SC-300 Microsoft Identity and Access Administrator Certification 5 — Questions and Answers
Question 1: A company needs to synchronize on-premises AD groups to Azure AD without deploying Azure AD Connect Sync. Which lightweight alternative should they use?
- Azure AD Connect cloud sync (Correct answer)
- Azure AD Connect Health
- Azure AD Password Protection proxy
- Microsoft Entra Private Access
Correct answer: Azure AD Connect cloud sync
Azure AD Connect cloud sync uses lightweight provisioning agents and is designed for scenarios where full Azure AD Connect Sync is not needed or desired.
Question 2: Which Microsoft Entra feature allows administrators to publish on-premises web applications securely to external users without a VPN?
- Microsoft Entra application proxy (Correct answer)
- Microsoft Entra Private Access
- Microsoft Entra Internet Access
- Azure AD B2B direct connect
Correct answer: Microsoft Entra application proxy
Entra Application Proxy publishes on-premises web applications through the cloud so external users access them via Azure AD authentication without a VPN tunnel.
Question 3: An access review is configured for an Azure AD group. What happens to group members who do not respond to the review and auto-apply is enabled with 'Remove access' as the result?
- They are automatically removed from the group at review completion (Correct answer)
- They receive an escalation email but remain in the group
- Their membership is flagged but no action is taken
- The reviewer is notified to manually take action
Correct answer: They are automatically removed from the group at review completion
When auto-apply is enabled with 'Remove access,' members who are not approved (including non-responses) are automatically removed from the group when the review period ends.
Question 4: A tenant administrator wants to prevent any user from consenting to third-party applications requesting high-privilege permissions. Which setting enforces this?
- User consent settings set to 'Do not allow user consent' or restricted to verified publishers only (Correct answer)
- Conditional Access requiring admin approval for apps
- App registration policy disabling user app creation
- Enterprise application assignment required flag
Correct answer: User consent settings set to 'Do not allow user consent' or restricted to verified publishers only
The User consent settings under Enterprise Applications > Consent and Permissions centrally controls whether users can grant consent and to what level of permissions.
Question 5: Which Azure AD role grants the minimum permissions needed to reset passwords for non-admin users and manage authentication methods for those users?
- Authentication Administrator (Correct answer)
- User Administrator
- Helpdesk Administrator
- Password Administrator
Correct answer: Authentication Administrator
The Authentication Administrator role can reset passwords and manage authentication methods for non-privileged users, with more scope than Helpdesk Administrator.
Question 6: A Conditional Access policy is set to report-only mode. What is the effect on end users?
- Users are not blocked or prompted; policy results are logged for analysis only (Correct answer)
- Users see a warning but can still proceed
- The policy is enforced but audit logs are suppressed
- MFA is required but access is not blocked on failure
Correct answer: Users are not blocked or prompted; policy results are logged for analysis only
Report-only mode evaluates the Conditional Access policy and logs what would have happened without enforcing any block or grant controls on users.
Question 7: An organization uses SSPR (Self-Service Password Reset). Which report shows which users have registered their authentication methods for SSPR?
- SSPR Registration Activity report in Azure AD > Monitoring > Usage & Insights (Correct answer)
- Identity Protection > Risky users report
- Azure AD > Audit Logs filtered by 'Register security info'
- Microsoft 365 admin center usage reports
Correct answer: SSPR Registration Activity report in Azure AD > Monitoring > Usage & Insights
The SSPR Registration Activity report under Usage & Insights shows authentication method registration status and trends for users in the tenant.
A company needs to synchronize on-premises AD groups to Azure AD without deploying Azure AD Connect Sync.
Which lightweight alternative should they use?