dc dotCreds
Microsoft Identity and Access Administrator

SC-300 Practice Test

Start today’s free 10-question SC-300 set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 12, 2026, 3:38 PM CDT

Go Pro - One Time Unlock

Unlock the full SC-300 bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 SC-300 questions

Use this SC-300 practice test to review Microsoft Identity and Access Administrator. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Implement cross-tenant access and synchronization Implement and manage user identities

A parent company wants employee B2B objects automatically created, updated, and removed in a subsidiary tenant as source identities change. Which capability should be configured?

Concept tested:
Question 2 of 10
Objective Plan, implement, and manage access reviews Plan and automate identity governance

Reviewers face hundreds of access decisions and want inactivity information to help prioritize questionable assignments, but the business owner must retain the final decision. What should the administrator enable?

Concept tested:
Question 3 of 10
Objective Create and manage users, groups, bulk operations, and licenses Implement and manage user identities

Every member of the Sales group should automatically receive the same Microsoft product license configuration, including future members. What should the administrator configure?

Concept tested:
Question 4 of 10
Objective Plan and implement privileged access with PIM Plan and automate identity governance

A database administrator needs a privileged Microsoft Entra role only during occasional maintenance. The user should have no role privileges until initiating an activation. Which PIM assignment type should be used?

Concept tested:
Question 5 of 10
Objective Implement and manage hybrid identity Implement and manage user identities

Domain users on supported corporate devices and networks encounter repeated cloud sign-in prompts. The organization wants to reduce those prompts without changing the underlying authentication method. What should be enabled?

Concept tested:
Question 6 of 10
Objective Implement Conditional Access App Control and app policies Plan and implement workload identities

Contractors may use a sensitive cloud application from unmanaged devices in a browser, but downloads must be blocked while other in-session work remains available. Which design meets both requirements?

Concept tested:
Question 7 of 10
Objective Plan and implement managed identities for Azure workloads Plan and implement workload identities

A new virtual machine is assigned an existing user-assigned managed identity used by a storage-access workload, but requests to the storage account return authorization failures. The identity is attached successfully and no secret may be introduced. What should the administrator verify or change?

Concept tested:
Question 8 of 10
Objective Manage identity risk with Microsoft Entra ID Protection Implement authentication and access management

Microsoft Entra ID Protection repeatedly flags a user's identity after leaked credentials are detected, even when the user's latest sign-in originates from a familiar office location. Which risk should the administrator use to evaluate the likelihood that the identity itself is compromised?

Concept tested:
Question 9 of 10
Objective Plan and implement privileged access with PIM Plan and automate identity governance

Before an eligible user activates a high-impact Microsoft Entra role, a named security manager must explicitly authorize the use. Which PIM requirement implements that human authorization gate?

Concept tested:
Question 10 of 10
Objective Plan and implement entitlement management Plan and automate identity governance

A researcher's access-package assignment expires next week, but the project has been renewed. Governance wants the researcher to request continued access before the current assignment ends. Which option should be enabled?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
SC-300 Pro $4.99 one-time

Best if you only need this one certification.

50 Exam Practice Test $1.99 one-time

A 50-question SC-300 PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

Microsoft Security Bundle $9.99 one-time

Unlock all 6 active Microsoft Security Bundle practice banks in one permanent purchase.

What’s includedSC-900, SC-200, SC-300, SC-401, SC-500, SC-100
All Access $6.99/month

Unlock every active practice exam, bundle and path experience, Pro course and study content, and included downloads.

What’s includedEvery current and future active practice exam, All active bundle and career-path practice content, Pro course lessons, study content, and supported paid downloads

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full SC-300 bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily SC-300 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily SC-300 set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 A parent company wants employee B2B objects automatically created, updated, and removed in a subsidiary tenant as source identities change. Which capability should be configured?

