Exam objective

SC-300

Monitor identity activity by using logs, workbooks, and reports

This objective sits in Plan and automate identity governance, which carries 28% of the Identity and Access Admin exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page ↗

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Plan and automate identity governance

An identity administrator holding the Security Reader role wants a single view that shows how many Conditional Access policies are enabled versus report-only, along with recent agent and user activity, application counts, and device counts. Where should the administrator look?

The Coverage tab on the Conditional Access page in the admin centerThe Coverage tab summarizes which applications have or lack policy coverage over seven days, not enabled versus report-only counts.
The Overview page on the Conditional Access blade in the admin centerCorrect · your answerCorrect: the Overview page consolidates enabled versus report-only counts with activity, application, and device summaries.
The risky users report inside Microsoft Entra ID ProtectionThe risky users report surfaces user risk detections from Identity Protection, not Conditional Access policy status.
The Sign-in logs blade in the Microsoft Entra admin centerSign-in logs record individual authentication events, not an aggregated policy status summary.
The Access reviews dashboard in Identity GovernanceThe Access reviews dashboard tracks periodic review campaigns, unrelated to Conditional Access policy activity.

Correct.

Checked against learn.microsoft.com, July 2026

Concept

Admin portals separate a summary surface from the drill-down surfaces beneath it. A summary answers what the state of a feature is right now, in aggregate counts. A drill-down answers a narrower question about one dimension: which applications lack protection, which users are risky, what happened on one sign-in. Asking for several unrelated counts at once is asking for the summary.

Why B

The Overview page shows a summary of recent activity related to Conditional Access policies, including enabled versus report-only counts, agent and user activity, applications, devices, and general security alerts, which matches every item the administrator wants to see in one place.

Source

The Overview page shows a summary of recent activity that relates to Conditional Access policies. Here you can see how many policies are enabled vs report-only, agent and user activity, applications, devices, and general security alerts with suggestions.

Conditional Access overview, checked July 2026
#conditional access#monitoring#overview page#admin center

Now you: practice questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Plan and automate identity governance

A compliance team needs a seven-day summary of which applications in the tenant currently have no Conditional Access policy applied, so they can prioritize remediation. The Overview page already shows enabled versus report-only policy counts, but not per-application gaps. Which page should they use instead?

Sample question 2 of 3

Plan and automate identity governance

A security administrator holding the Security Reader role opens Conditional Access in the Microsoft Entra admin center to review how many policies are enabled versus report-only, along with app, device, and agent activity. Which page shows this summary?

Sample question 3 of 3

Plan and automate identity governance

An identity team wants a Microsoft Entra product that detects and reports identity-based risks so administrators can investigate and remediate them, including feeding risk-based Conditional Access policies. Which product provides this?

Full Identity and Access Admin question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Plan and automate identity governance