Certification guide
SC-300Microsoft Identity and Access Administrator: the honest guide
SC-300 is the Microsoft identity exam that assumes you already do the job. Identity and Access Administrator covers tenant configuration, user and hybrid identity, authentication methods, Conditional Access, Identity Protection, workload identities and identity governance, and it asks which configuration solves a described problem rather than what a feature is called.
The exam is 40 to 60 questions in 100 minutes, scored 700 out of 1000, and it includes case studies alongside multiple choice, drag-and-drop and hot area items. A case study gives you a scenario with requirements and constraints and then asks several questions against it, which is closer to a design review than a quiz.
The four skill areas are weighted close to evenly: user identities around 22 percent, authentication and access management around 28 percent, workload identities around 22 percent, and identity governance around 28 percent. There is no domain you can safely skip, and the two heaviest are the two that need the most tenant time.
Who Identity and Access Admin is for
A good fit if
- You administer Entra ID now: users, groups, Conditional Access, MFA rollouts, guest access, and you want the credential to match.
- You are an Azure or Microsoft 365 administrator whose role is drifting toward identity, and identity governance is the part you have not done yet.
- You come from on-prem Active Directory and need to prove you can run the cloud directory, not just sync to it.
- You are moving into an IAM engineer role in an Entra-centric organisation and need something more specific than a general security certification.
- You already hold AZ-104 or SC-900 and identity is the direction you picked.
Probably not, if
- You have never used Entra ID. This exam does not teach the platform and the case studies assume operational judgement. Start with SC-900 or AZ-900, get tenant access, and come back.
- Your organisation runs Okta, Ping or a non-Microsoft identity provider. The concepts transfer, the exam does not, and none of the product-specific answers will be useful to you.
- You want a security operations or threat detection role. SC-200 is the Defender and Sentinel exam and it is a much closer match.
- You want a vendor-neutral IAM credential for a mixed estate. SC-300 is deliberately and entirely Microsoft-specific.
Is Identity and Access Admin worth it?
For a working Entra administrator, yes, and more clearly than most role-based exams. Identity is where the practical work in Microsoft security sits, SC-300 is the credential that names it directly, and the study forces you through the governance features (entitlement management, access reviews, PIM) that most administrators have licensed and never configured. Learning those is worth the $165 whether or not you sit the exam.
For someone whose identity experience is one narrow slice, such as MFA rollouts or guest access, the value is in the gaps it makes you fill. Expect the study to take real weeks rather than evenings, because the exam tests decisions and there is no way to memorise your way to a case study answer.
For someone without hands-on Entra experience, no. The failure mode is not that it is too hard to learn, it is that the reading feels productive and the case studies do not care what you read. People in this position pass it after six months in a job, not before.
As a hiring signal, it does real work in Entra-centric organisations. It is specific enough that a hiring manager knows exactly what you were tested on, which is the opposite of how a general security certification reads. Outside the Microsoft ecosystem it means much less.
What the exam actually asks you to do
Multiple choice and multiple response, plus drag-and-drop ordering, hot area items where you click a region of a screenshot, and case studies that hold one scenario across several linked questions.
Item formats
- Multiple choice
- Multiple response
- Drag and drop
- Hot area
- Case study
The highlighted formats are the ones you cannot answer from memory alone. Microsoft Learn, exam duration and question types ↗
Domain breakdown and official weightings
From the official Microsoft Learn study guides. Implement authentication and access management is the heaviest domain at 28 percent, followed by Plan and automate identity governance at 28 percent.
- Implement and manage user identities22%
- Implement authentication and access management28%
- Plan and implement workload identities22%
- Plan and automate identity governance28%
Study plans by experience level
Administering Entra ID daily, governance is the gap
3 to 4 weeksat 6 to 8 hours
- 1Read the current skills outline line by line and mark every task you have not personally performed. For most administrators in this group that list is entitlement management, access reviews, PIM configuration, and app registration permission grants.
