DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free Microsoft SC-300 Practice Questions & Answers 2026 Part4

Are you preparing for the Microsoft SC-300 certification exam? SPOTO offers the Microsoft SC-300 Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
You have an Azure AD tenant.You need to ensure that only users from specific external domains can be invited as guests to the tenant.Which settings should you configure?
A. External collaboration settings
B. All identity providers
C. Cross-tenant access settings
D. Linked subscriptions
View answer
Correct Answer: A
Question #2
You have an Azure Active Directory (Azure AD) tenant named contoso.com.All users who run applications registered in Azure AD are subject to conditional access policies.You need to prevent the users from using legacy authentication.What should you include in the conditional access policies to filter out legacy authentication attempts?
A. a cloud apps or actions condition
B. a user risk condition
C. a client apps condition
D. a sign-in risk condition
View answer
Correct Answer: C
Question #3
You have a Microsoft Entra tenant named contoso.com that contains an enterprise application named App1.A contractor uses the credentials of user1@outlook.com.You need to ensure that you can provide the contractor with access to App1. The contractor must be able to authenticate as user1@outlook.com.What should you do?
A. Implement Microsoft Entra Connect sync
B. Add a custom domain name to contoso
C. Implement Microsoft Entra Application Proxy
D. Run the New-MgInvitation cmdlet
View answer
Correct Answer: D
Question #4
You have an Azure subscription that contains a registered app named App1.You need to review the sign-in activity for App1. The solution must meet the following requirements:- Identify the number of failed sign-ins.- Identify the success rate of sign-ins.- Minimize administrative effort.What should you use?
A. sage & insights
B. ign-in logs
C. ccess reviews
D. udit logs
View answer
Correct Answer: A
Question #5
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Cloud Apps.You plan to increase app security for the subscription.You need to identify which apps do NOT require user authentication.What should you do in the Microsoft 365 Defender portal?
A. eview the cloud app catalog
B. reate an OAuth policy and review alerts
C. reate a snapshot Cloud Discovery report
D. reate a discovered app query
View answer
Correct Answer: D
Question #6
You have an Azure AD tenant that contains the external user shown in the following exhibit.You update the email address of the user.You need to ensure that the user can authenticate by using the updated email address.What should you do for the user?
A. Modify the Authentication methods settings
B. Reset the password
C. Revoke the active sessions
D. Reset the redemption status
View answer
Correct Answer: D
Question #7
Reference Scenario: click here You have an Azure Active Directory (Azure AD) tenant named contoso.com. All users who run applications registered in Azure AD are subject to conditional access policies. You need to prevent the users from using legacy authentication. What should you include in the conditional access policies to filter out legacy authentication attempts?
A. a cloud apps or actions condition
B. a user risk condition
C. a client apps condition
D. a sign-in risk condition
View answer
Correct Answer: C
Question #8
You have an Azure AD tenant that contains the external user shown in the following exhibit.You update the email address of the user.You need to ensure that the user can authenticate by using the updated email address.What should you do for the user?
A. Modify the Authentication methods settings
B. Reset the password
C. Revoke the active sessions
D. Reset the redemption status
View answer
Correct Answer: D
Question #9
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have an Active Directory forest that syncs to an Azure Active Directory (Azure AD) tenant.You discover that when a user account is disabled in Active Directory, the disabled user can still authenticate to Azure AD for up to 30 minutes.You need to ensure that when a user account is disabled in Active Directory, the user account is immediately prevented from authenticating to Azure AD.Solution: You configure Azure AD Password Protection.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #10
You have an Azure Active Directory (Azure AD) tenant that contains the following objects:-A device named Device1-Users named User1, User2, User3, User4, and User5-Groups named Group1, Group2, Group3, Group4, and Group5The groups are configured as shown in the following table.To which groups can you assign a Microsoft Office 365 Enterprise E5 license directly?
