SC-300 Microsoft Identity and Access Administrator Dumps 3 — Questions and Answers
Question 1: An administrator wants to ensure that Azure AD guests cannot enumerate other users in the directory. Which setting controls this behavior?
- Guest user access restrictions in External Identities settings (Correct answer)
- Conditional Access policy targeting guests
- Microsoft Entra ID governance entitlement management
- Azure AD audit log retention policy
Correct answer: Guest user access restrictions in External Identities settings
The 'Guest user access restrictions' in External Identities settings controls whether guests can enumerate directory objects like users and groups.
Question 2: Which Conditional Access session control can force a user to re-authenticate after a defined period, regardless of whether the session token is still valid?
- Persistent browser session
- Sign-in frequency (Correct answer)
- Use app enforced restrictions
- Continuous access evaluation
Correct answer: Sign-in frequency
The 'Sign-in frequency' session control sets a maximum interval before the user must reauthenticate.
Question 3: A company needs to provide time-limited, audited access to a sensitive Azure resource group for a contractor. Which PIM feature is best suited for this?
- Eligible Azure resource role assignment with expiration date (Correct answer)
- Permanent Azure AD directory role assignment
- Just-in-time VM access via Microsoft Defender for Cloud
- Access package in entitlement management with an expiration policy
Correct answer: Eligible Azure resource role assignment with expiration date
PIM supports time-bound eligible assignments for Azure resource roles, requiring activation and providing full audit trails.
Question 4: What is the primary purpose of the 'What If' tool in Azure AD Conditional Access?
- Simulate which Conditional Access policies apply to a specific user, app, and sign-in condition (Correct answer)
- Test Identity Protection risk policies before enabling them
- Preview the effect of a new named location before saving it
- Audit historical sign-ins against current Conditional Access policies
Correct answer: Simulate which Conditional Access policies apply to a specific user, app, and sign-in condition
The 'What If' tool lets administrators simulate a sign-in scenario and see which Conditional Access policies would apply and why.
Question 5: An application registered in Azure AD needs to read all users' profiles without a signed-in user. Which permission type is required?
- Delegated permission with User.Read scope
- Application permission with User.Read.All scope (Correct answer)
- Delegated permission with User.ReadAll scope
- Application permission with Directory.Read.All scoped to the app
Correct answer: Application permission with User.Read.All scope
Application permissions (app roles) allow a service or daemon to access the API without a signed-in user; User.Read.All grants access to all user profiles.
Question 6: After enabling Azure AD Self-Service Password Reset (SSPR), some users report they cannot reset their passwords. The administrator notices these users have not registered authentication methods. What should the administrator do?
- Force SSPR registration at next sign-in using the SSPR registration policy in Identity Protection (Correct answer)
- Manually set temporary passwords for all affected users
- Enable password writeback in Azure AD Connect
- Configure the Authentication methods policy to allow SMS
Correct answer: Force SSPR registration at next sign-in using the SSPR registration policy in Identity Protection
The SSPR registration policy in Identity Protection can enforce that users register their authentication methods on next sign-in.
Question 7: Which Azure AD feature allows administrators to review and certify whether users should retain access to groups, applications, or Azure AD roles on a recurring basis?
- Privileged Identity Management approval workflows
- Access reviews in Microsoft Entra ID Governance (Correct answer)
- Entitlement management access packages
- Conditional Access policy review
Correct answer: Access reviews in Microsoft Entra ID Governance
Access reviews periodically prompt reviewers to confirm or revoke access, automating recertification of group memberships, app assignments, and role assignments.
An administrator wants to ensure that Azure AD guests cannot enumerate other users in the directory.
Which setting controls this behavior?