20 free SC-300 practice questions with answers and explanations, covering Microsoft Entra user identities, authentication and Conditional Access, workload identities and identity governance.
Study the full SC-300 course, free to start.
Official SC-300 study guide on Microsoft Learn
Question 1. An administrator is retiring the domain oldbrand.com and the delete fails. There are roughly 300 users and 40 groups still carrying oldbrand.com addresses, and one of the applications with a matching app ID URI is registered as multitenant. What is the correct assessment?
Answer: C, ForceDelete cannot complete here, because it fails when one of the applications to be renamed is multitenant; that application must be dealt with first. ForceDelete renames user principal names, email and proxy addresses, group addresses and application identifier URIs to the initial onmicrosoft.com domain, and 340 objects is comfortably inside the 1,000 reference limit. The blocker is the multitenant application: ForceDelete returns an error when one of the applications to be renamed is multitenant. Making a domain non-primary does not remove references, and references do not expire on their own.
Question 2. Contractors joining the Facilities department should receive an Enterprise Mobility and Security licence on their first day and lose it automatically when they move on, with no ticket raised either way. Which configuration achieves that?
Answer: B, Create a security group with a membership rule over the department attribute and assign the product licence to that group. Group-based licensing assigns a product to a group and Microsoft Entra ID licenses every member automatically, removing licences again when membership ends, usually within minutes. Pairing it with a dynamic membership rule over the department attribute makes the membership self-maintaining, so neither joining nor leaving needs a ticket. Direct assignment is exactly the per-user work the feature exists to remove. An assigned group still needs somebody to add and remove members. Licences are not assigned to administrative units.
Question 3. An organisation wants leavers deprovisioned from Microsoft Entra ID automatically when HR marks them as terminated, but its HR platform is custom-built and exposes no SCIM endpoint. What is the supported approach?
Answer: B, Use API-driven inbound provisioning, with a script or automation tool reading from the HR system and posting the data to the Microsoft Entra provisioning API. API-driven inbound provisioning exists for authoritative sources that cannot push over SCIM. Any automation tool retrieves workforce data from the system of record and sends it to the Microsoft Entra provisioning API, which drives creation, update and deprovisioning. It reached general availability in March 2024. Nightly bulk deletes are manual and lag the HR event. Inbound application provisioning is built on SCIM, which is the constraint here. Cross-tenant synchronisation provisions B2B users between Microsoft Entra tenants of the same organisation and has nothing to do with an HR source.
Question 4. Two organisations want their staff to work together in a Microsoft Teams shared channel without guest accounts appearing in either directory. Your tenant has enabled outbound B2B direct connect for the partner, but the shared channel invitation still fails. What is missing?
Answer: B, The partner organisation has to enable inbound B2B direct connect for your tenant, because it requires a mutual trust relationship. B2B direct connect requires a mutual trust relationship: both the resource organisation and the external organisation must enable it in their own cross-tenant access settings, and it is blocked by default on both sides. Once the trust exists the external user reaches the shared channel from their own home tenant instance of Teams. Cross-tenant synchronisation creates B2B collaboration user objects, which is the opposite of what this scenario wants. Email one-time passcode is a B2B collaboration redemption fallback, and collaboration restrictions govern invitations rather than direct connect.
Question 5. An organisation is retiring AD FS in favour of password hash synchronisation. It wants a pilot of 150 users on cloud authentication for two weeks, with everyone else still going through AD FS, before it commits. What is the correct approach?
Answer: B, Enable staged rollout for password hash synchronisation and seamless single sign-on, add a cloud-only security group containing the pilot users, then convert the domains and turn staged rollout off. Staged rollout is designed for exactly this: selectively testing cloud authentication with groups of users while the domain remains federated, then cutting the domains over and switching the feature off. Groups must be cloud-only, nested and dynamic membership groups are not supported, and Microsoft advises keeping them to around 200 members initially to avoid timeouts, so 150 is comfortable. Password hash synchronisation combined with pass-through authentication in staged rollout is explicitly not supported. Converting the domain first removes the fallback the pilot exists to preserve, and renaming user principal name suffixes is disruptive and unnecessary.
