Exam objective
SC-300Plan and implement app registrations
This objective sits in Plan and implement workload identities, which carries 22% of the Identity and Access Admin exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.
Objective title verbatim from the official objectives. Microsoft Azure exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
A DevOps engineer registers an application in Microsoft Entra ID so a GitHub Actions pipeline can authenticate to an Azure subscription without a user account. Which solution secures this application's access using adaptive policies and custom security attributes?
Correct.
Checked against learn.microsoft.com, July 2026Concept
An app registration produces an identity that nobody logs into. Everything downstream follows from that: there is no second factor to prompt for, no manager to approve a request, no diploma to verify, and no VPN replacement involved. What the identity does need is a way to be scoped and conditioned, which is why nonhuman identities get their own policy surface.
Why C
The pipeline holds no user account, so the identity being secured is the registered application itself. Microsoft Entra Workload ID is the product that applies Conditional Access and custom security attributes to that kind of identity, which is exactly the pairing the question describes.
Source
What is Microsoft Entra ID, checked July 2026Microsoft Entra Workload ID is the identity and access management solution for workload identities — applications, services, and containers that require authentication and authorization policies. It lets organizations secure access to resources using adaptive policies and custom security attributes. For example, GitHub Actions need a workload identity to access Azure subscriptions to automate, customize, and execute software development workflows.
Now you: practice questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
An admin builds a Conditional Access policy targeting a registered application's workload identity authenticating to Azure resources. The tenant already holds Microsoft Entra ID P1. Which additional license is required for the policy to take effect on this identity type?
Sample question 2 of 3
A DevOps engineer configures a GitHub Actions pipeline that must authenticate directly to an Azure subscription without any user signing in, to run deployment scripts automatically. Which Microsoft Entra product manages this identity?
Sample question 3 of 3
An organization already holds Microsoft Entra ID P1 and enforces Conditional Access on user sign-ins. The admin now wants Conditional Access to also govern authentication requests from an application's workload identity. What additional requirement applies?
Full Identity and Access Admin question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.