DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free Microsoft SC-300 Practice Questions & Answers 2026 Part1

Are you preparing for the Microsoft SC-300 certification exam? SPOTO offers the Microsoft SC-300 Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
You have an Azure subscription that contains an Azure Automation account named Automation1.You need to grant Automation1 access to Azure resources. The solution must meet the following requirements:- Ensure that any permissions granted to Automation1 are removed whenthe account is deleted.- Minimize administrative effort.What should you use?
A. client secret
B. system-assigned managed identity
C. ser-assigned managed identity
D. certificate
View answer
Correct Answer: B
Question #2
You have a Microsoft 365 tenant.The Azure Active Directory (Azure AD) tenant syncs to an on-premises Active Directory domain.Users connect to the internet by using a hardware firewall at your company. The users authenticate to thefirewall by using their Active Directory credentials.You plan to manage access to external applications by using Azure AD.You need to use the firewall logs to create a list of unmanaged external applications and the users who accessthem.What should you use to gather the information?
A. Application Insights in Azure Monitor
B. access reviews in Azure AD
C. Cloud App Discovery in Microsoft Cloud App Security
D. enterprise applications in Azure AD
View answer
Correct Answer: C
Question #3
You have an Azure AD tenant and a .NET web app named App1.
A. the executable name
B. the bundle ID
C. the package name
D. the redirect URI
View answer
Correct Answer: D
Question #4
You have an Active Directory domain that syncs to an Azure Active Directory (Azure AD) tenant.The on-premises network contains a VPN server that authenticates to the on-premises Active Directory domain. The VPN server does NOT support Azure MultiFactor Authentication (MFA).You need to recommend a solution to provide Azure MFA for VPN connections.What should you include in the recommendation?
A. zure AD Application Proxy
B. n Azure AD Password Protection proxy
C. etwork Policy Server (NPS)
D. pass-through authentication proxy
View answer
Correct Answer: C
Question #5
You have an Azure AD tenant that contains an access package named Package1 and a user named User1. Package1 is configured as shown in the following exhibit. You need to ensure that User1 can modify the review frequency of Package1. The solution must use the principle of least privilege. Which role should you assign to User1? This question refers to Azure AD Entitlement Management under Identity Governance. The goal is to let User1 modify the review frequency (i.e., Access Reviews) for an existing access package named Package1, following the principle of least privilege. In Azure AD, the ability to create and manage access packages, catalogs, and access reviews is granted through certain administrative roles: Global Administrator and Identity Governance Administrator --- Full control over all Identity Governance settings. Catalog Owner or Access Package Manager --- Manage access packages and settings within a catalog. User Administrator --- Can configure access reviews and manage users, groups, and limited governance settings. Privileged Role Administrator, Security Administrator, and External Identity Provider Administrator --- Have no direct control over access review settings in Entitlement Management. From Microsoft documentation (''Azure AD Entitlement Management Delegation and Roles''): ''A user administrator can manage access reviews and entitlement management settings for the directory and assigned catalogs, including adjusting the review frequency or review settings.'' Thus, to modify the Access Review configuration (frequency, reviewers, etc.) in Package1, the User Administrator role provides the minimum necessary privilege without granting excessive permissions like Identity Governance Administrator or Global Administrator.
A. Privileged role administrator
B. User administrator
C. External Identity Provider administrator
D. Security administrator
View answer
Correct Answer: B
Question #6
You have a Microsoft Exchange organization that uses an SMTP address space of contoso.com.Several users use their contoso.com email address for self-service sign-up to Azure Active Directory (Azure AD).You gain global administrator privileges to the Azure AD tenant that contains the self-signed users.You need to prevent the users from creating user accounts in the contoso.com Azure AD tenant for self-service sign-up to Microsoft 365 services.Which PowerShell cmdlet should you run?
A. Set-MsolCompanySettings
B. Set-MsolDomainFederationSettings
C. Update-MsolfederatedDomain
D. Set-MsolDomain
View answer
Correct Answer: A
Question #7
You have a Microsoft 365 subscription.You need to ensure that when users access the Microsoft 365 portal from Microsoft Edge and have their browser language set to Spanish, they are presented with a Spanish sign-in form.What should you do in the Microsoft Entra admin center?
A. From Settings for the users, configure the Usage location setting
B. From Global Secure Access, configure the Session management settings
C. Configure the Company branding settings
D. Create a Conditional Access policy
View answer
Correct Answer: C
Question #8
Your company recently implemented Azure Active Directory (Azure AD) Privileged Identity Management (PIM). While you review the roles in PIM, you discover that all 15 users in the IT department at the company have permanent security administrator rights. You need to ensure that the IT department users only have access to the Security administrator role when required. What should you configure for the Security administrator role assignment?
