microsoft sc-300 practice test

microsoft identity and access administrator

Last exam update: Nov 12 ,2025
Page 1 out of 31. Viewing questions 1-10 out of 307

Question 1

HOTSPOT You need to create the LWGroup1 group to meet the management requirements.
How should you complete the dynamic membership rule? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Mark Question:
Answer:

Discussions
0 / 1000

Question 2

You have a Microsoft 365 tenant.
The Azure Active Directory (Azure AD) tenant syncs to an on-premises Active Directory domain.
You plan to create an emergency-access administrative account named Emergency1. Emergency1 will be assigned the Global administrator role in Azure AD.
Emergency1 will be used in the event of Azure AD functionality failures and on-premises infrastructure failures.
You need to reduce the likelihood that Emergency1 will be prevented from signing in during an emergency.
What should you do?

  • A. Configure Azure Monitor to generate an alert if Emergency1 is modified or signs in.
  • B. Require Azure AD Privileged Identity Management (PIM) activation of the Global administrator role for Emergency1.
  • C. Configure a conditional access policy to restrict sign-in locations for Emergency1 to only the corporate network.
  • D. Configure a conditional access policy to require multi-factor authentication (MFA) for Emergency1.
Mark Question:
Answer:

a

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 3

Your company has an Azure AD tenant that contains the users shown in the following table.



You have the app registrations shown in the following table.



A company policy prevents changes to user permissions.

Which user can create appointments in the calendar of each user at the company?

  • A. User1
  • B. User2
  • C. User3
  • D. User4
Mark Question:
Answer:

b

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 4

You work for a company named Contoso, Ltd. that has a Microsoft Entra tenant named contoso.com.

Contoso is working on a project with the following two partner companies:

A company named A. Datum Corporation that has a Microsoft Entra tenant named adatum.com.
A company named Fabrikam, Inc. that has a Microsoft Entra tenant named fabrikam.com.

When you attempt to invite a new guest user from adatum.com to contoso.com, you receive an error message.

You can successfully invite a new guest user from fabnkam.com to contoso.com.

You need to be able to invite new guest users from adatum.com to contoso.com.

What should you configure?

  • A. Guest invite settings
  • B. Verifiable credentials
  • C. Named locations
  • D. Collaboration restrictions
Mark Question:
Answer:

d

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 5

HOTSPOT You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table.

For which users can you configure the Job title property and the Usage location property in Azure AD? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Mark Question:
Answer:


Box 1: User1 and User2 only.
You can add or update a user's profile information using Azure Active Directory.
Add user profile information, including a profile picture, job-specific information, and some settings using Azure Active Directory (Azure AD).
The user profile includes:
Job info. Add any job-related information, such as the user's job title, department, or manager.

Box 2: User1, User2, and User3 -
Invite users with Azure Active Directory B2B collaboration, Update user's name and usage location.
To assign a license, the invited user's Usage location must be specified. Admins can update the invited user's profile on the Azure portal.
1. Go to Azure Active Directory > Users and groups > All users. If you don't see the newly created user, refresh the page.
2. Click on the invited user, and then click Profile.
3. Update First name, Last name, and Usage location.
4. Click Save, and then close the Profile blade.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-users-profile-azure-portal https://docs.microsoft.com/en-us/power-platform/admin/invite-users-azure-active-directory-b2b-collaboration#update-users-name-and-usage-location

Discussions
0 / 1000

Question 6

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Active Directory forest that syncs to an Azure Active Directory (Azure AD) tenant.
You discover that when a user account is disabled in Active Directory, the disabled user can still authenticate to Azure AD for up to 30 minutes.
You need to ensure that when a user account is disabled in Active Directory, the user account is immediately prevented from authenticating to Azure AD.
Solution: You configure password writeback.
Does this meet the goal?

  • A. Yes
  • B. No
Mark Question:
Answer:

b


Reference:
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/choose-ad-authn

User Votes:
A
50%
B
50%
Discussions
vote your answer:
A
B
0 / 1000

Question 7

You have an Azure subscription, a Google Cloud Platform (GCP) account, and an Amazon Web Services (AWS) account.

You need to recommend a solution to assess the risks associated with privilege assignments across all the platforms. The solution must minimize administrative effort.

What should you include in the recommendation?

  • A. Microsoft Sentinel
  • B. Microsoft Entra ID Protection
  • C. Microsoft Defender for Cloud Apps
  • D. Microsoft Entra Permissions Management
Mark Question:
Answer:

d

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 8

You have a Microsoft 365 subscription that contains the users shown in the following table.



From the tenant, you configure a naming policy for groups.

Which users are affected by the naming policy?

  • A. User2 only
  • B. User3only
  • C. User2 and User3 only
  • D. User3 and User4 only
  • E. User1, User2, and User3 only
  • F. User1, User2, User3, and User4
Mark Question:
Answer:

d

User Votes:
A
50%
B
50%
C
50%
D
50%
E
50%
F
50%
Discussions
vote your answer:
A
B
C
D
E
F
0 / 1000

Question 9

HOTSPOT

You have an Azure subscription named Sub1.

You plan to onboard Microsoft Entra Permissions Management.

You need to ensure that Permissions Management users can manage role assignments for Sub1. The solution must follow the principle of least privilege.

Which role should you assign and to which identity should you assign the role? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Mark Question:
Answer:

Discussions
0 / 1000

Question 10

HOTSPOT You have an Azure Active Directory (Azure AD) tenant that has an Azure Active Directory Premium Plan 2 license. The tenant contains the users shown in the following table.

You have the Device Settings shown in the following exhibit.

User1 has the devices shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Mark Question:
Answer:


Box 1: Yes -
Users may join 5 devices to Azure AD.

Box 2: No -
Cloud device administrator an enable, disable, and delete devices in Azure AD and read Windows 10 BitLocker keys in the Azure portal. The role does not grant permissions to manage any other properties on the device.

Box 3: No -
An additional local device administrator has not been applied
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/devices/device-management-azure-portal

Discussions
0 / 1000
Manohara
4 months ago

No
Yes
No .

To page 2