EnglishDeutschFrançaisEspañolPortuguês

Microsoft · SC-300 · Associate

Microsoft Identity and Access Administrator

The SC-300 certification validates skills in designing, implementing, and operating an organization's identity and access management using Microsoft Entra. 50+ AI-generated practice questions with explanations. Free trial, pass guarantee.

Start Free Trial

7-day free trial, no credit card required

50 Questions
100min Time Limit
700/ 1000 Pass Score

About the exam

The SC-300 certification validates skills in designing, implementing, and operating an organization's identity and access management using Microsoft Entra. It covers implementing identities in Microsoft Entra ID, authentication and access management, Conditional Access policies, identity governance, application access management, and Privileged Identity Management (PIM) for securing access to resources.

This certification is designed for identity and access administrators who manage user identities, authentication, authorization, and identity governance in Microsoft Entra. Candidates should have experience with Microsoft Entra ID (Azure AD), Conditional Access, multi-factor authentication, identity protection, and integrating SaaS applications with single sign-on.

What's on the exam

The exam consists of 40–60 questions to be completed in approximately 100 minutes (120 minutes if labs are included). Question types include multiple-choice, multiple-select, drag-and-drop, hot area, and case study formats. Questions are scenario-based, presenting identity and access challenges that require configuring Conditional Access policies, PIM, and identity governance. Expect detailed questions about authentication methods and external identity management.

Implement and manage user identities 24%

Configure and manage Microsoft Entra tenant, create/configure/manage Microsoft Entra identities, implement and manage identities for external users, and implement and manage hybrid identity

Implement authentication and access management 29%

Plan/implement/manage Microsoft Entra user authentication, Conditional Access, risk management with Microsoft Entra ID Protection, and Global Secure Access

Plan and implement workload identities 24%

Plan and implement identities for applications and Azure workloads, plan/implement/monitor enterprise application integration, plan and implement app registrations, and manage app access using Microsoft Defender for Cloud Apps

Plan and automate identity governance 23%

Plan and implement entitlement management, access reviews, privileged access with PIM, and monitor identity activity using logs, workbooks, and reports

What to expect

multiple choice
31%
drag drop
13%
command
11%
troubleshooting
11%
ordering
9%
multiple response
9%
dropdown selection
9%
true false
7%

Where candidates struggle

This exam goes deep into Microsoft Entra ID configuration. Candidates with general Azure administration experience who lack specific identity management and Conditional Access policy configuration skills often find it challenging.

  1. 01
    Conditional Access — Not understanding how Conditional Access policies evaluate, combine, and override each other with grant and session controls.
  2. 02
    PIM Configuration — Struggling with Privileged Identity Management role settings, approval workflows, and access reviews for just-in-time access.
  3. 03
    External Identities — Confusing B2B direct connect, B2B collaboration, and B2C scenarios and their respective configuration requirements.
  4. 04
    App Registration — Overlooking application registration, API permissions, consent frameworks, and service principal configurations in Entra ID.
  5. 05
    Identity Governance — Not understanding entitlement management access packages, access reviews, and lifecycle workflows for identity governance.

Exam logistics

Delivered via Pearson VUE online or at testing centers. Available in English, Japanese, Chinese, Korean, French, German, Spanish, and more. The certification is valid for 1 year with a free renewal assessment on Microsoft Learn.

Delivery Pearson VUE online proctored or at authorized testing centers worldwide
Retake policy 24-hour wait after the first attempt, 14 days between subsequent attempts, maximum 5 attempts per exam within a 12-month period
Validity 1 year
Career outcomes Identity and Access Administrator, IAM Engineer, Cloud Security Engineer, Entra ID Administrator, Identity Governance Specialist
Renewal Free renewal assessment on Microsoft Learn, available starting 6 months before expiration. Must be completed before the certification expires.
Study time ~50 hours
Official guide View on vendor site

Ready to pass?

Join thousands of professionals who passed with AI-powered practice.

Start Free Trial