Skip Navigation Links
 

Microsoft - SC-300: Microsoft Identity and Access Administrator

Sample Questions

Question: 454
Measured Skill: Plan and automate identity governance (25–30%)

You have a Microsoft Entra tenant that contains a user named User1 and uses Privileged Identity Management (PIM).

At 08:00 on Tuesday, User1 requests the activation of a Microsoft Entra role that requires approval.

You need to identify when the request will be deleted automatically if an approver has NOT responded.

What should you identify?

A08:00 on Sunday
B 08:00 on Thursday
C 08:00 on Wednesday
D 20:00 on Tuesday

Correct answer: C

Explanation:

Privileged Identity Management (PIM) in Microsoft Entra ID allows you to configure roles to require approval for activation, and choose one or multiple users or groups as delegated approvers. Delegated approvers have 24 hours to approve requests. If a request isn't approved within 24 hours, then the eligible user must re-submit a new request. The 24-hour approval time window isn't configurable.

Reference: Approve or deny requests for Microsoft Entra roles in Privileged Identity Management



Question: 455
Measured Skill: Plan and automate identity governance (25–30%)

You have a Microsoft Entra tenant named contoso.com.

You have a query named Query1 that contains the following statements.

SignInLogs
| where ResultType != 0 // 0 indicates success
| project TimeGenerated, UserPrincipalName, AppDisplayName,
ResourceDisplayName, ResultType, ResultDescription,
Location, IPAddress
| order by TimeGenerated desc

You need to ensure that you can run Query1 against the Microsoft Entra activity logs. The solution must minimize administrative effort.

What should you do first?

AFrom Diagnostic settings in the Microsoft Entra admin center, send the logs to a Log Analytics workspace.
B From Diagnostic settings in the Microsoft Entra admin center, stream the logs to an Azure event hub.
C From Diagnostic settings in the Microsoft Entra admin center, archive the logs to a storage account.
D From the Azure portal, create a data collection rule (DCR).

Correct answer: A

Explanation:

The query uses the SignInLogs table, which is available in Azure Monitor Log Analytics. To run KQL queries such as Query1 against Microsoft Entra sign-in activity logs, you must first configure Microsoft Entra diagnostic settings to send SigninLogs to a Log Analytics workspace.

Reference: Tutorial: Create a Log Analytics workspace to analyze sign-in logs



Question: 456
Measured Skill: Implement and manage user identities (20–25%)

You have a Microsoft 365 E5 subscription and an Azure Subscription that contains two administrative units named AU1 and AU2.

You create five users as shown in the following table.



For which users can User2 and User3 reset passwords?

(To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.)

www.cert2brain.com

AUser2 can reset password for: User1 and User4 only
User3 can reset password for: User1, User2, and User4
B User2 can reset password for: User1, User3, User4, and User5
User3 can reset password for: User2 and User4 only
C User2 can reset password for: User4 and User5 only
User3 can reset password for: User1 and User2 only
D User2 can reset password for: User4 only
User3 can reset password for: User1 only
E User2 can reset password for: User5 only
User3 can reset password for: User1, User2, and User4
F User2 can reset password for: User5 only
User3 can reset password for: User5 only

Correct answer: C

Explanation:

User2 is a Helpdesk Administrator scoped to AU1. User2 can reset the password for Helpdesk Admins (User4) and Users without admin role (User5) but not for Privileged Authentication Admins (User3).

User3 is a Privileged Authentication Admin scoped to AU2. User3 can reset the passwords for all users in AU2.

In the following table, the columns list the roles that can reset passwords and invalidate refresh tokens. The rows list the roles for which their password can be reset. For example, a Password Administrator can reset the password for Directory Readers, Guest Inviter, Password Administrator, and users with no administrator role. If a user is assigned any other role, the Password Administrator cannot reset their password.

References:

Who can reset passwords

Assign roles with administrative unit scope



Question: 457
Measured Skill: Implement and manage user identities (20–25%)

You have a Microsoft 365 E5 subscription that contains a user named User1.

