThe hybrid identity method that syncs a hash of the on-prem password hash to the cloud is:Pass-through AuthenticationPassword Hash Synchronization (PHS)FederationCertificate-based auth✓ Policy enforced. PHS synchronizes a hash of the password hash so users can sign in to Entra ID with the same password.✗ Access denied. Correct answer: Password Hash Synchronization (PHS). PHS synchronizes a hash of the password hash so users can sign in to Entra ID with the same password.User identitiesWhich hybrid method validates passwords against on-prem AD in real time via an agent?Password Hash SyncPass-through Authentication (PTA)Seamless SSO onlyB2B✓ Threat neutralized. PTA uses lightweight agents to validate sign-ins directly against on-prem AD.✗ Access denied. Correct answer: Pass-through Authentication (PTA). PTA uses lightweight agents to validate sign-ins directly against on-prem AD.User identitiesWhich tool synchronizes on-premises AD objects into Entra ID?Microsoft Entra ConnectGroup PolicyWSUSDFS✓ Clean scan. Entra Connect (and Cloud Sync) synchronize on-prem AD identities to the cloud tenant.✗ Access denied. Correct answer: Microsoft Entra Connect. Entra Connect (and Cloud Sync) synchronize on-prem AD identities to the cloud tenant.User identitiesThe lightweight, agent-based alternative to Entra Connect Sync is:Entra Connect Cloud SyncAD FSIntuneDefender✓ Root of trust intact. Cloud Sync uses a lightweight agent managed from the cloud, good for multiple/disconnected forests.✗ Access denied. Correct answer: Entra Connect Cloud Sync. Cloud Sync uses a lightweight agent managed from the cloud, good for multiple/disconnected forests.User identitiesTo delegate administration over only a subset of users (e.g., one region), you use:Administrative unitsA distribution groupA named locationA managed identity✓ Credentials accepted. Administrative units scope admin roles to a defined set of users, groups, or devices.✗ Access denied. Correct answer: Administrative units. Administrative units scope admin roles to a defined set of users, groups, or devices.User identitiesFollowing least privilege, which role manages users and groups but not global settings?Global AdministratorUser AdministratorSecurity ReaderOwner✓ Access granted. User Administrator is scoped to user/group management, avoiding excessive Global Admin rights.✗ Access denied. Correct answer: User Administrator. User Administrator is scoped to user/group management, avoiding excessive Global Admin rights.User identitiesThe most efficient way to assign licenses to many users is:One at a timeGroup-based licensingPowerShell onlyPer-device licensing✓ Authenticated. Group-based licensing assigns licenses to a group so members inherit them automatically.✗ Access denied. Correct answer: Group-based licensing. Group-based licensing assigns licenses to a group so members inherit them automatically.User identitiesA soft-deleted Entra user can be restored for how long before permanent deletion?24 hours7 days30 days1 year✓ Identity verified. Deleted users remain in a recoverable state for 30 days by default.✗ Access denied. Correct answer: 30 days. Deleted users remain in a recoverable state for 30 days by default.User identitiesA recommended design for emergency 'break-glass' accounts is that they are:Synced from on-premCloud-only, excluded from lock-out-causing CA, and closely monitoredShared with all adminsDisabled permanently✓ Trust established. Break-glass accounts are cloud-only, excluded from policies that could lock them out, and monitored.✗ Access denied. Correct answer: Cloud-only, excluded from lock-out-causing CA, and closely monitored. Break-glass accounts are cloud-only, excluded from policies that could lock them out, and monitored.User identitiesRegistering a personal BYOD device for SSO/Conditional Access without full org join is:Entra joinedEntra registeredHybrid joinedDomain joined✓ Privilege confirmed. Entra registered (workplace join) supports BYOD scenarios with device-based access.✗ Access denied. Correct answer: Entra registered. Entra registered (workplace join) supports BYOD scenarios with device-based access.User identitiesA corporate Windows device fully managed and joined directly to the cloud is:Entra registeredEntra joinedWorkgroupStandalone✓ Token validated. Entra joined devices are cloud-managed and support seamless sign-in and CA.✗ Access denied. Correct answer: Entra joined. Entra joined devices are cloud-managed and support seamless sign-in and CA.User identitiesWhich device state combines on-prem AD domain join with Entra registration?Entra hybrid joinedEntra joinedEntra registeredGuest✓ Session secured. Hybrid joined devices are AD domain-joined and also registered in Entra ID.✗ Access denied. Correct answer: Entra hybrid joined. Hybrid joined devices are AD domain-joined and also registered in Entra ID.User identitiesWhich attribute uniquely identifies a user object even if their UPN changes?Display nameObject ID (GUID)Job titleManager✓ Policy enforced. The immutable Object ID (GUID) is the stable identifier; UPN and other attributes can change.