Exam Details

  • Exam Code
    :SC-300
  • Exam Name
    :Microsoft Identity and Access Administrator
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :305 Q&As
  • Last Updated
    :Mar 29, 2025

Microsoft Microsoft Certifications SC-300 Questions & Answers

  • Question 141:

    You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table.

    User1 is the owner of Group1.

    You create an access review that has the following settings:

    1.

    Users to review: Members of a group

    2.

    Scope: Everyone

    3.

    Group: Group1

    4.

    Reviewers: Members (self)

    Which users can perform access reviews for User3?

    A. User1, User2, and User3

    B. User3 only

    C. User1 only

    D. User1 and User2 only

  • Question 142:

    You have an Azure Active Directory (Azure AD) tenant named conto.so.com that has Azure AD Identity Protection enabled. You need to Implement a sign-in risk remediation policy without blocking access. What should you do first?

    A. Configure access reviews in Azure AD.

    B. Enforce Azure AD Password Protection.

    C. implement multi-factor authentication (MFA) for all users.

    D. Configure self-service password reset (SSPR) for all users.

  • Question 143:

    You have a Microsoft Exchange organization that uses an SMTP' address space of contoso.com.

    Several users use their contoso.com email address for self-service sign up to Azure Active Directory (Azure AD).

    You gain global administrator privileges to the Azure AD tenant that contains the self-signed users.

    You need to prevent the users from creating user accounts in the contoso.com Azure AD tenant for self-service sign-up to Microsoft 365 services.

    Which PowerShell cmdlet should you run?

    A. Set-MsolCompanySettings

    B. Set-MsolDomainFederationSettings

    C. Update-MsolfederatedDomain

    D. Set-MsolDomain

  • Question 144:

    Your network contains an on-premises Active Directory domain that syncs to an Azure Active Directory (Azure AD) tenant. The tenant contains the users shown in the following table.

    All the users work remotely.

    Azure AD Connect is configured in Azure AD as shown in the following exhibit.

    Connectivity from the on-premises domain to the internet is lost. Which users can sign in to Azure AD?

    A. User1 only

    B. User1 and User 3 only

    C. User1, and User2 only

    D. User1, User2, and User3

  • Question 145:

    You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains an Azure AD enterprise application named App1.

    A contractor uses the credentials of [email protected].

    You need to ensure that you can provide the contractor with access to App1. The contractor must be able to authenticate as [email protected].

    What should you do?

    A. Run the New-AzureADMSInvitation cmdlet.

    B. Configure the External collaboration settings.

    C. Add a WS-Fed identity provider.

    D. Implement Azure AD Connect.

  • Question 146:

    You have a Microsoft 365 tenant.

    All users have computers that run Windows 10. Most computers are company-owned and joined to Azure Active Directory (Azure AD). Some computers are user-owned and are only registered in Azure AD.

    You need to prevent users who connect to Microsoft SharePoint Online on their user-owned computer from downloading or syncing files. Other users must NOT be restricted.

    Which policy type should you create?

    A. a Microsoft Cloud App Security activity policy that has Microsoft Office 365 governance actions configured

    B. an Azure AD conditional access policy that has session controls configured

    C. an Azure AD conditional access policy that has client apps conditions configured

    D. a Microsoft Cloud App Security app discovery policy that has governance actions configured

  • Question 147:

    You have an Azure Active Directory (Azure AD) tenant named contoso.com.

    You implement entitlement management to provide resource access to users at a company named Fabrikam, Inc. Fabrikam uses a domain named fabrikam.com.

    Fabrikam users must be removed automatically from the tenant when access is no longer required.

    You need to configure the following settings:

    1.

    Block external user from signing in to this directory: No Remove external user: Yes

    2.

    Number of days before removing external user from this directory: 90 What should you configure on the Identity Governance blade?

    A. Access packages

    B. Entitlement management settings

    C. Terms of use

    D. Access reviews

  • Question 148:

    You have an Azure Active Directory (Azure AD) tenant named contoso.com.

    All users who run applications registered in Azure AD are subject to conditional access policies.

    You need to prevent the users from using legacy authentication.

    What should you include in the conditional access policies to filter out legacy authentication attempts?

    A. a cloud apps or actions condition

    B. a user risk condition

    C. a client apps condition

    D. a sign-in risk condition

  • Question 149:

    Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while

    others might not have a correct solution.

    After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

    You have an Azure Active Directory (Azure AD) tenant that syncs to an Active Directory forest.

    You discover that when a user account is disabled in Active Directory, the disabled user can still authenticate to Azure AD for up to 30 minutes.

    You need to ensure that when a user account is disabled in Active Directory, the user account is immediately prevented from authenticating to Azure AD.

    Solution: You configure password writeback.

    Does this meet the goal?

    A. Yes

    B. No

  • Question 150:

    Your company has an Azure Active Directory (Azure AD) tenant named contosri.com. The company has the business partners shown in the following table.

    users can request access by using package 1.

    Users at Fabrikam and Litware use ail then respective domain names for email addresses.

    You plan to create an access package named packaqel that will be accessible only to the Fabrikam and Litware users.

    You need to configure connected organizations for Fabrikam and litware so that any of their users can request access by using package1.

    What is the minimum of connected organization that you should create.

    A. 1

    B. 2

    C. 3

    D. 4

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SC-300 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.