SC-300 Sample Questions & Answers
ID Protection, Conditional Access and Entra authentication carry the most weight, alongside creating and managing identities including external users, workload identities and app registrations, and automating identity governance like access reviews.
Launch the full SC-300 simulator →Free SC-300 Sample Questions with Answers
Real questions from the Microsoft Identity and Access Administrator practice test — answers and explanations included. Showing 10 of 20 free samples.
- Question 1Advanced
Plan and implement workload identities · Plan, implement, and monitor the integration of enterprise applications
Case Study: Litware, Inc. Identity Modernization
Company Background:
Litware, Inc. is a software development company with 2,000 employees. They have a hybrid identity environment using Microsoft Entra Connect to synchronize their on-premises Active Directory (ad.litware.com) with Microsoft Entra ID. They currently use Password Hash Synchronization and have an Azure AD Premium P2 license for all users.Current Situation:
Litware has a critical on-premises legacy application called 'CodeVault' that uses Kerberos authentication. Remote developers need to access CodeVault, but the company wants to avoid using a traditional VPN. Litware has recently acquired a smaller company that uses Google Workspace as their identity provider. Litware needs to grant these newly acquired employees access to a specific set of SaaS applications managed in the Litware Microsoft Entra tenant.Requirements:
- Provide remote access to the on-premises 'CodeVault' application without a VPN.
- The solution for 'CodeVault' must support Kerberos authentication and enforce Microsoft Entra Conditional Access policies.
- Allow the acquired company's employees to use their existing Google Workspace credentials to access designated SaaS apps in the Litware tenant.
- Minimize administrative overhead for managing the acquired users' identities.
Problem:
You are an Identity Architect tasked with designing a solution that meets all of Litware's requirements. Which of the following solutions is the most effective?graph TD subgraph Internet RemoteDev[Remote Developer] AcquiredUser[Acquired Co. User] end subgraph Litware Azure EntraID[Microsoft Entra ID] AppProxy[Application Proxy] SaaSApps[SaaS Apps] CAPolicy[CA Policies] end subgraph Litware On-Premises AD[ad.litware.com] CodeVault[CodeVault App] Connector[App Proxy Connector] end subgraph Acquired Co. Google[Google Workspace] end RemoteDev -->|1. Access Request| EntraID EntraID -->|2. Enforce CA| CAPolicy CAPolicy -->|3. Authenticate| EntraID EntraID -->|4. Forward to Proxy| AppProxy AppProxy -->|5. To Connector| Connector Connector -->|6. KCD| AD AD -->|7. Kerberos Ticket| Connector Connector -->|8. Access App| CodeVault AcquiredUser -->|1. Access Request| SaaSApps SaaSApps -->|2. Redirect to Entra| EntraID EntraID -->|3. Redirect to Google| Google Google -->|4. Authenticate User| AcquiredUser Google -->|5. SAML Token| EntraID EntraID -->|6. Grant Access| SaaSAppsShow answer & explanation
Correct answer: B
This solution correctly addresses all requirements. Microsoft Entra Application Proxy with KCD is the designated solution for publishing on-premises Kerberos-based applications securely while enabling the enforcement of Conditional Access policies. For the acquired users, setting up Google Workspace as a federated identity provider allows them to use their existing credentials (fulfilling requirement 3) and minimizes administrative overhead since user accounts don't need to be manually created or managed in the Litware tenant (fulfilling requirement 4).
- Question 2IntermediateSelect 2
Implement authentication and access management · Manage risk by using Microsoft Entra ID Protection
A security administrator is reviewing sign-in logs and notices several 'unfamiliar sign-in properties' risk detections. To automate the response, the administrator wants to configure a policy that forces users with a medium or high user risk level to perform a secure password change. Which two services should be configured to achieve this? (Select TWO)
Show answer & explanation
Correct answers: A, D
Microsoft Entra ID Protection is the service that detects and calculates user risk levels based on various signals, including 'unfamiliar sign-in properties'. It is where you create the user risk policy.
For the 'secure password change' remediation to be available, SSPR must be enabled and configured for the targeted users. The user risk policy in ID Protection relies on SSPR to facilitate the password reset process.
- Question 3Beginner
Implement and manage user identities · Create, configure, and manage Microsoft Entra identities
An organization is using group-based licensing to assign Microsoft 365 E5 licenses to all users in the 'Marketing' department. A new user, User1, is added to the 'Marketing' group. However, after 24 hours, User1 still does not have an E5 license. An administrator checks the group's licensing status and sees a processing error stating, 'License assignment failed for one or more users.' What is the most common reason for this specific error?
Show answer & explanation
Correct answer: A
While other issues can occur, the most frequent cause for a license assignment to fail for a new user being added to a licensed group is the exhaustion of available licenses in the tenant. Microsoft Entra cannot assign a license that it doesn't have. An administrator would need to purchase more licenses or free up existing ones for the assignment to succeed.
- Question 4Beginner
Implement authentication and access management · Plan, implement, and manage Microsoft Entra Conditional Access
A company is configuring a Conditional Access policy to protect a critical application. The policy must block access from all countries except for Canada and the United States. Which configuration for the 'Locations' condition is the correct way to implement this?