✗ Access denied. Correct answer: Object ID (GUID). The immutable Object ID (GUID) is the stable identifier; UPN and other attributes can change.User identitiesTo create many users at once from a spreadsheet in the portal, you use:Bulk operations / CSV importConditional AccessPIMSCIM✓ Threat neutralized. Bulk create uses a CSV template to provision multiple users at once.✗ Access denied. Correct answer: Bulk operations / CSV import. Bulk create uses a CSV template to provision multiple users at once.User identitiesCross-tenant access settings primarily control:DNS resolutionInbound/outbound B2B trust between Entra tenantsPassword lengthDevice compliance✓ Clean scan. Cross-tenant access settings govern how your tenant trusts and collaborates with other tenants.✗ Access denied. Correct answer: Inbound/outbound B2B trust between Entra tenants. Cross-tenant access settings govern how your tenant trusts and collaborates with other tenants.User identitiesEntra Password Protection helps by:Storing passwords in plaintextBlocking weak and banned passwords (cloud and optionally on-prem)Disabling MFARotating certificates✓ Root of trust intact. Password Protection enforces banned-password lists to stop weak/common passwords.✗ Access denied. Correct answer: Blocking weak and banned passwords (cloud and optionally on-prem). Password Protection enforces banned-password lists to stop weak/common passwords.User identitiesA user's sign-in name in Entra (UPN) typically looks like:A GUIDAn email-style name (user@domain)A phone numberA device ID✓ Credentials accepted. The User Principal Name is an email-like identifier used for sign-in.✗ Access denied. Correct answer: An email-style name (user@domain). The User Principal Name is an email-like identifier used for sign-in.User identitiesTo force users to re-register their security (MFA/SSPR) info, an admin can:Delete the tenantRequire re-registration of combined security infoDisable the account foreverRemove all licenses✓ Access granted. Admins can revoke/require re-registration of a user's combined MFA/SSPR methods.✗ Access denied. Correct answer: Require re-registration of combined security info. Admins can revoke/require re-registration of a user's combined MFA/SSPR methods.Authentication & accessConditional Access works by evaluating signals and then applying:Only email rulesAccess controls such as grant/block, require MFA, or session limitsDNS changesBackup jobs✓ Authenticated. CA evaluates conditions (user, location, device, risk) and enforces grant/session controls.✗ Access denied. Correct answer: Access controls such as grant/block, require MFA, or session limits. CA evaluates conditions (user, location, device, risk) and enforces grant/session controls.Authentication & accessWhich Conditional Access mode lets you observe policy impact without enforcing it?Report-onlyDisabledEnabledBlocking✓ Identity verified. Report-only logs what a policy would do, so you can validate before enforcing.✗ Access denied. Correct answer: Report-only. Report-only logs what a policy would do, so you can validate before enforcing.Authentication & accessSign-in frequency and persistent browser session are examples of:Grant controlsSession controlsNamed locationsRisk detections✓ Trust established. These are Conditional Access session controls that shape the session experience.✗ Access denied. Correct answer: Session controls. These are Conditional Access session controls that shape the session experience.Authentication & accessA policy that reacts to a risky sign-in relies on which capability?Entra ID Protection sign-in risk (P2)Group PolicyWSUSDHCP✓ Privilege confirmed. Sign-in risk comes from Entra ID Protection and requires Entra ID P2.✗ Access denied. Correct answer: Entra ID Protection sign-in risk (P2). Sign-in risk comes from Entra ID Protection and requires Entra ID P2.Authentication & accessA user-risk policy responds to:Printer errorsThe likelihood the account itself is compromised (e.g., leaked credentials)Disk spaceNetwork latency✓ Token validated. User risk reflects account compromise likelihood and often requires a secure password change.✗ Access denied. Correct answer: The likelihood the account itself is compromised (e.g., leaked credentials). User risk reflects account compromise likelihood and often requires a secure password change.Authentication & accessWhich is a phishing-resistant, passwordless hardware method?SMS codeFIDO2 security keySecurity questionsEmail OTP✓ Session secured. FIDO2 keys (WebAuthn/CTAP) provide phishing-resistant passwordless authentication.✗ Access denied. Correct answer: FIDO2 security key. FIDO2 keys (WebAuthn/CTAP) provide phishing-resistant passwordless authentication.Authentication & accessWindows passwordless sign-in using biometrics or a PIN bound to the device is:Windows Hello for BusinessSMS sign-inPassword sprayKerberos only✓ Policy enforced. Windows Hello for Business uses device-bound credentials with biometric/PIN unlock.