A. Group1 and Group4 only
B. Group1, Group2, Group3, Group4, and Group5
C. Group1 and Group2 only
D. Group1 only
E. Group1, Group2, Group4, and Group5 only
View answer
Correct Answer: B
Question #11
Your network contains an on-premises Active Directory domain that syncs to an Azure Active Directory (Azure AD) tenant.Users sign in to computers that run Windows 10 and are joined to the domain.You plan to implement Azure AD Seamless Single Sign-On (Azure AD Seamless SSO).You need to configure the Windows 10 computers to support Azure AD Seamless SSO.What should you do?
A. Configure Sign-in options from the Settings app
B. Enable Enterprise State Roaming
C. Modify the Intranet Zone settings
D. Install the Azure AD Connect Authentication Agent
View answer
Correct Answer: C
Question #12
You have an Azure Active Directory (Azure AD) tenant. You configure self-service password reset (SSPR) by using the following settings: - Require users to register when signing in: Yes - Number of methods required to reset: 1 What is a valid authentication method available to users?
A. a mobile app code
B. mobile app notification
C. an email to an address in your organization
D. home prison
View answer
Correct Answer: A
Question #13
Case StudyOverviewADatum Corporation is a consulting company in Montreal.ADatum recently acquired a Vancouver-based company named Litware, Inc.Existing Environment. ADatum EnvironmentThe on-premises network of ADatum contains an Active Directory Domain Services (AD DS) forest named adatum.com.ADatum has a Microsoft 365 E5 subscription. The subscription contains a verified domain that syncs with the adatum.com AD DS domain by using Azure AD Connect.ADatum has an Azure Active Directory (Azure AD) tenant named adatum.com. The tenant has Security defaults disabled.The tenant contains the users shown in the following table.The tenant contains the groups shown in the following table.Existing Environment. Litware EnvironmentLitware has an AD DS forest named litware.comExisting Environment. Problem StatementsADatum identifies the following issues:• Multiple users in the sales department have up to five devices. The sales department users report that sometimes they must contact the support department to join their devices to the Azure AD tenant because they have reached their device limit.• A recent security incident reveals that several users leaked their credentials, a suspicious browser was used for a sign-in, and resources were accessed from an anonymous IP address.• When you attempt to assign the Device Administrators role to IT_Group1, the group does NOT appear in the selection list.• Anyone in the organization can invite guest users, including other guests and non-administrators.• The helpdesk spends too much time resetting user passwords.• Users currently use only passwords for authentication.Requirements. Planned ChangesADatum plans to implement the following changes:• Configure self-service password reset (SSPR).• Configure multi-factor authentication (MFA) for all users.• Configure an access review for an access package named Package1.• Require admin approval for application access to organizational data.• Sync the AD DS users and groups of litware.com with the Azure AD tenant.• Ensure that only users that are assigned specific admin roles can invite guest users.• Increase the maximum number of devices that can be joined or registered to Azure AD to 10.Requirements. Technical RequirementsADatum identifies the following technical requirements:• Users assigned the User administrator role must be able to request permission to use the role when needed for up to one year.• Users must be prompted to register for MFA and provided with an option to bypass the registration for a grace period.• Users must provide one authentication method to reset their password by using SSPR. Available methods must include:- Email- Phone- Security questions- The Microsoft Authenticator app• Trust relationships must NOT be established between the adatum.com and litware.com AD DS domains.• The principle of least privilege must be used.You need to resolve the issue of IT_Group1.What should you do first?
A. Change Membership type of IT_Group1 to Dynamic User
B. Recreate the IT_Group1 group
C. Change Membership type of IT Group1 to Dynamic Device
D. Add an owner to IT_Group1
View answer
Correct Answer: B
Question #14
You have an Azure AD tenant.You need to ensure that only users from specific external domains can be invited as guests to the tenant.Which settings should you configure?
