CertSafari

    Free Microsoft Certified: Identity and Access Administrator Associate (SC-300) Sample Questions

    35 free sample questions from our bank of 340+, covering every exam domain, with answers and detailed explanations. Updated September 2026.

    Domain 1: Implement and manage user identities

    Subdomain 1.2: Create, configure, and manage Microsoft Entra identities

    1.Which built-in Microsoft Entra roles, at minimum, allow an administrator to assign licenses to a group using group-based licensing? Select all that apply.(Select 3)

    1. A.Groups Administrator
    2. B.License Administrator
    3. C.User Administrator
    4. D.Application Administrator
    5. E.Reports Reader
    Show answer & explanation

    Correct answers: A, B, CGroups Administrator; License Administrator; User Administrator

    • A. Groups Administrator is one of the roles listed as sufficient to assign licenses to a group through group-based licensing.
    • B. License Administrator is one of the roles listed as sufficient to assign licenses to a group through group-based licensing.
    • C. User Administrator is one of the roles listed as sufficient to assign licenses to a group through group-based licensing.
    • D. Application Administrator manages enterprise applications and app registrations, and it is not one of the roles documented as sufficient for group-based license assignment.
    • E. Reports Reader grants read-only access to usage and activity reports and does not include rights to assign licenses to a group.

    Subdomain 1.2: Create, configure, and manage Microsoft Entra identities

    2.An IT manager reports that after removing a user from a licensed group, the user immediately loses access to Exchange Online and Teams, and complains this is unexpected. Which explanation accounts for the correct, documented behavior?

    1. A.This is expected: group-based licensing unassigns the license as soon as the user is removed from the licensed group, so services can become unavailable immediately
    2. B.This indicates a misconfigured attribute set that must be repaired before removing users from licensed groups
    3. C.This indicates the group has exceeded the 20-group assignment limit and licenses are being revoked in error
    4. D.This indicates the user's Primary Refresh Token was revoked because the device fell out of hybrid join compliance
    Show answer & explanation

    Correct answer: AThis is expected: group-based licensing unassigns the license as soon as the user is removed from the licensed group, so services can become unavailable immediately

    • A. Removing a user from a licensed group triggers unassignment of that group's license, and until any other license source applies, the user loses access to the associated services, which matches the documented order-of-operations guidance for moving users between licensed groups.
    • B. Attribute sets relate to custom security attributes, not to group-based licensing, so a misconfigured attribute set would not cause this licensing behavior.
    • C. The 20-group limit governs how many groups can be assigned a subscription at once during assignment, not license removal behavior when a user leaves a group, so this is not the explanation.
    • D. Primary Refresh Tokens relate to device-based sign-in and Conditional Access evaluation, not to whether a Microsoft 365 license is assigned to a user, so this is unrelated to the described symptom.

    Subdomain 1.1: Configure and manage a Microsoft Entra tenant

    3.The Marketing administrative unit contains a security group called Marketing-All, but the individual users who belong to that group were never added to the administrative unit directly. An IT staff member holds the User Administrator role scoped to the Marketing administrative unit. What can this administrator do?

    1. A.Rename Marketing-All and change its group membership, but not reset the passwords of the individual users who belong to it
    2. B.Reset the passwords of every individual user who belongs to Marketing-All, since they are covered through the group
    3. C.Manage both the group properties and the authentication methods of every member of Marketing-All without restriction
    4. D.Perform no management actions at all, because a group cannot be placed inside an administrative unit
    Show answer & explanation

    Correct answer: ARename Marketing-All and change its group membership, but not reset the passwords of the individual users who belong to it

    • A. Adding a group to an administrative unit brings the group object itself into scope, so its name and membership can be managed, but the users who belong to the group remain out of scope unless separately added as direct members.
    • B. Administrative unit scope does not automatically extend to a group's members; those users must be added to the administrative unit directly before their passwords can be reset by a unit-scoped administrator.
    • C. Managing a member's authentication methods requires that member to be a direct administrative unit member, so an administrator scoped only through the group cannot manage those members' credentials.
    • D. Groups are a supported administrative unit member type, so placing Marketing-All inside the administrative unit is valid; the limitation is only on managing the individual members of that group.

    Subdomain 1.1: Configure and manage a Microsoft Entra tenant

    4.True or False: When a guest signs in to a resource using a personal Microsoft account, they see the resource tenant's custom company branding on the sign-in page.

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: BFalse

    • A. This is incorrect; company branding does not carry over to sign-ins performed with a personal Microsoft account, so the default Microsoft experience is shown instead.
    • B. This is correct; sign-in page branding is documented as not applying to personal Microsoft accounts, even when the resource tenant has custom branding configured.

    Subdomain 1.3: Implement and manage identities for external users and tenants

    5.Contoso's identity team wants to lock down who can send B2B collaboration invitations: only users holding the User Administrator role or the Guest Inviter role should be able to invite external users, and every other member and existing guest should be blocked from inviting anyone. Which guest invite setting satisfies this requirement?

