SC-300 — Frequently Asked Questions
Community-vetted answers to 96 common questions about this exam.
Questions from real practice questions
Each Q&A comes from a specific community question — follow the link for its full analysis.
Assigning Least Privilege for Entra Permissions Management License Purchase
This role manages the tool's configuration but does not grant permission to purchase the license from the Microsoft Store or billing portal.
Yes, but it violates the principle of least privilege. The exam requires the minimal role necessary, which is Billing Administrator.
Minimum Azure RBAC Assignments for Granular Access
Yes, Virtual Machine Contributor includes permissions to start, stop, and restart virtual machines along with create/delete operations.
A Contributor role at RG1 scope does not grant read access to RG2 or the subscription level. Reader is a separate role needed for broad visibility.
Configuring Collaboration Restrictions for Guest Invites
Guest Invite Settings control who can send invitations (members vs admins). Collaboration Restrictions control which external domains are allowed or blocked from being invited.
Because the issue is isolated to one domain (adatum.com) while another (fabrikam.com) works. Guest Invite Settings apply globally and cannot target specific external tenants.
Azure User-Assigned Managed Identity Regional Scope
No. While the identity resource is stored in a specific region, the associated Microsoft Entra ID service principal is available globally.
Yes. Azure Storage Accounts support both system-assigned and user-assigned managed identities for authentication.
SharePoint Guest Access with Email One-Time Passcode
User1 is an existing guest in the tenant. The Email OTP feature is designed for new guests or those who haven't redeemed their invitation yet.
No, existing guests are not affected. They continue to use their previous authentication method or sign-in state.
SC-300 Self-service access request eligibility
No. An approver typically already has access to manage the application. Since you cannot request access you already possess, User2 is excluded.
Not necessarily. Group1 is configured as the target group for newly assigned users. If User1 were already in the application's assignment list, they wouldn't need to request it. The question implies they need to request it.
Cross-Tenant Synchronization Identity Types
No. You can use groups to scope which users are synced, but the group objects themselves are not created in the target tenant.
Confusion arises because scoping filters allow selection by group. However, this only determines user inclusion, not group replication.
Conditional Access Template Exclusions for Policy Creator
Admin4 is excluded because they created the policy from a predefined template. Microsoft automatically excludes the creator to prevent accidental lockout.
No. The automatic exclusion only applies when a policy is created from a predefined Microsoft template. Manually configured policies do not have this default exclusion.
Minimum Access Packages for SC-300
Technically yes via multiple policies, but the exam logic treats distinct approval chains as requiring separate packages for minimum complexity.
Answer 2 combines Group1 and Group4. Because their approvers (Group2 vs Group5) are mutually exclusive, the exam requires them to be in separate packages.
Prerequisite for Microsoft Defender for Cloud Apps Session Policy
App onboarding connects the service, but session policies require a Conditional Access policy to route traffic through the proxy for inspection. Without CA, session policies cannot enforce controls.
No. Session policies rely on Conditional Access App Control (CAAC) to intercept and analyze network traffic. The CA policy is the gateway that makes session inspection possible.
Valid SSPR Authentication Methods with Single Method Requirement
While valid, it requires the Authenticator app to be installed. Exam questions often prioritize Email as the universal fallback if app configuration isn't explicitly stated.
No, Microsoft Teams is not an authentication method for Self-Service Password Reset in Microsoft Entra ID.
Which Authentication Method Is Valid for Entra SSPR?
It is on the SSPR method list, but it requires the Microsoft Authenticator app to be installed and registered with push notifications, which the scenario never guarantees.
Microsoft Entra lets users register a personal email as an SSPR method so they can reset a password even when they cannot access the corporate mailbox.
How Long Are Microsoft Entra Risky User Activity Logs Retained?
The 30-day figure is the shorter retention tier tied to sign-in log rotation on lower license levels; the Identity Protection risk data the question targets is retained for 90 days.
Risky users and workload identities are not deleted until the risk is remediated, but the queryable activity logs used for triage follow the 90-day retention window.