✗ Access denied. Correct answer: Windows Hello for Business. Windows Hello for Business uses device-bound credentials with biometric/PIN unlock.Authentication & accessMicrosoft Authenticator's passwordless sign-in option is called:Phone sign-inSMS relayVoice PINSmartcard✓ Threat neutralized. Authenticator phone sign-in approves logins with number matching, no password needed.✗ Access denied. Correct answer: Phone sign-in. Authenticator phone sign-in approves logins with number matching, no password needed.Authentication & accessWhich feature reduces MFA-fatigue attacks by showing a number to type in the app?Number matchingSmart lockoutSSPRSeamless SSO✓ Clean scan. Number matching forces the user to enter a displayed number, defeating blind push approvals.✗ Access denied. Correct answer: Number matching. Number matching forces the user to enter a displayed number, defeating blind push approvals.Authentication & accessA time-limited passcode used to onboard a user or recover passwordless access is a:Temporary Access Pass (TAP)Client secretRefresh tokenSAS token✓ Root of trust intact. A TAP is a short-lived passcode for onboarding and passwordless recovery.✗ Access denied. Correct answer: Temporary Access Pass (TAP). A TAP is a short-lived passcode for onboarding and passwordless recovery.Authentication & accessConditional Access 'authentication strengths' let you:Disable MFARequire a specific set of stronger methods (e.g., phishing-resistant) for sensitive accessExtend token lifetimeSkip sign-in✓ Credentials accepted. Authentication strengths enforce which credential combinations satisfy a policy.✗ Access denied. Correct answer: Require a specific set of stronger methods (e.g., phishing-resistant) for sensitive access. Authentication strengths enforce which credential combinations satisfy a policy.Authentication & accessNamed locations in Conditional Access are used to:Rename usersDefine trusted/known IP ranges or countries as conditionsSet passwordsCreate groups✓ Access granted. Named locations classify IPs/countries so policies can key off location.✗ Access denied. Correct answer: Define trusted/known IP ranges or countries as conditions. Named locations classify IPs/countries so policies can key off location.Authentication & accessTo stop legacy authentication protocols that can't do MFA, you should:Enable themCreate a CA policy that blocks legacy authenticationIgnore themUse SMS only✓ Authenticated. Blocking legacy auth removes a common bypass of modern MFA controls.✗ Access denied. Correct answer: Create a CA policy that blocks legacy authentication. Blocking legacy auth removes a common bypass of modern MFA controls.Authentication & accessSmart lockout protects against:Phishing emailsBrute-force/password-spray by locking after failed attempts while sparing the real userMalwareData loss✓ Identity verified. Smart lockout throttles attackers while trying not to lock out the genuine user.✗ Access denied. Correct answer: Brute-force/password-spray by locking after failed attempts while sparing the real user. Smart lockout throttles attackers while trying not to lock out the genuine user.Authentication & accessCombined security information registration means users:Register MFA and SSPR methods in one experienceCannot register at allOnly use passwordsShare one method org-wide✓ Trust established. Combined registration lets users set up MFA and SSPR methods together.✗ Access denied. Correct answer: Register MFA and SSPR methods in one experience. Combined registration lets users set up MFA and SSPR methods together.Authentication & accessThe recommended way to require MFA for administrators is:Per-user legacy MFAA Conditional Access policy targeting admin roles that requires MFAEmail remindersDisabling admins✓ Privilege confirmed. CA targeting privileged roles is the flexible, modern way to enforce admin MFA.✗ Access denied. Correct answer: A Conditional Access policy targeting admin roles that requires MFA. CA targeting privileged roles is the flexible, modern way to enforce admin MFA.Authentication & accessSecurity defaults are best suited for:Large enterprises with P2Smaller orgs needing baseline protection without P1Air-gapped networksGuest-only tenants✓ Token validated. Security defaults give baseline enforced MFA registration for orgs without CA/P1.✗ Access denied. Correct answer: Smaller orgs needing baseline protection without P1. Security defaults give baseline enforced MFA registration for orgs without CA/P1.Authentication & accessContinuous Access Evaluation (CAE) provides:Slower sign-insNear-real-time revocation of access on critical events (disable, password reset)More licensesBigger mailboxes✓ Session secured. CAE lets resources react quickly to security events instead of waiting for token expiry.