Answer choices

  1. A. Company branding, for the stated security, delivery, and accountability requirements.
  2. B. Application Proxy, within the defined security and accountability boundaries.
  3. C. A manual annual CSV import, as selected.
  4. D. Cross-tenant synchronization, for the required implement and manage user identities outcome.

Correct answer

Cross-tenant synchronization, for the required implement and manage user identities outcome.

Cross-tenant synchronization automates creation, update, and removal of B2B collaboration users in a target Microsoft Entra tenant. Manual imports cannot provide the required ongoing lifecycle response.

Wrong-answer review

  • A. Company branding, for the stated security, delivery, and accountability requirements.: Branding changes sign-in presentation and cannot provision external identities.
  • B. Application Proxy, within the defined security and accountability boundaries.: Application Proxy publishes on-premises web apps rather than synchronize B2B user objects.
  • C. A manual annual CSV import, as selected.: An annual import is neither automatic nor responsive to source identity changes.

Extra learning features

Interview question

Q: A parent company wants employee B2B objects automatically created, updated, and removed in a subsidiary tenant as source identities change. Describe the process and considerations for achieving this. Strong answer: Cross-tenant synchronization automates creation, update, and removal of B2B collaboration users in a target Microsoft Entra tenant. Manual imports cannot provide the required ongoing lifecycle response. Consider the impact on existing B2B relationships, potential conflicts with other synchronization processes, and the need for appropriate permissions and trust relationships between tenants.

  • lifecycle automation
  • B2B user lifecycle
  • target tenant
  • ongoing response
  • permissions and trust

Caution: Do not restate the multiple-choice stem or ask the learner merely to name a product, rule, or term.

Why this matters

Incorrectly configuring cross-tenant synchronization can lead to inconsistent B2B user data across tenants, potentially disrupting business processes and creating security vulnerabilities. This impacts data integrity and operational efficiency.

Objective/domain: Implement and manage user identities

Source: Cross-tenant access overview

Question 2 Reviewers face hundreds of access decisions and want inactivity information to help prioritize questionable assignments, but the business owner must retain the final decision. What should the administrator enable?

Answer choices

  1. A. Automatic approval of every active user, for the specified implementation requirement.
  2. B. A no-response action before the review starts, within the defined security and accountability boundaries.
  3. C. Supported decision recommendations based on signals such as inactivity, for this decision.
  4. D. Deletion of every assignment without recent sign-in activity, as described.

Correct answer

Supported decision recommendations based on signals such as inactivity, for this decision.

Objective/domain: Plan and automate identity governance

Source: Plan a Microsoft Entra access reviews deployment

Question 3 Every member of the Sales group should automatically receive the same Microsoft product license configuration, including future members. What should the administrator configure?

Answer choices

  1. A. Assign the product licenses to the Sales group, within the described operational context.
  2. B. Assign an administrative unit to each member, when applied.
  3. C. Create one guest account to hold all licenses, in this situation.
  4. D. Edit every current and future member individually, as the primary proposed approach.

Correct answer

Assign the product licenses to the Sales group, within the described operational context.

Objective/domain: Implement and manage user identities

Source: Assign or unassign licenses to a group in the Microsoft 365 admin center

Question 4 A database administrator needs a privileged Microsoft Entra role only during occasional maintenance. The user should have no role privileges until initiating an activation. Which PIM assignment type should be used?

Answer choices

  1. A. A permanently active assignment, for the stated implementation and support requirements.
  2. B. An Azure subscription Owner assignment outside PIM, for this task.
  3. C. An eligible assignment, within the proposed design.
  4. D. A guest invitation with no role assignment, as selected.

Correct answer

An eligible assignment, within the proposed design.

Objective/domain: Plan and automate identity governance

Source: Plan a Privileged Identity Management deployment

Question 5 Domain users on supported corporate devices and networks encounter repeated cloud sign-in prompts. The organization wants to reduce those prompts without changing the underlying authentication method. What should be enabled?

