Exam objective

SC-300

Plan and implement identities for applications and Azure workloads

This objective sits in Plan and implement workload identities, which carries 22% of the Identity and Access Admin exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page ↗

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Plan and implement workload identities

A developer builds an automated app that must create resources in one resource group without ever signing in as a user. Which security principal type should receive the Azure RBAC role assignment for the app?

A management group scope covering all subscriptions in the tenantA management group is a scope level for where access applies, not a security principal that requests access.
A user account created specifically for the application to sign in withA dedicated user account would work technically but does not follow the workload identity model and mixes human and application access.
A service principal representing the application's registered identityCorrect · your answerCorrect: a service principal is the security principal type that represents an application's identity for role assignment purposes.
A custom role definition granting only read and write actionsA role definition lists permitted actions but is not a security principal, so it cannot itself be assigned a role.
A security group containing the IT administrators who manage the appA security group represents people who manage the app, not the app's own identity, so it does not fit the role assignment target here.

Correct.

Checked against learn.microsoft.com, July 2026

Concept

Azure RBAC role assignments target a security principal, which can be a user, group, service principal, or managed identity, so applications and workloads get their own identity type rather than borrowing a user's credentials.

Why C

The app's registered identity in Microsoft Entra ID is represented as a service principal, which is one of the four security principal types that can receive a role assignment for an Azure resource.

Source

A security principal is an object that represents a user, group, service principal, or managed identity that is requesting access to Azure resources. You can assign a role to any of these security principals.

Azure RBAC overview, checked July 2026
#workload identity#service principal#security principal#azure rbac

Now you: practice questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Plan and implement workload identities

A service principal for an automated workload is assigned the Contributor role at the subscription scope and the Reader role directly on one resource group within that subscription. What are its effective permissions on that resource group?

Sample question 2 of 3

Plan and implement workload identities

A developer registers an application in Microsoft Entra ID. The app must run unattended and manage all resources in a resource group without any interactive sign-in. Which security principal type is created to represent this application's identity for the role assignment?

Sample question 3 of 3

Plan and implement workload identities

Why must an application be registered with a Microsoft Entra tenant before it can use the platform?

Full Identity and Access Admin question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Plan and implement workload identities