SC-300
Price range: $49.00 through $75.00
- Last updated
- August 12, 2026
- Product
- SC-300
- Exam
- SC-300
- Vendor
- Microsoft
Review product details
The full product description is available below before you decide.
Choose available options
Select the product option that best matches your preparation needs.
Need help before ordering?
Read FAQs or contact support with your question.
SC-300 Practice Test: Design and Operate Identity with Zero Trust
Practice identity lifecycle, authentication, authorization, workload identity, and governance decisions across Microsoft Entra and hybrid environments.
Think in identity lifecycles, not isolated settings
An identity and access administrator manages access from creation to removal. SC-300 scenarios often connect multiple stages: provisioning an identity, choosing authentication, granting appropriate authorization, monitoring access, reviewing risk, and removing privileges when circumstances change.
The strongest preparation combines Microsoft Entra portal experience with PowerShell, hybrid Active Directory knowledge, and the ability to interpret logs and reports. Familiarity with Azure and Microsoft 365 workloads helps you understand what the identities are protecting.
Four responsibility areas
User identities
Tenant settings, roles, users, groups, devices, licenses, external identities, cross-tenant access, and hybrid synchronization.
Authentication and access
MFA, authentication methods, Conditional Access, Identity Protection, passwordless access, SSO, and application access.
Workload identities
App registrations, service principals, managed identities, permissions, consent, certificates, secrets, and workload federation.
Identity governance
Entitlement management, access packages, access reviews, privileged identity management, lifecycle workflows, and automation.
The official ranges are 20–25% for user identities, 25–30% for authentication and access, and 20–25% each for workload identities and governance.
Use a Zero Trust decision sequence
- Verify explicitly: identify the signals available—user, device, location, risk, application, authentication strength, and session.
- Use least privilege: choose the narrowest role, scope, duration, and approval model that satisfies the task.
- Assume breach: monitor risky behavior, limit impact, require stronger controls, and retain evidence for investigation.
- Automate lifecycle events: joiner, mover, and leaver processes should remove manual gaps and stale access.
Lab evidence you should be able to produce
- A Conditional Access policy tested safely before enforcement.
- A user or group provisioned and licensed with the correct administrative scope.
- An enterprise application configured for SSO and appropriate consent.
- A managed identity used without storing an application secret.
- An access package and access review with expiration and approval controls.
- A privileged role activated through PIM with justification, duration, and audit history.