EnglishDeutschFrançaisEspañolPortuguês

Microsoft · SC-300 · Associate

Microsoft Identity and Access Administrator (SC-300) — Practice Questions and Mock Exam

Prepare for SC-300 with original practice questions and clear answer explanations. Ask Alex, your AI tutor, when you need more detail, use your results to identify topics to review, and practice your pacing with timed mock exams.

50Mock exam questions
100minTime limit
700/ 1000Passing score

Checked against Microsoft · August 2026 · Current exam version

About the exam

The SC-300 certification validates skills in designing, implementing, and operating an organization's identity and access management using Microsoft Entra. It covers implementing identities in Microsoft Entra ID, authentication and access management, Conditional Access policies, identity governance, application access management, and Privileged Identity Management (PIM) for securing access to resources.

This certification is designed for identity and access administrators who manage user identities, authentication, authorization, and identity governance in Microsoft Entra. Candidates should have experience with Microsoft Entra ID (Azure AD), Conditional Access, multi-factor authentication, identity protection, and integrating SaaS applications with single sign-on.

Try five SC-300 questions

Try five practice questions from the app’s current Microsoft Identity and Access Administrator question bank, with answers and explanations.

Plan and automate identity governance2 / 5

You are configuring PIM for Groups in the Microsoft Entra admin center. Your organization wants just-in-time access to Microsoft Entra roles via groups. For each of the following statements, select Yes if the statement is true. Otherwise, select No. 1. PIM for Groups allows just-in-time activation of both group membership and group ownership. 2. Role-assignable groups can have other groups nested inside them as active members. 3. PIM for Groups can provide just-in-time access to Azure roles, Key Vault, Intune, and third-party applications. 4. For roles with SharePoint/Exchange permissions, Microsoft recommends active user-to-group assignments with eligible group-to-role assignments.

AlexFull explanation from Alex

PIM for Groups enables just-in-time activation of both group membership and group ownership (docs.microsoft.com/entra/id-governance/privileged-identity-management). Statement 1: Yes — PIM for Groups supports JIT membership and ownership activation. Statement 2: No — role-assignable groups cannot have other groups nested inside them as active members per Microsoft Learn docs. Statement 3: Yes — PIM for Groups provides JIT access to Microsoft Entra roles, Azure roles, Azure SQL, Azure Key Vault, Intune, and third-party applications. Statement 4: Yes — for roles with SharePoint/Exchange permissions, Microsoft recommends active user-to-group assignments with eligible group-to-role assignments to avoid activation delays, since SharePoint/Exchange do not support real-time propagation of JIT membership. Exam tip: PIM for Groups = JIT membership + ownership. Role-assignable groups cannot nest groups. Use active user-to-group for SharePoint/Exchange roles.

Sourcelearn.microsoft.com

Plan and implement workload identities4 / 5

You need to configure Microsoft Entra ID to prevent deleted applications from being permanently lost. What is the retention period for soft-deleted applications?

AlexFull explanation from Alex

Soft-deleted applications in Microsoft Entra ID are retained for 30 days. Per Microsoft Learn (Deletion and recovery of applications FAQ): soft-deleted application and service principal objects go into the deleted items container and remain available to restore for up to 30 days. After 30 days, they are permanently deleted, freeing the quota. Both app registrations and their corresponding service principals follow the same 30-day lifecycle. Administrators with Cloud Application Administrator or Application Administrator roles can restore within this window. Exam tip: 30-day retention period for soft-deleted apps. Permanent deletion after window. Restorable by admins during retention.

Sourcelearn.microsoft.com

Implement authentication and access management5 / 5

Does Microsoft Entra ID support conditional access policies that target specific applications rather than all cloud apps?

AlexFull explanation from Alex

Yes, Conditional Access policies can target specific applications rather than all cloud apps. In the CA policy configuration under Target resources (formerly Cloud apps or actions), admins can select individual applications, groups of apps, or all cloud apps. This enables granular access control—for example, requiring MFA only for sensitive apps like Azure portal while allowing less restrictive access to general productivity apps. Built-in Microsoft applications and any Microsoft Entra integrated enterprise applications can be targeted. The 'No' answer is incorrect because application-level targeting is a fundamental CA capability documented as a key signal in policy configuration. Ref: learn.microsoft.com/entra/identity/conditional-access/concept-conditional-access-cloud-apps

Sourcelearn.microsoft.com

364 practice questions

Use the Pass-IT question pool to practice for SC-300. Mock exams are set to 50 questions in 100 minutes.

Pool details: SC-300

Exam details checked against MicrosoftAugust 28, 2026

date of the last check against the official Microsoft source

Passing score700 / 1,000

as published by Microsoft

Objectives in the guide114 objectives listed in the official guide

across 4 domains in the official exam guide

Pool size364 questions

= The pool size is equivalent to 7 sets of 50 questions; this does not mean that each mock exam uses a separate set.

Recorded as checked against sources364 of 364

questions recorded as having their answer, options, and explanation checked against official Microsoft documentation

What's on the exam

All four domains land in the same 20–25% band — user identities, authentication and access management, workload identities, and identity governance carry essentially equal weight, so no single skill area dominates the exam.

That even split means SC-300 tests the full identity lifecycle rather than rewarding depth in one corner of it: Conditional Access policy design counts for as much as PIM's approval workflows and access reviews, and workload identities (service principals, app registrations, managed identities) get the same exam-time investment as human user accounts. Candidates who know Entra ID from a general-admin angle but haven't configured B2B collaboration, entitlement-management access packages, or workload-identity federation are missing a quarter of the exam each.