A. Expire eligible assignments after from the Role settings details
B. Expire active assignments after from the Role settings details
C. Assignment type to Active
D. Assignment type to Eligible
View answer
Correct Answer: D
Question #9
You have an Azure Active Directory (Azure AD) tenant that: contains a user named User1.You need to ensure that User1 can create new catalogs and add1 resources to the catalogs they own.What should you do?
A. From the Roles and administrators blade, modify the Groups administrator role
B. From the Roles and administrators blade, modify the Service support administrator role
C. From the Identity Governance blade, modify the Entitlement management settings
D. From the Identity Governance blade, modify the roles and administrators for the General catalog
View answer
Correct Answer: C
Question #10
Your company has two divisions named Contoso East and Contoso West. The Microsoft 365 identity architecture for both divisions is shown in the following exhibit.You need to assign users from the Contoso East division access to Microsoft SharePoint Online sites in the Contoso West tenant. The solution must not require additional Microsoft 365 licenses.What should you do?
A. Configure Azure AD Application Proxy in the Contoso West tenant
B. Invite the Contoso East users as guests in the Contoso West tenant
C. Deploy a second Azure AD Connect server to Contoso East and configure the server to sync the Contoso East Active Directory forest to the Contoso West tenant
D. Configure the existing Azure AD Connect server in Contoso East to sync the Contoso East Active Directory forest to the Contoso West tenant
View answer
Correct Answer: B
Question #11
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have an Active Directory forest that syncs to an Azure Active Directory (Azure AD) tenant.You discover that when a user account is disabled in Active Directory, the disabled user can still authenticate to Azure AD for up to 30 minutes.You need to ensure that when a user account is disabled in Active Directory, the user account is immediately prevented from authenticating to Azure AD.Solution: You configure password writeback.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #12
You have 2,500 users who are assigned Microsoft Office 365 Enterprise E3 licenses. The licenses are assigned to individual users.From the Groups blade in the Azure Active Directory admin center, you assign Microsoft Office 365 Enterprise E5 licenses to a group that includes all users.You needed to remove the Office 365 Enterprise E3 licenses from the users by using the least amount of administrative effort.What should you use?
A. the Groups blade in the Azure Active Directory admin center
B. the Set-AzureAdUser cmdlet
C. the Identity Governance blade in the Azure Active Directory admin center
D. the Licenses blade in the Azure Active Directory admin center
View answer
Correct Answer: D
Question #13
You have an Azure AD tenant that contains a user named User1.User1 needs to manage license assignments and reset user passwords.Which role should you assign to User1?
A. Helpdesk administrator
B. Billing administrator
C. License administrator
D. User administrator
View answer
Correct Answer: D
Question #14
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have a Microsoft 365 E5 subscription.You create a user named User1.You need to ensure that User1 can update the status of Identity Secure Score improvement actions.Solution: You assign the SharePoint Administrator role to User1.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: A
Question #15
You have an Azure Active Directory (Azure AD) tenant that contains the following objects:✑ A device named Device1✑ Users named User1, User2, User3, User4, and User5✑ Groups named Group1, Group2, Group3, Group4, and Group5The groups are configured as shown in the following table.To which groups can you assign a Microsoft Office 365 Enterprise E5 license directly?
A. Group1 and Group4 only
B. Group1, Group2, Group3, Group4, and Group5
C. Group1 and Group2 only
D. Group1 only
E. Group1, Group2, Group4, and Group5 only
View answer
Correct Answer: B
Question #16
You have an Azure AD tenant that contains the external user shown in the following exhibit.You update the email address of the user.You need to ensure that the user can authenticate by using the updated email address.What should you do for the user?
A. Modify the Authentication methods settings
B. Reset the password
C. Revoke the active sessions
D. Reset the redemption status
View answer
Correct Answer: D
Question #17
You have a Microsoft Entra tenant that contains the devices shown in the following table. You plan to configure Microsoft Entra Private Access. You deploy the Global Secure Access client to compatible devices. From which devices can you use Private Access?
A. Device1 only
B. Device2 only
C. Device2 and Device4 only
D. Device1
E. Device1
View answer
Correct Answer: B
Question #18
You have a Microsoft Entra tenant named contoso.com that contains an enterprise application named App1.A contractor uses the credentials of[email protected].You need to ensure that you can provide the contractor with access to App1. The contractor must be able to authenticate as[email protected].What should you do?
A. un the New-MgUser cmdlet
B. onfigure the External collaboration settings
C. un the New-MgInvitation cmdlet
D. mplement Microsoft Entra Connect sync
View answer
Correct Answer: C
Question #19
You need to meet the authentication requirements for leaked credentials. What should you do?