- 2Week 1: identity governance, which is about 28 percent of the exam and almost certainly your weakest area. Build an access package with a catalog, a policy and an approval workflow. Run an access review from creation to applied results. Configure a PIM eligible assignment with justification, approval and an activation window.
- 3Week 2: workload identities. Register an app, configure client secrets and certificates, compare delegated with application permissions, grant admin consent, and set up a managed identity against an Azure resource. This is the area experienced user-side administrators most often underestimate.
- 4Week 3: sweep authentication and Conditional Access. You know the feature, so study the edge cases: report-only mode, what happens with multiple matching policies, named locations, authentication strengths, and the difference between sign-in risk and user risk policies.
- 5Week 4: case study practice under time. Read the requirements before the questions, and practise deciding which requirement each question actually turns on. Book when your timing is comfortable, not when your recall is.
Azure or M365 admin, identity is part of a wider role
6 to 8 weeksat 8 to 10 hours
- 1Weeks 1 to 2: tenant fundamentals done properly. Custom domains, company branding, administrative units, dynamic group membership rules, and the built-in directory roles with their actual boundaries. This is background you have half absorbed and the exam tests precisely.
- 2Week 3: external identities. B2B collaboration settings, cross-tenant access policies, guest invitation and redemption, and where B2C fits. This area is easy to skip and reliably examined.
- 3Week 4: hybrid identity. Entra Connect and cloud sync, password hash sync against pass-through authentication against federation, single sign-on from domain-joined devices, and what happens to each during an outage. If you have never run a sync, build a small domain controller in Azure and do it once.
- 4Weeks 5 to 6: authentication methods and Conditional Access in depth, then Identity Protection. Configure policies, put them in report-only mode, read the sign-in logs, and understand what the What If tool tells you.
- 5Week 7: identity governance and workload identities, in a tenant, not in a browser tab full of documentation.
- 6Week 8: full timed practice with case studies. Track accuracy by skill area and spend the last few days on the weakest one.
Coming from on-prem Active Directory, new to the cloud directory
10 to 12 weeksat 6 to 8 hours
- 1Weeks 1 to 2: unlearn the mapping. Entra ID is not Active Directory in Azure. There are no OUs, no group policy and no Kerberos, and roles work differently from delegation. Getting this wrong early is the single biggest source of wasted study time for AD administrators.
- 2Weeks 3 to 4: users, groups, administrative units and licensing in a tenant of your own. Do the tasks rather than reading them, including dynamic membership rules, which have their own syntax.
- 3Weeks 5 to 6: hybrid identity, which is your advantage. Entra Connect, the three authentication options and their failure modes, and filtering. You already understand what is being synchronised, so this is where you move fastest.
- 4Weeks 7 to 8: authentication methods, MFA, self-service password reset with writeback, and Conditional Access. Build policies and test them against real sign-ins with the What If tool.
- 5Weeks 9 to 10: workload identities. App registrations, service principals, managed identities and consent. There is no on-prem analogue for most of this, so budget the full two weeks.
- 6Weeks 11 to 12: identity governance and then timed case study practice. Book the exam only once the case studies stop feeling like reading comprehension.
Common mistakes
- Studying it the way you studied a fundamentals exam
- Reading the Microsoft Learn path end to end is necessary and nowhere near sufficient. SC-300 asks which configuration meets a stated requirement, and that judgement only comes from having built the thing and watched it behave.
- Skipping identity governance because your tenant is licensed P1
- PIM, access reviews, entitlement management and Identity Protection are P2 features and roughly a quarter of the exam. If your work tenant cannot do them, start a P2 trial in your own tenant. There is no way around this area.
- Testing Conditional Access in production
- A policy without the right exclusions locks out administrators, including you. Use a non-production tenant, keep a break-glass account excluded from every policy, and use report-only mode before enabling anything. This is exam content and operational reality at the same time.
- Underestimating workload identities
- App registrations, service principals, managed identities and consent are about a fifth of the exam, and administrators who spend their days on user accounts consistently arrive underprepared. The distinction between delegated and application permissions decides real questions.