Show answer & explanation
Correct answer: A
The standard best practice for creating a location-based block policy is to target 'Any location' in the 'Include' condition and then add the approved locations (in this case, a named location containing Canada and the US) to the 'Exclude' condition. This ensures that all traffic is evaluated, and only the explicitly excluded locations are allowed. Trying to include all countries except two is impractical and prone to error.
- Question 5Intermediate
Plan and implement workload identities · Plan and implement identities for applications and Azure workloads
A developer at your company has created an Azure Function App that needs to read secrets from an Azure Key Vault. To follow security best practices, you want to avoid storing any credentials or secrets in the Function App's configuration. What is the most secure and recommended method for the Function App to authenticate to the Key Vault?
Show answer & explanation
Correct answer: B
Using a system-assigned managed identity is the most secure and recommended approach. It creates an identity for the Azure Function App directly in Microsoft Entra ID without any credentials being stored in the application's code or configuration. You then grant this identity access to the Key Vault. The Function App can acquire an access token from the managed identity endpoint to authenticate to the Key Vault securely.
- Question 6Beginner
Plan and automate identity governance · Plan and implement entitlement management in Microsoft Entra
Your company wants to ensure that external guest users who are invited to collaborate on a project must agree to a non-disclosure agreement (NDA) before they can access any resources in the tenant. This NDA agreement must be presented to them upon their first sign-in. Which feature should you implement?
Show answer & explanation
Correct answer: B
Microsoft Entra Terms of Use (ToU) is designed for this exact scenario. You can upload the NDA document as a PDF, create a ToU policy, and then enforce it using a Conditional Access policy. The Conditional Access policy would be configured to target 'All guest and external users' and have the ToU as a grant control, ensuring they must accept it before being granted access.
- Question 7Beginner
Plan and automate identity governance · Monitor identity activity by using logs, workbooks, and reports
A consultant is reviewing a company's Microsoft Entra ID configuration and wants to get a quick, high-level overview of the identity security posture and receive prioritized recommendations for improvement. Which tool in the Microsoft Entra admin center provides this specific functionality?
Show answer & explanation
Correct answer: C
Identity Secure Score is a feature within Microsoft Entra ID that provides a numerical score representing the organization's identity security posture. It also offers a list of prioritized improvement actions, detailing the security impact and user impact of each recommendation, which directly matches the consultant's requirements.
- Question 8Intermediate
Plan and implement workload identities · Plan and implement app registrations
You are designing a solution for a new web application that will be registered in Microsoft Entra ID. The application's backend API needs to call Microsoft Graph to read data, even when no user is signed in. The API is hosted on an Azure App Service. Which of the following should you use to grant the API permissions to Microsoft Graph?
Show answer & explanation
Correct answer: B
Application permissions are required when an application needs to access an API with its own identity, without a signed-in user. This is often referred to as a daemon or background service scenario. Since the requirement explicitly states the API must call Microsoft Graph 'even when no user is signed in', application permissions are the correct choice. Delegated permissions require a user context.
- Question 9Advanced
Implement authentication and access management · Plan, implement, and manage Microsoft Entra Conditional Access
A company has implemented continuous access evaluation (CAE) in their Microsoft Entra tenant. A user, who is working from home, signs into SharePoint Online. An hour later, the company's network administrator adds the user's home IP address to a list of blocked IPs in a Conditional Access named location policy. What will happen to the user's SharePoint session?
Show answer & explanation
Correct answer: B
Continuous Access Evaluation (CAE) allows resource providers like SharePoint Online to subscribe to critical events in Microsoft Entra ID. A change in location that violates a Conditional Access policy is one of these critical events. When the user's IP is added to the block list, Microsoft Entra ID will publish this event. The CAE-capable client (SharePoint) will receive this event and enforce the policy by revoking the user's session in near real-time, without waiting for the access token to expire.
- Question 10IntermediateSelect 2
Implement authentication and access management · Implement Global Secure Access
Your organization wants to deploy Microsoft Entra Global Secure Access to provide secure access to internal web applications for remote users. You have deployed the Global Secure Access client to all user devices. What are the next TWO essential components you must configure to enable this functionality? (Select TWO)
sequenceDiagram participant UserDevice as User Device (GSA Client) participant GSA as Global Secure Access participant Connector as Private Network Connector participant InternalApp as Internal Web App UserDevice->>GSA: 1. Traffic for internal.app.com GSA->>Connector: 2. Forward request via tunnel Connector->>InternalApp: 3. Request resource InternalApp-->>Connector: 4. Response Connector-->>GSA: 5. Return response GSA-->>UserDevice: 6. Deliver contentShow answer & explanation
Correct answers: B, D
Private Network Connectors are lightweight agents installed on-premises that create a secure outbound tunnel to the Global Secure Access service. They are essential for relaying traffic from the cloud service to the internal applications.
You must define the internal application within the Private Access configuration. This involves creating a new enterprise application segment, specifying the FQDNs or IP addresses of the internal app, and assigning it to the appropriate connector group.
Ready for the real thing?
The full SC-300 simulator has every exam-style question, timed mode, and instant scoring.