SC-300 — Microsoft Identity and Access Administrator
Microsoft

Microsoft Identity and Access Administrator (SC-300) Practice Questions

5.0 357 verified reviews
80 questions
June 11, 2026 updated
Online quiz simulator

Domain coverage

  • Implement and manage user identities (20–25%)
  • Implement authentication and access management (25–30%)
  • Plan and implement workload identities (20–25%)
  • Plan and automate identity governance (20–25%)

Sample Questions (8 of 80 shown)

Q1 Plan and automate identity governance
An employee will leave in 30 days. They are currently an eligible owner of the Billing Administrator role in PIM. Their manager wants to ensure they cannot activate this role during the remaining 30 days while keeping their account active for knowledge transfer. What is the most effective solution?
  1. Remove the user's eligible role assignment in PIM
  2. Create a Conditional Access policy blocking the user from activating any PIM role
  3. Change the eligible assignment to an active assignment with no expiration
  4. Disable the user account in Entra ID
✓ Correct Answer: A
Removing the eligible role assignment in PIM directly prevents the user from activating the role while keeping their account available for normal work. Conditional Access cannot specifically target PIM role activation. Making it active (C) would grant permanent access. Disabling the account (D) blocks all work.
Q2 Plan and automate identity governance
A project team of 15 contractors needs access to three SharePoint sites and a Teams channel for 6 months, after which access should be automatically removed. The solution must allow self-service access requests with manager approval. What should you configure?
  1. Add contractors to a security group with a 6-month group expiration policy
  2. Configure an access package in Entitlement Management with 6-month expiration and approval workflow
  3. Individually assign each contractor and create a calendar reminder to remove access
  4. Create a Conditional Access policy to block contractors after 6 months
✓ Correct Answer: B
Entitlement Management access packages bundle multiple resources (SharePoint sites, Teams), enable self-service requests with approval, and automatically remove access when the assignment expires. Group expiration (A) handles group lifecycle but not specific resource access removal.
Q3 Plan and automate identity governance
You are configuring an access review for members of the Global Administrator role. The review should run quarterly, reviewed by each user's manager, and users not reviewed should have access automatically removed. What should you configure?
  1. Create an access review in Entra ID Identity Governance with reviewer set to user's manager, quarterly recurrence, and 'If reviewers don't respond' set to Remove access
  2. Create an access review in PIM for the Global Administrator role with reviewer set to user's manager, quarterly recurrence, and 'If reviewers don't respond' set to Remove access
  3. Create an access review with manually selected reviewers for each manager
  4. Create a PIM access review with auto-approval for self-attesting members
✓ Correct Answer: B
Access reviews for Entra ID roles (like Global Administrator) must be created in PIM, not in the general Identity Governance access reviews section. In PIM, set reviewer to user's manager, quarterly recurrence, and auto-remove on no response to meet all requirements.
Q4 Plan and automate identity governance
You need to implement a monthly access review for guest users who have access to the Salesforce app. The review must assign each guest's manager as reviewer, remove access after 5 days if not completed, and assign Megan Bowen as fallback reviewer for guests without a manager. What should you use?
  1. Conditional Access policy
  2. Access reviews in Identity Governance
  3. Privileged Identity Management
  4. Entitlement Management catalog
✓ Correct Answer: B
Access reviews in Identity Governance support periodic review of group memberships and application access. Configure: recurrence monthly, duration 5 days, reviewer set to user's manager, fallback reviewer = Megan Bowen, and 'Auto-apply results to resource' enabled for access removal on completion.
Q5 Plan and automate identity governance
You need to modify settings for the User Administrator role to require eligible assignments with appropriate expiration. Which two actions should you perform in PIM?
  1. Require justification on activation and ticket info
  2. Set all assignments to active
  3. Set all assignments to eligible and configure the eligible assignment expiration
  4. Modify the expiration of active assignments
✓ Correct Answer: C
In PIM, set assignments to eligible (not active) so users must request activation when needed. Configure eligible assignment expiration to meet the requirement (e.g., max 1 year). Active assignments grant permanent access and bypass the just-in-time security model.
Q6 Plan and automate identity governance
You need to identify which roles can create and manage access reviews for an access package. Which two roles can perform this task?
  1. Only User3
  2. Only User4
  3. Only User5
  4. User3 and User4
  5. User3 and User5
  6. User4 and User5
✓ Correct Answer: E
Roles that can create and manage access reviews for access packages: Global Administrator and Identity Governance Administrator (User3) can manage any review; the catalog owner or access package manager for the specific package can also create reviews. User Administrator (User4) alone cannot manage entitlement management reviews.
Q7 Plan and automate identity governance
What is the primary purpose of Microsoft Entra ID Governance entitlement management?
  1. To define Conditional Access policies for external users
  2. To manage the lifecycle of identities through automated provisioning, access packages, and separation of duties checks
  3. To configure multi-factor authentication for high-risk users
  4. To manage device compliance policies
✓ Correct Answer: B
Entitlement management in Microsoft Entra ID Governance manages the identity and access lifecycle at scale — automating provisioning, creating access packages that bundle resources (groups, apps, SharePoint sites), handling access requests with approval workflows, and performing regular access reviews for governance compliance.
Q8 Plan and automate identity governance
What is the purpose of an emergency access (break-glass) account in Microsoft Entra ID?
  1. To provide regular administrative access to the tenant
  2. To serve as a highly privileged, cloud-only account excluded from Conditional Access and MFA policies for emergency tenant access when normal admin accounts are unavailable
  3. To automate incident response in Microsoft Sentinel
  4. To provide delegated access to external auditors
✓ Correct Answer: B
Emergency access (break-glass) accounts are highly privileged, cloud-only accounts (typically Global Administrators) excluded from Conditional Access policies and MFA requirements. They provide emergency access when normal administrative accounts are unavailable due to misconfiguration, MFA device loss, or Conditional Access lockout.

