sc-300Associate
Microsoft Identity and Access Administrator
Microsoft Certified: Identity and Access Administrator Associate
SC-300 is the deepest Entra exam. The site's identity coverage is its strongest category, so this path is long and ordered the way the exam is: implement identities, then authentication and access, then apps, then governance. Do the how-to guides hands-on in a dev tenant.
For: Entra ID administrators: authentication, Conditional Access, app integration, and identity governance.
37 guides in 4sections. The sections are this site's grouping, written to follow the shape of the published skills outline; weightings and the current outline live on the exam page above and change between exam versions.
01Implement identities in Entra ID
- 1What is Microsoft Entra ID?What Microsoft Entra ID is: the identity service behind every Microsoft 365 sign-in, how it relates to Active Directory, and the licensing tiers that matter.
- 2Hybrid identity strategy for Microsoft 365How to plan the hybrid-identity journey from on-premises AD to Entra ID-only — staged, with the right choices at each stage.
- 3Entra Connect vs Entra Cloud SyncThe two ways to sync on-prem Active Directory to Entra ID — what each does, the scenarios that still force the old tool, and which to use today.
- 4Entra ID custom rolesHow to design and assign custom administrative roles in Microsoft Entra ID for fine-grained least-privilege access.
- 5Entra ID Administrative UnitsAdministrative Units scope admin roles to subsets of the directory — for delegated administration without tenant-wide privileges.
- 6Entra ID B2B guest accessHow Entra ID B2B brings external users into your tenant as guests — invitations, controls, and lifecycle.
- 7Cross-Tenant Access Settings designHow to design Cross-Tenant Access Settings (CTAS) — the foundational trust controls for B2B and cross-tenant collaboration.
- 8Entra ID Multi-Tenant OrganizationsMTO is Microsoft's modern model for running multiple Microsoft 365 tenants as one organisation. Here's what it provides.
02Authentication and access management
- 9Entra ID Conditional Access designDesigning a Conditional Access baseline: the policies, the principles, the order to write them in, and the habits that keep the estate healthy.
- 10Testing Conditional Access policiesHow to test Conditional Access policies before enforcing them — report-only mode, what-if, and rollout patterns.
- 11Conditional Access break-glass account designHow to design break-glass accounts that survive every Conditional Access disaster — credentials, monitoring, and recovery.
- 12How to create a break-glass account in Entra IDHow-toHow to create an emergency access (break-glass) account in Entra ID: cloud-only, permanent Global Admin, excluded from Conditional Access, FIDO2 keys, alerting.
- 13Rolling out a new named location without breaking Conditional AccessHow to add or change a named location in Entra without breaking Conditional Access: MFA and risk side effects, the report-only sequence, the egress-IP trap.
- 14Conditional Access for Microsoft 365 admin accountsConditional Access policies for admin accounts: phishing-resistant MFA, managed devices, short sessions, no legacy auth, plus exclusions and rollout order.
- 15How to block legacy authentication with Conditional AccessHow-toHow to block legacy authentication in Entra ID with Conditional Access: find who still uses it, build the block policy, run report-only, then enforce.
- 16Entra ID authentication contextsAuthentication contexts let Conditional Access trigger step-up authentication for specific actions, not just specific apps.
- 17Continuous Access Evaluation explainedHow CAE revokes access tokens in near real time when risk signals change — and what to do to make sure it works.
- 18Token protection and token theft in Microsoft 365Token theft has become a leading attack pattern. Here's how it works and what Microsoft 365 offers to defend against it.
- 19Entra ID passwordless authenticationThe realistic options for going passwordless in Microsoft 365 — Authenticator, FIDO2, Windows Hello, and passkeys.
- 20Microsoft Entra password protectionHow Entra ID's password protection blocks weak and breached passwords — for both cloud and on-prem AD accounts.
- 21Entra ID self-service password resetSSPR lets users reset their own passwords without calling the help desk. Here's the configuration and rollout.
- 22How to reset MFA for a user in Entra IDHow-toHow to reset a user's MFA in Entra ID when they have a new phone or lost their authenticator: re-register, revoke sessions, and issue a Temporary Access Pass.
03Access management for applications
- 23Entra ID app registrations and enterprise appsTwo sides of the same coin — app registrations define an app, enterprise apps grant it to your tenant. Here's how they relate.
- 24SAML SSO with Entra IDHow to set up SAML single sign-on between a third-party app and Microsoft Entra ID.
- 25SCIM provisioning to Entra IDHow SCIM auto-provisions users from HR and identity systems into Entra ID and downstream SaaS apps.
- 26App consent policies and the admin consent workflowHow to stop consent phishing without blocking legitimate apps: Entra ID app consent policies, the admin consent workflow, and a review process that scales.
- 27Entra ID Workload IdentitiesWorkload Identities is Entra ID's product for managing non-human identities — apps, services, scripts — and the risks they create.
- 28Microsoft 365 service principal best practicesHow to design, deploy, and operate service principals safely — credentials, permissions, and lifecycle.
04Identity governance and monitoring
- 29Entra ID Governance explainedEntra ID Governance explained: access reviews, entitlement management, lifecycle workflows, separation of duties, P2 vs Suite licensing, and rollout order.
- 30Entra ID Privileged Identity ManagementPIM turns standing admin access into just-in-time, approval-gated activation. The model, what it covers, role settings that work, and a rollout that sticks.
- 31How to set up PIM for the Global Administrator roleHow-toHow to set up Privileged Identity Management for Global Administrator in Entra ID: role settings, convert permanent admins to eligible, approvals, and alerts.
- 32PIM operational playbookHow to run Privileged Identity Management as a working process — onboarding, activation, approvals, and audit.
- 33Microsoft Entra ID Access ReviewsHow access reviews keep group memberships and role assignments healthy over time — periodic recertification at scale.
- 34Entitlement Management access packagesHow access packages bundle Microsoft 365 access into requestable, governed units — the modern way to provision access at scale.
- 35Entra ID Lifecycle WorkflowsLifecycle Workflows automate joiner-mover-leaver tasks based on user attribute triggers.
- 36Investigating a suspicious sign-in with Entra sign-in logsHow to work a suspicious sign-in in the Entra sign-in logs: which log, which columns matter, traveller vs attacker, and when to escalate to compromise.
- 37Compromised Microsoft 365 account response runbookCompromised Microsoft 365 account runbook: what to run in the first fifteen minutes, what to check in the first hour, and when it is safe to hand it back.
Independent site, not affiliated with Microsoft. Found a gap in this path? Send it through the contact form.