
Microsoft Identity and Access Administrator - SC-300 Exam Questions
QUESTION NO: 1
You have an Azure Active Directory (Azure AD) tenant named contoso.com.
All users who run applications registered in Azure AD are subject to conditional access policies.
You need to prevent the users from using legacy authentication.
What should you include in the conditional access policies to filter out legacy authentication attempts?
You have an Azure Active Directory (Azure AD) tenant named contoso.com.
All users who run applications registered in Azure AD are subject to conditional access policies.
You need to prevent the users from using legacy authentication.
What should you include in the conditional access policies to filter out legacy authentication attempts?
Correct Answer: D
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 2
You have an Azure subscription that contains an Azure Automation account named Automation1 and an Azure key vault named Vault1. Vault1 contains a secret named Secret 1.
You enable a system-assigned managed identity for Automation1.
You need to ensure that Automation! can read the contents of Secret1. The solution must meet the following requirements:
* Prevent Automation1 from accessing other secrets stored in Vault1.
* Follow the principle of least privilege.
What should you do?
You have an Azure subscription that contains an Azure Automation account named Automation1 and an Azure key vault named Vault1. Vault1 contains a secret named Secret 1.
You enable a system-assigned managed identity for Automation1.
You need to ensure that Automation! can read the contents of Secret1. The solution must meet the following requirements:
* Prevent Automation1 from accessing other secrets stored in Vault1.
* Follow the principle of least privilege.
What should you do?
Correct Answer: D
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 3
Your company has an Azure Active Directory (Azure AD) tenant named contoso.com.
The company is developing a web service named App1.
You need to ensure that App1 can use Microsoft Graph to read directory data in contoso.com.
Which three actions should yon perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them In the correct order.

Your company has an Azure Active Directory (Azure AD) tenant named contoso.com.
The company is developing a web service named App1.
You need to ensure that App1 can use Microsoft Graph to read directory data in contoso.com.
Which three actions should yon perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them In the correct order.

Correct Answer:

Explanation:

According to the Microsoft SC-300: Identity and Access Administrator Study Guide and Microsoft Learn module "Implement and manage enterprise applications," when developing an application that needs to access Microsoft Graph or other protected APIs on behalf of an organization, you must perform several configuration steps within Azure Active Directory (Azure AD).
Step 1 - Create an app registration:
Every application that requires access to Microsoft Graph must be registered in Azure AD. The registration process establishes an identity for the app and generates an Application (client) ID and a directory (tenant) ID.
This is done in Azure portal # Azure Active Directory # App registrations # New registration . This enables Azure AD to issue tokens to the app.
Step 2 - Add app permissions:
After registration, you must configure permissions under API permissions in the app's registration settings.
For server-to-server access (no user sign-in), Application permissions are used; for delegated access (on behalf of a user), Delegated permissions are added. In this case, since App1 will read directory data from Microsoft Graph, you assign the Microsoft Graph # Directory.Read.All permission.
Step 3 - Grant admin consent:
Application permissions require admin consent before the app can access directory data. An Azure AD administrator must grant these permissions by selecting "Grant admin consent for contoso.com." This allows the app to use the permissions organization-wide.
From Microsoft's documentation:
"To enable an application to call Microsoft Graph, register the app, configure required API permissions, and grant admin consent for those permissions."
# Correct Answer Order:
* Create an app registration
* Add app permissions
* Grant admin consent
QUESTION NO: 4
You have a Microsoft 365 E5 subscription that contains two groups named Group1 and Group2 and the users shown in the following table.

The subscription contains a Conditional Access policy that has the following settings:
* Name: Policy1
Target resources
* Include
* All cloud apps
* Access controls
* Grant
* Requite multifactor authentication
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

You have a Microsoft 365 E5 subscription that contains two groups named Group1 and Group2 and the users shown in the following table.

