Exam objective

SC-300

Implement and manage hybrid identity

This objective sits in Implement and manage user identities, which carries 22% of the Identity and Access Admin exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page ↗

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Implement and manage user identities

A company using Workday as its HR system wants new hires automatically created in both on-premises Active Directory and Microsoft Entra ID as soon as HR records them. Which capability should the identity administrator configure?

Azure role-based access control assignments scoped to a resource groupAzure RBAC governs access to Azure resources through role assignments, not identity creation from HR systems.
Inbound provisioning from HR sources such as Workday or SuccessFactorsCorrect · your answerCorrect: this is the feature that pulls HR data to create and maintain identities in both directories.
Entitlement management access packages for group and app assignmentEntitlement management assigns access packages such as group and app roles, it does not create the initial identity from HR records.
Recurring access reviews for guest account recertificationAccess reviews recertify existing guest access, they are unrelated to creating identities from an HR feed.
Lifecycle workflows triggered by employee status change eventsLifecycle workflows automate tasks at key events like start or leave dates, but they do not create the account from HR data itself.

Correct.

Checked against learn.microsoft.com, July 2026

Concept

Hybrid identity lifecycle management relies on inbound provisioning from an authoritative HR source to automatically maintain matching user identities across both Active Directory and Microsoft Entra ID.

Why B

Inbound provisioning from HR sources such as Workday or SuccessFactors is the feature described as automatically maintaining user identities in both Active Directory and Microsoft Entra ID based on HR signals, which matches the scenario's requirement.

Source

…inbound provisioning from your organization's HR sources, including retrieving from Workday and SuccessFactors, to automatically maintain user identities in both Active Directory and Microsoft Entra ID.

Identity governance overview, checked July 2026
#hybrid identity#inbound provisioning#identity lifecycle#entra id governance

Now you: practice questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Implement and manage user identities

Password hash synchronization is enabled between an on-premises directory and the cloud. What is synchronized?

Sample question 2 of 3

Implement and manage user identities

Which additional protection does enabling password hash synchronization make available for hybrid accounts?

Sample question 3 of 3

Implement and manage user identities

An organization enables password hash synchronization today. Which leaked credentials will be evaluated against its tenant?

Full Identity and Access Admin question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Implement and manage user identities