Exam objective

SC-300

Create, configure, and manage Microsoft Entra identities

This objective sits in Implement and manage user identities, which carries 22% of the Identity and Access Admin exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page ↗

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Implement and manage user identities

An organization is onboarding a new IT administrator who will be assigned the Global Administrator role. The admin's identity currently exists only as an on-premises Active Directory account. What should the identity team do before assigning the role?

Create a new cloud-native account and assign the Global Administrator role to itCorrect · your answerCorrect: a cloud-native account isolates the privileged Entra role from on-premises compromise risk.
Sync the admin's on-premises Active Directory account into Microsoft Entra IDSyncing the on-premises account is exactly the pattern the best practice warns against for privileged role assignments.
Assign the Global Administrator role directly to the synced on-premises accountAssigning the role to a synced account means an on-premises compromise directly compromises Entra resources.
Create a guest account from the on-premises identity and assign the role to itGuest accounts are meant for external collaboration, not for converting an internal admin's primary identity.
Configure the on-premises account as an emergency access break glass accountBreak glass accounts are reserved for emergency access scenarios, not routine new-admin onboarding.

Correct.

Checked against learn.microsoft.com, July 2026

Concept

Best practice recommends using cloud-native accounts for Microsoft Entra role assignments rather than on-premises synced accounts.

Why A

Creating a cloud-native account for the Global Administrator role assignment avoids linking a highly privileged Entra role to an identity whose compromise on-premises could cascade into the cloud tenant.

Source

Use cloud native accounts for Microsoft Entra roles Avoid using on-premises synced accounts for Microsoft Entra role assignments. If your on-premises account is compromised, it can compromise your Microsoft Entra resources as well.

Entra RBAC best practices, checked July 2026
#entra-id#cloud-native-account#global-administrator#identity-management

Now you: practice questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Implement and manage user identities

A tenant already uses Privileged Identity Management for just-in-time activation of the Helpdesk Administrator role. Security wants role activation to also require multifactor authentication and a compliant device. Which additional layered control should be configured?

Sample question 2 of 3

Implement and manage user identities

A Global Administrator wants a helpdesk group to be able to reset passwords for the User Administrator role only when needed, without holding the permission at all times. Which approach best meets this goal?

Sample question 3 of 3

Implement and manage user identitiesChoose 2

A tenant needs a regional helpdesk admin to reset passwords only for users in their own region, with the role assignment time-bound and requiring approval before activation. Which two controls should be combined with a custom role scoped to the task?

Full Identity and Access Admin question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Implement and manage user identities