Browse Certification Practice Tests by Exam Family

Microsoft SC-300 Cheat Sheet: Identity and Access

Review the Microsoft Identity and Access Administrator (SC-300) scope, Microsoft Entra ID, Conditional Access, MFA, privileged access, app consent, lifecycle, and governance traps before practicing.

SC-300 is an identity exam. Use this cheat sheet to keep the access-control model clear: who the subject is, what resource is being accessed, which conditions apply, and how Microsoft Entra governance keeps access current.

Use this with practice. Review the identity checkpoints, then return to the SC-300 exam page for sample questions and update tracking.

Open SC-300 practice page Compare Microsoft Security routes

Exam snapshot

FieldDetail
IssuerMicrosoft
Certification laneMicrosoft Identity and Access Administrator
Exam codeSC-300
Main scopeMicrosoft Entra identity, authentication, authorization, lifecycle, applications, and governance
IT Mastery statusSample questions available

Identity map

AreaWhat to knowCommon trap
Authentication methodsMFA, passwordless, registration, method policy, user rollout, and risk-based enforcementAssuming MFA works before users have registered methods
Conditional AccessUser, group, app, device, location, risk, grant controls, and session controlsApplying broad policies without exclusions or break-glass planning
Privileged accessPIM, eligible roles, activation, approval, audit, access reviews, and least privilegeMaking privilege permanent because activation feels inconvenient
App access and consentApp registrations, delegated permissions, application permissions, admin consent, and scopesTreating consent as harmless when it grants tenant data access
External identitiesB2B collaboration, guest access, entitlement management, lifecycle, and access reviewsSharing internal accounts with partners
Identity governanceAccess packages, reviews, lifecycle workflows, group governance, and stale-access removalOnly granting access and never reviewing it

Must-know distinctions

DistinctionHow to decide
Authentication vs authorizationAuthentication proves identity; authorization decides what the identity can do.
MFA vs Conditional AccessMFA is a control; Conditional Access decides when and where controls apply.
Eligible role vs active roleEligible users can activate a role; active users currently hold the role.
Delegated permission vs application permissionDelegated access acts as a signed-in user; application access acts as the app itself.
Guest access vs external accessGuest access brings an external identity into the tenant; external access enables communication across tenants.
Access review vs access packageReviews validate existing access; packages bundle access for request and lifecycle management.

High-yield checklist

  • Identify the identity type: employee, admin, guest, workload, or application.
  • Check whether the issue is sign-in, consent, role assignment, lifecycle, or governance.
  • Apply least privilege before broad administrator roles.
  • Use Conditional Access when the scenario includes risk, device state, location, app, or session conditions.
  • Use PIM for privileged roles that should not be permanently active.
  • Use access reviews for stale group, guest, or privileged access.
  • Use app consent governance when third-party or internal apps request tenant data.
  • Use passwordless or stronger authentication when reducing password risk is the goal.
  • Keep break-glass accounts and testing in mind for restrictive policies.

Common traps

  • Choosing a new group when the real problem is stale access review.
  • Assigning global administrator for helpdesk tasks.
  • Ignoring application permissions because no human user is involved.
  • Applying Conditional Access without considering service accounts or emergency access.
  • Treating guest access as an unmanaged exception.
  • Solving a lifecycle problem with one-time manual cleanup only.

Practice strategy

For SC-300 misses, classify the item as authentication, authorization, app consent, privileged access, external identity, or governance. Then explain which Microsoft Entra control changes access over time, not just at the moment of creation.

Revised on Monday, May 25, 2026