Microsoft SC-300 Exam (page: 7)
Microsoft Identity and Access Administrator
Updated on: 25-Dec-2025

Viewing Page 7 of 83

HOTSPOT (Drag and Drop is not supported)
Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains computers that run Windows 11.
You have a Microsoft 365 E5 subscription.
You plan to enable hybrid join and enroll the computers in Microsoft Intune.
You need to recommend the software that should be deployed to the domain, and the actions that should be performed in Intune.
What should you include in the recommendation? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

  1. See Explanation section for answer.

Answer(s): A

Explanation:



DRAG DROP (Drag and Drop is not supported)
You need to resolve the recent security incident issues.
What should you configure for each incident? To answer, drag the appropriate policy types to the correct issues. Each policy type may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Select and Place:

  1. See Explanation section for answer.

Answer(s): A

Explanation:


Box 1: A user risk policy
User-linked detections include:
Leaked credentials: This risk detection type indicates that the user's valid credentials have been leaked. When cybercriminals compromise valid passwords of legitimate users, they often share those credentials.
User risk policy.
Identity Protection can calculate what it believes is normal for a user's behavior and use that to base decisions for their risk. User risk is a calculation of probability that an identity has been compromised. Administrators can make a decision based on this risk score signal to enforce organizational requirements. Administrators can choose to block access, allow access, or allow access but require a password change using Azure AD self-service password reset.
Box 2: A sign-in risk policy
Suspicious browser: Suspicious browser detection indicates anomalous behavior based on suspicious sign-in activity across multiple tenants from different countries in the same browser.
Box 3: A sign-in risk policy
A sign-in risks include activity from anonymous IP address: This detection is discovered by Microsoft Defender for Cloud Apps. This detection identifies that users were active from an IP address that has been identified as an anonymous proxy IP address.
Note: The following three policies are available in Azure AD Identity Protection to protect users and respond to suspicious activity. You can choose to turn the policy enforcement on or off, select users or groups for the policy to apply to, and decide if you want to block access at sign-in or prompt for additional action.
* User risk policy
Identifies and responds to user accounts that may have compromised credentials. Can prompt the user to create a new password.
* Sign in risk policy
Identifies and responds to suspicious sign-in attempts. Can prompt the user to provide additional forms of verification using Azure AD Multi-Factor Authentication.
* MFA registration policy
Makes sure users are registered for Azure AD Multi-Factor Authentication. If a sign-in risk policy prompts for MFA, the user must already be registered for Azure
AD Multi-Factor Authentication.


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/concept-identity-protection-policies



HOTSPOT (Drag and Drop is not supported)
You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table.
For which users can you configure the Job title property and the Usage location property in Azure AD? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:


Box 1: User1 and User2 only.
You can add or update a user's profile information using Azure Active Directory.
Add user profile information, including a profile picture, job-specific information, and some settings using Azure Active Directory (Azure AD).
The user profile includes:
Job info. Add any job-related information, such as the user's job title, department, or manager.
Box 2: User1, User2, and User3
Invite users with Azure Active Directory B2B collaboration, Update user's name and usage location.
To assign a license, the invited user's Usage location must be specified. Admins can update the invited user's profile on the Azure portal.
1. Go to Azure Active Directory > Users and groups > All users. If you don't see the newly created user, refresh the page.
2. Click on the invited user, and then click Profile.
3. Update First name, Last name, and Usage location.
4. Click Save, and then close the Profile blade.


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-users-profile-azure-portal https://docs.microsoft.com/en-us/power-platform/admin/invite-users-azure-active-directory-b2b-collaboration#update-users-name-and-usage-location



You have an Azure Active Directory (Azure AD) tenant that: contains a user named User1.
You need to ensure that User1 can create new catalogs and add1 resources to the catalogs they own.
What should you do?

  1. From the Roles and administrators blade, modify the Groups administrator role.
  2. From the Roles and administrators blade, modify the Service support administrator role.
  3. From the Identity Governance blade, modify the Entitlement management settings.
  4. From the Identity Governance blade, modify the roles and administrators for the General catalog.

Answer(s): C

Explanation:

Create and manage a catalog of resources in Azure AD entitlement management.
Create a catalog.
A catalog is a container of resources and access packages. You create a catalog when you want to group related resources and access packages. A user who has been delegated the catalog creator role can create a catalog for resources that they own. Whoever creates the catalog becomes the first catalog owner. A catalog owner can add more users, groups of users, or application service principals as catalog owners.
Prerequisite roles: Global administrator, Identity Governance administrator, User administrator, or Catalog creator.
Incorrect:
* Groups Administrator - Members of this role can create/manage groups, create/manage groups settings like naming and expiration policies, and view groups activity and audit reports.
* Service Support Administrator
Users with this role can create and manage support requests with Microsoft for Azure and Microsoft 365 services, and view the service dashboard and message center in the Azure portal and Microsoft 365 admin center.


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/governance/entitlement-management-catalog-create https://docs.microsoft.com/en-us/azure/active-directory/roles/permissions-reference



Your network contains an on-premises Active Directory domain that syncs to an Azure Active Directory (Azure AD) tenant.
Users sign in to computers that run Windows 10 and are joined to the domain.
You plan to implement Azure AD Seamless Single Sign-On (Azure AD Seamless SSO).
You need to configure the Windows 10 computers to support Azure AD Seamless SSO.
What should you do?

  1. Configure Sign-in options from the Settings app.
  2. Enable Enterprise State Roaming.
  3. Modify the Local intranet Zone settings.
  4. Install the Azure AD Connect Authentication Agent.

Answer(s): C

Explanation:

Enable Seamless SSO through Azure AD Connect.
At the User sign-in page, select the Enable single sign on option.

Note:
The option will be available for selection only if the Sign On method is Password Hash Synchronization or Pass-through Authentication.
Seamless SSO can be combined with either the Password Hash Synchronization or Pass-through Authentication sign-in methods.


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sso-quick-start



Viewing Page 7 of 83



Share your comments for Microsoft SC-300 exam with other users:

siva 5/17/2023 12:32:00 AM

very helpfull
Anonymous


Jorn 7/13/2023 5:05:00 AM

relevant questions
UNITED KINGDOM