    1. A.Any user, including existing guests, can send guest invitations
    2. B.Member users or users in specific admin roles can send guest invitations
    3. C.Only users assigned to specific admin roles can send guest invitations
    4. D.No user in the organization, including admins, can send guest invitations
    Show answer & explanation

    Correct answer: COnly users assigned to specific admin roles can send guest invitations

    • A. This is the most permissive guest invite setting and lets every member and existing guest send invitations, which does not restrict inviting to the two named admin roles.
    • B. This setting still allows ordinary member users without any admin role to invite guests, so it does not meet the requirement to limit invitations to User Administrator or Guest Inviter.
    • C. This setting restricts invitations to users assigned specific admin roles, and the Guest Inviter role exists precisely to grant this ability without assigning a broader administrator role, so User Administrator and Guest Inviter holders can still invite while everyone else is blocked.
    • D. This is the most restrictive setting and blocks every user, including administrators, from sending invitations at all, which would prevent even the intended admin roles from inviting guests.

    Subdomain 1.3: Implement and manage identities for external users and tenants

    6.An admin is reviewing the guest user access options available under External collaboration settings in the Microsoft Entra admin center. Which of the following are actual configurable levels of guest user access in that setting?(Select 3)

    1. A.Guest users have the same access as members
    2. B.Guest users have limited access to properties and memberships of directory objects
    3. C.Guest user access is restricted to properties and memberships of their own directory objects
    4. D.Guest users can only sign in during business hours defined by policy
    5. E.Guest users automatically inherit the role assignments of their inviter
    Show answer & explanation

    Correct answers: A, B, CGuest users have the same access as members; Guest users have limited access to properties and memberships of directory objects; Guest user access is restricted to properties and memberships of their own directory objects

    • A. This is the most inclusive guest user access level, giving guests the same visibility into Microsoft Entra resources and directory data that member users have.
    • B. This is the default guest user access level, which blocks guests from certain directory tasks like enumerating users or groups while still letting them see membership of non-hidden groups.
    • C. This is the most restrictive guest user access level, limiting a guest to viewing only their own profile and preventing them from seeing other users, groups, or group memberships.
    • D. There is no guest user access level that restricts sign-in to defined business hours; time-based sign-in restrictions are not part of this setting and would require a different Conditional Access construct.
    • E. Guest user access levels control directory visibility only; they do not grant guests any role assignments, and there is no mechanism that automatically copies the inviter's roles onto a guest.

    Subdomain 1.4: Implement and manage hybrid identity

    7.An administrator is preparing to move a tenant off AD FS and wants to test Microsoft Entra multifactor authentication, Conditional Access, and Identity Protection with a specific pilot group of users before any domain is converted from federated to managed. Which capability should the administrator use to run this pilot?

    1. A.Microsoft Entra Connect Health usage analytics
    2. B.Staged rollout
    3. C.Kerberos decryption key rollover
    4. D.Seamless SSO quick start
    Show answer & explanation

    Correct answer: BStaged rollout

    • A. Usage analytics reports on existing AD FS authentication traffic; it does not let a subset of users authenticate through a different, cloud-based sign-in method before cutover.
    • B. Staged rollout lets an administrator route a chosen group of users to cloud authentication features like MFA, Conditional Access, and Identity Protection while the domain is still federated, so behavior can be validated before the full cutover.
    • C. Kerberos decryption key rollover is an ongoing maintenance task for seamless single sign-on and has no role in piloting cloud authentication before a domain conversion.
    • D. The seamless SSO quick start configures automatic sign-in for domain-joined devices; it does not provide a mechanism to test a subset of users against cloud authentication ahead of a full federation cutover.

    Subdomain 1.4: Implement and manage hybrid identity

    8.Tenant Contoso uses pass-through authentication, and a user attempts to sign in as a guest into partner tenant Fabrikam, but the sign-in attempt fails. What happens to the failed sign-in's identity information in Fabrikam's sign-in logs?

    1. A.Fabrikam sees the log entry, but identifying attributes such as UPN are replaced with unresolved GUIDs because the user never consented to share identity data with Fabrikam
    2. B.Fabrikam receives no log entry at all for cross-tenant pass-through authentication failures
    3. C.Fabrikam sees the user's full UPN and other personal details regardless of whether the sign-in succeeded
    4. D.Contoso is notified to manually approve release of the user's identity details to Fabrikam before any log entry appears
    Show answer & explanation

    Correct answer: AFabrikam sees the log entry, but identifying attributes such as UPN are replaced with unresolved GUIDs because the user never consented to share identity data with Fabrikam

    • A. For a failed cross-tenant pass-through authentication attempt, Microsoft Entra ID publishes the sign-in log to both tenants but masks personally identifiable attributes like UPN with unresolved GUIDs in the resource tenant's log, since the user never consented to share their identity.
    • B. A sign-in log entry is still published to the resource tenant; it simply withholds identifying details rather than omitting the event entirely.
    • C. Full identity details are only exposed to the resource tenant once the user actually succeeds and becomes a B2B guest, not on a failed attempt.
    • D. There is no manual approval step from the home tenant for log visibility; the masking of personal data happens automatically based on sign-in outcome.

    Domain 2: Implement authentication and access management

    Subdomain 2.1: Plan, implement, and manage Microsoft Entra user authentication

    9.Which statement correctly describes Microsoft Authenticator passwordless sign-in via push notification?

    1. A.It functions as a primary authentication method, letting a user sign in by approving a notification instead of entering a password.
    2. B.It functions only as a secondary MFA challenge and can never replace the password as the first authentication factor.
    3. C.It requires the user to also possess a FIDO2 security key before Microsoft Entra ID will send the push notification.
    4. D.It requires the device to be Microsoft Entra hybrid joined before push notifications can be sent to Authenticator.
    Show answer & explanation

    Correct answer: AIt functions as a primary authentication method, letting a user sign in by approving a notification instead of entering a password.