Answer choices

  1. A. Seamless single sign-on, for the required outcome.
  2. B. A new federation outage, as proposed.
  3. C. An access review, for the described technical objective.
  4. D. Application Proxy passthrough, within the defined security and accountability boundaries.

Correct answer

Seamless single sign-on, for the required outcome.

Objective/domain: Implement and manage user identities

Source: Microsoft Entra Connect user sign-in options

Question 6 Contractors may use a sensitive cloud application from unmanaged devices in a browser, but downloads must be blocked while other in-session work remains available. Which design meets both requirements?

Answer choices

  1. A. Use an access policy to block the application before entry, for the described technical objective and its associated operational control requirements, in practice.
  2. B. Route matching sessions through Conditional Access App Control and apply a session policy that blocks downloads, for this scenario.
  3. C. Use an application-enforced restriction without routing the session to Defender for Cloud Apps, for the stated implementation and support requirements.
  4. D. Allow the session and rely on Identity Protection user risk, under the documented operational and governance requirements.

Correct answer

Route matching sessions through Conditional Access App Control and apply a session policy that blocks downloads, for this scenario.

Objective/domain: Plan and implement workload identities

Source: Use Defender for Cloud Apps Conditional Access app control

Question 7 A new virtual machine is assigned an existing user-assigned managed identity used by a storage-access workload, but requests to the storage account return authorization failures. The identity is attached successfully and no secret may be introduced. What should the administrator verify or change?

Answer choices

  1. A. Create a system-assigned identity and grant permissions to that different identity, for the required business outcome.
  2. B. Grant the user-assigned identity’s service principal the required storage RBAC role, then retest the workload
  3. C. Place a client secret in the virtual machine configuration, within the documented operational, security, ownership, and validation requirements.
  4. D. Grant every virtual-machine administrator Owner access to the storage account, under the documented operational and governance requirements.

Correct answer

Grant the user-assigned identity’s service principal the required storage RBAC role, then retest the workload

Objective/domain: Plan and implement workload identities

Source: Managed identities for Azure resources

Question 8 Microsoft Entra ID Protection repeatedly flags a user's identity after leaked credentials are detected, even when the user's latest sign-in originates from a familiar office location. Which risk should the administrator use to evaluate the likelihood that the identity itself is compromised?

Answer choices

  1. A. User risk, as the primary proposed approach.
  2. B. Sign-in risk, under the documented operational and governance requirements.
  3. C. Application risk, as selected.
  4. D. Device compliance risk, as selected.

Correct answer

User risk, as the primary proposed approach.

Objective/domain: Implement authentication and access management

Source: Microsoft Entra ID Protection risk-based access policies

Question 9 Before an eligible user activates a high-impact Microsoft Entra role, a named security manager must explicitly authorize the use. Which PIM requirement implements that human authorization gate?

Answer choices

  1. A. Notification after activation, as the recommended response to this scenario.
  2. B. MFA at activation, for the described technical objective.
  3. C. Approval for activation, for the stated requirement.
  4. D. A justification field with no reviewer

Correct answer

Approval for activation, for the stated requirement.

Objective/domain: Plan and automate identity governance

Source: Plan a Privileged Identity Management deployment

Question 10 A researcher's access-package assignment expires next week, but the project has been renewed. Governance wants the researcher to request continued access before the current assignment ends. Which option should be enabled?

Answer choices

  1. A. Permanent assignment with no review, within this context.
  2. B. Automatic deletion of the access package, in the described situation.
  3. C. Assignment extensions, for the affected environment.
  4. D. A Conditional Access block, as the recommended response to this scenario.

Correct answer

Assignment extensions, for the affected environment.

Objective/domain: Plan and automate identity governance

Source: What is entitlement management?

Where to go after the daily web set

How are SC-300 questions generated?

dotCreds builds SC-300 practice questions from public exam objectives and Microsoft Learn and exam-objective references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start SC-300 practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.