SC-300 Exam Details

  • Exam Code
    :SC-300
  • Exam Name
    :Microsoft Identity and Access Administrator
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :465 Q&As
  • Last Updated
    :May 29, 2026

Microsoft SC-300 Online Questions & Answers

  • Question 221:

    DRAG DROP

    You have an on-premises Microsoft Exchange organization that uses an SMTP address space of contoso.com.

    You discover that users use their email address for self-service sign-up to Microsoft 365 services.

    You need to gain global administrator privileges to the Azure Active Directory (Azure AD) tenant that contains the self-signed users.

    Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

    Select and Place:

  • Question 222:

    You have a Microsoft Entra tenant.

    You need to implement smart lockout with a lockout threshold of 10 failed sign-ins.

    What should you configure in the Microsoft Entra admin center?

    A. User risk policy
    B. Password protection
    C. Authentication strengths
    D. Sign-in risk policy

  • Question 223:

    You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Cloud Apps.

    You need to identify which users access Facebook from their devices and browsers. The solution must minimize administrative effort.

    What should you do first?

    A. From the Microsoft Defender for Cloud Apps portal, unsanctioned Facebook.
    B. Create an app configuration policy in Microsoft Endpoint Manager.
    C. Create a Defender for Cloud Apps access policy.
    D. Create a Conditional Access policy.

  • Question 224:

    HOTSPOT

    You have an Azure subscription that contains the resources shown in the following table.

    You need to configure access to Vault1. The solution must meet the following requirements:

    1. Ensure that User1 can manage and create keys in Vault1.

    2. Ensure that User2 can access a certificate stored in Vault1.

    3. Use the principle of least privilege.

    Which role should you assign to each user? To answer select the appropriate options in the answer area.

    NOTE: Each correct selection is worth one point.

  • Question 225:

    You need to modify the settings of the User administrator role to meet the technical requirements.

    Which two actions should you perform for the role? Each correct answer presents part of the solution.

    NOTE: Each correct selection is worth one point.

    A. Select Require justification on activation.
    B. Set all assignments to Active.
    C. Set all assignments to Eligible.
    D. Modify the Expire eligible assignments after setting.
    E. Select Require ticket information on activation.

  • Question 226:

    SIMULATION

    You need to assign a Windows 10/11 Enterprise E3 license to the Sg-Retail group.

    A. See the Explanation Below
    B. PlaceHolder
    C. PlaceHolder
    D. PlaceHolder

  • Question 227:

    A user named User1 receives an error message when attempting to access the Microsoft Defender for Cloud Apps portal.

    You need to identify the cause of the error. The solution must minimize administrative effort.

    What should you use?

    A. Log Analytics
    B. sign-in logs
    C. audit logs
    D. provisioning logs

  • Question 228:

    You have an Azure Active Directory (Azure AD) tenant named contoso.com.

    All users who run applications registered in Azure AD are subject to conditional access policies.

    You need to prevent the users from using legacy authentication.

    What should you include in the conditional access policies to filter out legacy authentication attempts?

    A. a cloud apps or actions condition
    B. a user risk condition
    C. a client apps condition
    D. a sign-in risk condition

  • Question 229:

    HOTSPOT

    How should the access be setup to the on-premises applications?

  • Question 230:

    You have an Azure subscription named Sub1 that contains a virtual machine named VM1.

    You need to enable Microsoft Entra login for VM1 and configure VM1 to access the resources in Sub1.

    Which type of identity should you assign to VM1?

    A. system-assigned managed identity
    B. Azure Automation account
    C. Microsoft Entra user account
    D. user-assigned managed identity

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SC-300 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.