SC-300 sample questions with answers

10 free practice questions for the Microsoft Certified: Identity and Access Administrator Associate exam. Try each one, then open the answer to see why the right option wins and every other option loses.

Question 1Implement and manage user identities

Consolidated Messenger has five Active Directory forests left over from three acquisitions. Two of the forests have no network connectivity to the other three. The identity team must decide where Microsoft Entra Cloud Sync is a better fit than Microsoft Entra Connect Sync. Which two requirements can Cloud Sync meet that Connect Sync cannot? Each correct answer presents a complete solution. (Choose TWO.)

Choose 2.

  1. A.

    Synchronize users from multiple disconnected Active Directory forests to one Microsoft Entra tenant without any network connectivity between the forests.

  2. B.

    Synchronize Windows device objects to support Microsoft Entra hybrid join.

  3. C.

    Synchronize users and groups so that password hash synchronization can be used for sign-in.

  4. D.

    Filter the objects that are synchronized by organizational unit.

  5. E.

    Provide high availability for synchronization by running several lightweight provisioning agents that share the workload.

  6. F.

    Support Exchange hybrid deployments that require attribute writeback to Active Directory.

Show answer

Answer: A, E

Cloud Sync's differentiators are support for disconnected forests and built-in high availability from multiple lightweight agents; device sync and Exchange hybrid writeback still require Connect Sync.

  • A. Each Cloud Sync agent reaches only its own forest, so disconnected forests can target one tenant.
  • B. Device object synchronization for hybrid join is supported only by Microsoft Entra Connect Sync.
  • C. Both products support password hash synchronization, so it is not a Cloud Sync differentiator.
  • D. Organizational unit filtering exists in both products and therefore decides nothing.
  • E. Multiple lightweight provisioning agents share the load and provide high availability with no staging server.
  • F. Exchange hybrid writeback needs the Connect Sync engine; Cloud Sync does not support it.
Question 2Implement and manage user identities

Margie's Travel requires multifactor authentication for all users through a Conditional Access policy. Consultants from a partner tenant are invited as guests and complain that they must register and perform MFA again in Margie's Travel even though their home tenant already enforces MFA. You must stop the duplicate registration for that partner only. What should you configure?

  1. A.

    In Cross-tenant access settings, add the partner as an organization and enable the inbound trust setting that trusts multifactor authentication from Microsoft Entra tenants.

  2. B.

    Configure direct federation with the partner's identity provider in External Identities > All identity providers.

  3. C.

    In Cross-tenant access settings, change the default inbound settings to trust multifactor authentication from Microsoft Entra tenants.

  4. D.

    Exclude the partner's guest accounts from the Conditional Access policy that requires multifactor authentication.

Show answer

Answer: A

Inbound trust settings configured on an organizational entry for that partner let Microsoft Entra ID accept the MFA claim issued by the partner's home tenant, without weakening anything for other tenants.

  • A. An organizational entry with the inbound MFA trust enabled accepts the partner's MFA claim for that tenant only.
  • B. Direct federation serves partners without a Microsoft Entra tenant and does not carry MFA trust claims.
  • C. Changing the default extends MFA trust to every external Microsoft Entra tenant, which the requirement restricts.
  • D. Excluding the guests removes MFA enforcement altogether rather than honouring MFA performed elsewhere.
Question 3Implement and manage user identities

Adatum Corporation will deploy pass-through authentication on two domain-joined member servers. Before the change board approves it, the security team asks which firewall rules the authentication agents need. What should you tell the change board?

  1. A.

    Only outbound HTTPS from the agent servers; no inbound port has to be published.

  2. B.

    Outbound HTTPS from the agent servers, plus inbound LDAP from Microsoft Entra ID to the domain controllers.

  3. C.

    Inbound TCP 443 to a reverse proxy in the perimeter network that forwards requests to the agent servers.

  4. D.

    Inbound TCP 443 published to the agent servers so that Microsoft Entra ID can contact them.

Show answer

Answer: A

Pass-through authentication agents poll the service over outbound HTTPS, so nothing is exposed inbound and no perimeter publishing is required.

  • A. Agents maintain outbound connections and receive work over them, so no inbound rule is required.
  • B. No inbound directory traffic from the cloud exists; the agent talks to domain controllers from inside.
  • C. A reverse proxy in a perimeter network belongs to the federation model, not to pass-through authentication.
  • D. Microsoft Entra ID never initiates a connection into the network; the agent polls outward.
Question 4Implement and manage user identities

As part of retiring Active Directory Federation Services, Fabrikam enables staged rollout for password hash synchronization. The identity team adds a cloud security group named Grp-AuthPilot whose membership comes from the rule user.department -eq "Sales", and the audit log confirms the group was added to the rollout policy. Two days later every pilot user is still redirected to the AD FS sign-in page. What should you do?