A. Enable federation with PingFederate in Azure AD Connect
B. Configure Azure AD Password Protection
C. Enable password hash synchronization in Azure AD Connect
D. Configure an authentication method policy in Azure AD
View answer
Correct Answer: C
Question #20
Your organization is considering allowing employees to work remotely and to use their own devices to access many of the organizations resources. However, to help protect against potential data loss, your organization needs to ensure that only approved applications can be used to access the company data. What can you configure to meet this requirement?
A. rivileged Identity Management
B. zure Security Center
C. onditional Access Policies
D. BAC roles
View answer
Correct Answer: C
Question #21
You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains an Azure AD enterprise application named App1.A contractor uses the credentials of user1@outlook.com.You need to ensure that you can provide the contractor with access to App1. The contractor must be able to authenticate as user1@outlook.com.What should you do?
A. Run the New-AzADUser cmdlet
B. Configure the External collaboration settings
C. Add a WS-Fed identity provider
D. Create a guest user account in contoso
View answer
Correct Answer: D
Question #22
You have 2,500 users who are assigned Microsoft Office 365 Enterprise E3 licenses. The licenses are assigned to individual users.From the Groups blade in the Azure Active Directory admin center, you assign Microsoft Office 365 Enterprise E5 licenses to a group that includes all users.You need to remove the Office 365 Enterprise E3 licenses from the users by using the least amount of administrative effort.What should you use?
A. the Set-MsolUserLicense cmdlet
B. the Set-AzureADGroup cmdlet
C. the Set-WindowsProductKey cmdlet
D. the Administrative units blade in the Azure Active Directory admin center
View answer
Correct Answer: A
Question #23
You have an Azure AD tenant.You need to ensure that only users from specific external domains can be invited as guests to the tenant.Which settings should you configure?
A. External collaboration settings
B. All identity providers
C. Cross-tenant access settings
D. Linked subscriptions
View answer
Correct Answer: A
Question #24
You have two Microsoft Entra tenants named contoso.com and fabrikam.com. Contoso.com contains the identities shown in the following table.You configure cross-tenant synchronization from contoso.com to fabrikam.com.Which identities will sync with fabrikam.com?
A. User1 only
B. User1 and Group1 only
C. User1 and Group2 only
D. User1, Group1, and Group2
View answer
Correct Answer: A
Question #25
You have a Microsoft 365 tenant that uses the domain named fabrikam.com. The Guest invite settings for Azure Active Directory (Azure AD) are configured as shown in the exhibit. (Click the Exhibit tab.)A user named bsmith@fabrikam.com shares a Microsoft SharePoint Online document library to the users shown in the following table.Which users will be emailed a passcode?
A. User2 only
B. User1 only
C. User1 and User2 only
D. User1, User2, and User3
View answer
Correct Answer: B
Question #26
You have a Microsoft 365 tenant that uses the domain named fabrikam.com. The Guest invite settings for Azure Active Directory (Azure AD) are configured as shown in the exhibit. (Click the Exhibit tab.)A user named bsmith@fabrikam.com shares a Microsoft SharePoint Online document library to the users shown in the following table.Which users will be emailed a passcode?
A. User2 only
B. User1 only
C. User1 and User2 only
D. User1, User2, and User3
View answer
Correct Answer: B
Question #27
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have an Active Directory forest that syncs to an Azure Active Directory (Azure AD) tenant.You discover that when a user account is disabled in Active Directory, the disabled user can still authenticate to Azure AD for up to 30 minutes.You need to ensure that when a user account is disabled in Active Directory, the user account is immediately prevented from authenticating to Azure AD.Solution: You configure password writeback.Does this meet the goal?
A. es
B. o
View answer
Correct Answer: B
Question #28
You have 2,500 users who are assigned Microsoft Office 365 Enterprise E3 licenses. The licenses are assigned to individual users.From the Groups blade in the Azure Active Directory admin center, you assign Microsoft Office 365 Enterprise E5 licenses to a group that includes all users.You need to remove the Office 365 Enterprise E3 licenses from the users by using the least amount of administrative effort.What should you use?
A. the Administrative units blade in the Azure Active Directory admin center
B. the Set-MsolUserLicense cmdlet
C. the Groups blade in the Azure Active Directory admin center
D. the Set-WindowsProductKey cmdlet
View answer
Correct Answer: B
Question #29
You have a Microsoft Entra tenant named contoso.com that contains an enterprise application named Appl. A contractor uses the credentials of [email protected]. You need to ensure that you can provide the contractor with access to App1. The contractor must be able to authenticate as user1 @outlook.com. What should you do?
A. ARun the New-Mguser cmdlet
B. BRun the New-Mglnvitation cmdlet
C. CConfigure the External collaboration settings
D. DImplement Microsoft Entra Connect sync
View answer
Correct Answer: B

View The Updated Microsoft Exam Questions

SPOTO Provides 100% Real Microsoft Exam Questions for You to Pass Your Microsoft Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us