✗ Access denied. Correct answer: Near-real-time revocation of access on critical events (disable, password reset). CAE lets resources react quickly to security events instead of waiting for token expiry.Authentication & accessWhich license is required for risk-based Conditional Access and Identity Protection?FreeEntra ID P1Entra ID P2E3 only✓ Policy enforced. Risk-based policies and Identity Protection require Entra ID P2.✗ Access denied. Correct answer: Entra ID P2. Risk-based policies and Identity Protection require Entra ID P2.Authentication & accessEntra ID Protection classifies risk into:Sign-in risk and user riskHigh and low onlyRed and greenInbound and outbound✓ Threat neutralized. Identity Protection separates sign-in risk (this login) from user risk (the account).✗ Access denied. Correct answer: Sign-in risk and user risk. Identity Protection separates sign-in risk (this login) from user risk (the account).Authentication & accessA grant control that requires a healthy device is:Require compliant or hybrid Entra joined deviceRequire SMSRequire legacy authRequire guest✓ Clean scan. CA can require the device be marked compliant (Intune) or hybrid Entra joined.✗ Access denied. Correct answer: Require compliant or hybrid Entra joined device. CA can require the device be marked compliant (Intune) or hybrid Entra joined.Authentication & accessBetween legacy per-user MFA and Conditional Access MFA, the recommended approach is:Per-user MFAConditional Access (contextual and flexible)No MFASMS only✓ Root of trust intact. CA-based MFA is contextual and preferred over blanket per-user MFA.✗ Access denied. Correct answer: Conditional Access (contextual and flexible). CA-based MFA is contextual and preferred over blanket per-user MFA.Authentication & accessOATH tokens provide:Passwordless pushTime-based one-time passcodes (hardware or software)Certificate enrollmentDevice compliance✓ Credentials accepted. OATH TOTP tokens generate rotating one-time codes as a second factor.✗ Access denied. Correct answer: Time-based one-time passcodes (hardware or software). OATH TOTP tokens generate rotating one-time codes as a second factor.Authentication & accessWhich of these is NOT a valid Conditional Access condition?User or groupDevice platformSign-in riskThe user's shoe size✓ Access granted. CA conditions include identity, location, device, app and risk — not arbitrary attributes like shoe size.✗ Access denied. Correct answer: The user's shoe size. CA conditions include identity, location, device, app and risk — not arbitrary attributes like shoe size.Authentication & accessRequiring users to accept a policy document before access uses:Terms of Use as a CA grant controlA dynamic groupA managed identityA named location✓ Authenticated. Terms of Use can be enforced as a Conditional Access grant control.✗ Access denied. Correct answer: Terms of Use as a CA grant control. Terms of Use can be enforced as a Conditional Access grant control.Authentication & accessFIDO2 passwordless authentication is built on which standards?SMTP/IMAPWebAuthn/CTAPSNMPLDAP✓ Identity verified. FIDO2 uses the WebAuthn and CTAP standards for phishing-resistant sign-in.✗ Access denied. Correct answer: WebAuthn/CTAP. FIDO2 uses the WebAuthn and CTAP standards for phishing-resistant sign-in.Authentication & accessTo investigate why Conditional Access allowed or blocked a sign-in, you check:The mailboxEntra sign-in logs (Conditional Access details) / the What If toolThe registryDNS logs✓ Trust established. Sign-in logs show which CA policies applied; the What If tool models policy outcomes.✗ Access denied. Correct answer: Entra sign-in logs (Conditional Access details) / the What If tool. Sign-in logs show which CA policies applied; the What If tool models policy outcomes.Authentication & accessA good layered defense against password spray includes:Only long passwordsPassword Protection + smart lockout + MFA/passwordlessDisabling loggingShared accounts✓ Privilege confirmed. Combining banned-password protection, lockout, and strong auth blunts spray attacks.✗ Access denied. Correct answer: Password Protection + smart lockout + MFA/passwordless. Combining banned-password protection, lockout, and strong auth blunts spray attacks.Authentication & accessThe Authentication methods policy lets admins:Enable, disable, and scope methods like Authenticator, FIDO2, or SMSDelete tenantsAssign licensesCreate mailboxes✓ Token validated. It controls which authentication methods are available and to whom.✗ Access denied. Correct answer: Enable, disable, and scope methods like Authenticator, FIDO2, or SMS. It controls which authentication methods are available and to whom.Authentication & accessExcluding break-glass accounts from an MFA-enforcing CA policy is important because:They need no securityIt prevents an outage from locking every admin outMFA is illegalIt saves licenses✓ Session secured. If MFA infrastructure fails, excluded (monitored) emergency accounts preserve access.