  1. A.

    Replace Grp-AuthPilot with an assigned cloud security group that lists the pilot users, and add that group to the password hash synchronization rollout

  2. B.

    Add Grp-AuthPilot to the seamless single sign-on rollout as well, because a group takes effect only once it is added to every rollout feature

  3. C.

    Convert the Fabrikam domain to a managed domain, because staged rollout takes effect only after the domain conversion has completed

  4. D.

    Reduce Grp-AuthPilot to fewer than 200 members, because staged rollout ignores any group that holds more than 200 users

Show answer

Answer: A

Staged rollout does not support dynamic membership groups, so the rule-based group is accepted by the portal but never enables anyone; an assigned group is required.

  • A. Staged rollout supports assigned security groups only, so replacing the rule-based group with an assigned cloud group is what makes the pilot take effect.
  • B. Seamless single sign-on is an independent rollout feature affecting silent sign-in, and it is not required for a password hash synchronization rollout to apply.
  • C. Staged rollout works only while the domain is still federated; converting the domain is the cut over that ends the pilot rather than enabling it.
  • D. The 200-user figure limits how many members a group may hold when it is first added to avoid a portal time-out; more users can be added directly afterwards.
Question 5Implement and manage user identities

Northwind Traders has 14,000 users in one Microsoft Entra tenant. A helpdesk team in Osaka must be able to reset passwords only for the 900 users whose city attribute is Osaka. The team must not be able to modify any other user. You must minimize the number of role assignments and avoid granting tenant-wide permissions. What should you do?

  1. A.

    Create a custom Microsoft Entra role that contains the password reset permission and assign it at tenant scope to the Osaka helpdesk.

  2. B.

    Create a dynamic security group for city Osaka and assign the Osaka helpdesk the Password Administrator role with the group as the assignment scope.

  3. C.

    Create an administrative unit with a dynamic user membership rule for city Osaka, then assign the Osaka helpdesk the Password Administrator role scoped to that administrative unit.

  4. D.

    Assign the Osaka helpdesk the Helpdesk Administrator role at tenant scope and create a Conditional Access policy that blocks other users.

Show answer

Answer: C

Administrative units are the only container that scopes a Microsoft Entra directory role to a subset of users, and a dynamic membership rule keeps the Osaka population current automatically.

  • A. Trimming permissions with a custom role does not narrow scope; at tenant scope it still affects every user.
  • B. A security group cannot be the scope of a Microsoft Entra directory role assignment; only the tenant, an administrative unit, or an object can.
  • C. Administrative units scope a directory role to their members, and a dynamic rule keeps the Osaka membership current.
  • D. Conditional Access governs sign-in, not administrative reach, so the tenant-wide role would still cover all users.
Question 6Implement and manage user identities

At Relecloud, a Global Administrator reports that the Custom security attributes section of a user profile shows no values, although the compliance team maintains attributes there. You must let that Global Administrator read the values. What should you do?

  1. A.

    Assign the Global Administrator the Attribute Definition Administrator role, which also grants read access to the values assigned to users.

  2. B.

    Consent the CustomSecAttributeAssignment.Read.All delegated permission on behalf of the organization for the Microsoft Entra admin center.

  3. C.

    Assign the Global Administrator the Attribute Assignment Reader role over the attribute set.

  4. D.

    Turn on the setting that includes custom security attributes in the tenant properties of the Microsoft Entra admin center.

Show answer

Answer: C

Custom security attributes are deliberately outside the Global Administrator role, so an explicit attribute role must be assigned before the values are visible.

  • A. Definition roles cover attribute sets and attribute definitions, not the values assigned to users.
  • B. A Microsoft Graph permission applies to an application's calls and does not grant an administrator access in the portal.
  • C. Attribute Assignment Reader is the role that grants read access to the values assigned to objects, and it can be scoped to the attribute set.
  • D. No tenant property reveals custom security attributes; visibility is controlled entirely by role assignment.
Question 7Implement and manage user identities

Blue Yonder Airlines must ensure that no helpdesk administrator can reset the passwords or change the authentication methods of its 12 executive accounts. The helpdesk keeps the Helpdesk Administrator role at tenant scope for every other user. What should you recommend?

  1. A.

    Create a Conditional Access policy that blocks the helpdesk from the Microsoft Entra admin center whenever the account being edited is an executive account.

  2. B.

    Create a dynamic administrative unit that contains the executive accounts and assign the helpdesk the Helpdesk Administrator role scoped to a second administrative unit that excludes them.

  3. C.

    Add the executive accounts to a restricted management administrative unit.