The subscription contains a Conditional Access policy that has the following settings:
* Name: Policy1
Target resources
* Include
* All cloud apps
* Access controls
* Grant
* Requite multifactor authentication
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
User1 must use multifactor authentication (MFA) when signing in to Microsoft 365 apps. = Yes User2 must use multifactor authentication (MFA) when signing in to Microsoft 365 apps. = Yes User3 must use multifactor authentication (MFA) when signing in to Microsoft 365 apps. = No Comprehensive and Detailed Explanation with all Microsoft SC-300: Identity and Access Administrator documents : = In Conditional Access, enforcement is determined by Assignments # Users or workload identities (which specify who the policy applies to) and Target resources (which specify what apps/resources are protected).
When a policy's Grant control is set to Require multifactor authentication , all identities included in the policy's user assignment scope must perform MFA when accessing the targeted resources. Being a member of multiple groups does not weaken enforcement; if a user is in any included group, the policy applies.
Conversely, users not included in the policy's user assignment scope are not prompted by that policy, even if they hold privileged roles. Holding the Global Administrator role does not automatically force MFA unless the tenant uses Security defaults or a Conditional Access policy targets that admin account or its group.
Applying this to the scenario: Policy1 targets All cloud apps (so the apps side is universal), and-given the group context-its user assignment is scoped to Group1 . User1 (Group1) and User2 (Group1 and Group2) are both in scope and therefore must perform MFA. User3 is only in Group2 ; since Group2 is not within the policy's user assignment, Policy1 does not apply to User3, despite the Global Administrator role. Hence:
Yes for User1, Yes for User2, and No for User3.
QUESTION NO: 5
You have an Azure AD tenant that contains the users shown in the following table.

User2 reports that he can only configure multi-factor authenticating (MFA) to use the Microsoft Authenticator app.
You need to ensure that User2 can configure alternate MFA methods.
Which configuration is required, and which user should perform the configuration? To answer, select the appropriate options in the answer area.

You have an Azure AD tenant that contains the users shown in the following table.

User2 reports that he can only configure multi-factor authenticating (MFA) to use the Microsoft Authenticator app.
You need to ensure that User2 can configure alternate MFA methods.
Which configuration is required, and which user should perform the configuration? To answer, select the appropriate options in the answer area.

Correct Answer:

Explanation:
In Microsoft Entra ID (Azure AD), Security Defaults is a built-in baseline security configuration that enforces basic identity protection, such as requiring all users to register for multi-factor authentication (MFA) using the Microsoft Authenticator app. When security defaults are enabled, users cannot select alternate MFA methods (like SMS or phone call).
According to the Microsoft SC-300 Official Study Guide and Azure AD Identity Protection documentation , only administrators with elevated security roles-specifically the Security Administrator, Global Administrator, or Conditional Access Administrator-can enable or disable security defaults.
Here's the detailed reasoning:
* User1 (Security Administrator): This role can manage identity security settings, including modifying MFA configurations and security defaults.
* User2 (Privileged Authentication Administrator): This role can reset MFA details for other users but cannot modify tenant-wide MFA or security default settings.
* User3 (Service Support Administrator): This role is limited to viewing service health and support tickets and has no permissions to modify security configurations.
Since User2 is restricted by security defaults (which enforce Microsoft Authenticator only), the only way to allow alternative MFA methods is to disable or customize security defaults. That configuration must be done by User1 (Security Administrator).
Microsoft Documentation: "To enable or disable security defaults, you must be a Global Administrator, Security Administrator, or Conditional Access Administrator."

QUESTION NO: 6
You have an Azure subscription named Sub1 that contains a resource group named RG1. RG1 contains two Azure key vaults named KV1 and KV2 that use Azure role-based access control (Azure RBAC).
The subscription contains the users shown in the following table.

KV1 contains a secret named Secret 1. KV2 contains a secret named Secret2.
Which users can read the values of each secret? To answer, select the appropriate options in the answer area.
NOTE Each correct selection is worth one point.

You have an Azure subscription named Sub1 that contains a resource group named RG1. RG1 contains two Azure key vaults named KV1 and KV2 that use Azure role-based access control (Azure RBAC).
The subscription contains the users shown in the following table.

KV1 contains a secret named Secret 1. KV2 contains a secret named Secret2.
Which users can read the values of each secret? To answer, select the appropriate options in the answer area.
NOTE Each correct selection is worth one point.

Correct Answer:

Explanation:

QUESTION NO: 7
Your network contains an on-premises Active Directory domain named contoso.com. The domain contains the objects shown in the following table.

