Instiq
Chapter 1 · Entra tenant and user identities·v1.0.0·Updated 6/28/2026·~14 min

What's changed: Created SC-300 Chapter 1 (Domain 1 first-half: tenant config/built-in-custom roles/effective permissions/administrative units; users-groups (assigned/dynamic)/group-based assignment/device join-registration/licenses; custom security attributes/ABAC/bulk operations/Microsoft Graph PowerShell).

1.2Users, groups, devices, and licenses

Key points

Understand creating/managing Microsoft Entra users and groups (assigned/dynamic; security/Microsoft 365), device join/registration, and license assignment/reporting.

You manage the substance of identity daily—users, groups, devices. Groups in particular are the central design unit for assigning access, licenses, and policies in bulk.

1.2.1Assigned and dynamic groups

Groups are security groups (assign access/licenses/policies) or Microsoft 365 groups (collaboration). Membership can be assigned (manual) or dynamic. Dynamic groups auto-maintain membership via attribute rules (e.g., department eq "Sales"), following joiners/movers/leavers. For "when the department changes, change access automatically," use dynamic groups. Group-based assignment of permissions/licenses is the key to operational efficiency.

1.2.2Device join and registration

Linking devices to Entra lets you use conditions like Conditional Access "allow only compliant devices." Use Microsoft Entra join for corporate Windows, Entra registered for personal (BYOD), and hybrid join alongside on-prem AD. A device’s compliant state is evaluated by Microsoft Intune compliance policies (encryption, patching, PIN, etc.), and that result feeds Conditional Access as a signal. Device state (joined/registered/compliant) is an important signal for identity and access control.

1.2.3License assignment and reporting

Features (MFA, PIM, ID Protection, etc.) depend on licenses. Assign licenses to groups via group-based licensing so they distribute automatically as members are added, simplifying operations. Check assignment status and conflicts with license reporting. Many "feature unavailable" issues stem from missing required licenses (e.g., Entra ID P1/P2).

Exam point

Cues: "auto-update access on a move" = dynamic group (attribute rule). "assign access/licenses in bulk" = security group + group-based assignment. "manage corporate Windows" = Entra join; "personal BYOD" = Entra registered. "feature unavailable" = check required licenses.

Warning

Watch the mix-ups: (1) Security groups (access) and Microsoft 365 groups (collaboration) serve different purposes. (2) Dynamic group membership is attribute-driven—you cannot add members manually. (3) Distinguish Entra join (corporate) from Entra registered (BYOD).

Diagram of security/M365 and dynamic groups (attribute rules), device Entra join (corporate)/registered (BYOD)/hybrid join, and group-based licensing.
Group as the unit

1.2.4Section summary

  • Groups = security (access/licenses) and M365 (collaboration); dynamic groups auto-maintain via attribute rules
  • Devices = Entra join (corporate)/registered (BYOD)/hybrid join; state is a CA signal
  • Assign licenses via group-based licensing (auto-distribute); check conflicts via reporting; features depend on P1/P2

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. When an employee’s department changes, you want department app access auto-granted/revoked. Which is best?

Q2. You want to link a personal smartphone (BYOD) to Entra for corporate resource access. Which is best?

Q3. You want adding a new employee to a group to auto-assign the needed licenses. Which is best?

Q4. Which correctly distinguishes security groups from Microsoft 365 groups?

Q5. A user cannot use MFA or PIM. What is most appropriate to check first?

Check your understandingPractice questions for Chapter 1: Entra tenant and user identities