    • A. Microsoft Authenticator passwordless sign-in via notification is listed as a primary authentication method, meaning it can serve as the first factor in place of a password.
    • B. This describes ordinary Authenticator push notifications used for MFA, but the passwordless variant is explicitly supported as a first-factor sign-in method, not just a secondary challenge.
    • C. Passwordless phone sign-in doesn't require a separate FIDO2 security key; the Authenticator app itself holds the credential used for sign-in.
    • D. Hybrid join isn't a prerequisite for passwordless phone sign-in; the method works based on the user's registration in Microsoft Entra ID regardless of that device join state.

    Subdomain 2.1: Plan, implement, and manage Microsoft Entra user authentication

    10.Contoso is a cloud-only organization with no on-premises Active Directory, and wants to block passwords containing its brand name and product names in addition to the default protections. Which licensing requirement applies to this scenario?

    1. A.Microsoft Entra ID P1 or P2
    2. B.Microsoft Entra ID Free
    3. C.No license is required
    4. D.Microsoft 365 E3 only
    Show answer & explanation

    Correct answer: AMicrosoft Entra ID P1 or P2

    • A. A custom banned password list for cloud-only users requires a Microsoft Entra ID P1 or P2 license, unlike the global banned password list which is included at no extra cost.
    • B. The free tier covers only the global banned password list; adding Contoso's own custom terms needs the paid P1 or P2 tier.
    • C. Some license is required specifically for the custom list feature for cloud-only users, even though the global list itself needs no license.
    • D. Microsoft 365 E3 licensing is a different product bundle and isn't the specific Microsoft Entra ID license tier that governs the custom banned password list feature.

    Subdomain 2.3: Manage risk by using Microsoft Entra ID Protection

    11.Which administrator role is the least privileged role required to create or edit Conditional Access policies, including risk-based policies?

    1. A.Conditional Access Administrator
    2. B.Security Administrator
    3. C.Security Reader
    4. D.Authentication Policy Administrator
    Show answer & explanation

    Correct answer: AConditional Access Administrator

    • Conditional Access Administrator. This is the least privileged role documented as required to create or edit Conditional Access policies, including risk-based sign-in and user risk policies.
    • Security Administrator. This role manages ID Protection settings such as the MFA registration policy, but it is not the role documented for creating or editing Conditional Access policies themselves.
    • Security Reader. This role only grants read access to risk reports and security settings, not the ability to create or edit Conditional Access policies.
    • Authentication Policy Administrator. This role manages the authentication methods policy, such as registration campaigns, but does not grant rights to create or edit Conditional Access policies.

    Subdomain 2.3: Manage risk by using Microsoft Entra ID Protection

    12.An administrator wants to run an MFA registration campaign that nudges users to set up Microsoft Authenticator for push notifications immediately after every successful MFA attempt, with no grace period before the next nudge. Which snoozeDurationInDays value achieves this?

    1. A.0
    2. B.1
    3. C.3
    4. D.14
    Show answer & explanation

    Correct answer: A0

    • 0. A value of zero means the user is nudged during every MFA attempt with no delay, which matches the requirement for no grace period between nudges.
    • 1. This is the default snooze value and still introduces a one-day gap before the next nudge, which does not meet the no-grace-period requirement.
    • 3. This value introduces a three-day gap between nudges, which is far from the immediate, every-attempt nudging the administrator wants.
    • 14. This is the maximum allowed snooze value and would nudge the user far less often than required, not immediately on every attempt.

    Subdomain 2.3: Manage risk by using Microsoft Entra ID Protection

    13.Which grant and session controls are available when configuring a sign-in risk-based Conditional Access policy? (Select all that apply.)(Select 3)

    1. A.Block access
    2. B.Require multifactor authentication
    3. C.Require reauthentication (sign-in frequency)
    4. D.Require risk remediation
    5. E.Require device compliance only
    Show answer & explanation

    Correct answers: A, B, CBlock access; Require multifactor authentication; Require reauthentication (sign-in frequency)

    • Block access. Blocking access is a documented control organizations can apply based on sign-in risk to stop an authentication request outright.
    • Require multifactor authentication. Requiring MFA is a core sign-in risk control, letting the user self-remediate the risky sign-in by proving their identity through a registered method.
    • Require reauthentication (sign-in frequency). Requiring sign-in frequency of every time is recommended alongside MFA for sign-in risk policies to force reauthentication for risky sign-ins.
    • Require risk remediation. This adaptive control is specific to user risk policies for handling both password and passwordless remediation, and it is not documented as a sign-in risk control.
    • Require device compliance only. Device compliance is a general Conditional Access control unrelated to the specific sign-in risk conditions and controls documented for ID Protection.

    Subdomain 2.2: Plan, implement, and manage Microsoft Entra Conditional Access

    14.Retail store staff share unmanaged kiosk computers to access a scheduling application through a browser. The security team wants every browser session on these kiosks to end completely when the browser window is closed, so the next employee cannot resume a previous employee's signed-in session. Which session control addresses this requirement?