How Do You Require Terms of Use Acceptance in a Conditional Access Policy?
Session controls only cover sign-in frequency, persistent browser sessions, and app-enforced restrictions. Terms of use is published in Entra ID and attached as a Grant control that gates access.
Yes. Target resources defines which cloud apps or user actions Policy1 protects; Grant then enforces accepting Terms1 for those resources.
How Can Automation1 Read Only Secret1 in Vault1?
Vault-scoped IAM grants the managed identity read permission on every secret in Vault1, which breaks the requirement to prevent Automation1 from accessing other secrets and violates least privilege.
No. Identity settings only enable or manage the system-assigned managed identity; the data-plane permission on Secret1 still has to be granted through an RBAC role assignment on the secret.
No. Per-secret IAM only appears after the key vault is switched to the Azure role-based access control permission model in Access configuration.
Which role lets AKS1's managed identity access Azure Cosmos DB?
It is a Cosmos DB data-plane role granted through Cosmos DB's own RBAC on an account, database or container, not an Azure IAM role assignment at the RG1 scope the option names.
Both scopes are far broader than the AKS1 workload needs, violating least privilege, and neither targets the DB1 Cosmos DB account access AKS1 actually requires.
Which Microsoft Graph permission type should App1 use for a user's calendar?
Application permissions are app-only: no signed-in user exists, so Graph would target a mailbox the admin scopes rather than the interactive user's own calendar.
No. Entra RBAC roles control administrative actions such as user or group management; Graph calendar access comes from OAuth scopes like Calendars.Read granted as delegated permissions.
A consent grant (user or admin) for the Graph scope, then an authorization-code token request so the call runs in the context of the signed-in user.
Which Additional Clouds Can Microsoft Entra Permissions Management Manage?
Permissions Management onboarding currently covers Azure, AWS, and GCP only; Alibaba Cloud lacks a supported connector, so option E is incorrect.
Yes. AWS and GCP are supported additional cloud environments, but each must be connected or onboarded separately in Permissions Management.
Which Entra tool evaluates and remediates privileged account risk?
PIM activates privileged roles just in time but gives no cross-subscription permission risk assessment. Permissions Management discovers and remediates over-provisioned privileged accounts in one tenant-wide view.
No. It can be onboarded with Azure subscriptions only, so it still centralizes permission risk evaluation for a single Entra tenant and its three subscriptions.
How to Replace a User's Azure Permissions with Read-Only in Permissions Management
Creating a role only defines a custom role object; you would still have to assign it and revoke every existing permission, which adds work instead of minimizing it.
Assign Read-Only Status. It is one of four quick actions alongside Revoke Unused, Revoke High-Risk, and Revoke Delete Tasks, and it changes a user's access in a single click.
What Should You Do First to Give a User Permissions Management Access?
Permissions Management uses its own group-based access model; a direct user role assignment in Entra ID does not grant product access, so you must add the user to a security group first.
Yes, because you assign Permissions Management roles to the group once and then manage access by group membership, which is easier than repeating per-user role assignments as more users join.
Which role for the Permissions Management service principal?
Contributor can manage Azure resources but has no Microsoft.Authorization permissions, so it cannot create the custom role definitions or assign the right-sized roles Permissions Management generates.
User Access Administrator already includes Microsoft.Authorization/*/read, so role assignments and role definitions can be read. Reader alone is insufficient because it cannot implement any role change.
How to Give a Contractor Access to App1 Using Their outlook.com Credentials?
External collaboration settings only enable B2B invitations and define who can be invited; New-MgInvitation actually creates the guest user object for [email protected] so it can be granted access to App1.
New-MgUser creates a member account inside contoso.com with a contoso.com credential, but the contractor must authenticate as [email protected], which requires a B2B guest invitation.
How to Remove Directly Assigned Office 365 E3 Licenses After Group-Based E5 Assignment?
Group-based licensing is additive: the group grants E5, but a license a user already holds through a direct assignment stays until someone removes that SKU explicitly.
