SC-300 Study Guide
A curated learning path for the SC-300 exam: the best documentation, videos, blog posts and tutorials for every exam objective.A curated learning path for the SC-300 exam: the best documentation, videos, blog posts and tutorials for every exam objective, in the order worth studying them.
Microsoft Certified: Identity and Access Administrator Associate
Exam at a Glance
SC-300 measures whether you can run an organization's identity platform on Microsoft Entra: managing users, groups, and hybrid sync, securing sign-ins with MFA, passwordless, and Conditional Access, integrating and protecting applications, and automating who-has-access-to-what with entitlement management, access reviews, and PIM.
| SC-300 | Microsoft Identity and Access Administrator |
|---|---|
| Certification | Microsoft Certified: Identity and Access Administrator Associate |
| Level | Intermediate (associate role-based exam) |
| Exam length | 100 minutes |
| Questions | Typically 40 to 60; the number and format mix can vary |
| Passing score | 700 out of 1000 |
| Question formats | Multiple choice, multiple select, drag and drop, build list, hot area, case studies |
| Microsoft Learn access | Available within the exam; browsing is restricted and the timer continues |
| Skills measured version | April 27, 2026 |
| Renewal | Certification expires annually; renew with a free online assessment on Microsoft Learn |
| Cost | Depends on your country or region; shown when you schedule |
What the Exam Covers
The exam has four domains with nearly even weights. Authentication and access management is the highest-weight domain. Everything is Microsoft Entra: if you can explain how a sign-in gets evaluated end to end, you are studying the right things.
Implement and manage user identities — 20-25%
Tenant configuration, built-in and custom Entra roles, administrative units, domains, users and groups, custom security attributes, bulk operations, device join and registration, licenses, external users and B2B collaboration, cross-tenant access and synchronization, external identity providers, hybrid identity with Entra Connect Sync and Cloud Sync, password hash sync, pass-through authentication, seamless SSO, Connect Health.
Implement authentication and access management — 25-30%
Authentication methods (certificate-based, Temporary Access Pass, Microsoft Authenticator, passkeys/FIDO2), tenant-wide MFA settings, self-service password reset, Windows Hello for Business, password protection, Entra Kerberos, Conditional Access end to end (assignments, controls, session management, continuous access evaluation, authentication context, protected actions, templates), risk management with Entra ID Protection, and Global Secure Access (clients, Private Access, Internet Access).
Plan and implement workload identities — 20-25%
Choosing between managed identities, service principals, and service accounts; creating and assigning managed identities; enterprise application integration (settings, roles, consent, App Proxy, SaaS apps, application collections); app registrations (authentication, API permissions, app roles); and monitoring app access with Microsoft Defender for Cloud Apps (cloud discovery, Conditional Access app control, session policies, OAuth app policies).
Plan and automate identity governance — 20-25%
Entitlement management (catalogs, access packages, connected organizations, terms of use, external user lifecycle), access reviews, Privileged Identity Management for Entra roles, Azure resources, and groups, break-glass accounts, and monitoring with sign-in/audit/provisioning logs, diagnostic settings, KQL in Log Analytics, workbooks, and Identity Secure Score.
The full bullet-level list lives in the official study guide. Treat it as your checklist:
The Official SC-300 Study Guide
How This Maps to CertiAce Practice Modules
The CertiAce question bank is organized by the same topic areas the exam measures, so you can drill each area in isolation:
| CertiAce practice module | What you will drill there |
|---|---|
| Explore identity in Microsoft Entra ID | Tenant and role fundamentals, administrative units, users, groups, devices, licenses |
| Implement an identity management solution using Microsoft Entra ID | Hybrid identity (Connect Sync vs Cloud Sync), external identities and B2B, cross-tenant access, domains |
| Implement an authentication and access management solution | MFA and passwordless methods, SSPR, password protection, Conditional Access, Identity Protection |
| Implement access management for apps | Enterprise applications, app registrations, consent, App Proxy and Global Secure Access, Defender for Cloud Apps |
| Plan and implement an identity governance strategy | Entitlement management, access reviews, PIM, lifecycle workflows, monitoring and reporting |
Where SC-300 Fits
| Certification | What it validates | When to take it |
|---|---|---|
| SC-900: Security, Compliance, and Identity Fundamentals | Foundational knowledge of Microsoft security, compliance, and identity solutions | Optional first step if you are new to the Microsoft security stack |
| SC-300: Identity and Access Administrator Associate (this exam) | Designing and operating identity and access management with Microsoft Entra | You are here |
| SC-100: Cybersecurity Architect Expert | Designing an organization-wide cybersecurity strategy on Zero Trust principles | After SC-300, if you move toward architecture (earning Identity and Access Administrator Associate satisfies the SC-100 prerequisite) |
SC-300 is also a stepping stone: earning Microsoft Certified: Identity and Access Administrator Associate (exam SC-300) satisfies the certification prerequisite for Microsoft Certified: Cybersecurity Architect Expert (exam SC-100). That expert certification requires at least one of three associate certifications in addition to passing SC-100: Identity and Access Administrator Associate (exam SC-300), Security Operations Analyst Associate (exam SC-200), or Cloud and AI Security Engineer Associate (exam SC-500).
