SC-300 Cheat Sheet 2026

The 30 highest-yield SC-300 facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

50 questions
100 min time limit
70.00% to pass
  1. Which claim in a JWT access token issued by Azure AD uniquely identifies the tenant that issued the token? tid
  2. Which Conditional Access control can restrict what users can do within a cloud application session without blocking access entirely? Session control: Use Conditional Access App Control
  3. Which Identity Protection configuration setting controls the percentage of the organization's users who must be covered by the MFA registration policy? Users scope — All users or specific groups
  4. Which report in Azure AD helps administrators identify users who have NOT registered for MFA? Authentication methods activity report
  5. What is the minimum number of authentication methods a user must register when SSPR is configured to require 2 methods? 2
  6. Which Entitlement Management feature allows users from partner organizations with a different Azure AD tenant to request access packages? Connected organizations
  7. Which Azure AD feature automatically detects when a user's credentials have been leaked on the dark web and flags their sign-in as high risk? Azure AD Identity Protection leaked credentials detection
  8. Which of the following authentication methods supports SMS as a verification option in Azure AD? Self-Service Password Reset (SSPR)
  9. Which Azure AD feature allows bulk invitation of multiple guest users by uploading a CSV file? Bulk invite users feature in the Azure portal
  10. A company wants to enforce that users can only access Microsoft 365 from compliant devices. Which Conditional Access grant control should be configured? Require device to be marked as compliant
  11. Which Azure AD feature allows users to reset their own passwords without contacting the helpdesk? Self-Service Password Reset (SSPR)
  12. An administrator configures a Conditional Access policy with the 'Require approved client app' grant control. Which scenario will this control block? A user accessing Exchange Online from a native mail app that is not Intune-managed
  13. A Privileged Role Administrator wants to prevent any user from having a permanent eligible Global Administrator assignment. Which PIM setting enforces this? Set assignment expiration for eligible assignments
  14. Which Azure AD cross-tenant access setting controls whether your users can be invited as guests into another organization's tenant? Outbound settings — B2B collaboration
  15. A Conditional Access policy is set to 'Report-only' mode. What is the effect on users? Policy evaluates but does not enforce; results are logged only
  16. What action does 'Apply results' perform at the end of an Access Review? It implements the decisions made during the review by adding or removing access
  17. An admin needs to automatically revoke all refresh tokens for a user suspected of compromise without deleting the account. Which action accomplishes this? Revoke sign-in sessions in Azure AD user properties
  18. An organization uses SSPR (Self-Service Password Reset). Which report shows which users have registered their authentication methods for SSPR? SSPR Registration Activity report in Azure AD > Monitoring > Usage & Insights
  19. A security team wants to detect when an Azure AD privileged role is assigned outside of PIM. Which monitoring approach should they implement? Azure Monitor alert on 'Add member to role' audit event outside PIM
  20. A company deploys Azure AD Password Protection on-premises. Which component on domain controllers enforces the banned password list? Azure AD Password Protection DC Agent
  21. An administrator needs to enforce that users can only register security information from trusted locations. Which Azure AD feature should be configured? Named Locations in Conditional Access
  22. An administrator needs to extend a user's expiring eligible role assignment without having the user re-activate. Which PIM action should the administrator take? Update the existing assignment's end date using the 'Extend' option
  23. A Privileged Identity Management (PIM) role assignment is set to 'eligible.' What must the user do before they can use the role? Activate the role themselves, optionally providing a justification
  24. In PIM for Azure resources, which assignment type makes a user a permanent owner of a resource without any activation required? Active assignment
  25. A user successfully completes SSPR to reset their password after being flagged by Identity Protection. What is the result on their user risk level? User risk is automatically remediated and reset to none
  26. An administrator enables Azure AD Security Defaults. Which statement about Security Defaults and MFA is correct? Security Defaults enforce MFA for all users and block legacy authentication protocols
  27. Which named location type in Conditional Access allows you to specify trusted locations using IP ranges? IP ranges location
  28. Which claim in a JSON Web Token (JWT) represents the unique identifier of the user in Azure AD? oid (object ID)
  29. To achieve the monitoring criteria, you must configure the detection of many staged attacks. What should you do? Add Azure Sentinel data connectors.
  30. Which Azure AD feature provides a self-service portal where users can view and revoke their own active sessions and app authorizations? My Account portal (myaccount.microsoft.com)
Was this helpful?