SC-300 Cheat Sheet 2026
The 30 highest-yield SC-300 facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
50 questions
100 min time limit
70.00% to pass
- Which claim in a JWT access token issued by Azure AD uniquely identifies the tenant that issued the token? → tid
- Which Conditional Access control can restrict what users can do within a cloud application session without blocking access entirely? → Session control: Use Conditional Access App Control
- Which Identity Protection configuration setting controls the percentage of the organization's users who must be covered by the MFA registration policy? → Users scope — All users or specific groups
- Which report in Azure AD helps administrators identify users who have NOT registered for MFA? → Authentication methods activity report
- What is the minimum number of authentication methods a user must register when SSPR is configured to require 2 methods? → 2
- Which Entitlement Management feature allows users from partner organizations with a different Azure AD tenant to request access packages? → Connected organizations
- Which Azure AD feature automatically detects when a user's credentials have been leaked on the dark web and flags their sign-in as high risk? → Azure AD Identity Protection leaked credentials detection
- Which of the following authentication methods supports SMS as a verification option in Azure AD? → Self-Service Password Reset (SSPR)
- Which Azure AD feature allows bulk invitation of multiple guest users by uploading a CSV file? → Bulk invite users feature in the Azure portal
- A company wants to enforce that users can only access Microsoft 365 from compliant devices. Which Conditional Access grant control should be configured? → Require device to be marked as compliant
- Which Azure AD feature allows users to reset their own passwords without contacting the helpdesk? → Self-Service Password Reset (SSPR)
- An administrator configures a Conditional Access policy with the 'Require approved client app' grant control. Which scenario will this control block? → A user accessing Exchange Online from a native mail app that is not Intune-managed
- A Privileged Role Administrator wants to prevent any user from having a permanent eligible Global Administrator assignment. Which PIM setting enforces this? → Set assignment expiration for eligible assignments
- Which Azure AD cross-tenant access setting controls whether your users can be invited as guests into another organization's tenant? → Outbound settings — B2B collaboration
- A Conditional Access policy is set to 'Report-only' mode. What is the effect on users? → Policy evaluates but does not enforce; results are logged only
- What action does 'Apply results' perform at the end of an Access Review? → It implements the decisions made during the review by adding or removing access
- An admin needs to automatically revoke all refresh tokens for a user suspected of compromise without deleting the account. Which action accomplishes this? → Revoke sign-in sessions in Azure AD user properties
- An organization uses SSPR (Self-Service Password Reset). Which report shows which users have registered their authentication methods for SSPR? → SSPR Registration Activity report in Azure AD > Monitoring > Usage & Insights
- A security team wants to detect when an Azure AD privileged role is assigned outside of PIM. Which monitoring approach should they implement? → Azure Monitor alert on 'Add member to role' audit event outside PIM
- A company deploys Azure AD Password Protection on-premises. Which component on domain controllers enforces the banned password list? → Azure AD Password Protection DC Agent
- An administrator needs to enforce that users can only register security information from trusted locations. Which Azure AD feature should be configured? → Named Locations in Conditional Access
- An administrator needs to extend a user's expiring eligible role assignment without having the user re-activate. Which PIM action should the administrator take? → Update the existing assignment's end date using the 'Extend' option
- A Privileged Identity Management (PIM) role assignment is set to 'eligible.' What must the user do before they can use the role? → Activate the role themselves, optionally providing a justification
- In PIM for Azure resources, which assignment type makes a user a permanent owner of a resource without any activation required? → Active assignment
- A user successfully completes SSPR to reset their password after being flagged by Identity Protection. What is the result on their user risk level? → User risk is automatically remediated and reset to none
- An administrator enables Azure AD Security Defaults. Which statement about Security Defaults and MFA is correct? → Security Defaults enforce MFA for all users and block legacy authentication protocols
- Which named location type in Conditional Access allows you to specify trusted locations using IP ranges? → IP ranges location
- Which claim in a JSON Web Token (JWT) represents the unique identifier of the user in Azure AD? → oid (object ID)
- To achieve the monitoring criteria, you must configure the detection of many staged attacks. What should you do? → Add Azure Sentinel data connectors.
- Which Azure AD feature provides a self-service portal where users can view and revoke their own active sessions and app authorizations? → My Account portal (myaccount.microsoft.com)
Turn these facts into recall:
Was this helpful?