Exam objective

SC-300

Plan, implement, and manage access reviews in Microsoft Entra

This objective sits in Plan and automate identity governance, which carries 28% of the Identity and Access Admin exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page ↗

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Plan and automate identity governance

A B2B collaboration tenant has hundreds of guest accounts added to Microsoft 365 groups over time. The identity team wants a recurring process that has reviewers recertify each guest's continued need for access, with AI-powered suggestions to assist reviewers, and automatic removal of guests whose access is denied. Which capability should they configure?

Microsoft Entra access reviews scoped to the guest group membershipsCorrect · your answerCorrect: this is the feature purpose-built for recurring recertification of existing guest access with AI-powered reviewer suggestions.
Entitlement management access packages for guest onboarding requestsAccess packages govern how new guests request and are granted access initially, not recurring recertification of guests already in the directory.
Lifecycle workflows configured for guest offboarding eventsLifecycle workflows automate tasks tied to lifecycle events like joiner or leaver status, not recurring access recertification decisions by reviewers.
Privileged Identity Management eligible role assignment reviewsPIM role reviews recertify privileged role assignments, not general guest group membership, so it does not fit this scenario.
Conditional Access policies requiring guest terms of useTerms of use policies require agreement before sign-in but do not provide recurring recertification or removal of unneeded guest access.

Correct.

Checked against learn.microsoft.com, July 2026

Concept

Access reviews automate recurring recertification of existing guest access and use AI-powered suggestions to help reviewers decide, removing identities when access is denied or no longer needed.

Why A

Access reviews scoped to the group memberships directly matches the described scenario: recurring review of existing guests, AI-assisted decisions, and automatic removal on denial.

Source

…access reviews that automates recurring reviews of existing guests already in your organization's directory, and removes those identities from your organization's directory when they no longer need access. AI-powered suggestions help reviewers make better informed decisions.

Identity governance overview, checked July 2026
#access reviews#guest lifecycle#entra id governance

Now you: practice questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Plan and automate identity governance

An organization has many guest users already present in its directory from past projects. Security wants recurring reviews that automatically remove guests who no longer need access, using AI-generated suggestions to help reviewers decide. Which capability should be configured?

Sample question 2 of 3

Plan and automate identity governance

Which situation is named as a good reason to run an access review?

Sample question 3 of 3

Plan and automate identity governance

What does the convenience of self-service access create a need for?

Full Identity and Access Admin question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Plan and automate identity governance