Microsoft Identity and Access Administrator (SC-300) Exam Blueprint

SC-300

40Questions
100 minDuration
700/1-1000Passing Score
$165Price
12Languages
Practice Microsoft Identity and Access Administrator on QuizForge

Exam Domains

1.0 Implement and manage user identities (20–25%) 22%
  • 1.1Configure and manage a Microsoft Entra tenant
  • 1.2Configure and manage built-in and custom Microsoft Entra roles
  • 1.3Recommend when to use administrative units
  • 1.4Configure and manage administrative units
  • 1.5Evaluate effective permissions for Microsoft Entra roles
  • 1.6Configure and manage domains in Microsoft Entra ID and Microsoft 365
  • 1.7Configure Company branding settings
  • 1.8Configure tenant properties, user settings, group settings, and device settings
  • 1.9Create, configure, and manage Microsoft Entra identities
  • 1.10Create, configure, and manage users
  • 1.11Create, configure, and manage groups
  • 1.12Manage custom security attributes
  • 1.13Automate bulk operations by using the Microsoft Entra admin center and PowerShell
  • 1.14Manage device join and device registration in Microsoft Entra ID
  • 1.15Assign, modify, and report on licenses
  • 1.16Implement and manage identities for external users and tenants
  • 1.17Manage External collaboration settings in Microsoft Entra ID
  • 1.18Invite external users, individually or in bulk
  • 1.19Manage external user accounts in Microsoft Entra ID
  • 1.20Implement Cross-tenant access settings
  • 1.21Implement and manage cross-tenant synchronization
  • 1.22Configure external identity providers, including protocols such as SAML and WS-Fed
2.0 Implement authentication and access management (25–30%) 28%
  • 2.1Plan, implement, and manage Microsoft Entra user authentication
  • 2.2Implement and manage authentication methods, including certificate-based authentication, Temporary Access Pass, OAuth 2.0 tokens, Microsoft Authenticator, and passkeys (FIDO2)
  • 2.3Implement and manage tenant-wide multifactor authentication (MFA) settings
  • 2.4Configure and deploy self-service password reset (SSPR)
  • 2.5Implement and manage Windows Hello for Business
  • 2.6Disable accounts and revoke user sessions
  • 2.7Implement and manage Microsoft Entra password protection
  • 2.8Enable Microsoft Entra Kerberos authentication for hybrid identities
  • 2.9Plan, implement, and manage Microsoft Entra Conditional Access
  • 2.10Plan Conditional Access policies
  • 2.11Implement Conditional Access policy assignments
  • 2.12Implement Conditional Access policy controls
  • 2.13Test and troubleshoot Conditional Access policies
  • 2.14Implement session management
  • 2.15Implement device-enforced restrictions
  • 2.16Implement continuous access evaluation
  • 2.17Configure authentication context
  • 2.18Implement protected actions
  • 2.19Create a Conditional Access policy from a template
  • 2.20Manage risk by using Microsoft Entra ID Protection
  • 2.21Implement and manage user risk by using Microsoft Entra ID Protection or Conditional Access policies
  • 2.22Implement and manage sign-in risk by using Microsoft Entra ID Protection or Conditional Access policies
  • 2.23Implement and manage multifactor authentication registration by using authentication methods and registration campaigns
  • 2.24Monitor, investigate and remediate risky users and risky sign-ins
  • 2.25Monitor, investigate, and remediate risky workload identities
  • 2.26Implement Global Secure Access
  • 2.27Deploy Global Secure Access clients
  • 2.28Deploy and manage Private Access
  • 2.29Deploy and manage Internet Access
  • 2.30Deploy and manage Internet Access for Microsoft 365
3.0 Plan and implement workload identities (20–25%) 22%
  • 3.1Plan and implement identities for applications and Azure workloads
  • 3.2Select appropriate identities for applications and Azure workloads, including managed identities, service principals, user accounts, and managed service accounts
  • 3.3Create managed identities
  • 3.4Assign a managed identity to an Azure resource