SC-300 has no official prerequisites, but it assumes working familiarity with Azure and Microsoft 365. If identity is your first step into the Microsoft security world, SC-900 first is a gentle on-ramp; if you already administer Entra ID day to day, go straight to SC-300.
Before You Start
The exam assumes practical administration experience. Check yourself against this table. Anything unfamiliar is where your preparation should start:
| Area | You should be comfortable with |
|---|---|
| Microsoft Entra ID basics | Users, groups, roles, what a tenant is, the Entra admin center |
| Azure and Microsoft 365 | How Azure resources and M365 workloads consume identity; portals and admin centers |
| Active Directory Domain Services | On-premises AD concepts. The hybrid identity domain assumes you know what is being synchronized |
| PowerShell | Reading and running basic Microsoft Graph PowerShell for bulk operations |
| KQL awareness | Reading simple Kusto queries. The monitoring objectives use Log Analytics |
Step-by-Step Study Plan
How long you need depends on where you start. Treat these estimates as planning guidance and adjust them to your starting knowledge and weekly study hours:
| Your starting point | Suggested prep time |
|---|---|
| Administering Entra ID weekly | 2 to 4 weeks |
| General Azure/M365 admin, newer to identity depth | 4 to 8 weeks |
Step 1: Read the Official Study Guide
Skim the full skills-measured list once, and mark every bullet you could not explain to a colleague. That marked-up list is your personal syllabus: everything else in this plan exists to clear it. Note the April 27, 2026 update: Global Secure Access now has its own objective group, and older study materials miss it entirely.
Step 2: Schedule Your Exam
Choose a realistic target date after reviewing the skills list and your available study time. A date on the calendar turns studying into a countdown, so pick one using the prep-time table above and plan backwards from it.
Certification and Exam Details Page
Step 3: Work Through the Official Course Material
Complete the SC-300 course modules on Microsoft Learn. Take notes on every concept you cannot explain in one sentence, and flag anything that needs hands-on practice. You will come back to those in Step 4.
Official Course Page (SC-300T00)
Step 4: Get Hands-On Practice
SC-300 rewards people who have actually clicked through the Entra admin center. A free tenant gets you started, but the Conditional Access, PIM, and governance exercises below need Microsoft Entra ID P2 licensing, so activate a P2 trial before you begin (a Microsoft Entra ID Governance trial adds lifecycle workflows on top). Aim for hands-on time with:
- A Conditional Access policy in report-only mode, then enforced
- MFA and passwordless registration, SSPR, and a Temporary Access Pass
- An app registration plus an enterprise app with user assignment and admin consent
- An access package with an approval flow, and an access review
- PIM activation for an Entra role, with approval and audit history
Watch how the sign-in logs record each experiment. Reading a sign-in log entry fluently is worth several exam questions.
Step 5: Benchmark Your Knowledge
Use CertiAce to benchmark your readiness module by module. The practice modules map to the exam domains as shown above, so use the module mapping and the topics behind your missed questions to identify the skills-measured areas to revisit. Microsoft also offers a free official practice assessment. Aim for consistent performance across every module, not one lucky high score.
Free Official Practice Assessment
Step 6: Take the Exam
The day before, review only your weak topics: no brand-new material. On exam day, read each question for what it is truly asking (most SC-300 scenarios hinge on picking the least-privileged role or the right policy scope) and eliminate wrong options first.
Worth knowing before you sit down:
- Microsoft Learn is available during the exam in a split screen. Use it to check details you genuinely need: the timer keeps running, and the exam is deliberately too long to look up every answer. Browsing is limited to Microsoft Learn itself (no Q&A, practice assessments, or profile), and personal notes and other websites are unavailable.
- You can take unscheduled breaks, but the clock keeps running and you cannot return to questions you already saw.
- Watch the naming: the exam uses current product names such as Microsoft Entra ID (not Azure AD), Entra ID Protection, Global Secure Access, so cross-check older product names and objectives against the current study guide.
- Try the exam sandbox beforehand so the question formats and interface hold no surprises: Exam Sandbox
Additional Learning Resources
| Resource | Type | Why it is useful |
|---|---|---|
| Free Official Practice Assessment | Practice | Microsoft's own question-style preview, free |
| Exam Readiness Zone: SC-300 | Video series | Microsoft Certified Trainer prep videos per exam domain |
| Microsoft Entra documentation | Docs hub | The entire exam lives in this doc set: Entra ID, ID Protection, ID Governance, Global Secure Access |
| Microsoft Entra ID Governance documentation | Docs hub | Entitlement management, access reviews, PIM, and lifecycle workflows in depth |
| Security, compliance, and identity community hub | Community | Microsoft's official SCI community: announcements and discussions |
Realistic SC-300 exam-style questions with instant feedback and detailed explanations.
Practice SC-300 now