Objective create.manage-entra-identitiesSC-300

Create, configure, and manage Microsoft Entra identities

Objective create.manage-entra-identities sits in Implement and manage user identities, which carries 22% of the Identity and Access Admin exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Implement and manage user identitiesModerate

An organization is onboarding a new IT administrator who will be assigned the Global Administrator role. The admin's identity currently exists only as an on-premises Active Directory account. What should the identity team do before assigning the role?

Correct.

The concept

Best practice recommends using cloud-native accounts for Microsoft Entra role assignments rather than on-premises synced accounts.

Why this answer

Creating a cloud-native account for the Global Administrator role assignment avoids linking a highly privileged Entra role to an identity whose compromise on-premises could cascade into the cloud tenant.

  • Correct: a cloud-native account isolates the privileged Entra role from on-premises compromise risk.
  • BSyncing the on-premises account is exactly the pattern the best practice warns against for privileged role assignments.
  • CAssigning the role to a synced account means an on-premises compromise directly compromises Entra resources.
  • DGuest accounts are meant for external collaboration, not for converting an internal admin's primary identity.
  • EBreak glass accounts are reserved for emergency access scenarios, not routine new-admin onboarding.
Read the sourceEntra RBAC best practices
Verified against learn.microsoft.com · 2026-07-28
entra-idcloud-native-accountglobal-administratoridentity-management

Now you: objective create.manage-entra-identities questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Implement and manage user identitiesHard

A tenant already uses Privileged Identity Management for just-in-time activation of the Helpdesk Administrator role. Security wants role activation to also require multifactor authentication and a compliant device. Which additional layered control should be configured?

Sample question 2 of 3

Implement and manage user identitiesModerate

A Global Administrator wants a helpdesk group to be able to reset passwords for the User Administrator role only when needed, without holding the permission at all times. Which approach best meets this goal?

Sample question 3 of 3

Implement and manage user identitiesHardChoose 2

A tenant needs a regional helpdesk admin to reset passwords only for users in their own region, with the role assignment time-bound and requiring approval before activation. Which two controls should be combined with a custom role scoped to the task?

Full Identity and Access Admin question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Implement and manage user identities