Microsoft Identity and Access AdministratorStudy guide
The associate certification for designing, implementing, and operating identity and access management with Microsoft Entra (SC-300).
About Microsoft Identity and Access Administrator (SC-300)
Microsoft Identity and Access Administrator (SC-300) is a Associate-level certification from Microsoft. This page organizes the exam scope into a 5-chapter, 18-section study guide and lets you check your understanding with exam-style practice questions. A good flow is to read the chapters below in order, then test yourself via "Practice questions."
Exam domains (approximate weighting)
- Implement and manage user identities~22%
- Implement authentication and access management~28%
- Plan and implement workload identities~25%
- Plan and automate identity governance~25%
Weights are approximate guidance for the live exam. Each domain is covered in detail in the chapters and sections below.
Official exam information: https://learn.microsoft.com/en-us/credentials/certifications/resources/study-guides/sc-300
1Entra tenant and user identities
- 1.1Configuring the Entra tenant, roles, and administrative units
Understand configuring a Microsoft Entra tenant (tenant/user/group/device settings, domains, branding), built-in/custom Entra roles and evaluating effective permissions, and delegating administrative scope with administrative units.
- 1.2Users, groups, devices, and licenses
Understand creating/managing Microsoft Entra users and groups (assigned/dynamic; security/Microsoft 365), device join/registration, and license assignment/reporting.
- 1.3Custom security attributes and bulk operations
Understand classifying objects with custom security attributes (the basis for attribute-based access control) and bulk operations via the Microsoft Entra admin center and PowerShell (Microsoft Graph PowerShell).
2External and hybrid identity
- 2.1External ID, B2B collaboration, and cross-tenant access
Understand inviting/managing external users with Microsoft Entra External ID (B2B collaboration), External collaboration settings, Cross-tenant access settings, and cross-tenant synchronization.
- 2.2External identity providers and federation
Understand configuring external identity providers (IdPs) and delegating authentication via federation protocols such as SAML and WS-Fed.
- 2.3Implementing hybrid identity
Understand Microsoft Entra Connect Sync and Cloud Sync, password hash synchronization (PHS)/pass-through authentication (PTA)/seamless SSO, Microsoft Entra Connect Health, and migrating from AD FS.
3Authentication and Conditional Access
- 3.1Authentication methods and multifactor authentication
Understand authentication methods (certificate-based auth, Temporary Access Pass, Microsoft Authenticator, passkeys/FIDO2), tenant-wide MFA settings, self-service password reset (SSPR), Windows Hello for Business, Entra password protection, and Entra Kerberos for hybrid.
- 3.2Conditional Access
Understand planning/assigning/controlling Conditional Access policies, session management, device-enforced restrictions, continuous access evaluation (CAE), authentication context, protected actions, and creating from templates.
- 3.3Managing risk with Microsoft Entra ID Protection
Understand detecting user risk and sign-in risk with Microsoft Entra ID Protection, risk-based response via Conditional Access, MFA registration campaigns, and monitoring/investigating/remediating risky users/sign-ins/workload identities.
- 3.4Global Secure Access
Understand deploying Global Secure Access clients and Microsoft Entra Private Access (ZTNA to internal apps) and Microsoft Entra Internet Access (secure web gateway for internet/SaaS and Microsoft 365).
4Workload identities and app integration
- 4.1Choosing workload identities and managed identities
Understand choosing the right identity for apps and Azure workloads (managed identities, service principals, user accounts, managed service accounts), and creating/assigning managed identities and using them to access other resources.
- 4.2Integrating enterprise applications
Understand enterprise-application app/tenant-level settings, SaaS SSO integration, publishing on-prem apps via Microsoft Entra Application Proxy, assigning users/groups/app roles, and managing user and admin consent.
- 4.3App registrations
Understand app registrations for your own apps, app authentication (redirect URIs, secrets/certificates, federated credentials), API permissions (delegated/application), and app roles.
- 4.4Managing app access with Defender for Cloud Apps
Understand Microsoft Defender for Cloud Apps (CASB): cloud discovery, connected apps, app-enforced restrictions, Conditional Access app control, access/session policies, OAuth app policies, and the Cloud app catalog.
5Identity governance and monitoring
- 5.1Entitlement management
Understand Microsoft Entra entitlement management: catalogs and access packages, access requests/approval, terms of use (ToU), external-user lifecycle, and connected organizations.
- 5.2Access reviews
Understand periodically re-certifying existing access to groups/apps/roles with Microsoft Entra access reviews, and planning/creating/monitoring reviews and responding to results.
- 5.3Privileged Identity Management (PIM)
Understand Just-In-Time elevation of Entra roles/Azure resources/groups with Microsoft Entra Privileged Identity Management (PIM), request/approval, settings (MFA, justification, expiry), audit history, and break-glass accounts.
- 5.4Monitoring identity activity
Understand analyzing sign-in/audit/provisioning logs, diagnostic settings (sending to Log Analytics/storage/Event Hubs), KQL queries, workbooks and reports, and improving posture with Identity Secure Score.

