Skip to main content

SC-300 Real Exam Questions

Microsoft Identity and Access Administrator

494 questions available · Page 1 of 50

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Hotspot

HOTSPOT

Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains computers that run Windows 11.

You have a Microsoft 365 E5 subscription.

You plan to enable hybrid join and enroll the computers in Microsoft Intune.

You need to recommend the software that should be deployed to the domain, and the actions that should be performed in Intune.

What should you include in the recommendation? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

stem image

Question diagram
Show answer and explanation
Correct answer diagram
Explanation

Box 1: Domain - Intune Connector for Active Directory

Deploy Microsoft Entra hybrid joined devices by using Intune and Windows Autopilot

Intune connector server requirements:
1. The Intune Connector for Active Directory must be installed on a computer that's running Windows
Server 2016 or later with.NET Framework version 4.7.2 or later.
2. The server hosting the Intune Connector must have access to the Internet and Active Directory.

Box 2: Intune - Modify the mobile device management (MDM) User scope

Set up Windows automatic MDM enrollment

1. Sign in to the Azure portal and select Microsoft Entra ID.
2. In the left hand pane, select Manage | Mobility (MDM and WIP) > Microsoft Intune.
3. Make sure users of a group included in MDM User scope. who deploy Microsoft Entra joined devices by using Intune and Windows are members 4. Use the default values in the MDM Terms of use URL, MDM Discovery URL, and MDM Compliance
URL boxes, and then select Save.

References:
https://learn.microsoft.com/en-us/autopilot/windows-autopilot-hybrid

Question 2 Single choice

You plan to deploy a new Azure AD tenant.

Which multifactor authentication (MFA) method will be enabled by default for the tenant?

  1. A

    Microsoft Authenticator

  2. B

    SMS

  3. C

    voice call

  4. D

    email OTP

Show answer and explanation

Correct answer: A

Explanation

A newly deployed Azure AD tenant has Microsoft Authenticator enabled as its default multifactor authentication method. It supports MFA through app-based approval or verification codes. SMS, voice call, and email OTP are separate authentication methods and are not the default MFA method identified for the new tenant.

Question 3 Single choice

You have a Microsoft Entra tenant.

You have the devices shown in the following table.

You configure Microsoft Entra Internet Access for the tenant.

On which devices can you use Global Secure Access?

  1. A

    Device1 only

  2. B

    Device3 only

  3. C

    Device1 and Device2 only

  4. D

    Device1, Device3, and Device4 only

  5. E

    Device1, Device2, Device3, and Device4

Show answer and explanation

Correct answer: B

Explanation

Among these devices, Device3 is the Microsoft Entra joined Windows 10 device and is the only one that meets the required platform and join combination for this Global Secure Access use. Device1 and Device4 are merely registered, while Device2 has no Microsoft Entra join relationship, so those devices do not qualify.

Question 4 Hotspot

HOTSPOT

You have a Microsoft Entra tenant that contains the users shown in the following table.

The tenant contains the administrative units shown in the following table.

The tenant contains the groups shown in the following table.

You perform the following actions:

  • Assign User1 the User Administrator role for AU2.
  • Assign User3 the Groups Administrator role for AU1.
  • Assign User5 the Authentication Administrator role for AU3.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

stem image

Question diagram
Show answer and explanation
Correct answer diagram
Explanation

User1 has the User Administrator role scoped to AU2, and User3 belongs to AU2, so User1 can perform supported user-management operations such as resetting User3’s password. User3’s Groups Administrator role is scoped to AU1, while Group2 belongs to AU2, so User3 cannot manage Group2. User5’s Authentication Administrator role scoped to AU3 permits management of authentication methods for users within that administrative unit, but it does not grant permission to configure tenant-wide authentication method policies.

Question 5 Hotspot

HOTSPOT

You have a Microsoft Entra tenant that contains the users shown in the following table.

You have the locations shown in the following table.

The tenant contains a named location that has the following configurations:

  • Name: Location1
  • Mark as trusted location: Enabled
  • IPv4 range: 10.10.0.0/16

MFA has a trusted IP address range of 193.17.17.0/24.