No. Update-MgUser edits profile attributes; license SKU removal requires Set-MgUserLicense's -RemoveLicenses parameter against the E3 service plan ID.
How should you remove direct E3 licenses after Entra group-based E5 assignment?
It requires per-user scripting or a loop across 2,500 accounts, while the Licenses blade can remove direct licenses for the product in one bulk operation.
No. Direct assignments remain until removed, so users can temporarily hold both E3 and E5 unless you remove the E3 direct licenses.
How Do You Block Entra Self-Service Sign-Up for contoso.com?
No. Setting AllowedToSignUpEmailBasedSubscriptions to False only prevents future email-verified sign-ups; existing accounts in the contoso.com tenant must be removed separately.
Update-MgDomain only changes domain properties such as default status, supported services and authentication type. Email-based self-service sign-up is a tenant-wide authorization policy setting instead.
The older MSOnline command Set-MsolCompanySettings with -AllowEmailVerifiedUsers $false performs the same block for email-verified self-service sign-up before the Graph migration.
Which Roles Can Manage Microsoft Entra Internet Access?
Privileged Role Administrator only manages role assignments and PIM; it has no permissions to configure Global Secure Access traffic forwarding or Internet Access policies.
Yes. Global Administrator holds complete permissions across Microsoft Entra, which includes managing Entra Internet Access alongside the dedicated Global Secure Access Administrator role.
Which role can create access reviews for Microsoft Entra roles?
It can manage access reviews for groups, apps, and access packages, but it lacks permission to create access reviews scoped to Microsoft Entra directory role assignments.
Yes, but Global Administrator is broader than necessary; least privilege requires Privileged Role Administrator for this task.
Which Authentication Methods Are Phishing-Resistant MFA for Admins?
Authenticator phone sign-in with number matching is MFA, but a proxy phishing site can still relay the approval in real time, so Microsoft places it below the phishing-resistant strength tier.
Yes — Microsoft lists certificate-based authentication (multi-factor) in the built-in phishing-resistant MFA strength, because it relies on a device-bound certificate plus a second factor rather than a transferable code.
Valid SSPR Authentication Method When Only One Reset Method Is Required
Microsoft gates the Authenticator push behind the two-method setting: with one required method, verification code is the only app option, so notification cannot complete the reset.
No. The email method targets an alternate address the user can reach while locked out; an in-organization mailbox is the resource protected by the forgotten password.
No. Smartcards are a sign-in credential, not part of the SSPR set (mobile app notification, mobile app code, email, mobile phone, office phone, security questions).
Microsoft Entra User Risk vs Sign-in Risk Detections
No, password spray is classified as a sign-in risk because it relates to a specific authentication attempt rather than the user's overall account compromise status.
User risk scores are primarily triggered by Microsoft Entra threat intelligence detecting that an account's credentials have appeared in known breaches or malicious lists.
Microsoft Entra Private Access Device Compatibility
Private Access requires the Global Secure Access client, which mandates a full Microsoft Entra Joined or Hybrid Joined identity context for security enforcement.
While Android is a supported platform, the device must still meet the identity requirements (typically Joined or managed) rather than just being Registered.
Least Privilege Permission to Onboard a Subscription to Permissions Management
Onboarding creates a new role assignment granting the Permissions Management app Reader on Sub1, and creating an assignment requires write permission; read alone can only view existing assignments.
Group1 also contains Sub2, so management-group scope would let User1 modify role assignments on a subscription that is not part of the onboarding task, breaking least privilege.
Enable Private Access Profile in Microsoft Entra Global Secure Access
It is located under Global Secure Access > Connect > Traffic forwarding.
Traffic forwarding manages access policies and profiles, while Security profiles handle threat detection and monitoring integrations.
Microsoft Entra Internet Access Device Support
Entra Registered devices are typically personal devices with limited management capabilities, lacking the full compliance and configuration profiles required for secure internet access policies.