✗ Access denied. Correct answer: It prevents an outage from locking every admin out. If MFA infrastructure fails, excluded (monitored) emergency accounts preserve access.Workload identitiesRegistering an application in Entra creates:Only a mailboxAn application object plus a service principal in your tenantA new tenantA dynamic group✓ Policy enforced. App registration yields an app object (globally) and a service principal (locally) for sign-in and permissions.✗ Access denied. Correct answer: An application object plus a service principal in your tenant. App registration yields an app object (globally) and a service principal (locally) for sign-in and permissions.Workload identitiesA service principal is:A human adminThe local identity of an app in a tenant used to authenticate and hold permissionsA firewall ruleA license✓ Threat neutralized. The service principal represents the app instance in a tenant.✗ Access denied. Correct answer: The local identity of an app in a tenant used to authenticate and hold permissions. The service principal represents the app instance in a tenant.Workload identitiesThe main benefit of a managed identity is:Free licensingAzure manages the credentials so code needn't store secretsFaster networkingMore storage✓ Clean scan. Managed identities remove the need to handle secrets in code by letting Azure manage them.✗ Access denied. Correct answer: Azure manages the credentials so code needn't store secrets. Managed identities remove the need to handle secrets in code by letting Azure manage them.Workload identitiesA system-assigned managed identity's lifecycle is:Independent of any resourceTied to a single Azure resource and deleted with itShared across tenantsPermanent✓ Root of trust intact. System-assigned identities are created with, and destroyed alongside, their resource.✗ Access denied. Correct answer: Tied to a single Azure resource and deleted with it. System-assigned identities are created with, and destroyed alongside, their resource.Workload identitiesA user-assigned managed identity is:Bound to one resource onlyA standalone identity reusable across multiple resourcesA guest accountA certificate✓ Credentials accepted. User-assigned identities exist independently and can be attached to many resources.✗ Access denied. Correct answer: A standalone identity reusable across multiple resources. User-assigned identities exist independently and can be attached to many resources.Workload identitiesDelegated permissions let an app act:As itself with no userOn behalf of the signed-in userAs a domain controllerWithout any consent✓ Access granted. Delegated permissions are exercised in the context of a signed-in user.✗ Access denied. Correct answer: On behalf of the signed-in user. Delegated permissions are exercised in the context of a signed-in user.Workload identitiesApplication permissions let an app act:On behalf of a userAs the application itself, typically requiring admin consentOnly offlineAs a guest✓ Authenticated. Application permissions run without a user and usually need admin consent.✗ Access denied. Correct answer: As the application itself, typically requiring admin consent. Application permissions run without a user and usually need admin consent.Workload identitiesAdmin consent is required when an app requests:Basic profile onlyHigh-privilege or application-level permissionsNothingA display name✓ Identity verified. Sensitive/app permissions require an administrator to consent on behalf of the org.✗ Access denied. Correct answer: High-privilege or application-level permissions. Sensitive/app permissions require an administrator to consent on behalf of the org.Workload identitiesFor production apps, the more secure credential type is:A client secretA certificateA shared passwordNo credential✓ Trust established. Certificate credentials are preferred over client secrets for production workloads.✗ Access denied. Correct answer: A certificate. Certificate credentials are preferred over client secrets for production workloads.Workload identitiesOpenID Connect (OIDC) primarily provides:Authorization onlyAuthentication (an ID token) on top of OAuth 2.0Encryption of disksDNS resolution✓ Privilege confirmed. OIDC adds an identity/authentication layer (ID tokens) over OAuth 2.0.✗ Access denied. Correct answer: Authentication (an ID token) on top of OAuth 2.0. OIDC adds an identity/authentication layer (ID tokens) over OAuth 2.0.Workload identitiesOAuth 2.0 primarily provides:Authentication onlyAuthorization via access tokens for delegated accessFile sharingPassword storage✓ Token validated. OAuth 2.0 issues access tokens that authorize delegated access to resources.✗ Access denied. Correct answer: Authorization via access tokens for delegated access. OAuth 2.0 issues access tokens that authorize delegated access to resources.Workload identitiesAn 'enterprise application' in Entra represents:A physical serverA service principal instance of an app used in your tenant (SSO, provisioning)A user mailboxA subnet✓ Session secured. Enterprise apps are the tenant's instances of applications, where you configure SSO and provisioning.