- Losing the exam on case study pacing
- 100 minutes is enough time only if you read each case study once, properly, and then answer. Candidates who reread the scenario for every question run out of clock with questions unanswered, which is a preventable failure.
- Learning old terminology from old material
- Azure AD is Entra ID, Azure AD Connect is Entra Connect, and several governance features have been renamed or moved since. Material more than a year or two old will use terms the exam no longer uses.
What comes after passing
SC-300 is valid for one year and renews free through an unproctored online assessment on Microsoft Learn. The window opens six months before expiry, so set the reminder on the day you pass rather than trusting the email.
The renewal assessment is short and open book, but it tracks changes to the platform, which on identity are frequent. Treat it as the yearly nudge to read what has changed in Conditional Access and governance rather than as an obstacle.
The natural next steps depend on where you want to sit. SC-200 if detection and response interests you, AZ-500 if you want Azure infrastructure security, and AZ-104 if you skipped general Azure administration and keep hitting the gap. Each of those is role-based with the same yearly renewal.
The most valuable thing to do in the month after passing is put the governance features into production. An access review on your privileged groups and PIM on your global administrator assignments are two changes you can now justify, implement and point to, and they carry more weight in your next interview than the certificate does.
Costs across the full renewal cycle are on the Identity and Access Admin cost page.
Frequently asked questions
Is SC-300 worth it?
For working Entra administrators and people moving into IAM roles in Microsoft shops, yes. It is specific enough that a hiring manager knows what you were tested on, and the study forces you through governance features most administrators have licensed and never used. Outside the Microsoft ecosystem it means much less.
How hard is SC-300?
Harder than it looks on paper. It is 40 to 60 questions in 100 minutes with case studies, passing at 700 out of 1000, and it tests configuration decisions rather than definitions. Without hands-on Entra experience it is a difficult exam to pass by studying.
How long does SC-300 take to study for?
Three to four weeks at 6 to 8 hours a week if you administer Entra ID daily, six to eight weeks if identity is only part of your role, and ten to twelve weeks coming from on-prem Active Directory with no cloud directory experience.
Do I need SC-900 before SC-300?
No, there is no formal prerequisite. SC-900 is a useful primer if the Microsoft security product family is unfamiliar, and skippable if you already work in Entra ID. What you actually need is tenant access, not another certificate.
Should I take AZ-104 or SC-300 first?
They overlap on Entra basics and diverge quickly after that. If your role is identity-focused, SC-300 first is fine. General Azure administrators usually take AZ-104 first because it covers the wider platform their work touches.
Can I pass SC-300 without hands-on Entra experience?
It is possible with a lab tenant and a P2 trial, but it takes considerably longer and the case studies punish anyone who has only read about the features. Build the access packages, access reviews and PIM assignments yourself before you book.
Do I need an Entra ID P2 licence to study for SC-300?
For a large part of the exam, yes. PIM, Identity Protection, access reviews and entitlement management are all P2 features. A trial tenant covers it at no cost if you sequence the trial for when you are ready to use it.
Does SC-300 expire?
It is valid for one year and renews free through an online assessment on Microsoft Learn, available from six months before the expiry date. Miss the window and the certification lapses, and the route back is sitting the full exam again.
Keep reading
- Identity and Access Admin practice questions
Free sample questions with the full explanation on every answer.
- Free Identity and Access Admin practice test
Ten real questions, playable now. No account, no card.
- Identity and Access Admin exam objectives
The full official blueprint, with practice pages on covered objectives.
- Identity and Access Admin passing score
The exact cut score, what kind of number it is, and the retake terms.
- How hard is Identity and Access Admin?
An honest difficulty read from the format, the clock and the weights.
- What Identity and Access Admin costs
The voucher price, the retake, and what renewal costs across the cycle.
Cheat sheets
Printable reference tables, free.
Practise Identity and Access Admin for free while you decide
Original questions written from the published objectives, with the concept, the reasoning, and a note on every wrong option. No account needed to start.
Start free Identity and Access Admin questions