You have a Conditional Access policy that has the following settings:

Name: CAPolicy1

Assignments:

  • Users or workload identities: Group1
  • Cloud apps or actions: All cloud apps

Conditions:

  • Locations: All trusted locations

Access controls:

  • Grant access: Require multi-factor authentication
  • Session: 0 controls selected

Enable policy: On

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

stem image

Question diagram
Show answer and explanation
Correct answer diagram
Explanation

Microsoft Entra evaluates the public IP address seen by the service, not the client’s private IP address. Therefore, connections from Location1 are seen as 20.93.15.0/24, not 10.10.0.0/16, so the configured named location does not match those connections. Location2 is seen as 193.17.17.0/24, which is configured as an MFA trusted IP range. Users connecting from trusted IPs bypass per-user MFA. Conditional Access applies only to Group1, so the resulting MFA behavior depends on both the effective public IP and the user’s MFA configuration.

Question 6 Lab simulation

Simulation

Use the following login credentials as needed:

To enter your username, place your cursor in the Sign in box and click the username below.
To enter your password, place your cursor in the Enter password box and click the password below.

Microsoft 365 Username: [email protected]

Microsoft 365 Password: 1122334455667788

If the Microsoft 365 portal does not load successfully in the browser, press CTRL+K to reload the portal in a new browser tab.

The following information is for technical support purposes only:
Lab Instance: 99999999

You need to enforce multi-factor authentication (MFA) for users in the Executives group when they connect to Microsoft Office 365 apps. The solution must affect only the users in the Executives group.

To complete this task, sign in to the appropriate admin center.

Show answer and explanation

Section: (none)

Enforce multi-factor authentication when connecting to Microsoft Office 365 apps.

Set up multifactor authentication for Microsoft 365

Use Conditional Access policies. If your organization has more granular sign-in security needs, Conditional Access policies can offer you more control. Conditional Access lets you create and define policies that react to sign-in events and request additional actions before a user is granted access to an application or service.

Part 1: Create a Conditional Access policy

First, create a Conditional Access policy and assign your test group of users as follows:

Step 1: Sign in to the Microsoft Entra admin center as at least a Conditional Access Administrator.

Step 2: Browse to Protection > Conditional Access, select + New policy, and then select Create new policy.

Step 3: Enter a name for the policy, such as MFA Pilot.

Step 4: Under Assignments, select the current value under Users or workload identities.

Step 5: Under What does this policy apply to?, verify that Users and groups is selected.

Step 6: Under Include, choose Select users and groups, and then select Users and groups.

Since no one is assigned yet, the list of users and groups (shown in the next step) opens automatically.

Step 7: Browse for and select your Microsoft Entra group, such as MFA-Test-Group, and then choose Select.

[Select the Executives group]

We’ve selected the group to apply the policy to. In the next section, we configure the conditions under which to apply the policy.

Part 2: Configure the conditions for multifactor authentication

Now that the Conditional Access policy is created and a test group of users is assigned, define the cloud apps or actions that trigger the policy.

Configure which apps require multifactor authentication

Step 1: Select the current value under Cloud apps or actions, and then under Select what this policy applies to, verify that Cloud apps is selected.

Step 2: Under Include, choose Select apps. Since no apps are yet selected, the list of apps (shown in the next step) opens automatically.

Step 3: Browse the list of available apps and select Microsoft Office 365 apps.

[Select Microsoft Office 365 apps]

References:
https://learn.microsoft.com/en-us/entra/identity/authentication/tutorial-enable-azure-mfa
https://learn.microsoft.com/en-us/microsoft-365/admin/security-and-compliance/set-up-multi-factor-authentication

Question 7 Drag & drop

DRAG DROP

You have a Microsoft 365 E5 subscription and an Azure subscription.