✗ Access denied. Correct answer: A service principal instance of an app used in your tenant (SSO, provisioning). Enterprise apps are the tenant's instances of applications, where you configure SSO and provisioning.Workload identitiesTo give a group access to an enterprise application, you:Edit DNSAssign users/groups on the enterprise appCreate a CA named locationRotate a secret✓ Policy enforced. User/group assignment on the enterprise app controls who can access it.✗ Access denied. Correct answer: Assign users/groups on the enterprise app. User/group assignment on the enterprise app controls who can access it.Workload identitiesApp roles are used to:Store passwordsDefine app-specific roles/claims for authorization inside the appCreate tenantsManage DNS✓ Threat neutralized. App roles let an application implement its own RBAC via role claims in the token.✗ Access denied. Correct answer: Define app-specific roles/claims for authorization inside the app. App roles let an application implement its own RBAC via role claims in the token.Workload identitiesConditional Access for workload identities can restrict:User mailboxesService principal sign-ins by location or riskPrinter driversDisk quotas✓ Clean scan. CA for workload identities limits where/how service principals can authenticate.✗ Access denied. Correct answer: Service principal sign-ins by location or risk. CA for workload identities limits where/how service principals can authenticate.Workload identitiesConsent phishing is best mitigated by:Allowing all consentRestricting user consent (e.g., verified publishers) and using an admin consent workflowDisabling MFASharing admin accounts✓ Root of trust intact. Limiting user consent and routing risky requests to admin approval reduces illicit consent grants.✗ Access denied. Correct answer: Restricting user consent (e.g., verified publishers) and using an admin consent workflow. Limiting user consent and routing risky requests to admin approval reduces illicit consent grants.Workload identitiesWhere do you review and revoke permissions an app was granted?Enterprise app > Permissions (admin consent)The mailbox rulesThe registryDNS zone✓ Credentials accepted. The enterprise app's Permissions blade shows and lets you revoke granted permissions.✗ Access denied. Correct answer: Enterprise app > Permissions (admin consent). The enterprise app's Permissions blade shows and lets you revoke granted permissions.Workload identitiesAutomated user provisioning to SaaS apps in Entra uses:SCIM-based provisioningGroup PolicyWSUSDHCP✓ Access granted. Entra app provisioning uses the SCIM standard to create/update/deprovision accounts in SaaS apps.✗ Access denied. Correct answer: SCIM-based provisioning. Entra app provisioning uses the SCIM standard to create/update/deprovision accounts in SaaS apps.Workload identitiesWorkload identity federation lets external workloads:Store secrets in codeAccess Entra-protected resources without managing secrets by trusting external IdP tokensBypass all authDisable OAuth✓ Authenticated. Federation trusts tokens from an external IdP (e.g., GitHub, another cloud) so no secret is stored.✗ Access denied. Correct answer: Access Entra-protected resources without managing secrets by trusting external IdP tokens. Federation trusts tokens from an external IdP (e.g., GitHub, another cloud) so no secret is stored.Workload identitiesA 'verified publisher' badge on an app indicates:The app is freeMicrosoft has verified the developer's identity (a trust signal)The app is open sourceThe app has no permissions✓ Identity verified. Verified publisher status confirms the developer's identity, aiding consent decisions.✗ Access denied. Correct answer: Microsoft has verified the developer's identity (a trust signal). Verified publisher status confirms the developer's identity, aiding consent decisions.Identity governanceEntitlement management packages related access into:Access packagesNamed locationsService principalsMailboxes✓ Trust established. Access packages bundle groups, apps, and sites so users can request a meaningful set of access.✗ Access denied. Correct answer: Access packages. Access packages bundle groups, apps, and sites so users can request a meaningful set of access.Identity governanceA catalog in entitlement management is:A CA policyA container of resources (groups, apps, sites) used by access packagesA device groupA license SKU✓ Privilege confirmed. Catalogs organize the resources that access packages can grant.✗ Access denied. Correct answer: A container of resources (groups, apps, sites) used by access packages. Catalogs organize the resources that access packages can grant.Identity governanceConnected organizations in entitlement management enable:Blocking all guestsExternal partner users to request access packages under governanceDisabling MFAPassword reset✓ Token validated. Connected organizations let defined external orgs request access via B2B governance.