You've viewed 3 of 80 questions. Start the free practice exam to answer all questions with instant feedback.

What Our Customers Say 357 verified reviews

5.0 Based on 357 reviews
The question explanations for SC-300 really dig into the AWS (or relevant) concepts. Helped me understand things at a deeper level.
— Hazel C.
I used this alongside video courses for SC-300 prep. The questions helped solidify what I learned from the lectures.
— Aria N.
Quick shipping? LOL jk — instant access was great. Started studying SC-300 questions right after purchase, no delays.
— Colton W.
The SC-300 practice test is spot-on. The multi-select questions and explanations are exactly what you need for the real exam.
— Emily R.
Straightforward and effective. No fluff in the SC-300 practice set, just relevant questions with solid answer keys.
— Owen P.
The SC-300 exam was brutal, but these practice questions prepared me for the worst. Came out with a solid pass.
— Carter H.

Log in to rate this exam and leave a review.

Submitted for moderation before publishing. Keep it helpful and respectful.

Frequently Asked Questions

The single biggest pitfall is failing to distinguish between Microsoft Entra Connect Sync and Cloud Sync—their feature sets overlap but have hard boundaries (for example, Cloud Sync does not support device writeback or group writeback, while Connect Sync does). The second major stumbling block is Conditional Access policy evaluation precedence: candidates consistently misjudge how multiple policies interact when block and grant controls intersect across nested group memberships. Our practice questions include targeted scenario items that force you to reason through both of these exactly as the real exam presents them.

Treat SC-300 as a closed-book exam. You have exactly 100 minutes of active exam time for up to 60 complex questions, including case studies with un-reviewable blocks that can consume 10–15 minutes each. Navigating Microsoft Learn for basic concepts will guarantee you run out of time. Use the integrated documentation window only to confirm precise Microsoft Graph PowerShell cmdlet syntax, API attribute names, or specific Entra admin center configuration paths—never to learn a concept from scratch. Our timed practice mode trains you to recognize these questions without needing to look anything up.

Start with the free, official Microsoft Learn Practice Assessment on the SC-300 certification landing page—it mirrors real exam phrasing and surfaces your weakest domains. For a deeper breakdown of trick questions and subtle distractors, work through the four-part Exam Readiness Zone video series on Microsoft Learn, where identity experts analyze target topics and explain common traps in the multiple-choice format. Our practice question bank is aligned to the same January 2024 updated blueprint and includes detailed answer explanations that call out the exact distractor logic Microsoft uses.

The credential expires exactly one year from the date it is issued. Microsoft opens a 6-month renewal eligibility window before expiration, during which you can pass a short, unproctored online assessment on Microsoft Learn at no cost—it covers only platform feature updates since your last exam (for example, Global Secure Access endpoints and the latest Entra ID Governance features). Our PDF download includes a certification timeline checklist so you do not miss the renewal window.

The real SC-300 exam gives you 100 minutes of active time for 40–60 questions, including case studies with un-reviewable blocks that simulate complex multi-tenant identity scenarios. Our mock exam mode enforces the same 100-minute clock and case-study format, so you learn exactly how fast you need to move through Conditional Access policy design questions versus Entra Connect architecture drag-and-drop items. Practicing under time pressure is the only way to avoid running out of minutes on exam day—especially given that case studies cannot be reviewed once you submit them.

Yes—the downloadable PDF packages the full question bank in a print-friendly format that you can use on flights, commutes, or anywhere without reliable internet. The PDF includes the same detailed answer explanations as the online version, with references to the specific Microsoft Learn documentation paths for Entra PIM activation settings, Access Package lifecycle policies, and Entra ID Governance audit KQL queries. Many candidates use the PDF for a final review of PIM role assignment vs. activation and Access Package approval workflow diagrams the morning of their exam sitting.

After a failed first attempt, you must wait 24 hours before rescheduling. A third or subsequent attempt requires a 14-day waiting period between sittings, and you are capped at five attempts within any rolling 12-month period. Our mock exam mode is designed to simulate the real timing and question distribution, so you can identify domain-level gaps—especially in the easily-missed Entra Connect vs. Cloud Sync comparison and Conditional Access policy precedence—and avoid needing a retake in the first place.

Free Study Resources

Community-verified analysis of 134 topics from real test-taker discussions — 7 deep analyses and 0 FAQs.