    1. A.Persistent browser session set to Never persistent
    2. B.Sign-in frequency set to reauthenticate every time
    3. C.Customize continuous access evaluation set to disabled
    4. D.Require the device to be marked as compliant
    Show answer & explanation

    Correct answer: APersistent browser session set to Never persistent

    • A. Setting persistent browser session to never persistent ensures the browser does not retain the signed-in session token after the window closes, forcing the next person at that kiosk to authenticate from scratch.
    • B. Sign-in frequency forces reauthentication after a time period or on every access attempt, but a session can still remain active within the browser tab between closes if persistence is not also addressed, so it does not by itself guarantee the session ends when the window closes.
    • C. Disabling continuous access evaluation changes how fast policy and risk changes propagate to a resource provider; it says nothing about whether a browser retains a session after the window is closed.
    • D. Requiring a compliant device only lets Intune-managed devices satisfy the policy at all; unmanaged kiosk devices would simply be blocked, which does not address the goal of ending sessions when the browser closes.

    Subdomain 2.2: Plan, implement, and manage Microsoft Entra Conditional Access

    15.An organization allows employees to access SharePoint Online from personal, unmanaged devices but wants those sessions to automatically switch to a limited, view-only browser experience instead of full Office client functionality. Microsoft Entra ID needs to pass the device's managed or compliant state to SharePoint Online itself so the service can apply that limited experience. Which session control accomplishes this?

    1. A.Application enforced restrictions
    2. B.Conditional Access application control
    3. C.Sign-in frequency
    4. D.Require an approved client app
    Show answer & explanation

    Correct answer: AApplication enforced restrictions

    • A. Application enforced restrictions pass device signals like managed or compliant state directly to the cloud app, and SharePoint Online uses that signal to switch unmanaged sessions into its built-in limited, view-only experience.
    • B. Conditional Access application control routes traffic through a reverse proxy for real-time monitoring and blocking of actions like downloads, which is a different mechanism than passing device state for the app's own native limited-access mode.
    • C. Sign-in frequency only controls how often a user must reauthenticate over time; it has no role in telling SharePoint Online to render a restricted browser experience for unmanaged devices.
    • D. Requiring an approved client app restricts which mobile application can be used to reach data, but it does not configure the native limited SharePoint web experience for browser-based unmanaged access.

    Subdomain 2.4: Implement Global Secure Access

    16.Which three Internet Access traffic forwarding policies contain predefined rules that an administrator cannot modify? (Choose 3)(Select 3)

    1. A.Default Bypass
    2. B.Default Acquire
    3. C.Agentic Acquire
    4. D.Custom Bypass
    5. E.Custom Acquire
    Show answer & explanation

    Correct answers: A, B, CDefault Bypass; Default Acquire; Agentic Acquire

    • Default Bypass. Default Bypass contains predefined traffic, such as private IP ranges, that the Internet Access profile excludes, and its rules cannot be changed by an administrator.
    • Default Acquire. Default Acquire contains the predefined rule that acquires internet traffic on ports 80 and 443 over TCP, and it takes lowest precedence with rules that can't be edited.
    • Agentic Acquire. Agentic Acquire is a special policy that signals the client to acquire traffic from local AI agents such as Copilot CLI or Claude CLI, and its rules cannot be changed, only enabled or disabled.
    • Custom Bypass. Custom Bypass is explicitly user-defined: administrators add their own destinations and ports to exclude from the Internet Access profile.
    • Custom Acquire. Custom Acquire is explicitly user-defined: administrators specify their own IP addresses, subnets, or FQDNs to selectively acquire, often for side-by-side deployment with another SWG vendor.

    Subdomain 2.4: Implement Global Secure Access

    17.A security team wants to stop standard, non-admin users on managed Windows devices from disabling the Global Secure Access client, while still letting IT staff with local admin rights disable it during troubleshooting. Which configuration achieves this?

    1. A.Set `RestrictNonPrivilegedUsers` to `1` so a UAC prompt requires admin credentials to disable it
    2. B.Set `HideDisableButton` to `1` and leave `RestrictNonPrivilegedUsers` at its default value
    3. C.Set `IsPrivateAccessDisabledByUser` to `1` on every managed device in the fleet
    4. D.Remove the Sign out and Advanced diagnostics actions from the client's tray menu
    Show answer & explanation

    Correct answer: ASet `RestrictNonPrivilegedUsers` to `1` so a UAC prompt requires admin credentials to disable it

    • Set `RestrictNonPrivilegedUsers` to `1` so a UAC prompt requires admin credentials to disable it. Setting `RestrictNonPrivilegedUsers` to `1` restricts standard users from disabling or enabling the client and requires a UAC prompt with local administrator credentials to do so, matching exactly what the team needs.
    • Set `HideDisableButton` to `1` and leave `RestrictNonPrivilegedUsers` at its default value. Hiding the Disable button only removes it from view; without also restricting non-privileged users, other means of disabling the client remain available and no admin credential is enforced.
    • Set `IsPrivateAccessDisabledByUser` to `1` on every managed device in the fleet. This registry value disables the Private Access channel specifically and does not control whether users can disable the client as a whole, so it does not meet the requirement.
    • Remove the Sign out and Advanced diagnostics actions from the client's tray menu. Removing unrelated menu actions like Sign out or Advanced diagnostics has no bearing on the Disable action and does not require elevated credentials to disable the client.