Question 6. Most users have registered Microsoft Authenticator but only ever type the six-digit code, and the service desk wants them to be able to approve push notifications instead because typing codes is generating support calls. What is the correct change in the Authentication methods policy?
Answer: C, Set the Microsoft Authenticator authentication mode to Any or Push, and have the affected users add a push registration in Security info. Authentication mode Any permits both push notifications and passwordless phone sign-in, and Push permits push only; either allows the behaviour the service desk wants. Passwordless mode restricts the app to phone sign-in and also makes those accounts ineligible for a push registration nudge, so it is the wrong direction. Third party software OATH tokens governs other authenticator applications rather than Microsoft Authenticator, and it produces codes, not notifications. Hardware OATH tokens are physical devices and cannot send anything. Note that the registration itself is per method, so users who registered only for codes have to add the push registration.
Question 7. A tenant on Microsoft Entra ID Free needs a basic level of protection today while a licensing case is prepared. Which statement correctly describes what the identity administrator can and cannot do?
Answer: B, Security defaults can be enabled at no cost, but they offer no exclusions, no per-application targeting and no report-only mode. There is no Conditional Access at all on Microsoft Entra ID Free or on a free Office 365 subscription, including report-only mode, so the first and last options are wrong. Security defaults are available to every tenant at no cost, but they are deliberately all or nothing: no exclusions, no application targeting, no report-only. That is precisely why an organisation with service accounts that cannot perform multifactor authentication, or with complex requirements, is told to move to Conditional Access instead.
Question 8. A review shows that a handful of accounts are still reaching Exchange Online over IMAP4 and SMTP without any multifactor authentication prompt, despite a policy requiring multifactor authentication for all users and all resources. What is the correct explanation and fix?
Answer: C, Legacy authentication clients pass no device state and cannot perform multifactor authentication, so a policy is needed with the client apps condition set to Exchange ActiveSync clients and Other clients, granting Block access. Legacy authentication protocols do not support multifactor authentication, so a grant control requiring it simply blocks them, which is the intended outcome, but only where the policy actually evaluates those clients. Writing an explicit block policy with the client apps condition set to the two legacy categories, which include SMTP, IMAP4, POP3, MAPI over HTTP, Exchange Web Services and Exchange Online PowerShell, is the documented approach and matches the Block legacy authentication template. App passwords are worth revoking but are a separate legacy feature and would not by themselves explain protocol-level access. Sign-in frequency does not change protocol support. IMAP4 and SMTP are protocols, not service principals.
Question 9. An organisation with Microsoft Entra ID P2 wants any account whose credentials appear in a known breach to be forced through a secure password change. The identity administrator writes a Conditional Access policy with the user risk condition set to high, the grant control Require password change, and also selects Require device to be marked as compliant so that the change happens on a managed machine. The policy will not save. Why?
Answer: A, Require password change cannot be combined with any other grant control, and the policy must target All resources. The password change control has three documented constraints: the policy must be assigned to All resources, so that an attacker cannot reset the account's risk by signing in to some other application; it cannot be used with other controls such as a compliant device requirement; and it only works with the user and group assignment, an all-resources cloud app assignment and user risk conditions. Require password change is available in Conditional Access as well as in ID Protection. User risk is a standard Conditional Access condition and works with grant controls. Require risk remediation is the newer alternative for passwordless users, but it is a choice rather than a requirement.
Question 10. A school needs to block gambling and adult content for pupils but not for staff, on both school-owned laptops and staff Macs, without buying a separate web filtering appliance. Which configuration delivers this?
Answer: A, Create web content filtering policies for the categories, group them into a security profile, and link the profile to a Conditional Access policy assigned to the pupils group. Web content filtering in Microsoft Entra Internet Access is exactly this capability, and the identity-aware part comes from grouping filtering policies into a security profile and linking that profile to a Conditional Access policy assigned to a particular group, so pupils and staff can get different profiles. Clients exist for Windows and macOS, so both device types are covered. Named locations describe where a sign-in comes from, not which websites a user may visit. The Microsoft traffic profile carries Microsoft service traffic and Bypass simply stops acquiring it. Tenant restrictions govern signing in with external accounts, not web browsing.
Question 11. A Global Administrator reports that they can see every subscription in the tenant but cannot create a resource group in any of them. What should the identity administrator explain?
