← SC-300: identity, access, and operations
11 / 11 · 40 MIN

Governance and operational evidence

Connect partners, terms acceptance, logs, and recommendations to verifiable decisions.

Connected organizations and requests

A connected organization represents an external relationship for entitlement management. To restrict requests to named partners, also configure the access package policy with those organizations. Creating the relationship does not itself grant every resource. In a fictional migration, two partners need different roles and access periods. Define catalog, resources, approval, and expiry according to need. For Entra organizations, scope can include accounts using other verified domains in the same tenant; do not assume the entered domain string alone limits the entire population.

Terms and renewed acceptance

Terms of use presents a document and records acceptance through the configured Conditional Access flow. Updating the PDF lets you choose whether users must accept again. In a fictional case, version two changes usage conditions and the team assumes everyone received a new prompt. Inspect Require reaccept, policy scope, and reports. If renewed acceptance was not required, previous acceptance can remain current. Define expected behavior before publication and check an existing and a new user, keeping document updates separate from evidence of renewed acceptance.

Log export and observation

Diagnostic settings selects categories and destinations for Entra logs. Creating a workspace alone does not forward events. In a fictional exercise, AuditLogs reaches the destination but SigninLogs was not selected; the authentication workbook is empty. Check category, destination, time range, and permissions before concluding no activity occurred. Initial arrival can take time; documentation allows up to three days. Plan activation before cutover, use an identifiable test event, and define retention and access. The dashboard depends on the dataset actually ingested.

Secure Score and improvement planning

Identity Secure Score indicates alignment with Microsoft recommendations, not the probability of having no incident. In a fictional steering meeting, the score rises after authentication changes while a critical application still has a temporary exception. Report the trend together with residual risk, covered population, and exception expiry. Prioritize actions by service impact and exposure, assigning an owner and acceptance criteria. The score helps guide the backlog; it does not replace alert investigation or evidence that a control works on the relevant operational path.

IN PRACTICE

The dashboard is empty because only AuditLogs was exported. Define the required categories and verify ingestion before concluding no sign-ins occurred.

Common pitfalls

Registered partner as granted access; updated PDF as renewed acceptance; empty chart as absence; score as a guarantee.

Related topics: Tenant, scope, and objects · Hybrid identity and partners · Methods and emergency access

Take this idea with you

Keep the decision, execution, and available evidence traceable.

Create account

Reference: Entra diagnostic settings · SC-300 objectives effective 2026-04-27; product documentation reviewed 2026-10-01; 2026-10-28 English update compared separately