Microsoft / Associate / SC-300
Identity and Access Administrator
Manage Entra identities, authentication, application access and the full lifecycle of privileged entitlements.
This path targets Microsoft’s published October 28, 2026 update. Check the outline for an earlier sitting. At review, the official page gives inconsistent percentage ranges for authentication/access in its overview and detailed heading, so this page does not present one as definitive.
THE REVISION PATH
Your topics, in order.
Read. Recall. Explain the alternative.
Tenants, Administrative Scope and Identity Lifecycle
Directory role manages identity; Azure role manages a resource scope.
Hybrid Identity and Authentication Paths
Synchronization moves identity data; authentication proves the sign-in.
Authentication Methods, Recovery and Passwordless Access
Strong proof matters at enrollment, sign-in and recovery.
Conditional Access, Risk and Global Secure Access
Evaluate signals, enforce controls, test before broad rollout.
Application Registrations, Consent and Workload Identities
Registration defines the app; service principal represents it in a tenant.
Entitlements, Access Reviews and Privileged Elevation
Grant for a reason, expire on purpose, review with evidence.
Identity Logs, KQL and Operational Investigation
Find the actual actor, resource and policy result.
How this guide is organised
Original revision notes arranged around practical decisions. The linked official objectives define the mapped scope; primary documentation supports the explanations. Read each topic, answer without looking, then explain why another option would fail.
- Official exam guide ↗ Scope authority
Revision material supports preparation; it does not guarantee every possible exam question. Check the exam version and official objectives before booking.