You install Microsoft Entra Connect. You configure the Domain and OU filtering settings as shown in the Domain and OU Filtering exhibit. (Click the Domain and OU Filtering tab.)

You configure the Filter users and devices settings as shown in the Filter Users and Devices exhibit. (Click the Filter Users and Devices tab.) For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Your network contains an on-premises Active Directory domain named contoso.com. The domain contains the objects shown in the following table.

You install Microsoft Entra Connect. You configure the Domain and OU filtering settings as shown in the Domain and OU Filtering exhibit. (Click the Domain and OU Filtering tab.)

You configure the Filter users and devices settings as shown in the Filter Users and Devices exhibit. (Click the Filter Users and Devices tab.) For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
< User1 syncs to the Microsoft Entra tenant: Yes
User2 syncs to the Microsoft Entra tenant: No
Group2 syncs to the Microsoft Entra tenant: Yes
QUESTION NO: 8
Your network contains an on-premises Active Directory domain that syncs to an Azure Active Directory (Azure AD) tenant- Users sign in to computers that run Windows 10 and are joined to the domain.
You plan to implement Azure AD Seamless Single Sign-On (Azure AD Seamless SSO).
You need to configure the computers for Azure AD Seamless SSO.
What should you do?
Your network contains an on-premises Active Directory domain that syncs to an Azure Active Directory (Azure AD) tenant- Users sign in to computers that run Windows 10 and are joined to the domain.
You plan to implement Azure AD Seamless Single Sign-On (Azure AD Seamless SSO).
You need to configure the computers for Azure AD Seamless SSO.
What should you do?
Correct Answer: A
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 9
You have an Azure subscription named Sub1 that uses Microsoft Entra Permissions Management. Sub1 contains a user named User1. User1 is granted multiple permissions across Sub1.
You need to replace all the permissions granted to User1 with read-only permissions. The solution must minimize administrative effort.
What should you do on the Remediation tab in Permissions Management?
You have an Azure subscription named Sub1 that uses Microsoft Entra Permissions Management. Sub1 contains a user named User1. User1 is granted multiple permissions across Sub1.
You need to replace all the permissions granted to User1 with read-only permissions. The solution must minimize administrative effort.
What should you do on the Remediation tab in Permissions Management?
Correct Answer: B
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 10
You have a Microsoft Entra tenant that contains the users shown in the following table.

The tenant contains the administrative units shown in the following table.

You perform the following actions:
* Assign User1 the User Administrator role for AU2.
* Assign User3 the Groups Administrator role for AU1.
* Assign User5 the Authentication Administrator role for AU3.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

You have a Microsoft Entra tenant that contains the users shown in the following table.

The tenant contains the administrative units shown in the following table.

You perform the following actions:
* Assign User1 the User Administrator role for AU2.
* Assign User3 the Groups Administrator role for AU1.
* Assign User5 the Authentication Administrator role for AU3.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:

QUESTION NO: 11
You have a Microsoft Entra tenant that contains the users shown in the following table:

Admin4 creates a Conditional Access policy named Policy1 by using the " Require multifactor authentication for Azure management " template.
Which users will be required to use multi-factor authentication (MFA) the next time they sign in?
You have a Microsoft Entra tenant that contains the users shown in the following table:

Admin4 creates a Conditional Access policy named Policy1 by using the " Require multifactor authentication for Azure management " template.
Which users will be required to use multi-factor authentication (MFA) the next time they sign in?
Correct Answer: C
QUESTION NO: 12
Your network contains an on-premises Active Directory domain that sync to an Azure Active Directory (Azure AD) tenant. The tenant contains the shown in the following table.

All the users work remotely.
Azure AD Connect is configured in Azure as shown in the following exhibit.

Connectivity from the on-premises domain to the internet is lost.
Which user can sign in to Azure AD?
Your network contains an on-premises Active Directory domain that sync to an Azure Active Directory (Azure AD) tenant. The tenant contains the shown in the following table.

All the users work remotely.
Azure AD Connect is configured in Azure as shown in the following exhibit.

Connectivity from the on-premises domain to the internet is lost.
Which user can sign in to Azure AD?
Correct Answer: B
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).




