SC-300: identity, access, and operations
SC-300 with delegation, hybrid authentication, Conditional Access, application identities, and governance.
Objectives and progression
Eleven lessons, 50 questions, and five original cases connect identity to project work and support. Regular distribution across four domains: 12/14/12/12. Internal assessment of 38 decisions in 75 minutes. Initial coverage without executable labs or reproduction of official interactive formats. Compared the applicable 2026-04-27 outline, recovered from the official source index, with the English guide announced for 2026-10-28. The future revision changes the OAuth reference, Global Secure Access names, and emergency-account wording. Authentication and access weighting still conflicts: 25–30% at a glance and 20–25% in the detailed heading. Practice provisionally follows the summary; it does not confirm weights or fully reproduce the exam.
Audience: IAM professionals, L3 support, cloud administrators, and technical managers responsible for migrations and handover.
Prerequisites: Entra, Azure, Microsoft 365, on-premises AD, networking, and application foundations. PowerShell and KQL familiarity helps; practice does not replace operational experience.
485 estimated study minutes
- Distinguish management delegation, membership, and effective state.
- Design authentication and collaboration with explicit dependencies and recovery.
- Prepare registration, recovery, and strong authentication with known limits.
- Evaluate the policy set and deployment impact.
- Separate application representation, credentials, authorization, and provisioning.
- Connect temporary need with approval, expiry, and execution.
- Demonstrate effective remediation and communicate each stage’s state.
- Resolve attribute permissions, partial imports, and recreated guests.
- Distinguish methods, privileged-action requirements, and traffic acquisition.
- Diagnose callbacks and control application actions with explicit scope.
- Connect partners, terms acceptance, logs, and recommendations to verifiable decisions.
Modules
- Tenant, scope, and objects
- Hybrid identity and partners
- Methods and emergency access
- Conditional Access and risk
- Applications, identities, and consent
- Privileges, packages, and lifecycle
- Reviews, logs, and handover
- Objects, attributes, and external lifecycle
- Authentication, actions, and traffic
- Applications, sessions, and OAuth governance
- Governance and operational evidence
Continue learning
- SC-900 — Security, Compliance and Identity Fundamentals
- SC-200 — Security Operations Analyst
- AZ-104 — Azure Administrator
- Production Support L3
References and version
SC-300 objectives effective 2026-04-27; product documentation reviewed 2026-10-01; 2026-10-28 English update compared separately
- SC-300 certification · 2026-09-30
- SC-300 study guide · 2026-10-01
- Microsoft exam scoring · 2026-09-30
- Administrative units · 2026-09-30
- Hybrid authentication choices · 2026-09-30
- Cloud Sync overview · 2026-09-30
- Conditional Access report-only · 2026-09-30
- Build Conditional Access policies · 2026-09-30
- Conditional Access overview · 2026-09-30
- Emergency access accounts · 2026-09-30
- Temporary Access Pass · 2026-09-30
- Authentication strengths · 2026-09-30
- Revoke access in emergencies · 2026-09-30
- Application objects and service principals · 2026-09-30
- Permissions and consent · 2026-09-30
- Managed identities · 2026-09-30
- Application proxy overview · 2026-09-30
- PIM role settings · 2026-09-30
- Complete access reviews · 2026-09-30
- Entitlement management · 2026-09-30
- Lifecycle workflows · 2026-09-30
- Sign-in logs · 2026-09-30
- Audit logs · 2026-09-30
- Provisioning logs · 2026-09-30
- Cross-tenant access · 2026-09-30
- Device identities · 2026-09-30
- Group license assignment · 2026-09-30
- Identity Protection · 2026-09-30
- Global Secure Access · 2026-09-30
- Custom security attributes · 2026-10-01
- Bulk create users · 2026-10-01
- Cross-tenant synchronization governance · 2026-10-01
- SAML and WS-Fed federation · 2026-10-01
- Authentication methods and recovery · 2026-10-01
- Certificate-based authentication · 2026-10-01
- Configure protected actions · 2026-10-01
- Microsoft traffic profile · 2026-10-01
- My Apps collections · 2026-10-01
- Redirect URI matching · 2026-10-01
- Defender for Cloud Apps session policies · 2026-10-01
- Create app governance policies · 2026-10-01
- Connected organizations · 2026-10-01
- Terms of use · 2026-10-01
- Entra diagnostic settings · 2026-10-01
- Identity Secure Score · 2026-10-01
What you will explore
0 / 11Tenant, scope, and objects
Distinguish management delegation, membership, and effective state.
Hybrid identity and partners
Design authentication and collaboration with explicit dependencies and recovery.
Methods and emergency access
Prepare registration, recovery, and strong authentication with known limits.
Conditional Access and risk
Evaluate the policy set and deployment impact.
Applications, identities, and consent
Separate application representation, credentials, authorization, and provisioning.
Privileges, packages, and lifecycle
Connect temporary need with approval, expiry, and execution.
Reviews, logs, and handover
Demonstrate effective remediation and communicate each stage’s state.
Objects, attributes, and external lifecycle
Resolve attribute permissions, partial imports, and recreated guests.
Authentication, actions, and traffic
Distinguish methods, privileged-action requirements, and traffic acquisition.
Applications, sessions, and OAuth governance
Diagnose callbacks and control application actions with explicit scope.
Governance and operational evidence
Connect partners, terms acceptance, logs, and recommendations to verifiable decisions.