Exam objective
SC-300Implement and manage identities for external users and tenants
This objective sits in Implement and manage user identities, which carries 22% of the Identity and Access Admin exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.
Objective title verbatim from the official objectives. Microsoft Azure exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
A security team discovers many B2B guest accounts already in the directory that were never added through an access package request. The team wants a recurring process to confirm each guest still needs access and remove those who do not. Which feature fits?
Correct.
Checked against learn.microsoft.com, July 2026Concept
Governance features split by when they act. One decides whether access should be granted at all, creating the account as a side effect. Another runs on employment or contract events. A third asks on a repeating schedule whether an entitlement that already exists is still justified, and it is the only one that can clean up objects nobody requested through a governed path.
Why D
Because these guests already exist in the directory outside the access package request flow, recurring access reviews are the mechanism that periodically validates their continued need for access and removes them when it no longer applies.
Source
Identity governance overview - Microsoft Learn, checked July 2026…access reviews that automates recurring reviews of existing guests already in your organization's directory, and removes those identities from your organization's directory when they no longer need access.
Now you: practice questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
A company configures entitlement management so approved partner organizations can request access to a marketing app. A partner user's request is approved. What happens to that user's identity in the directory?
Sample question 2 of 3
A governance team wants guest users who currently hold no access package assignments removed from the directory automatically, even if no recurring review was ever scheduled for them. Which capability should they configure?
Sample question 3 of 3
A partner accepts a B2B collaboration invitation to a workforce tenant. How are they represented afterwards?
Full Identity and Access Admin question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.