Answer: C, Microsoft Entra roles and Azure RBAC are separate authorisation systems, so an Azure role assignment such as Contributor is needed at the right scope. Microsoft Entra roles grant permissions over directory objects, and Azure RBAC grants permissions over Azure resources through Azure Resource Manager. The two do not overlap by default, which is why a Global Administrator holds no rights over a subscription until somebody creates an Azure role assignment naming them. Privileged Identity Management changes when a role is active, not what it covers, and Privileged Role Administrator is another directory role. Deny assignments do exist and are evaluated before role assignments, but you cannot create or delete them yourself, so removing one is not an option available to an administrator.
Question 12. A software as a service application will be used by around 400 people whose membership changes weekly as staff move between departments, and the application requires assignment. What is the least effort way to keep the assignment list correct?
Answer: B, Assign a dynamic membership group whose rule matches the department attribute, which needs Microsoft Entra ID P1. Group-based assignment requires Microsoft Entra ID P1 or P2, and pairing it with a dynamic membership group means the application population maintains itself from user attributes with no ticket when somebody moves department. Nested group membership is not supported for group-based assignment to applications, so assigning a parent group grants access to its direct members only, which is the trap in the third option. Individual assignment works on any licence but is exactly the manual effort the question is trying to remove, and Conditional Access decides the conditions of access rather than entitlement, so it is the wrong control for the requirement.
Question 13. A tenant has Users can register applications set to No. Three developers need to create and update their own app registrations, and the security team will not grant any role that can manage enterprise applications. Which role should be assigned?
Answer: A, Application Developer. Application Developer exists for exactly this case: it can create and update app registrations even when the tenant setting blocks members from registering applications, and the holder is added as owner of what they create, so they can manage it afterwards. It cannot manage enterprise applications or application proxy, which is what the security team asked for. Cloud Application Administrator and Application Administrator both manage all enterprise applications and can consent on the tenant's behalf, so both are too broad. Directory Writers can update extension properties but is not the registration role.
Question 14. A policy must let people open documents in the browser, but any download of a file the classification service identifies as containing bank details should arrive as a labelled, encrypted copy instead of being blocked. Which session control type and action combination does that?
Answer: C, Session control type Control file download (with inspection), with the action Protect and a Microsoft Purview sensitivity label. Protect is available only when the session control type is Control file download (with inspection), and it applies a Microsoft Purview sensitivity label with its encryption and permissions to the downloaded copy while leaving the original in the cloud app untouched. The sensitivity label has to be configured in Microsoft Purview to apply encryption before it appears as an option, and the supported file types are Word, Excel, PowerPoint and PDF. Monitor only watches the login activity alone, Block activities is for actions such as print and copy rather than for transforming a download, and an upload policy addresses the opposite direction of travel.
Question 15. A session policy that blocks downloads works in Chrome and Microsoft Edge but has no effect for people using the Microsoft Teams desktop application. What is the correct response?
Answer: D, The Teams desktop application is not supported for session controls, so use an access control that prevents sign-in from the desktop client while allowing browser access. Microsoft states that the Microsoft Teams desktop application is not supported for Conditional Access App Control session controls, and that if desktop access is allowed users may still download content through it even when browser session controls are configured. The supported approach is to prevent sign-in from the desktop application for the targeted users while allowing browser access, where the session controls can be enforced, and then to validate the behaviour in both clients. Onboarding does not extend session control to an unsupported client, application-enforced restrictions would not give the granular download control being asked for, and the reverse proxy is a browser mechanism, so disabling in-browser protection changes nothing for a desktop client.
Question 16. A request policy uses Manager as approver for internal staff. During a pilot, several requests sit unactioned and then automatically deny. The identity administrator confirms the requestors are in scope and the approval window is 14 days. What should they check first?
Answer: D, Whether a fallback approver is configured and whether the requestors have the Manager attribute populated. Entitlement management resolves the approver from the Manager attribute on the requestor's Microsoft Entra profile. When that attribute is empty the request goes to the fallback approver instead, and if no fallback is configured there is nobody to act, so the request sits until the decision window closes and is denied automatically. A missing justification blocks submission rather than causing a silent denial later. Hidden only controls whether requestors can discover the package. Adding a second stage would add another approval to a workflow whose first stage already has nobody in it.
