SC-300 Practice Questions & Exam Prep — Microsoft Identity and Access Administrator
Get exam-ready for SC-300 (Microsoft Identity and Access Administrator) on iPhone or iPad. Azure Mastery uses on-device AI to predict your readiness score across all four SC-300 domains, build a personalised study plan from your weak spots, and surface topics you're forgetting. Core study stays on-device and works offline; optional sync uses your private iCloud account.
The exam
What is the SC-300 exam?
SC-300 is the Microsoft Certified: Identity and Access Administrator Associate exam — the credential hiring managers expect when posting "Identity Administrator", "IAM Engineer", "Microsoft Entra Administrator", or "Identity and Access Manager" roles. SC-300 covers the day-to-day of operating Microsoft Entra ID at scale — identities, authentication, Conditional Access, workload identities, and identity governance. It pairs with SC-900 on the way in, and is one of the prereqs for SC-100 (Cybersecurity Architect Expert).
SC-300 is hands-on and Entra-deep. It validates that you can implement and manage user identities (cloud-only, hybrid, guest), configure authentication (passwordless, MFA, password protection, SSPR), design and operate Conditional Access and Microsoft Entra ID Protection, plan workload identities (service principals, managed identities, app registrations, OAuth flows, app proxy), and run identity governance via entitlement management, access reviews, and Privileged Identity Management (PIM). Expect scenario questions that show you a Conditional Access policy JSON or an access-package configuration and ask what you'd change.
Microsoft updated the SC-300 skills outline on 27 April 2026. Every question in Azure Mastery's SC-300 bank is mapped to the current outline — no leftover questions on retired services. Read the official outline at learn.microsoft.com.
Questions40–60 multiple choice
Duration100 minutes (120 min seat)
Pass score700 / 1000
CostUSD $165 (≈ £128 UK)
ValidityRenew annually (Associate)
FormatOnline or test centre
Skills measured · April 2026
SC-300 exam objectives
Four domains, with weights set by Microsoft's April 2026 update. Every domain summary below is paraphrased from the official skills outline; bullet-level objectives in Azure Mastery are tagged so you always know which domain you're being tested on and where your weak spots cluster.
Security skill mapIdentityProtectDetectGovern
Implement and manage user identities20–25%
Explore key topics
The directory layer. Configure and manage Microsoft Entra ID tenant settings, identity types (cloud-only, hybrid, guest), bulk operations, dynamic groups, group writeback. Hybrid identity with Microsoft Entra Connect Sync and cloud sync — pick between Password Hash Sync (PHS), Pass-through Authentication (PTA), and federation. Self-service password reset (SSPR), B2B collaboration, lifecycle workflows. Around 8–15 questions per sitting.
Implement authentication and access management25–30%
Explore key topics
The largest domain. Authentication methods — passwordless (FIDO2, Windows Hello for Business, Microsoft Authenticator), MFA registration policies, password protection, smart-lockout, security defaults vs Conditional Access. Design and configure Conditional Access — named locations, sign-in risk, session controls, app-enforced restrictions, Defender for Cloud Apps integration. Microsoft Entra ID Protection — risky users, risky sign-ins, automated remediation. Around 10–18 questions.
Plan and implement workload identities20–25%
Explore key topics
The application layer. Service principals, managed identities (system-assigned, user-assigned, federated credentials), app registrations, OAuth 2.0 and OpenID Connect flows, app permissions vs delegated permissions, admin consent. Microsoft Entra Application Proxy and SAML/SSO for legacy apps, custom-developed apps, and gallery apps. Conditional Access for workload identities. Around 8–15 questions.
Plan and automate identity governance20–25%
Explore key topics
The lifecycle layer. Entitlement management — access packages, catalogs, assignment policies, lifecycle policies, separation of duties. Access reviews — recurring reviews of users, group membership, app access, role assignments. Privileged Identity Management (PIM) — eligibility, just-in-time activation, approval workflows, role and access reviews. Microsoft Entra Permissions Management for multi-cloud scenarios. Around 8–15 questions.
Designed for SC-300
How Azure Mastery helps you pass SC-300
Azure Mastery ships with 357 SC-300 practice questions, every one written specifically against the current (April 2026) skills outline. Each question carries a domain tag mapped to the official four domains (user identities, authentication and access, workload identities, identity governance), so you always know which area you're being tested on and where your weak spots are clustered. Conditional Access policy snippets, access package configurations, and PIM role assignments appear throughout — matching the format of the live exam.
The on-device Exam IQ engine predicts your SC-300 score before you sit the exam. After roughly 30 questions it has enough signal to give a confidence-scored prediction (e.g. "786 ±37, 68% confidence") — and tells you the specific topics that are dragging your readiness down. No vague "study more" advice; just a ranked list of objectives where improvement would move your score the furthest.