    Domain 3: Plan and implement workload identities

    Subdomain 3.1: Plan and implement identities for applications and Azure workloads

    18.When an Azure virtual machine with a system-assigned managed identity is deleted, what happens to the associated Microsoft Entra service principal?

    1. A.It is automatically deleted, since it shares the virtual machine's lifecycle
    2. B.It remains in Microsoft Entra ID until an administrator removes it manually
    3. C.It converts automatically into a user-assigned managed identity for later reuse
    4. D.It is only disabled, while its existing role assignments remain intact indefinitely
    Show answer & explanation

    Correct answer: AIt is automatically deleted, since it shares the virtual machine's lifecycle

    • A. A system-assigned managed identity's service principal has a lifecycle tied directly to the resource it was enabled on, so Azure automatically removes the service principal when that resource is deleted.
    • B. Manual cleanup describes user-assigned managed identities, which have an independent lifecycle; a system-assigned identity does not linger after its resource is gone.
    • C. There is no automatic conversion between system-assigned and user-assigned identities; they are distinct identity types with different lifecycles.
    • D. The service principal is removed rather than merely disabled, so no leftover role assignments remain attached to it after the resource is deleted.

    Subdomain 3.1: Plan and implement identities for applications and Azure workloads

    19.An operations team runs a legacy batch job on an on-premises Windows server (not hosted in Azure) that must call Microsoft Graph unattended, and the job's certificate credential is rotated manually by the security team. Which identity is appropriate here?

    1. A.A system-assigned managed identity enabled directly on that on-premises server
    2. B.A service principal from an app registration, secured with the certificate
    3. C.A user-assigned managed identity directly attached to the on-premises server
    4. D.A managed identity as a federated credential trusted by the on-premises job
    Show answer & explanation

    Correct answer: BA service principal from an app registration, secured with the certificate

    • A. Managed identities can only be enabled on Azure compute or Azure-hosted platforms, so a server that lives entirely outside Azure cannot have a system-assigned managed identity.
    • B. An app registration's service principal can hold a certificate credential and authenticate from anywhere, including on-premises servers, which fits a workload that runs outside Azure.
    • C. Like system-assigned identities, user-assigned managed identities can only be attached to Azure resources, so they are not available to a server outside Azure.
    • D. Using a managed identity as a federated credential still requires the workload to run on Azure compute that holds the managed identity, which an on-premises server does not have.

    Subdomain 3.1: Plan and implement identities for applications and Azure workloads

    20.A Virtual Machine Scale Set frequently recycles individual instances, but every instance must retain the same consistent permissions to a shared Cosmos DB account. Which identity design meets this requirement?

    1. A.Enable a system-assigned managed identity on each new instance as it is created
    2. B.Assign one user-assigned managed identity that persists across the whole scale set
    3. C.Store a shared connection string with keys inside each instance's configuration
    4. D.Provision a brand-new Microsoft Entra user account each time an instance is recycled
    Show answer & explanation

    Correct answer: BAssign one user-assigned managed identity that persists across the whole scale set

    • A. A system-assigned identity is deleted along with the instance it belongs to, so recycled instances would each get a brand-new identity and permissions would need to be reassigned every time.
    • B. A user-assigned managed identity has an independent lifecycle and can be reattached to new instances as the scale set recycles them, so permissions granted once on Cosmos DB stay consistent.
    • C. Storing connection string keys inside instance configuration reintroduces credential management and rotation risk that managed identities are meant to avoid.
    • D. Creating a fresh interactive user account for every recycled instance is unmanageable at scale and mixes human sign-in identities with automated workload access.

    Subdomain 3.3: Plan and implement app registrations

    21.You are defining a custom app role on an app registration so that it can be granted to another application's service principal as an application permission, not just to individual users. Which Allowed member types setting must you choose for the role?

    1. A.Applications
    2. B.Users/Groups
    3. C.Both Users/Groups and Applications
    4. D.Managed identities only
    Show answer & explanation

    Correct answer: AApplications

    • A. Setting the allowed member type to applications makes the role appear as an application permission that another app registration's service principal, including a daemon service, can request under My APIs.
    • B. This setting only makes the role assignable to individual users and groups signing in interactively; it does not expose the role as an application permission for another app to request.
    • C. Choosing both member types is a valid app role configuration, but it is broader than what the scenario asks for and is not the minimal setting required specifically to expose the role to applications.
    • D. There is no member type option that restricts an app role to managed identities exclusively; managed identities are assigned roles as a service principal, which falls under the applications member type.

    Subdomain 3.3: Plan and implement app registrations

    22.Registering an application in Microsoft Entra ID establishes a bidirectional trust relationship, meaning the Microsoft identity platform also trusts the registering tenant by default.

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: BFalse

    • A. The trust established by app registration is unidirectional: the application trusts the Microsoft identity platform, not the reverse, so describing it as bidirectional is incorrect.
    • B. Registration establishes a one-way trust from the application to the Microsoft identity platform; the platform does not extend automatic trust back to the tenant simply because an app was registered there.

    Subdomain 3.2: Plan, implement, and monitor the integration of enterprise applications

    23.An application collection can be used to group related enterprise applications for organized display and delegated management, and the same application can be included in more than one collection.

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: ATrue

    • A. This is accurate: collections let administrators organize enterprise applications for purposes such as delegated management, and an individual application is not limited to membership in a single collection.
    • B. This would be incorrect: collections do support grouping applications for management purposes, and membership in one collection does not prevent an application from also belonging to another.

