Exam objective
SC-300Plan, implement, and manage Microsoft Entra Conditional Access
This objective sits in Implement authentication and access management, which carries 28% of the Identity and Access Admin exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.
Objective title verbatim from the official objectives. Microsoft Azure exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
A company assigns a helpdesk technician to review Conditional Access policies in the Microsoft Entra admin center, without making any changes. Which role satisfies the minimum requirement for this task?
Correct.
Checked against learn.microsoft.com, July 2026Concept
A least-privilege question asks for the smallest role that still completes the task, so the test is not whether a role works but whether a smaller one also would. Read-only tasks are satisfied by reader-tier roles, and any role that can create or edit the object is over-privileged for viewing it. Between two reader roles, the narrower scope wins.
Why B
Security Reader is the minimum role documented for locating and viewing Conditional Access policies, matching the read-only task described.
Source
Conditional Access overview, checked July 2026Admins with at least the Security Reader role can find Conditional Access in the Microsoft Entra admin center under Entra ID > Conditional Access.
Now you: practice questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
An administrator wants a Conditional Access policy that requires multifactor authentication when a user's sign-in risk is calculated as high. Beyond a Microsoft Entra ID P1 license, which license is required to use this risk signal?
Sample question 2 of 3
A Conditional Access administrator wants a policy that requires multifactor authentication whenever Microsoft Entra ID Protection calculates a medium or high sign-in risk. Which license must the tenant have to support this risk-based policy?
Sample question 3 of 3
Contoso configured its Conditional Access policies under a Microsoft Entra ID P1 trial that has since expired. An administrator now tries to edit an existing policy to add a new group. What happens?
Full Identity and Access Admin question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.