Question 17. A partner firm has no Microsoft Entra tenant and no federation with your organisation, but every member of its staff has an email address at fabrikam.example. You want them to be able to request one access package. How should the connected organisation be defined?
Answer: B, By the shared domain name, so that identities with an email address at that domain are in scope. Entitlement management accepts three definitions of a connected organisation, and the third exists for precisely this case: identities in a non-Entra directory whose email addresses all share one domain name. Direct federation would require the partner to run an identity provider and for you to configure federation with it, which is not the situation described. There is no requirement for a partner to hold a Microsoft Entra tenant, and a connected organisation holds exactly one directory or domain, so the domain-name definition is both sufficient and the only one that fits.
Question 18. A recurring review of guest accounts should remove access when a guest is denied, and should also stop that guest signing in to the tenant at all, while leaving a window in which an administrator can undo a mistake. Which setting delivers this?
Answer: C, Action to apply on denied guest users set to Block user from signing in for 30 days, then remove user from the tenant. The block-then-delete option is the only one that reaches beyond the reviewed resource: the guest is disabled immediately, can be restored by an administrator at any point in the 30 days, and is deleted from the tenant if nothing happens. Removing membership from the resource leaves the guest able to sign in and use anything else they hold. The no-response setting decides what happens to identities nobody reviewed, not what happens to identities who were actively denied. Scoping to Everyone actually removes the choice, because the denied-guest action is only configurable on reviews scoped to guests alone.
Question 19. A tier zero operations team needs just-in-time access to the Exchange Administrator, Teams Administrator, Search Administrator and Office Apps Administrator roles together, wants one request rather than four, and needs partner staff subject to stricter activation rules than employees. What should the identity administrator build?
Answer: D, Two role-assignable groups enabled in PIM for Groups, each made eligible for all four roles, with different activation policies on each group. This is the scenario PIM for Groups exists for: a role-assignable group made eligible for several Microsoft Entra roles turns four elevations into one, and building two groups over the same four roles lets you run a relaxed policy for trusted employees and a stricter one, for example requiring approval, for partners invited through B2B collaboration. A custom role is built from a preset permission list and cannot simply absorb four built-in roles. Role settings in PIM are defined per role and apply to every assignment of that role, so they cannot vary by person. An access package would grant the roles for a period rather than just in time.
Question 20. A security operations team already runs Splunk as its security information and event management system, and wants Microsoft Entra sign-in and audit activity in it. What should the identity administrator configure?
Answer: A, A diagnostic setting streaming the chosen log categories to an event hub, with the Splunk Add-on for Microsoft Cloud Services reading from it. The event hub is the documented route to a security information and event management system outside Azure, and Microsoft names Splunk, SumoLogic and ArcSight as supported, with IBM QRadar and custom consumers built on the Event Hubs API as further options. On the Splunk side the Add-on for Microsoft Cloud Services reads the event hub, or the events can be forwarded to the Splunk HTTP Event Collector by an Azure function triggered on new messages. A Log Analytics workspace is the right destination when the analysis happens in Azure Monitor or Microsoft Sentinel. A manual download is capped at 250,000 records and bounded by retention, so it is not a pipeline. Polling an archive storage account is neither supported nor timely.
It's an associate-level exam for people who run Microsoft Entra day to day. Conditional Access and Privileged Identity Management come up throughout, and many questions hinge on choosing the right setting for a scenario.
Most people studying part-time plan four to six weeks. If you already administer Entra at work, the material will feel familiar and you can move faster.
No. Microsoft exam questions are confidential, and sharing them breaks the agreement every candidate accepts. These are original questions written to the published skills outline, so they test the same knowledge in the same style.
You can enrol free with no card. Free accounts get the opening modules of every course; Pro (£9.99 a month, or £79.99 a year) unlocks every module, the full timed mock exam and an adaptive study plan.
Answer each one before you look at the explanation, and keep a list of the ones you get wrong. That list is your study plan: it's made of exactly the things you don't know yet.
CertBuddi is an independent study aid, not affiliated with or endorsed by Microsoft. These are original practice questions, not real exam questions.