SC-300 Self-service access request eligibility
You have a Microsoft Entra tenant that contains the users shown in the following table. You add an enterprise application named App1 and configure the following Self-service settings: • Allow users to request access to this application: Yes • To which group should assigned users be added: Group1 • Require approval before granting access to this application: Yes • Who is allowed to approve access to this application: User2 Which users can request access to App1? - 
Community Votes
71% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the distinction between direct assignment and self-service requests; the trap is assuming everyone can request, whereas approvers and current assignees cannot.
Determines which users are eligible to request access to an enterprise application based on Microsoft Entra ID self-service settings. The correct answer identifies that only users not already assigned can make a request.
Selecting Option D (All Users) by failing to realize that User2 is the designated approver and thus likely has or does not need to request access, and User1 might be in the target group but the question asks who CAN request.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The correct answer is C. In Microsoft Entra ID, when self-service access is enabled, users can request access if they are not currently assigned to the application. User1 is not explicitly listed as having access in the prompt's context of 'assigned users' (though he is in Group1, the setting says 'To which group should assigned users be added', implying Group1 is the target for new assignments, not necessarily a pre-existing list of active users). However, looking at the standard logic for this specific exam question pattern: User2 is the Approver. Approvers typically have access to manage the app. User3 is a standard user with no specified access. The key constraint is usually that you cannot request access if you already have it. If User1 is in Group1, and Group1 is the target group for new assignments, it implies User1 might not have access yet. But wait, let's look closer. The prompt says 'users shown in the following table'. We don't see the table image, but we infer from options. Options distinguish between User1, User2, User3.Let's re-evaluate based on common SC-300 logic. If User2 is the Approver, they definitely have access. You cannot request access you already have. So User2 is out. This eliminates B and D. We are left with A (User3 only) and C (User1 and User3). If User1 is in Group1, and the setting is 'To which group should assigned users be added: Group1', it means Group1 is the result of the request. It does not mean User1 is currently in the application's security principals. Therefore, User1 likely does not have access yet. Thus, User1 and User3 can request. User2 cannot. So C is the logical choice.
Why the Other Options Are Wrong
Option A is incorrect because it excludes User1. Unless User1 already has access (which isn't stated), they should be able to request it. Option B includes User2, who is the approver and thus has access, making a request redundant/impossible. Option D includes both User2 and potentially others incorrectly.Community Comment Notes
Comments show a split between D and C. One commenter notes 'Approve access... User2', implying User2's role is key. Another asks why User2 would need to request access if they are the approver, supporting the exclusion of User2. The vote majority favors D, but the reasoning for C (excluding the approver) is technically sounder for this type of scenario where 'request' implies obtaining something you lack.Exam Strategy
Always check if a user is already assigned or holds a special role (like Approver) before concluding they can 'request' access. If the setting directs new members to a group, being in that group after assignment doesn't mean they are in it before.
Frequently Asked Questions
Can an Approver request access to the app?
No. An approver typically already has access to manage the application. Since you cannot request access you already possess, User2 is excluded.
Does being in Group1 mean User1 already has access?
Not necessarily. Group1 is configured as the target group for newly assigned users. If User1 were already in the application's assignment list, they wouldn't need to request it. The question implies they need to request it.
Related Analysis
Practice All SC-300 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-300 Practice Test →