You need to meet the following requirements:

1. Ensure that users can sign in to Azure virtual machines by using their Microsoft 365 credentials.

2. Delegate the ability to create new virtual machines.

What should you use for each requirement? To answer, drag the appropriate features to the correct requirements. Each feature may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

stem image

Question diagram
Show answer and explanation
Correct answer diagram
Explanation

Box 1: Azure role-based access control (RBAC)

Ensure that users can sign in to Azure virtual machines by using their Microsoft 365 credentials.

Organizations can improve the security of Windows virtual machines (VMs) in Azure by integrating with Azure Active Directory (Azure AD) authentication. You can then centrally control and enforce Azure role-based access control (RBAC) and Conditional Access policies that allow or deny access to the VMs.

There are many security benefits of using Azure AD-based authentication to log in to Windows VMs in Azure. They include:

* With Azure RBAC:

Specify who can log in to a VM as a regular user or with administrator privileges. When users join or leave your team, you can update the Azure RBAC policy for the VM to grant access as appropriate. When employees leave your organization and their user accounts are disabled or removed from Azure AD, they no longer have access to your resources.

* Use Azure AD credentials to log in to Windows VMs in Azure. The result is federated and managed domain users.

* Reduce reliance on local administrator accounts.

* etc.

Box 2: Azure AD built-in roles

Delegate the ability to create new virtual machines.

In Azure Active Directory (Azure AD), if another administrator or non-administrator needs to manage Azure AD resources, you assign them an Azure AD role that provides the permissions they need. For example, you can assign roles to allow adding or changing users, resetting user passwords, managing user licenses, or managing domain names.

References:
https://learn.microsoft.com/en-us/azure/active-directory/devices/howto-vm-sign-in-azure-ad-windows
https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference

Question 8 Single choice

You have an Azure subscription. The subscription contains 50 virtual machines that run Windows Server and have Login with Microsoft Entra ID enabled.

Users report that they cannot sign in to the virtual machines by using their Microsoft Entra credentials.

You need to ensure that the users can sign in to the virtual machines.

What should you do first?

  1. A

    From the Microsoft Entra admin center, delete the device registrations of the virtual machines.

  2. B

    Revoke the primary refresh token.

  3. C

    Enable SSH client support for OpenSSH.

  4. D

    Ensure that the virtual machines can access https://enterpriseregistration.windows.net.

Show answer and explanation

Correct answer: D

Explanation

Microsoft Entra sign-in for these Windows Server virtual machines depends on connectivity to the enterprise registration service. Ensuring that the machines can reach the enterprise registration endpoint allows the device identity operations required by Microsoft Entra login. Deleting registrations or revoking user tokens would not repair blocked service connectivity.

Question 9 Single choice

Administrators need a Microsoft Entra role only during approved maintenance windows, with multifactor authentication, justification, and a limited activation duration. Which assignment should be configured in Privileged Identity Management?

  1. A

    A time-bound eligible directory role assignment with the required activation controls

  2. B

    A permanent active Azure resource role assignment with no activation controls

  3. C

    An eligible Azure resource role assignment for the similarly named subscription role

  4. D

    An active group membership outside PIM that administrators retain between maintenance windows

Show answer and explanation

Correct answer: A

Explanation

An eligible Microsoft Entra directory role assignment keeps the administrators without standing role permissions between maintenance windows. PIM activation controls can require approval, MFA, justification, and a bounded activation duration when access is needed. Making the eligibility itself time-bound also limits the period during which an administrator may request activation.

Question 10 Single choice

You have a Microsoft 365 ES subscription that user Microsoft Defender for Cloud Apps and Yammer.

You need prevent users from signing in to Yammer from high-risk locations.

What should you do in the Microsoft Defender for Cloud Apps portal?

  1. A

    Create an access Policy.

  2. B

    Create an activity policy.

  3. C

    Unsanction Yammer.

  4. D

    Create an anomaly detection policy.

Show answer and explanation

Correct answer: A

Explanation

An access policy in Microsoft Defender for Cloud Apps controls whether a user may enter a cloud application session based on conditions such as location. It can therefore block Yammer access when the sign-in originates from a high-risk location. Activity and anomaly policies detect behavior rather than enforcing this sign-in boundary.