Exam blueprint: SC-300

Implement and manage user identities20–25%

Configure and manage Microsoft Entra tenant, create/configure/manage Microsoft Entra identities, implement and manage identities for external users, and implement and manage hybrid identity

≈ 13 h
Implement authentication and access management20–25%

Plan/implement/manage Microsoft Entra user authentication, Conditional Access, risk management with Microsoft Entra ID Protection, and Global Secure Access

≈ 13 h
Plan and implement workload identities20–25%

Plan and implement identities for applications and Azure workloads, plan/implement/monitor enterprise application integration, plan and implement app registrations, and manage app access using Microsoft Defender for Cloud Apps

≈ 13 h
Plan and automate identity governance20–25%

Plan and implement entitlement management, access reviews, privileged access with PIM, and monitor identity activity using logs, workbooks, and reports

≈ 13 h

Exam format and question types

The exam draws 40–60 questions from a mix of multiple-choice, multiple-select, drag-and-drop, hot-area, and case-study formats inside a 100-minute window. Most items are scenario-based, presenting an identity or access problem and asking you to configure Conditional Access, PIM, or an identity-governance workflow to solve it. Authentication-method and external-identity questions go into enough detail that recognizing a feature by name isn't the same as knowing how to configure it.

Question types: SC-300

Multiple Choice41%

Select the single answer that best meets the question’s requirements.

Drag & Drop17%

Move items into the slots, groups, or sequence specified by the task.

Ordering11%

Arrange the steps in the sequence needed to complete the process.

Multiple Response11%

Select multiple answers. Follow the question’s instructions on how many to choose.

Dropdown11%

Choose options from dropdown menus to complete a statement or configuration.

True / False9%

Decide whether a statement is true or false, paying attention to its conditions and wording.

See Microsoft for official question-format information. The shares shown describe the Pass-IT practice pool; they do not establish the proportions on the official exam.

Preparing for SC-300

The exam runs through Pearson VUE, either online with a remote proctor or at an authorized testing center, and is offered in English, Japanese, Chinese, Korean, French, German, Spanish, and several other languages. Certification holds for one year, and Microsoft opens a free renewal assessment on Learn starting six months before it expires.

Preparation and logistics: SC-300

Preparation

Illustrative study time30–75 h

illustrative planning range: 30 h with relevant experience to 75 h when starting out; your needs may fall outside this range

LevelAssociate

Taking and maintaining the certification

DeliveryPearson VUE online proctored or at authorized testing centers worldwide
Retake policy24-hour wait after the first attempt, 14 days between subsequent attempts, maximum 5 attempts per exam within a 12-month period
Certification validity1 year

Free renewal assessment on Microsoft Learn, available starting 6 months before expiration. Must be completed before the certification expires.

Common pitfalls

Topics to review: SC-300

  1. 01Conditional Access

    Not understanding how Conditional Access policies evaluate, combine, and override each other with grant and session controls.

  2. 02PIM Configuration

    Struggling with Privileged Identity Management role settings, approval workflows, and access reviews for just-in-time access.

  3. 03External Identities

    Confusing B2B direct connect, B2B collaboration, and B2C scenarios and their respective configuration requirements.

  4. 04App Registration

    Overlooking application registration, API permissions, consent frameworks, and service principal configurations in Entra ID.

  5. 05Identity Governance

    Not understanding entitlement management access packages, access reviews, and lifecycle workflows for identity governance.

Frequently asked questions

How long is the Microsoft Identity and Access Administrator exam?

The SC-300 exam has 50 questions and a 100-minute time limit.

What is the passing score for Microsoft Identity and Access Administrator?

The passing score for the SC-300 exam is 700 / 1000.

Which pitfalls should I review when preparing for Microsoft Identity and Access Administrator?

Topics to review include Conditional Access, PIM Configuration, External Identities, App Registration, Identity Governance. Work through examples to check that you understand the distinctions and can explain your answer.

How is SC-300 weighted?

All four areas carry exactly 25%: managing user identities, authentication and access management, workload identities, and identity governance and automation. That is the only perfectly even weighting in our catalog. It means workload identities and governance are worth as much as the user-facing material that most people study first.

Do you need SC-900 before SC-300?

No, Microsoft sets no prerequisite. SC-900 is a fundamentals exam covering security, compliance and identity concepts, so it helps if Entra ID is new ground and adds little if you already administer it. The catalog budget for SC-300 is around 50 hours.

What should you take after SC-300?

SC-100 is the architect-level step if you are moving towards designing security across a whole estate. SC-200 fits if detection and response is the direction, and SC-401 if information protection in Microsoft 365 is. None of them require SC-300 first, but all of them assume the identity material it covers.

How long does SC-300 stay valid?

One year from the pass date. Microsoft renews it through a free online assessment on Microsoft Learn that opens six months before expiry. Because Entra ID changes continuously, the assessment tends to cover features that did not exist when you sat the exam.

One certification, 12 months

Practice for SC-300

Focus your practice on one certification, or choose Pro to practice across all certifications.

Start a free practice sessionTry the first 20 questions without a card to see whether the practice suits you.

For eligible purchases: money-back guarantee if you fail your exam.

View guarantee terms →