The adaptive study plan rebuilds itself from your answer history. Miss a Conditional Access scenario? You'll see another sign-in-risk question in the next session. Master "PIM eligibility vs assignment" three sessions running and the engine backs off, surfacing fresh access-package or workload-identity scenarios. The plan optimises for the gap between where you are and the 700 pass score, not for blind volume.
Knowledge decay tracking matters more for SC-300 than for foundational exams — four identity-admin domains span a lot of Microsoft Entra surface area, and the policy you mastered three weeks ago is the policy you'll forget by exam day if you stop revising. Azure Mastery tracks every topic's decay curve and flags topics approaching expiry. The padlock icon on the Today screen is your "revisit before you forget" cue, and weak-spot drills automatically pull from decayed topics first.
Real exam simulation mode runs at SC-300's actual length and time pressure: a randomised 40–60-question set drawn from the full 357-question bank, weighted by domain percentages from the April 2026 outline, with the 100-minute timer running and no jumping back to flag-and-review. It's the closest you can get to the live Pearson VUE / online-proctored experience without sitting the exam.
Answer Coach turns each missed answer into a private, grounded lesson: the misconception, key distinction, and rule to remember. It always uses authored certification guidance; on supported devices, an optional on-device model may rewrite the note only when it passes grounding checks.
During your first week, Aura adapts the next step as you go. Every session ends with a concise recap of what changed, what to focus on, and the best follow-up.
Everything essential runs on-device. Your answer history, readiness gauge, and coaching stay private. Optional sync uses your private iCloud account; there is no Azure Mastery account, tracking, or external processing server.
6-week study plan
Suggested SC-300 study plan
Most candidates pass SC-300 after four to eight weeks of focused study, depending on prior Microsoft Entra experience. The six-week plan below maps onto the four SC-300 domains, Azure Mastery's adaptive sessions, and the in-app exam simulator. Adjust pace to taste — the readiness gauge tells you when you're done, not the calendar.
User identities and authentication
Days 1–3: Microsoft Entra tenant settings, identity types (cloud-only, hybrid, guest), bulk operations, dynamic groups, group writeback.
Days 4–6: Hybrid identity — Microsoft Entra Connect Sync vs cloud sync, picking between PHS, PTA, and federation. SSPR registration policies, B2B collaboration, lifecycle workflows.
Days 7–10: Authentication methods — passwordless (FIDO2, Windows Hello, Authenticator), MFA, password protection, smart-lockout, security defaults vs Conditional Access.
Days 11–14: Conditional Access design — named locations, sign-in risk, session controls, app-enforced restrictions, Defender for Cloud Apps integration.
Access and workload identities
Days 15–17: Microsoft Entra ID Protection — risky users, risky sign-ins, automated remediation, policy thresholds.
Days 18–20: Workload identity types — service principals, managed identities (system-assigned, user-assigned, federated credentials).
Days 21–24: App registrations, OAuth 2.0 and OpenID Connect flows, app permissions vs delegated permissions, admin consent workflows.
Days 25–28: Microsoft Entra Application Proxy, SAML and SSO for legacy and gallery apps, Conditional Access for workload identities.
Identity governance, sharpen, simulate
Days 29–32: Entitlement management — access packages, catalogs, assignment policies, lifecycle policies, separation of duties.
Days 33–36: Access reviews (recurring users / groups / apps / roles), Privileged Identity Management — eligibility, just-in-time activation, approval workflows, role and access reviews. Microsoft Entra Permissions Management for multi-cloud.
Days 37–40: Run Focus Weak Spots every morning. Authentication and access management is 25–30% — weight your time accordingly.
Days 41–42: Two end-to-end Exam Simulator runs at full 100-minute length. Review carefully. If readiness gauge is 750+ with reasonable confidence, schedule the exam.
Inside the app
Every Microsoft question type, on iPhone
SC-300's question bank uses the same formats Microsoft puts on the live exam — not just multiple choice. Each visualisation below is a faithful mock of how the type renders inside Azure Mastery on iPhone and iPad. Exam-simulator mode runs all of them at full 100-minute length with no flag-and-review jumps, mirroring Pearson VUE.
What is the minimum number of owners required for a Microsoft 365 group?
0
1
2
3
Multiple choice
A real SC-300 question-bank example with one correct answer. The app explains every option after you answer.
Exam-specific sample
Which TWO conditions are part of a Conditional Access policy? (Choose 2)
Sign-in risk
Bandwidth usage
Device platforms
Azure VM size
Multi-select
A real SC-300 multi-select item. Every required selection must be correct to earn the mark.
All-or-nothing
Order the steps to create and safely roll out a Conditional Access policy.
