CertGrid
Microsoft Study Guide

SC-300: Microsoft Identity and Access Administrator Study Guide

SC-300 (Microsoft Identity and Access Administrator) validates your ability to design and operate identity and access in Microsoft Entra ID, covering identity provisioning, authentication, application access, and identity governance. It targets identity administrators, security engineers, and IT professionals who manage Entra ID tenants, Conditional Access, and privileged access. The exam is 120 minutes, scored 1000 with 700 to pass, and draws from roughly 644 question scenarios.

Domain 1: Implement Identities in Microsoft Entra ID

Key concepts you must know · 170 practice questions

Domain 2: Implement Authentication and Access Management

Key concepts you must know · 158 practice questions

Domain 3: Implement Access Management for Applications

Key concepts you must know · 154 practice questions

Domain 4: Plan and Implement Identity Governance

Key concepts you must know · 162 practice questions

SC-300 exam tips

Study guide FAQ

How is the SC-300 exam structured and scored?

It is roughly 120 minutes with multiple-choice, multi-select, case studies, and sometimes drag-and-drop or yes/no series. It is scored on a 1000-point scale with 700 required to pass, and questions are weighted across the four identity domains rather than counted equally.

Do I need hands-on Microsoft Entra ID experience to pass?

Yes. SC-300 is heavily scenario-based and assumes practical familiarity with the Microsoft Entra admin center - configuring Conditional Access, PIM, entitlement management, app registrations, and Entra Connect. Studying definitions alone is rarely enough; practice in a trial tenant is strongly recommended.

Which authentication method should I choose by default - PHS, PTA, or federation?

Microsoft recommends Password Hash Synchronization (PHS) for most organizations because it is simple, resilient, and enables leaked-credential detection. Choose Pass-through Authentication when on-prem password validation is required without storing hashes in the cloud, and federation (AD FS) only when an explicit requirement such as 'credentials must never leave on-premises' applies.

What is the difference between access reviews, PIM, and entitlement management?

Access reviews recertify existing access on a schedule (auto-removing it if not approved); PIM provides just-in-time, time-bound activation of privileged roles with approval and justification; entitlement management lets users request bundled resources (access packages) through a self-service catalog with approval and expiration. All three are Entra ID Governance / P2 features and are frequently combined in scenarios.