  • 3.5Use a managed identity assigned to an Azure resource to access other Azure resources
  • 3.6Plan, implement, and monitor the integration of enterprise applications
  • 3.7Plan and implement settings for enterprise applications, including application-level and tenant-level settings
  • 3.8Assign appropriate Microsoft Entra roles to users to manage enterprise applications
  • 3.9Design and implement integration for on-premises apps by using Microsoft Entra Application Proxy
  • 3.10Design and implement integration for software as a service (SaaS) apps
  • 3.11Assign, classify, and manage users, groups, and app roles for enterprise applications
  • 3.12Configure and manage user and admin consent
  • 3.13Create and manage application collections
  • 3.14Plan and implement app registrations
  • 3.15Plan for app registrations
  • 3.16Create app registrations
  • 3.17Configure app authentication
  • 3.18Configure API permissions
  • 3.19Create app roles
  • 3.20Manage and monitor app access by using Microsoft Defender for Cloud Apps
  • 3.21Configure and analyze cloud discovery results by using Defender for Cloud Apps
  • 3.22Configure connected apps
  • 3.23Implement application-enforced restrictions
  • 3.24Configure Conditional Access app control
  • 3.25Create access and session policies in Defender for Cloud Apps
  • 3.26Implement and manage policies for OAuth apps
  • 3.27Manage the Cloud app catalog
4.0 Plan and automate identity governance (20–25%) 22%
  • 4.1Plan and implement entitlement management in Microsoft Entra
  • 4.2Plan entitlements
  • 4.3Create and configure catalogs
  • 4.4Create and configure access packages
  • 4.5Manage access requests
  • 4.6Implement and manage terms of use (ToU)
  • 4.7Manage the lifecycle of external users
  • 4.8Configure and manage connected organizations
  • 4.9Plan, implement, and manage access reviews in Microsoft Entra
  • 4.10Plan for access reviews
  • 4.11Create and configure access reviews
  • 4.12Monitor access review activity
  • 4.13Manually respond to access review activity
  • 4.14Plan and implement privileged access
  • 4.15Plan and manage Microsoft Entra roles in Microsoft Entra Privileged Identity Management (PIM), including settings and assignments
  • 4.16Plan and manage Azure resources in PIM, including settings and assignments
  • 4.17Plan and configure PIM for Groups
  • 4.18Manage the PIM request and approval process
  • 4.19Analyze PIM audit history and reports
  • 4.20Create and manage break-glass accounts
  • 4.21Monitor identity activity by using logs, workbooks, and reports
  • 4.22Review and analyze sign-in, audit, and provisioning logs by using the Microsoft Entra admin center
  • 4.23Configure diagnostic settings, including configuring destinations such as Log Analytics workspaces, storage accounts, and Azure Event Hubs
  • 4.24Monitor Microsoft Entra ID by using KQL queries in Log Analytics
  • 4.25Analyze Microsoft Entra ID by using workbooks and reporting
  • 4.26Monitor and improve the security posture by using Identity Secure Score

Exam Details

Question TypesMultiple Choice, Multiple Response, Drag and Drop, Case Study, Build List, Hot Area, Repeated Answer Choices
FormatLinear
Online ProctoringAvailable
ID RequirementsOne valid, government-issued photo ID. Name on ID must match registration. For online: webcam required, room must be clear of people and materials.
RenewalRequired -- Microsoft certifications (Associate/Expert/Specialty) are renewed annually for free via a short renewal assessment on Microsoft Learn. Renewal assessment available 6 months before expiry. Fundamentals certifications do not expire.
Retake PolicyNo waiting period for first retake if score >= 500 on failed attempt. If score < 500: 14-day waiting period before retake. Maximum 5 attempts per exam per year (365 days). Free retake voucher sometimes included in official instructor-led training.
LanguagesEnglish, Simplified Chinese, Traditional Chinese, French, German, Japanese, Korean, Portuguese, Russian, Spanish, Arabic, Indonesian

Official Study Resources