Microsoft Identity and Access Administrator

Here you have the best Microsoft SC-300 practice exam questions

  • You have 413 total questions across 83 pages (5 per page)
  • These questions were last updated on February 4, 2026
  • This site is not affiliated with or endorsed by Microsoft.
Question 1 of 413
You have an Azure Active Directory (Azure AD) tenant that contains the following objects:
✑ A device named Device1
✑ Users named User1, User2, User3, User4, and User5
✑ Groups named Group1, Group2, Group3, Group4, and Group5
The groups are configured as shown in the following table.
Exam SC-300: Question 1 - Image 1
To which groups can you assign a Microsoft Office 365 Enterprise E5 license directly?
Suggested Answer: E

In Azure Active Directory, Microsoft 365 Enterprise E5 licenses can be assigned to both security groups and Microsoft 365 groups, provided these groups have the 'SecurityEnabled' attribute set to true. Assuming the groups were created in the Azure AD portal where the 'SecurityEnabled' attribute is true by default, licenses can be assigned directly to the following groups: Group1, Group2, Group4, and Group5. Group3 is a dynamic device group, which does not make sense for user-based licensing like Office 365 Enterprise E5, so it is excluded. Hence, licenses can be assigned to Group1, Group2, Group4, and Group5.

Community votes

No votes yet

Question 2 of 413
You have a Microsoft Exchange organization that uses an SMTP address space of contoso.com.
Several users use their contoso.com email address for self-service sign-up to Azure Active Directory (Azure AD).
You gain global administrator privileges to the Azure AD tenant that contains the self-signed users.
You need to prevent the users from creating user accounts in the contoso.com Azure AD tenant for self-service sign-up to Microsoft 365 services.
Which PowerShell cmdlet should you run?
Suggested Answer: A

To prevent users from creating user accounts in the contoso.com Azure AD tenant for self-service sign-up to Microsoft 365 services, you need to use the Set-MsolCompanySettings cmdlet. This cmdlet allows you to configure settings at the company level, including the ability to control whether users can perform self-service sign-up with the -AllowAdHocSubscriptions parameter set to $false. This will disable all self-service sign-ups for Microsoft cloud services in the tenant.

Community votes

No votes yet

Question 3 of 413
You have a Microsoft 365 tenant that uses the domain named fabrikam.com. The Guest invite settings for Azure Active Directory (Azure AD) are configured as shown in the exhibit. (Click the Exhibit tab.)
Exam SC-300: Question 3 - Image 1
A user named bsmith@fabrikam.com shares a Microsoft SharePoint Online document library to the users shown in the following table.
Exam SC-300: Question 3 - Image 2
Which users will be emailed a passcode?
Suggested Answer: A

User2 will receive an email passcode. User1, being an existing guest user in the fabrikam.com domain, will continue using their existing authentication method and will not be emailed a passcode. User3, being a user within the fabrikam.com domain, will also not be emailed a passcode as they are already part of the organization.

Community votes

No votes yet

Question 4 of 413
You have 2,500 users who are assigned Microsoft Office 365 Enterprise E3 licenses. The licenses are assigned to individual users.
From the Groups blade in the Azure Active Directory admin center, you assign Microsoft 365 Enterprise E5 licenses to the users.
You need to remove the Office 365 Enterprise E3 licenses from the users by using the least amount of administrative effort.
What should you use?
Suggested Answer: C

The Licenses blade in the Azure Active Directory admin center is the correct tool for managing and removing licenses from users with minimal administrative effort. This interface allows administrators to view and modify license assignments for individual users or entire groups. By navigating to the Licenses blade, you can efficiently manage the reassignment or removal of Office 365 Enterprise E3 licenses after assigning Microsoft 365 Enterprise E5 licenses to the users.

Community votes

No votes yet

Question 5 of 413
HOTSPOT -
You have a Microsoft 365 tenant named contoso.com.
Guest user access is enabled.
Users are invited to collaborate with contoso.com as shown in the following table.
Exam SC-300: Question 5 - Image 1
From the External collaboration settings in the Azure Active Directory admin center, you configure the Collaboration restrictions settings as shown in the following exhibit.
Exam SC-300: Question 5 - Image 2
From a Microsoft SharePoint Online site, a user invites user3@adatum.com to the site.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:
Exam SC-300: Question 5 - Image 3
Suggested Answer:
Box 1: Yes -
Invitations can only be sent to outlook.com. Therefore, User1 can accept the invitation and access the application.

Box 2. Yes -
Invitations can only be sent to outlook.com. However, User2 has already received and accepted an invitation so User2 can access the application.

Box 3. No -
Invitations can only be sent to outlook.com. Therefore, User3 will not receive an invitation. Exam SC-300: Question 5 - Image 4

Community votes

No votes yet

About the Microsoft SC-300 Certification Exam

About the Exam

The Microsoft SC-300 (Microsoft Identity and Access Administrator) validates your knowledge and skills. Passing demonstrates proficiency and can boost your career prospects in the field.

How to Prepare

Work through all 413 practice questions across 83 pages. Focus on understanding the reasoning behind each answer rather than memorizing responses to be ready for any variation on the real exam.

Why Practice Exams?

Practice exams help you familiarize yourself with the question format, manage your time, and reduce anxiety on the test day. Our SC-300 questions are regularly updated to reflect the latest exam objectives.