Instiq

Microsoft Identity and Access AdministratorStudy guide

The associate certification for designing, implementing, and operating identity and access management with Microsoft Entra (SC-300).

About Microsoft Identity and Access Administrator (SC-300)

Microsoft Identity and Access Administrator (SC-300) is a Associate-level certification from Microsoft. This page organizes the exam scope into a 5-chapter, 18-section study guide and lets you check your understanding with exam-style practice questions. A good flow is to read the chapters below in order, then test yourself via "Practice questions."

Exam domains (approximate weighting)

  • Implement and manage user identities~22%
  • Implement authentication and access management~28%
  • Plan and implement workload identities~25%
  • Plan and automate identity governance~25%

Weights are approximate guidance for the live exam. Each domain is covered in detail in the chapters and sections below.

Official exam information: https://learn.microsoft.com/en-us/credentials/certifications/resources/study-guides/sc-300

1Entra tenant and user identities

  • 1.1Configuring the Entra tenant, roles, and administrative units

    Understand configuring a Microsoft Entra tenant (tenant/user/group/device settings, domains, branding), built-in/custom Entra roles and evaluating effective permissions, and delegating administrative scope with administrative units.

  • 1.2Users, groups, devices, and licenses

    Understand creating/managing Microsoft Entra users and groups (assigned/dynamic; security/Microsoft 365), device join/registration, and license assignment/reporting.

  • 1.3Custom security attributes and bulk operations

    Understand classifying objects with custom security attributes (the basis for attribute-based access control) and bulk operations via the Microsoft Entra admin center and PowerShell (Microsoft Graph PowerShell).

2External and hybrid identity

3Authentication and Conditional Access

  • 3.1Authentication methods and multifactor authentication

    Understand authentication methods (certificate-based auth, Temporary Access Pass, Microsoft Authenticator, passkeys/FIDO2), tenant-wide MFA settings, self-service password reset (SSPR), Windows Hello for Business, Entra password protection, and Entra Kerberos for hybrid.

  • 3.2Conditional Access

    Understand planning/assigning/controlling Conditional Access policies, session management, device-enforced restrictions, continuous access evaluation (CAE), authentication context, protected actions, and creating from templates.

  • 3.3Managing risk with Microsoft Entra ID Protection

    Understand detecting user risk and sign-in risk with Microsoft Entra ID Protection, risk-based response via Conditional Access, MFA registration campaigns, and monitoring/investigating/remediating risky users/sign-ins/workload identities.

  • 3.4Global Secure Access

    Understand deploying Global Secure Access clients and Microsoft Entra Private Access (ZTNA to internal apps) and Microsoft Entra Internet Access (secure web gateway for internet/SaaS and Microsoft 365).

4Workload identities and app integration

  • 4.1Choosing workload identities and managed identities

    Understand choosing the right identity for apps and Azure workloads (managed identities, service principals, user accounts, managed service accounts), and creating/assigning managed identities and using them to access other resources.

  • 4.2Integrating enterprise applications

    Understand enterprise-application app/tenant-level settings, SaaS SSO integration, publishing on-prem apps via Microsoft Entra Application Proxy, assigning users/groups/app roles, and managing user and admin consent.

  • 4.3App registrations

    Understand app registrations for your own apps, app authentication (redirect URIs, secrets/certificates, federated credentials), API permissions (delegated/application), and app roles.

  • 4.4Managing app access with Defender for Cloud Apps

    Understand Microsoft Defender for Cloud Apps (CASB): cloud discovery, connected apps, app-enforced restrictions, Conditional Access app control, access/session policies, OAuth app policies, and the Cloud app catalog.

5Identity governance and monitoring

  • 5.1Entitlement management

    Understand Microsoft Entra entitlement management: catalogs and access packages, access requests/approval, terms of use (ToU), external-user lifecycle, and connected organizations.

  • 5.2Access reviews

    Understand periodically re-certifying existing access to groups/apps/roles with Microsoft Entra access reviews, and planning/creating/monitoring reviews and responding to results.

  • 5.3Privileged Identity Management (PIM)

    Understand Just-In-Time elevation of Entra roles/Azure resources/groups with Microsoft Entra Privileged Identity Management (PIM), request/approval, settings (MFA, justification, expiry), audit history, and break-glass accounts.

  • 5.4Monitoring identity activity

    Understand analyzing sign-in/audit/provisioning logs, diagnostic settings (sending to Log Analytics/storage/Event Hubs), KQL queries, workbooks and reports, and improving posture with Identity Secure Score.