Microsoft Identity and Access Administrator SC-300 Dumps in PDF

Free Microsoft SC-300 Real Questions (page: 6)

You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table.
You create a dynamic user group and configure the following rule syntax.
user.usageLocation -in ["US","AU"] -and (user.department -eq "Sales") -and -not (user.jobTitle -eq "Manager") –or (user. jobTitle -eq "SalesRep")
Which users will be added to the group?

  1. User1 only
  2. User2 only
  3. User3 only
  4. User1 and User2 only
  5. User1 and User3 only
  6. User1, User2, and User3

Answer(s): D



You have an Azure AD tenant that contains a user named User1.
User1 needs to manage license assignments and reset user passwords.
Which role should you assign to User1?

  1. Helpdesk administrator
  2. Billing administrator
  3. License administrator
  4. User administrator

Answer(s): D



You have 2,500 users who are assigned Microsoft Office 365 Enterprise E3 licenses. The licenses are assigned to individual users.
From the Groups blade in the Azure Active Directory admin center, you assign Microsoft Office 365 Enterprise E5 licenses to a group that includes all users.
You need to remove the Office 365 Enterprise E3 licenses from the users by using the least amount of administrative effort.
What should you use?

  1. the Set-MsolUserLicense cmdlet
  2. the Set-AzureADGroup cmdlet
  3. the Set-WindowsProductKey cmdlet
  4. the Administrative units blade in the Azure Active Directory admin center

Answer(s): A



HOTSPOT (Drag and Drop is not supported)
You have a Microsoft Entra tenant that contains a user named User1.
An administrator deletes User1.
You need to identify the following:
• What is the maximum number of days for which you have the option to restore the User1 account?
• Which is the least privileged role that can be used to restore User1?
To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

  1. See Explanation section for answer.

Answer(s): A

Explanation:



You have 2,500 users who are assigned Microsoft Office 365 Enterprise E3 licenses. The licenses are assigned to individual users.
From the Groups blade in the Azure Active Directory admin center, you assign Microsoft 365 Enterprise E5 licenses to a group that includes all the users.
You need to remove the Office 365 Enterprise E3 licenses from the users by using the least amount of administrative effort.
What should you use?

  1. the Set-AzureADGroup cmdlet
  2. the Identity Governance blade in the Azure Active Directory admin center
  3. the Set-WindowsProductKey cmdlet
  4. the Set-MsolUserLicense cmdlet

Answer(s): D



You have a Microsoft Entra tenant named contoso.com that contains an enterprise application named App1.
A contractor uses the credentials of user1@outlook.com.
You need to ensure that you can provide the contractor with access to App1. The contractor must be able to authenticate as user1@outlook.com.
What should you do?

  1. Run the New-MgUser cmdlet.
  2. Run the New-MgInvitation cmdlet.
  3. Configure the External collaboration settings.
  4. Implement Microsoft Entra Connect sync.

Answer(s): B



HOTSPOT (Drag and Drop is not supported)
Your on-premises network contains an Active Directory domain that uses Azure AD Connect to sync with an Azure AD tenant.
You need to configure Azure AD Connect to meet the following requirements:
• User sign-ins to Azure AD must be authenticated by an Active Directory domain controller.
• Active Directory domain users must be able to use Azure AD self-service password reset (SSPR).
What should you use for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

  1. See Explanation section for answer.

Answer(s): A

Explanation:



You have 2,500 users who are assigned Microsoft Office 365 Enterprise E3 licenses. The licenses are assigned to individual users.
From the Groups blade in the Azure Active Directory admin center, you assign Microsoft Office 365 Enterprise E5 licenses to a group that includes all users.
You needed to remove the Office 365 Enterprise E3 licenses from the users by using the least amount of administrative effort.
What should you use?

  1. the Groups blade in the Azure Active Directory admin center
  2. the Set-AzureADGroup cmdlet
  3. the Identity Governance blade in the Azure Active Directory admin center
  4. the Set-MsolUserLicense cmdlet

Answer(s): D



Share your comments for Microsoft SC-300 exam with other users:

A
AI Tutor Explanation
7/31/2026 3:09:48 AM

Question 4:
You're right to flag that. The key concept is this:

  • Group-based licensing can be applied to groups in Azure AD, but it only works with security groups. Microsoft 365 groups (formerly Office 365 groups) are not eligible for direct license assignment.

If Group4 and Group5 are actually Microsoft 365 groups, they cannot receive the E5 license directly. The license would only be assignable to the security groups in the list (whatever groups among Group1–Group5 are security groups).
How to verify in your environment:
  • In the Azure portal, go to Groups > select a group > check the Group Type. It will show either "Security" or "Microsoft 365".
  • If you’re using PowerShell/Graph, look for the group type or the presence of a “Unified” group type for M365 groups (security groups won’t have that).

If you can tell me which of Group1–Group5 are security groups vs Microsoft 365 groups, I can pinpoint the exact correct option.

S
siva
5/17/2023 12:32:00 AM

very helpfull

J
Jorn
7/13/2023 5:05:00 AM

relevant questions

AI Tutor 👋 I’m here to help!