Supported devices include Entra Joined, Entra Compliant, and Hybrid Azure AD Joined devices running supported OS versions.
Temporary Access with Entra Entitlement Management
Conditional Access evaluates requests at sign-in but cannot automatically revoke access or expire memberships after a fixed duration like 90 days.
Not necessarily; you can configure them to auto-approve assignments for specific groups, minimizing administrative effort.
Microsoft Entra PIM for Groups Eligibility
Dynamic groups have membership determined by rules. PIM requires explicit role assignments and activation workflows that conflict with automated dynamic membership management.
No. Groups synchronized from on-premises environments cannot be enabled for PIM for Groups because their attributes and membership are controlled by the local source system.
ABAC Support for Azure Built-in Roles
No, the Contributor role is a management role and does not support ABAC conditions. ABAC is currently limited to specific data plane roles.
Virtual Machine Contributor manages compute resources but lacks the specific data actions (like blob storage) required to enable ABAC conditions.
Which two auth methods enable passwordless Entra sign-in to a Linux VM?
SMS is out-of-band but works only as a second factor on top of a password, and it is not supported as a primary sign-in method for Azure VMs, so it fails the no-password requirement.
A Temporary Access Pass is a time-limited code for onboarding and credential recovery, not a standing passwordless method users would authenticate to a Linux VM with.
Granting VM Managed Identity Access to Azure Key Vault
Access policies require manual configuration per secret and do not scale well. Roles are centralized and easier to manage.
No, the VM already has a system-assigned managed identity. You only need to assign it the appropriate role.
How Does WebApp1 Read and Write to storage1 with Its Managed Identity?
A SAS is a signed, time-limited token that must be stored and rotated inside the app, and it authorizes the request itself rather than the app's system-assigned managed identity, so it never satisfies identity-based access.
For blob data, assign Storage Blob Data Contributor (Storage Blob Data Reader for read-only). For Azure Files, assign Storage File Data SMB Share Contributor via the same Access control (IAM) blade.
Which Two Credentials Let App1 Access App2 Across Tenants?
Managed identities are tied to an Azure resource in a single tenant and have no service principal that the partner tenant can consent to, so they cannot obtain a token for App2.
No. A guest user is a human identity used for delegated access; App1 signs in as itself, so it needs a certificate or client secret registered on the app.
What to do first for certificate-based authentication in Entra ID?
Azure Key Vault stores and manages secrets or certificates, but it does not make Entra ID trust CA1 as an issuer. Entra ID needs CA1 registered as a certificate authority before it can validate user certificates.
In the Azure portal, go to Microsoft Entra ID > Security > Certificate Authorities, then upload CA1's root certificate and CRL and configure the CRL distribution point.
How to Assess Privilege Assignment Risks Across Azure, GCP, and AWS?
Defender for Cloud Apps is a CASB for SaaS app access and session controls; it does not inventory and assess IAM privilege assignments across Azure, GCP, and AWS.
Sentinel is a SIEM/SOAR that can ingest logs and build analytics, but it does not provide native multicloud permissions risk assessment without significant administrative effort.
How Do You Configure Continuous Access Evaluation for App Sign-Ins?
A sign-in risk policy is Conditional Access driven by Microsoft Entra ID Protection risk signals and triggers MFA or password change; it has no continuous access evaluation session control to scope CAE to Application Administrators.
Access reviews are periodic recertifications of group, role, or app access, while CAE evaluates live token and session state in near real time, so a recurring review cannot implement it.
How to Remove Unused Managed Identity Permissions in Entra Permissions Management
The report only surfaces the unused permissions; a human must still review it and remove each permission, which does not meet the requirement to minimize administrative effort.
Yes. Autopilot rules scope by conditions such as identity type and last-used age, so managed identities holding unused permissions can be remediated automatically.
Ready to practice?
Access 80 SC-300 questions with instant feedback and detailed explanations.
View SC-300 Practice Questions →← Back to SC-300 Microsoft Identity and Access Administrator Study Guide