  4. D.

    Move the executive accounts to a separate Microsoft Entra tenant and invite them back into the airline tenant as B2B collaboration guests.

Show answer

Answer: C

A restricted management administrative unit is the only construct that removes objects from the reach of tenant-scoped administrators without changing those administrators' assignments.

  • A. Conditional Access evaluates the sign-in, not the object an administrator later edits, so it cannot express this restriction.
  • B. A second administrative unit does not revoke the helpdesk's existing tenant-scoped assignment, which still covers the executives.
  • C. Restricted management administrative units remove their members from the reach of tenant-scoped role assignments.
  • D. A separate tenant achieves isolation at a disproportionate cost and turns the executives into external guests.
Question 8Implement and manage user identities

Alpine Ski House acquires a resort business with 600 staff. The resort must have its own identity administrators who can manage only resort accounts. All staff must share one Microsoft 365 subscription, one set of Conditional Access policies, and one licence pool. What should you recommend?

  1. A.

    Create a security group that contains the resort accounts and add the resort administrators as owners of that group.

  2. B.

    Assign the resort administrators the User Administrator role at tenant scope and publish a written policy stating that they may manage resort accounts only.

  3. C.

    Create an administrative unit that contains the resort accounts and assign the resort administrators roles scoped to that unit.

  4. D.

    Create a second Microsoft Entra tenant for the resort and configure cross-tenant synchronization so that resort staff also appear in the Alpine Ski House tenant.

Show answer

Answer: C

An administrative unit delegates administration over a subset of accounts inside one tenant, which is the only option that keeps a single policy set and licence pool.

  • A. A security group cannot be the scope of a Microsoft Entra role assignment, and ownership only confers group membership management.
  • B. A tenant-scoped role gives the resort administrators authority over every account; a written policy is not a technical control.
  • C. Administrative units are the in-tenant boundary for directory role assignments, preserving one policy set and licence pool.
  • D. A second tenant splits Conditional Access policies and licensing, which the requirements explicitly forbid.
Question 9Implement and manage user identities

A regional support team at Margie's Travel must be able to enable, disable, and delete Microsoft Entra device objects and read BitLocker recovery keys. The team must not be able to change any user account. Which role should you assign?

  1. A.

    Cloud Device Administrator

  2. B.

    Intune Administrator, because device objects are governed by the mobile device management service

  3. C.

    Helpdesk Administrator, which covers device support tasks alongside password resets

  4. D.

    Windows 365 Administrator

Show answer

Answer: A

Cloud Device Administrator is the role built for device object management and BitLocker key recovery, and it contains no user management permissions.

  • A. Cloud Device Administrator covers exactly device enable, disable, delete, and BitLocker key read, with no user permissions.
  • B. Intune Administrator governs the mobile device management service and grants far more than the requirement.
  • C. Helpdesk Administrator's core capability is resetting user passwords, which the requirement forbids.
  • D. Windows 365 Administrator manages Cloud PCs rather than the tenant's device objects.
Question 10Implement and manage user identities

Blue Yonder Airlines' identity architect is documenting how cross-tenant access settings work so that the service desk can answer partner questions without escalating every one of them. Which two statements are correct? (Choose TWO.)

Choose 2.

  1. A.

    Blocking outbound B2B collaboration for a partner prevents that partner's users from being invited into your tenant.

  2. B.

    B2B direct connect lets users from a partner tenant join a Microsoft Teams shared channel without a guest object being created in your tenant.

  3. C.

    An organizational setting for a named tenant replaces the default settings for that tenant.

  4. D.

    Cross-tenant access settings also govern guests who sign in with a Microsoft account or a Google identity.

  5. E.

    Cross-tenant access settings remove the need to configure external collaboration settings for guest invitations.

  6. F.

    Trusting a partner's compliant device claim requires the partner's devices to be enrolled in your own device management service.

Show answer

Answer: B, C

Organizational settings replace rather than extend the default, and B2B direct connect is the only external model that creates no object in the resource tenant.

  • A. Outbound settings govern where your own users may go; inbound settings govern who may come in.
  • B. B2B direct connect grants access to a Teams shared channel with no guest object in the resource tenant.
  • C. A per-organization configuration replaces the default settings for that partner entirely.
  • D. Microsoft accounts and social identities are governed by external collaboration settings and identity providers.
  • E. External collaboration settings still control invitation restrictions and guest directory permissions.
  • F. The trust setting exists precisely so that you can accept the partner's own device compliance assessment.

Keep going with 511 more SC-300 questions

Free papers every day, in the real exam formats, with progress by exam domain. Unlock every paper and timed mock exam when you are ready.

SC-300 sample questions with answers (10 free) · CertifyCloudx