✗ Access denied. Correct answer: External partner users to request access packages under governance. Connected organizations let defined external orgs request access via B2B governance.Identity governanceAccess reviews are used to:Provision serversPeriodically recertify that users still need their accessRotate certificatesAssign licenses✓ Session secured. Access reviews have owners attest whether access is still required.✗ Access denied. Correct answer: Periodically recertify that users still need their access. Access reviews have owners attest whether access is still required.Identity governanceAccess reviews can target:Only mailboxesGroup memberships, app assignments, and privileged rolesOnly devicesOnly DNS✓ Policy enforced. Reviews can cover groups, applications, and privileged role assignments.✗ Access denied. Correct answer: Group memberships, app assignments, and privileged roles. Reviews can cover groups, applications, and privileged role assignments.Identity governanceRecurring access reviews primarily help with:One-time cleanup onlyOngoing recertification cadence for complianceFaster networkingLarger storage✓ Threat neutralized. Recurring reviews maintain continuous compliance rather than a single cleanup.✗ Access denied. Correct answer: Ongoing recertification cadence for compliance. Recurring reviews maintain continuous compliance rather than a single cleanup.Identity governancePrivileged Identity Management (PIM) provides:Always-on admin rightsJust-in-time, time-bound activation of privileged rolesPassword vaulting for appsDevice compliance✓ Clean scan. PIM reduces standing privilege via on-demand, time-limited role activation.✗ Access denied. Correct answer: Just-in-time, time-bound activation of privileged roles. PIM reduces standing privilege via on-demand, time-limited role activation.Identity governanceIn PIM, an 'eligible' assignment differs from 'active' because eligible:Is always onMust be activated when neededCannot be usedRequires no MFA✓ Root of trust intact. Eligible roles require activation (often with MFA/justification); active roles are always on.✗ Access denied. Correct answer: Must be activated when needed. Eligible roles require activation (often with MFA/justification); active roles are always on.Identity governancePIM role activation can be configured to require:NothingMFA, justification, approval, and a time limitA new tenantA public IP✓ Credentials accepted. Activation controls can enforce MFA, business justification, approval, and expiry.✗ Access denied. Correct answer: MFA, justification, approval, and a time limit. Activation controls can enforce MFA, business justification, approval, and expiry.Identity governancePIM alerts help detect:Printer jamsExcessive global admins or stale standing privilegeDisk errorsDNS drift✓ Access granted. PIM surfaces risks like too many privileged roles or unused assignments.✗ Access denied. Correct answer: Excessive global admins or stale standing privilege. PIM surfaces risks like too many privileged roles or unused assignments.Identity governanceTerms of Use in governance are typically enforced through:A Conditional Access grant controlA managed identityA named locationA dynamic group✓ Authenticated. ToU acceptance is enforced as a CA grant control before access is allowed.✗ Access denied. Correct answer: A Conditional Access grant control. ToU acceptance is enforced as a CA grant control before access is allowed.Identity governanceLifecycle workflows automate:Certificate rotationJoiner-mover-leaver tasks such as onboarding and offboardingDNS updatesLicense purchasing✓ Identity verified. Lifecycle workflows run automated tasks at join, move, and leave events.✗ Access denied. Correct answer: Joiner-mover-leaver tasks such as onboarding and offboarding. Lifecycle workflows run automated tasks at join, move, and leave events.Identity governanceSeparation of Duties in access packages prevents:Users from signing inA user from holding conflicting packages/roles that create riskMFA promptsPassword reuse✓ Trust established. SoD stops incompatible access combinations that could enable fraud or error.✗ Access denied. Correct answer: A user from holding conflicting packages/roles that create risk. SoD stops incompatible access combinations that could enable fraud or error.Identity governanceWhich license is required for PIM, access reviews, and entitlement management?FreeEntra ID P1Entra ID P2No license✓ Privilege confirmed. These identity governance features require Entra ID P2 (or the Governance add-on).✗ Access denied. Correct answer: Entra ID P2. These identity governance features require Entra ID P2 (or the Governance add-on).Identity governancePrivileged access groups allow:Static admin membership onlyPIM-style just-in-time membership for a groupGuest-only accessDisabling roles✓ Token validated. Privileged access groups extend just-in-time activation to group membership.