User1 needs to perform the following tasks:
  • Create a Microsoft 365 group named Group1 that has dynamic user membership.
  • Assign a Microsoft Entra Suite license to Group1.
In which portals can User1 perform each task?

(To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.)

www.cert2brain.com

ACreate Group1: Microsoft Entra admin center only
Assign a Microsoft Entra Suite license to Group1: Microsoft 365 admin center only
B Create Group1: Microsoft 365 admin center only
Assign a Microsoft Entra Suite license to Group1: Microsoft Entra admin center and Microsoft 365 admin center only
C Create Group1: Microsoft Entra admin center and Microsoft 365 admin center only
Assign a Microsoft Entra Suite license to Group1: Microsoft Entra admin center only
D Create Group1: Microsoft Entra admin center and Microsoft Intune admin center only
Assign a Microsoft Entra Suite license to Group1: Microsoft 365 admin center only
E Create Group1: Microsoft Entra admin center, Microsoft 365 admin center, and Microsoft Intune admin center
Assign a Microsoft Entra Suite license to Group1: Microsoft Entra admin center and Microsoft 365 admin center only
F Create Group1: Microsoft Entra admin center, Microsoft 365 admin center, and Microsoft Intune admin center
Assign a Microsoft Entra Suite license to Group1: Microsoft Entra admin center, Microsoft 365 admin center, and Microsoft Intune admin center

Correct answer: A

Explanation:

To create a Microsoft 365 group with dynamic user membership, you must configure a dynamic membership rule. Dynamic User membership groups are created and managed in the Microsoft Entra admin center under Groups > New Group > Membership type = Dynamic User. The Microsoft 365 admin center and Intune admin center do not provide the interface for creating a Microsoft 365 group with dynamic membership rules.

Microsoft has moved license assignment management to the Microsoft 365 admin center. If you have security groups, mail enabled groups, or Microsoft 365 groups, you can assign or unassign licenses for those groups on the Licenses page in the Microsoft 365 admin center.

References:

Create or update a dynamic membership group in Microsoft Entra ID

Assign or unassign licenses to a group in the Microsoft 365 admin center



Question: 458
Measured Skill: Implement and manage user identities (20–25%)

You have a Microsoft 365 tenant that contains the administrative units shown in the following table.



The subscription contains the administrators shown in the following table.



The subscription contains the users shown in the following table.



For each of the following statements, select Yes if the statement is true. Otherwise, select No.

(NOTE: Each correct selection is worth one point.)

www.cert2brain.com

AAdmin1 can reset the password of User1: Yes
Admin2 can reset the password of User2: Yes
Admin3 can reset the password of User3: Yes
B Admin1 can reset the password of User1: Yes
Admin2 can reset the password of User2: Yes
Admin3 can reset the password of User3: No
C Admin1 can reset the password of User1: Yes
Admin2 can reset the password of User2: No
Admin3 can reset the password of User3: Yes
D Admin1 can reset the password of User1: No
Admin2 can reset the password of User2: Yes
Admin3 can reset the password of User3: No
E Admin1 can reset the password of User1: No
Admin2 can reset the password of User2: No
Admin3 can reset the password of User3: Yes
F Admin1 can reset the password of User1: No
Admin2 can reset the password of User2: No
Admin3 can reset the password of User3: No

Correct answer: C

Explanation:

In Microsoft Entra ID, for more granular administrative control, you can assign a Microsoft Entra role with a scope that's limited to one or more administrative units. When a Microsoft Entra role is assigned at the scope of an administrative unit, role permissions apply only when managing members of the administrative unit itself, and don't apply to tenant-wide settings or configurations.

Admin1 is a Password Administrator scoped to AU1. User1 is a member of AU1. Admin1 can reset the password of User1.

Admin2 is a Password Administrator scoped to AU2. User2 is a member of AU1. Admin2 cannot reset the password of User2.

Admin3 is a tenant-wide Password Administrator. Admin3 can reset the passwords of User1, User2, and User3.

Reference: Assign roles with administrative unit scope





 
Tags: exam, examcollection, exam simulation, exam questions, questions & answers, training course, study guide, vce, braindumps, practice test
 
 

© Copyright 2014 - 2026 by cert2brain.com