A. External collaboration settings
B. All identity providers
C. Cross-tenant access settings
D. Linked subscriptions
View answer
Correct Answer: A
Question #15
You have an Azure subscription. The subscription contains 50 virtual machines that run Windows Server and have Login with Microsoft Entra ID enabled.
A. From the Microsoft Entra admin center, delete the device registrations of the virtual machines
B. Revoke the primary refresh token
C. Enable SSH client support for OpenSSH
D. Ensure that the virtual machines can access https://enterpriseregistration
View answer
Correct Answer: D
Question #16
You have a Microsoft Entra tenant. You need to configure continuous access evaluation for app sign-ins and assign the configuration to users that are assigned the Application Administrator role. What should you configure?
A. Aa Conditional Access policy
B. Bthe Admin consent settings
C. Ca sign-in risk policy
D. Dan access review
View answer
Correct Answer: A
Question #17
You have an Azure Active Directory (Azure AD) tenant that contains the objects shown in the following table.Which objects can you add as members to Group3?
A. User2 and Group2 only
B. User2, Group1, and Group2 only
C. User1, User2, Group1 and Group2
D. User1 and User2 only
E. User2 only
View answer
Correct Answer: E
Question #18
You have a Microsoft 365 subscription that uses Microsoft Defender for Cloud Apps.You have multiple third-party apps that access the resources in the subscription.You need to monitor the access of the third-party apps.What should you create?
A. an OAuth app policy
B. an endpoint protection policy
C. an app permission policy
D. an access policy
View answer
Correct Answer: A
Question #19
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have an Active Directory forest that syncs to an Azure AD tenant.You discover that when a user account is disabled in Active Directory, the disabled user can still authenticate to Azure AD for up to 30 minutes.You need to ensure that when a user account is disabled in Active Directory, the user account is immediately prevented from authenticating to Azure AD.Solution: You configure conditional access policies.Does this meet the goal?
A. Yes
B. No
View answer
Correct Answer: B
Question #20
You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table.You have an administrative unit named Au1. Group1, User2, and User3 are members of Au1.User5 is assigned the User administrator role for Au1.For which users can User5 reset passwords?
A. User1, User2, and User3
B. User1 and User2 only
C. User3 and User4 only
D. User2 and User3 only
View answer
Correct Answer: D
Question #21
You have an Azure Active Directory (Azure AD) tenant named contoso.com.You implement entitlement management to provide resource access to users at a company named Fabrikam, Inc. Fabrikam uses a domain named fabrikam.com.Fabrikam users must be removed automatically from the tenant when access is no longer required.You need to configure the following settings:Block external user from signing in to this directory: NoRemove external user: YesNumber of days before removing external user from this directory: 90What should you configure on the Identity Governance blade?
A. ccess packages
B. ntitlement management settings
C. erms of use
D. ccess reviews settings
View answer
Correct Answer: B
Question #22
You have an Azure Active Directory (Azure AD) tenant named contoso.com. You implement entitlement management to provide resource access to users at a company named Fabrikam, Inc. Fabrikam uses a domain named fabrikam.com. Fabrikam users must be removed automatically from the tenant when access is no longer required. You need to configure the following settings: - Block external user from signing in to this directory: No - Remove external user: Yes - Number of days before removing external user from this directory: 90 What should you configure on the Identity Governance blade?
A. Access packages
B. Settings
C. Terms of use
D. Access reviews
View answer
Correct Answer: B
Question #23
You have 2,500 users who are assigned Microsoft Office 365 Enterprise E3 licenses. The licenses are assigned to individual users.From the Groups blade in the Azure Active Directory admin center, you assign Microsoft 365 Enterprise E5 licenses to the users.You need to remove the Office 365 Enterprise E3 licenses from the users by using the least amount of administrative effort.What should you use?
