certslothcertsloth
SC-300/Topic 01

Microsoft / Associate

Tenants, Administrative Scope and Identity Lifecycle

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Directory role manages identity; Azure role manages a resource scope.

Must remember

A Microsoft Entra tenant is an identity directory boundary. Entra roles authorize directory administration; Azure RBAC roles authorize supported Azure resource operations. A subscription owner is not automatically a tenant Global Administrator, and directory administration does not automatically grant access to every subscription’s data.

Use groups, built-in/custom roles and administrative units to delegate appropriate administration. Administrative units scope supported role management; they are not isolated tenants and do not hide all directory objects from everyone. Evaluate effective grants, inherited/group-based access and privileged assignments rather than only one visible role.

Manage verified domains, user/group/device settings, company branding and lifecycle processes. Device registration, Entra join and hybrid join describe different relationships; registration alone does not prove device compliance. Licenses enable product capabilities and can be assigned directly or through supported group processes; troubleshoot assignment conflicts and capacity separately from sign-in.

External collaboration settings govern guest collaboration; cross-tenant access settings govern supported inbound/outbound trust and collaboration. Cross-tenant synchronization provisions supported identities; it does not merge tenants. External identity-provider federation can use supported SAML/WS-Fed arrangements. Review who may invite, what trust is accepted and how guests are removed.

Use supported Microsoft Graph PowerShell or admin-center bulk operations with scoped permissions. Custom security attributes classify identities for supported policy/use cases and have their own administration/access considerations. Always preview the target population before a bulk lifecycle change.

Choose under exam pressure

Requirement Choice and reason
Delegate support for one department Administrative unit plus an appropriate scoped Entra role.
Grant VM management Azure RBAC at the needed resource scope.
Collaborate with another company External identity and cross-tenant policy design.

Traps

  • An administrative unit is not a separate tenant.
  • Device join is not the same as compliance or trust for every application.

Active recall

1. Entra role versus Azure role?

Directory administration versus Azure resource authorization.

2. Why inspect effective permissions?

Access can come from several direct/group/inherited assignments.

3. Does cross-tenant synchronization merge directories?

No; it provisions supported identity relationships between distinct tenants.

4. What does a verified domain establish?

Control of the domain for supported tenant identity use.

5. Why separate license and access troubleshooting?

A user can authenticate yet lack the license or authorization for a capability.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.