✗ Access denied. Correct answer: PIM-style just-in-time membership for a group. Privileged access groups extend just-in-time activation to group membership.Identity governanceReviewers in an access review can be:Only the CEOResource owners, selected users, or the users themselves (self-review)Only external auditorsNobody✓ Session secured. Access reviews support owner review, designated reviewers, or self-attestation.✗ Access denied. Correct answer: Resource owners, selected users, or the users themselves (self-review). Access reviews support owner review, designated reviewers, or self-attestation.Identity governance'Auto-apply results' in an access review means:Nothing changesDenied access is automatically removed when the review endsEveryone is approvedThe tenant is deleted✓ Policy enforced. Auto-apply enforces the review's decisions, removing access that reviewers denied.✗ Access denied. Correct answer: Denied access is automatically removed when the review ends. Auto-apply enforces the review's decisions, removing access that reviewers denied.Identity governanceGuest (external user) access is best governed with:No controlsAccess reviews for guests plus access-package expirationShared admin accountsDisabling logging✓ Threat neutralized. Reviewing guests and expiring their access keeps external access from lingering.✗ Access denied. Correct answer: Access reviews for guests plus access-package expiration. Reviewing guests and expiring their access keeps external access from lingering.Identity governanceThe approval workflow for an access request is configured in:Access package policiesA named locationA managed identityDNS✓ Clean scan. Access package assignment policies define requestors, approvers, and lifecycle.✗ Access denied. Correct answer: Access package policies. Access package assignment policies define requestors, approvers, and lifecycle.Identity governanceThe overarching goal of identity governance is to ensure:Everyone is an adminThe right people have the right access at the right time, with visibility and complianceNo one has accessPasswords never expire✓ Root of trust intact. Governance balances access with oversight and auditable compliance.✗ Access denied. Correct answer: The right people have the right access at the right time, with visibility and compliance. Governance balances access with oversight and auditable compliance.Identity governanceAn access package assignment can be set to automatically:Never expire under any settingExpire after a set duration, prompting re-request/renewalGrant global adminDelete the user✓ Credentials accepted. Assignments can expire, requiring renewal so access does not persist indefinitely.✗ Access denied. Correct answer: Expire after a set duration, prompting re-request/renewal. Assignments can expire, requiring renewal so access does not persist indefinitely.Identity governanceWhich pairing best supports audit and compliance evidence?Shared logins + no logsAccess reviews + PIM activation recordsDisabled auditingAnonymous access✓ Access granted. Review outcomes and PIM activation history provide the audit trail auditors expect.✗ Access denied. Correct answer: Access reviews + PIM activation records. Review outcomes and PIM activation history provide the audit trail auditors expect.Identity governanceTo grant least-privilege admin access only when needed, combine:Standing Global Admin for allEligible PIM roles activated just-in-timeShared admin passwordsNo roles at all✓ Authenticated. Eligible-only roles activated via PIM achieve least privilege for administrators.✗ Access denied. Correct answer: Eligible PIM roles activated just-in-time. Eligible-only roles activated via PIM achieve least privilege for administrators.Identity governanceEntitlement management is especially useful for:Single-user tenantsScaling access requests/approvals for many users and external partnersRotating TLS certsConfiguring DNS✓ Identity verified. Access packages streamline governed self-service access at scale, including for partners.✗ Access denied. Correct answer: Scaling access requests/approvals for many users and external partners. Access packages streamline governed self-service access at scale, including for partners.Identity governanceA key benefit of just-in-time access over standing privilege is:It is slowerReduced attack surface — no always-on rights to steal or misuseMore passwordsLess logging✓ Trust established. JIT removes persistent privileged rights, shrinking what an attacker can abuse.✗ Access denied. Correct answer: Reduced attack surface — no always-on rights to steal or misuse. JIT removes persistent privileged rights, shrinking what an attacker can abuse. Ready for the real thing? You’ve been practicing the SC-300 objectives. When you’re scoring well, book the official exam and make it count. Register for SC-300 Back to Cert Zone Unofficial practice questions created by Oluma Digital for study purposes. Not affiliated with or endorsed by Microsoft. Always verify current objectives on the official exam page. Correct Answered Restart