    Subdomain 3.2: Plan, implement, and monitor the integration of enterprise applications

    24.Which of the following are components of the Microsoft Entra Application Proxy architecture that participate in delivering a request to a published on-premises application? (Choose all that apply.)(Select 3)

    1. A.The private network connector running on an on-premises server
    2. B.The application proxy service running as part of Microsoft Entra ID
    3. C.Microsoft Entra ID acting as the identity provider for authentication
    4. D.An on-premises Active Directory Federation Services proxy server
    5. E.A VPN gateway appliance placed in the perimeter network
    Show answer & explanation

    Correct answers: A, B, CThe private network connector running on an on-premises server; The application proxy service running as part of Microsoft Entra ID; Microsoft Entra ID acting as the identity provider for authentication

    • A. The private network connector is a required component; it runs inside the internal network and forwards authenticated requests from the cloud service to the on-premises application using only outbound connections.
    • B. The application proxy service is a required cloud component; it accepts the incoming request from the client, extracts the token information, and passes the request to the connector.
    • C. Microsoft Entra ID is a required component; it performs the initial authentication and issues the token that the client presents to the application proxy service.
    • D. An AD FS proxy server is not part of the Application Proxy architecture; Application Proxy replaces the need for this kind of perimeter-network federation server rather than depending on one.
    • E. A VPN gateway is not part of the Application Proxy architecture; the connector uses only outbound connections over standard web ports, removing the need for a VPN appliance in the perimeter network.

    Subdomain 3.4: Manage and monitor app access by using Microsoft Defender for Cloud Apps

    25.Contoso needs to stop sensitive files from being downloaded out of OneDrive when a session originates from an unmanaged device, while leaving the rest of the browsing experience unrestricted. Which configuration meets this requirement?

    1. A.Create a session policy using the Control file download control type and block downloads for unmanaged devices
    2. B.Create an access policy that blocks OneDrive access entirely for sessions from unmanaged devices
    3. C.Create a Conditional Access policy that blocks OneDrive access outright for unmanaged devices
    4. D.Enable application-enforced restrictions in SharePoint Online to limit downloads for all devices
    Show answer & explanation

    Correct answer: ACreate a session policy using the Control file download control type and block downloads for unmanaged devices

    • A. A session policy with the Control file download control type keeps the session active while inspecting and selectively blocking specific downloads that match the policy's filters, which is exactly the granular, download-only restriction the scenario needs.
    • B. An access policy makes an all-or-nothing decision, so blocking OneDrive access for unmanaged devices would prevent normal browsing entirely rather than just restricting downloads.
    • C. A Conditional Access policy that blocks the app outright removes access completely, which goes further than the requirement to only restrict downloads while keeping the rest of the session usable.
    • D. Application-enforced restrictions apply device-based limits at the SharePoint Online/OneDrive service level for all devices uniformly, rather than providing the fine-grained, unmanaged-device-only download control described in the scenario.

    Subdomain 3.4: Manage and monitor app access by using Microsoft Defender for Cloud Apps

    26.Which of the following actions can a Defender for Cloud Apps access or session policy enforce during a Conditional Access App Control session? (Select 3)(Select 3)

    1. A.Block the download of sensitive files to unmanaged devices
    2. B.Block the upload of files flagged as malware by threat intelligence scanning
    3. C.Reevaluate Conditional Access claims through step-up authentication mid-session
    4. D.Automatically rotate the app registration's client secret on a schedule
    5. E.Reassign the connected app's owner to a different Microsoft Entra user
    6. F.Permanently remove the cloud app from the Cloud App Catalog
    Show answer & explanation

    Correct answers: A, B, CBlock the download of sensitive files to unmanaged devices; Block the upload of files flagged as malware by threat intelligence scanning; Reevaluate Conditional Access claims through step-up authentication mid-session

    • A. Preventing sensitive file downloads to unmanaged devices is one of the core data-exfiltration-prevention actions that access and session policies apply through Conditional Access App Control.
    • B. Blocking uploads of files identified as malware by threat intelligence scanning is a supported session policy action, used to stop malicious files from reaching a protected cloud app.
    • C. Redirecting the session back to Conditional Access for reevaluation of claims like multifactor authentication when a sensitive activity occurs is a documented session policy action.
    • D. Rotating an app registration's client secret is an app registration and credential management task performed in Microsoft Entra ID, not something an access or session policy enforces during a session.
    • E. Reassigning an app's owner is an administrative change made to the connected app's configuration, not an action that access or session policies apply to live sessions.
    • F. Removing an app from the catalog is a Cloud App Catalog administration action, not a real-time enforcement action available to access or session policies.