⋮⋮1Define the assignments: target users, roles, and cloud apps
⋮⋮2Add the conditions, such as sign-in risk or device platform
⋮⋮3Configure the grant controls, such as require MFA and a compliant device
⋮⋮4Run the policy in report-only mode to assess impact
⋮⋮5Enable the policy for the targeted users
Drag-and-drop
A real SC-300 interactive-format prompt, rendered for touch on iPhone and iPad.
Interactive item
In a Conditional Access policy's Grant controls, which option requires users to complete multifactor authentication before access is granted?
Hotspot
A real SC-300 prompt that tests recognition inside a visual or contextual interface.
Tap target
Fabrikam — Governing access for contractors Fabrikam onboards hundreds of external contractors who need bundled access to specific apps and groups for fixed engagements. Today access is granted ad hoc, rarely…
1How should Fabrikam bundle the access a contractor needs into one requestable…
2How should Fabrikam periodically recertify that contractors still need access?
3How should Fabrikam remove standing privileged access for admins?
4How can Fabrikam automate onboarding tasks when a contractor joins?
Case studies
A real SC-300 case-study scenario with linked questions that share the same requirements and environment.
Multi-question
✕Your answer: 1
✨ Answer Coach:A single owner is best-practice guidance rather than a platform-enforced floor; the service does not block creation or persistence of an ownerless group, so one is not the minimum it requires.
— grounded in authored certification guidance
Answer Coach
Answer Coach uses the bank's authored rationale to explain the misconception, key distinction, and rule to remember. On supported devices, an optional on-device model may rewrite the note only when it passes grounding checks.
App exclusive
Frequently asked
SC-300 FAQs
How much does the SC-300 exam cost?
The SC-300 voucher is USD $165 in the United States. Pricing varies by region — in the UK it's typically around £128. Microsoft sometimes runs free-voucher promotions during events such as Microsoft Build or Microsoft Ignite, so check your Microsoft Learn profile for any active offers before booking. SC-300 also requires annual renewal (free, online), so factor that into long-term cost planning.
Does the SC-300 certification expire?
Yes. Microsoft Associate certifications including SC-300 expire annually. Renewal is free — a 25–30 question online assessment on Microsoft Learn within the six-month window before your expiration date. The renewal targets recent skills outline updates, so staying current is straightforward if you remain broadly active in the role. (Fundamentals certifications such as AZ-900 are different — those don't expire.)
What is the SC-300 retake policy if I fail?
The first retake is allowed after 24 hours. Second and third retakes each require a 14-day wait. Microsoft caps retakes at five attempts per 12-month rolling period. Each attempt requires a new voucher purchase.
How long should I study for SC-300?
Most candidates plan four to eight weeks with Microsoft Entra administration experience. Practise identity lifecycle, authentication, Conditional Access, workload identities, application access, entitlement management, access reviews, and privileged access; use the portal and Microsoft Graph or PowerShell where the task calls for automation. Azure Mastery's readiness gauge tells you when you're exam-ready.
SC-300 vs SC-900 — which should I take first?
SC-900 first if security and identity concepts are new to you. SC-900 (Microsoft Security, Compliance, and Identity Fundamentals) builds the cross-cutting Microsoft security vocabulary including identity, but doesn't expect hands-on Conditional Access, PIM, or workload-identity work. SC-300 is the role-based Associate exam: it expects you to operate Microsoft Entra ID at scale day-to-day. Most candidates pass SC-900 in a few weeks then spend two to three months on SC-300.
SC-300 vs SC-200 — different security roles?
Different angles on Microsoft security. SC-300 is the Identity and Access Administrator Associate cert — it focuses on operating Microsoft Entra ID end-to-end (identities, authentication, Conditional Access, workload identities, governance). SC-200 is the Security Operations Analyst Associate cert — it focuses on running Microsoft Defender XDR and Sentinel as a SOC analyst. They overlap on Conditional Access and Microsoft Entra ID Protection, but SC-300 goes much deeper on identity and SC-200 covers a broader detection / response surface.
Where SC-300 fits
Certification paths that include SC-300
SC-300 is the Microsoft Identity and Access Administrator Associate cert. It pairs with SC-900 as recommended fundamentals and is one of the prereqs for SC-100 (Cybersecurity Architect Expert). Tap any linked exam below to see its dedicated study app page.
SC-300 sits at the identity-admin Associate tier. SC-900 builds the cross-cutting Microsoft security vocabulary; SC-100 is the Expert next step. SC-200 is the natural sibling for SecOps-focused candidates.
Ready to pass SC-300?
Download Azure Mastery free. 357 SC-300 practice questions across all four domains, AI score prediction, full-length exam simulator, adaptive study plan. iPhone & iPad.