Microsoft Identity and Access Administrator SC-300 Exam Questions

Page: 1 / 14
Total 370 questions
Question 1

You need to implement the planned changes for Package1. Which users can create and manage the access review?



Answer : E

For Identity Governance (Entitlement Management), the materials clarify who can create and manage access reviews of access packages: ''To create or manage access reviews for access packages, you must be a Global administrator, an Identity Governance administrator, a catalog owner for the catalog that contains the access package, or an access package manager.'' The exam text also states: ''User administrator does not grant the ability to manage entitlement management access reviews unless the user is delegated as a catalog owner or access package manager.'' Given the scenario's user roles, User3 (Identity Governance administrator) and User5 (Global administrator) satisfy these permissions and therefore can create and manage the access review for Package1. By contrast, User4 (User administrator) cannot perform this task by role alone. This selection follows the least-privilege guidance emphasized in SC-300: use specialized governance roles (Identity Governance admin or delegated catalog roles) rather than broad directory roles when possible.


Question 2

You have an Azure Active Directory (Azure AD) tenant that contains the groups shown in the following table.

For which groups can you create an access review?



Answer : D

The SC-300 official study guide and Microsoft Learn: Manage Access Reviews confirm that Access Reviews in Azure AD can target user-based groups, Azure AD roles, and enterprise applications. However, dynamic device groups are not supported for access reviews.


Question 3

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it as a result, these questions will not appear in the review screen.

You have an Amazon Web Services (AWS) account, a Google Workspace subscription, and a GitHub account.

You deploy an Azure subscription and enable Microsoft 365 Defender.

You need to ensure that you can monitor OAuth authentication requests by using Microsoft Defender for Cloud Apps.

Solution: From the Microsoft 365 Defender portal, you add the Amazon Web Services app connector.

Does this meet the goal?



Answer : A

The AWS connector in Microsoft Defender for Cloud Apps is designed to integrate activity logs, user authentication data, and app permissions granted through OAuth. This connector enables monitoring of OAuth token use, identity federation events, and cross-service authentication.

From the official Microsoft Learn content:

''When the AWS app connector is added, Defender for Cloud Apps collects OAuth activity and permissions information to detect anomalous behavior or excessive app permissions.''

This fulfills the requirement to monitor OAuth authentication requests from AWS and its associated accounts. Therefore, adding the AWS app connector meets the goal.


Question 4

You need to meet the planned changes for the User administrator role.

What should you do?



Answer : B

In Azure AD Privileged Identity Management (PIM) for Azure AD roles, the exam materials describe that you tailor how a role (for example, User administrator) is used by editing its Role settings. These settings control activation behavior, including require multi-factor authentication, justification, approval, assignment/activation durations, and notifications. The guide states that administrators can ''configure activation requirements and time-bound eligibility on a per-role basis'' and ''enforce approval workflows and MFA at activation.'' Access reviews are used to periodically verify who still needs a role, but they do not implement the operational changes to how the role is activated. Active assignments simply shows and changes who currently holds active/eligible assignments; it does not set policy for the role's activation behavior. Administrative units scope certain directory tasks, but they are not how you change PIM activation/approval/MFA requirements. Therefore, to meet planned changes for the User administrator role (such as least privilege activation with approval, justification, and MFA), you update PIM Azure AD roles User administrator Role settings. This aligns with the SC-300 objective to ''configure PIM settings and policies for Azure AD roles,'' ensuring governance by policy rather than ad-hoc assignment.


Question 5

You have an Azure subscription that contains a user named User1. The subscription is onboarded to Microsoft Entra Permissions Management. You need to provide User! with access to Permissions Management. The solution must meet the following requirements:

* Follow the principle of least privilege.

* Minimize administrative effort.

What should you do first?



Answer : C

When onboarding to Microsoft Entra Permissions Management (a CIEM solution), before a user can perform any functions inside Permissions Management, that user must be granted an appropriate Permissions Management role in the Entra tenant. The principle of least privilege dictates that you grant only the minimal role necessary (for example, a Permissions Management Approver, Viewer, or Controller). The SC-300 study materials and Microsoft's documentation emphasize that administrative access must begin by assigning roles within Entra ID.

Creating a security group (option A) is a useful organizational practice but doesn't itself grant the user permissions inside Permissions Management. Creating a role/policy template (option B) is about defining permission scopes and is not a first step to allow a user access. Creating a request in My Requests (option D) presupposes that User1 already has some entitlement to make requests (i.e. some role), which they don't yet.

Therefore, the first action is to assign a Permissions Management role to User1 from the Entra admin center, thus giving them appropriate access while adhering to least privilege.


Question 6

You have an Azure AD tenant that contains the users shown in the following table.

The User settings for enterprise applications have the following configuration.

* Users can consent to apps accessing company data on their behalf:

* Users can consent to apps accessing company data for the groups they

* Users can request admin consent to apps they are unable to consent to: Yes

* Who can review admin consent requests: Admin2, User2

User1 attempts to add an app that requires consent to access company data.

Which user can provide consent?



Answer : D

In Azure AD, user consent and admin consent workflows control which users or administrators can approve access to organizational data requested by applications.

The question states:

''Users can request admin consent to apps they are unable to consent to: Yes''

''Who can review admin consent requests: Admin2, User2''

When User1 attempts to add an app that requires consent to access company data, and if that app requires admin consent, the request is routed to those designated as admin consent reviewers. In this case, Admin2 and User2 are listed, but only one has the administrative capability to approve the request.

Based on Microsoft documentation:

''Only users who hold an administrative role such as Global Administrator, Cloud Application Administrator, or Authentication Administrator and are designated as reviewers can grant consent on behalf of the organization.''

Here, Admin2 holds the Authentication Administrator role --- an Azure AD admin-level role --- while User2 has no administrative privileges. Thus, Admin2 is the only eligible user to approve the admin consent request.


Question 7

You havean Azure AD tenant that contains the users shown in the following table.

You add an enterprise application named App1 to Azure AD and set User1 as the owner of App1 requires admin consent to access Azure AD before the app can be used.

You configure the Admin consent requests strong as shown in the following exhibit.

Admin consent requests.



Answer : B

This scenario involves Admin Consent Requests in Azure AD. When users try to use apps that require admin consent, requests are sent to designated reviewers who can approve or deny them.

Admin1: Cloud Application Administrator --- can review and approve admin consent requests.

Admin2: Application Administrator --- can review and approve admin consent requests.

Admin3: Security Administrator --- cannot approve app consent requests because this role does not have application management privileges.

User1: No role assigned --- can be listed as a reviewer but cannot approve, only receive notifications.

From Microsoft Documentation:

''Only users with sufficient permissions, such as the Application Administrator or Cloud Application Administrator roles, can grant admin consent in response to consent requests.''

Therefore, only Admin1 and Admin2 meet the requirement to review and approve.


Page:    1 / 14   
Total 370 questions