    Subdomain 3.4: Manage and monitor app access by using Microsoft Defender for Cloud Apps

    27.Which of the following are prerequisites for creating a Defender for Cloud Apps session policy that uses Conditional Access App Control? (Select 3)(Select 3)

    1. A.A Defender for Cloud Apps license
    2. B.A Microsoft Entra ID P1 license
    3. C.The target app onboarded to Conditional Access App Control
    4. D.Global Administrator role assigned to every policy author
    5. E.A third-party Secure Web Gateway license
    6. F.Defender for Endpoint deployed to every managed device
    Show answer & explanation

    Correct answers: A, B, CA Defender for Cloud Apps license; A Microsoft Entra ID P1 license; The target app onboarded to Conditional Access App Control

    • A. A Defender for Cloud Apps license, standalone or bundled, is a documented prerequisite for creating session policies.
    • B. A Microsoft Entra ID P1 license, standalone or bundled, is required alongside the Defender for Cloud Apps license before session policies can be configured.
    • C. The app must already be onboarded to Conditional Access App Control, automatically for Microsoft Entra ID apps or manually for other identity providers, before a session policy targeting it will work.
    • D. Creating session policies requires appropriate administrative permissions, but the documented prerequisites don't require every policy author to hold the tenant-wide Global Administrator role.
    • E. A Secure Web Gateway integration is an optional way to enhance cloud discovery, not a requirement for creating Conditional Access App Control session policies.
    • F. Defender for Endpoint integration is one optional method for continuous cloud discovery, not a prerequisite for configuring session policies through Conditional Access App Control.

    Domain 4: Plan and automate identity governance

    Subdomain 4.1: Plan and implement entitlement management in Microsoft Entra

    28.A compliance team requires that access to a finance access package be periodically re-certified so that assignments don't persist indefinitely without justification, on top of a fixed expiration date. What should be configured in the access package's lifecycle settings to meet this requirement?

    1. A.Set the expiration to Never and rely solely on manual removal by administrators when access is no longer needed
    2. B.Enable the Require an access review toggle on the lifecycle tab in addition to the expiration setting
    3. C.Disable the option that allows users to extend their access so that assignments cannot be renewed under any circumstance
    4. D.Add a second policy with a shorter expiration window and hide the access package from the catalog
    Show answer & explanation

    Correct answer: BEnable the Require an access review toggle on the lifecycle tab in addition to the expiration setting

    • A. Leaving expiration set to Never and depending on manual removal doesn't provide periodic re-certification, and it also contradicts the requirement for a fixed expiration.
    • B. Turning on the access review requirement on the lifecycle tab adds recurring re-certification of assignments alongside whatever expiration date is configured, which is exactly what periodic re-certification calls for.
    • C. Preventing extensions only affects whether users can renew access themselves; it doesn't introduce any periodic review of existing assignments.
    • D. Adding another policy with a different expiration changes who can request access and for how long, but it doesn't add a recertification mechanism to the existing assignments.

    Subdomain 4.1: Plan and implement entitlement management in Microsoft Entra

    29.Before an administrator can require terms of use acceptance for users who authenticate to access resources governed by entitlement management, what must first be prepared and uploaded in the Microsoft Entra admin center?

    1. A.A terms of use document in PDF format, added under Conditional Access with a display name
    2. B.A terms of use record embedded inside the access package's Requestor information tab as a question
    3. C.A signed Word document attached to the connected organization's Sponsors settings
    4. D.A custom claim added to the access package's resource attributes for the requestor's profile
    Show answer & explanation

    Correct answer: AA terms of use document in PDF format, added under Conditional Access with a display name

    • A. Terms of use documents are created under Conditional Access as PDF uploads with a user-facing display name, which is the prerequisite before any policy can enforce acceptance.
    • B. Requestor information questions collect free-text or multiple-choice answers from requestors; terms of use isn't configured as a question field on that tab.
    • C. Terms of use only accepts PDF documents, not Word files, and it isn't configured through the connected organization's sponsor settings.
    • D. Resource attributes capture data about the requestor for approvers to review; they aren't how a terms of use document is created or enforced.

    Subdomain 4.2: Plan, implement, and manage access reviews in Microsoft Entra

    30.A security group being reviewed contains a nested group as one of its members. How does the access review display and act on the users from that nested group?

    1. A.Nested group members appear individually, and denying one removes only direct membership, not the nested's.
    2. B.The nested group appears as a single reviewable entry, and its individual members are excluded from the review.
    3. C.Nested group members are skipped automatically, since access reviews evaluate only direct top-level membership.
    4. D.The review refuses to start until an administrator manually flattens the nested group beforehand.
    Show answer & explanation

    Correct answer: ANested group members appear individually, and denying one removes only direct membership, not the nested's.

    • A. This is correct because access reviews automatically flatten nested groups so their users appear as individuals, and denying a flagged user only removes their direct membership in the reviewed group, not their membership in the nested group itself.
    • B. The nested group does not appear as a single collapsed entry; its individual members are surfaced and reviewed one by one.
    • C. Members of nested groups are not skipped; flattening specifically brings them into scope as individual reviewees.
    • D. No manual flattening step is required before the review can start, since Microsoft Entra ID performs the flattening automatically.

    Subdomain 4.2: Plan, implement, and manage access reviews in Microsoft Entra

    31.An administrator is configuring the "Upon completion settings" section of a new access review. Which of the following can be configured there? (Choose 3.)(Select 3)

    1. A.Auto apply results to resource
    2. B.If reviewers don't respond
    3. C.Action to apply on denied guest users
    4. D.Requiring multi-factor authentication for reviewers
    5. E.The Conditional Access policy applied to reviewers
    6. F.Assigning a break-glass emergency access account
    Show answer & explanation

    Correct answers: A, B, CAuto apply results to resource; If reviewers don't respond; Action to apply on denied guest users

    • A. This toggle controls whether denied users' access is automatically removed once the review duration ends, and it belongs to the upon completion settings.
    • B. This dropdown determines the outcome applied to users nobody reviewed, such as no change, removal, approval, or taking the system recommendation, and it also lives in this section.
    • C. This setting, available for guest-scoped reviews, decides whether a denied guest simply loses resource membership or is also blocked from tenant sign-in, and it is part of this section.
    • D. Enforcing MFA for reviewers is a Conditional Access or authentication methods concern, not a setting inside the review's completion options.
    • E. Assigning a Conditional Access policy to reviewers is not part of access review configuration at all.
    • F. Break-glass emergency access accounts are a Privileged Identity Management and tenant resilience concept, unrelated to review completion settings.