A. the Identity Governance blade in the Azure Active Directory admin center
B. the Set-AzureAdUser cmdlet
C. the Licenses blade in the Azure Active Directory admin center
D. the Set-WindowsProductKey cmdlet
View answer
Correct Answer: C
Question #24
You have a Microsoft Exchange organization that uses an SMTP address space of contoso.com.Several users use their contoso.com email address for self-service sign-up to Azure AD.You gain global administrator privileges to the Azure AD tenant that contains the self-signed users.You need to prevent the users from creating user accounts in the contoso.com Azure AD tenant for self-service sign-up to Microsoft 365 services.Which PowerShell cmdlet should you run?
A. Update-MgOrganization
B. Update-MgPolicyPermissionGrantPolicyExclude
C. Update-MgDomain
D. Update-MgDomainFederationConfiguration
View answer
Correct Answer: B
Question #25
Case StudyOverviewADatum Corporation is a consulting company in Montreal.ADatum recently acquired a Vancouver-based company named Litware, Inc.Existing Environment. ADatum EnvironmentThe on-premises network of ADatum contains an Active Directory Domain Services (AD DS) forest named adatum.com.ADatum has a Microsoft 365 E5 subscription. The subscription contains a verified domain that syncs with the adatum.com AD DS domain by using Azure AD Connect.ADatum has an Azure Active Directory (Azure AD) tenant named adatum.com. The tenant has Security defaults disabled.The tenant contains the users shown in the following table.The tenant contains the groups shown in the following table.Existing Environment. Litware EnvironmentLitware has an AD DS forest named litware.comExisting Environment. Problem StatementsADatum identifies the following issues:Multiple users in the sales department have up to five devices. The sales department users report that sometimes they must contact the support department to join their devices to the Azure AD tenant because they have reached their device limit.A recent security incident reveals that several users leaked their credentials, a suspicious browser was used for a sign-in, and resources were accessed from an anonymous IP address.When you attempt to assign the Device Administrators role to IT_Group1, the group does NOT appear in the selection list.Anyone in the organization can invite guest users, including other guests and non-administrators.The helpdesk spends too much time resetting user passwords.Users currently use only passwords for authentication.Requirements. Planned ChangesADatum plans to implement the following changes:Configure self-service password reset (SSPR).Configure multi-factor authentication (MFA) for all users.Configure an access review for an access package named Package1.Require admin approval for application access to organizational data.Sync the AD DS users and groups of litware.com with the Azure AD tenant.Ensure that only users that are assigned specific admin roles can invite guest users.Increase the maximum number of devices that can be joined or registered to Azure AD to 10.Requirements. Technical RequirementsADatum identifies the following technical requirements:Users assigned the User administrator role must be able to request permission to use the role when needed for up to one year.Users must be prompted to register for MFA and provided with an option to bypass the registration for a grace period.Users must provide one authentication method to reset their password by using SSPR. Available methods must include:- Email- Phone- Security questions- The Microsoft Authenticator appTrust relationships must NOT be established between the adatum.com and litware.com AD DS domains.The principle of least privilege must be used.You need to implement the planned changes for Package1.Which users can create and manage the access review?
A. ser3 only
B. ser4 only
C. ser5 only
D. ser3 and User4
E. ser3 and User5
F. ser4 and User5
View answer
Correct Answer: E
Question #26
You have a Microsoft Exchange organization that uses an SMTP address space of contoso.com.Several users use their contoso.com email address for self-service sign-up to Azure Active Directory (Azure AD).You gain global administrator privileges to the Azure AD tenant that contains the self-signed users.You need to prevent the users from creating user accounts in the contoso.com Azure AD tenant for self-service sign-up to Microsoft 365 services.Which PowerShell cmdlet should you run?
A. Set-MsolCompanySettings
B. Set-MsolDomainFederationSettings
C. Update-MsolfederatedDomain
D. Set-MsolDomain
View answer
Correct Answer: A

View The Updated Microsoft Exam Questions

SPOTO Provides 100% Real Microsoft Exam Questions for You to Pass Your Microsoft Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us