    Subdomain 4.4: Monitor identity activity by using logs, workbooks, and reports

    32.An identity administrator configured an HR-driven provisioning connector that creates accounts in a third-party SaaS application from Workday records. A new hire reports they cannot access the application even though their Workday profile was updated three days ago. Which log should the administrator check first to confirm whether the account was created in the target application?

    1. A.Provisioning logs
    2. B.Audit logs
    3. C.Sign-in logs
    4. D.Usage and insights report
    Show answer & explanation

    Correct answer: AProvisioning logs

    • A. Provisioning logs record the outcome of each provisioning cycle, including whether a user was successfully created, updated, or skipped in the target application.
    • B. Audit logs cover tasks performed directly in the tenant, such as manual object changes, and do not show the step-by-step outcome of an automated provisioning cycle.
    • C. Sign-in logs only capture authentication attempts, so they would not show whether the account was ever created in the downstream application.
    • D. The usage and insights report summarizes application and service principal activity trends over time rather than the result of an individual provisioning run.

    Subdomain 4.4: Monitor identity activity by using logs, workbooks, and reports

    33.A compliance officer needs Microsoft Entra ID audit logs retained for three years to satisfy a regulatory requirement, but the organization has no SIEM or analytics tooling in place. Which diagnostic settings destination best meets this need at the lowest ongoing cost?

    1. A.Azure Storage account
    2. B.Azure Event Hub
    3. C.Log Analytics workspace
    4. D.Microsoft Sentinel workspace
    Show answer & explanation

    Correct answer: AAzure Storage account

    • A. A storage account is built for cheap, long-term archival of log data and does not require ongoing query or ingestion costs, making it well suited for multi-year retention alone.
    • B. An event hub is a streaming pass-through used to forward events to consumers in near real time and is not designed to hold years of archived data on its own.
    • C. A Log Analytics workspace bills based on data ingestion and retention, so keeping three years of logs there costs considerably more than simple archival storage.
    • D. A Microsoft Sentinel workspace is a Log Analytics workspace with SIEM capabilities layered on top, which adds unnecessary analytics cost for an organization that only needs archival.

    Subdomain 4.3: Plan and implement privileged access

    34.For how long can Microsoft Entra role administrators view PIM audit history for role assignments and activations in the admin center?

    1. A.Within the past 30 days.
    2. B.Within the past 7 days.
    3. C.Within the past 90 days.
    4. D.Within the past 12 months.
    Show answer & explanation

    Correct answer: AWithin the past 30 days.

    • A. This is correct because the admin center displays PIM audit history for role assignments and activations covering the past 30 days.
    • B. This is incorrect because the visible window in the admin center is longer than one week; a 7-day window would omit most of the recorded events administrators need to review.
    • C. This is incorrect because the admin center's built-in audit view covers 30 days, not a quarter; longer retention requires exporting the events elsewhere.
    • D. This is incorrect because a full year of history is not shown directly in the admin center view; organizations that need year-long retention must export audit events periodically.

    Subdomain 4.3: Plan and implement privileged access

    35.A security architect is designing Conditional Access policies that require multifactor authentication and compliant devices for all administrators. How should the organization's two emergency access break-glass accounts be treated in this design?

    1. A.Exclude the break-glass accounts from the Conditional Access policies, so administrators can still sign in if the normal authentication methods fail.
    2. B.Include the break-glass accounts in every Conditional Access policy, since emergency accounts must meet the same MFA requirements as all others.
    3. C.Assign the break-glass accounts as eligible PIM roles, so they must be activated through the same approval workflow as regular administrators.
    4. D.Delete the break-glass accounts entirely once Conditional Access policies are enforced, since they are no longer needed in a modern tenant.
    Show answer & explanation

    Correct answer: AExclude the break-glass accounts from the Conditional Access policies, so administrators can still sign in if the normal authentication methods fail.

    • A. This is correct because break-glass accounts are meant to remain usable during an authentication outage, so they are excluded from policies like MFA and device compliance that could themselves fail and lock everyone out.
    • B. This is incorrect because forcing these accounts through the same MFA and device requirements defeats their purpose; if the MFA or Conditional Access system is unavailable, the accounts would be unusable exactly when they're needed.
    • C. This is incorrect because break-glass accounts should be permanently and actively assigned the Global Administrator role, not made eligible through PIM, since an approval workflow could also fail during an outage.
    • D. This is incorrect because emergency access accounts remain a recommended safeguard regardless of how mature the Conditional Access design is; deleting them removes the fallback path entirely.

    Want the full experience?

    These are just samples. Practice the full Microsoft Certified: Identity and Access Administrator Associate (SC-300) question bank in quiz mode — free, no signup, with domain practice and exam simulation.