Choose your language
Microsoft Identity and Access Administrator SC-300 Exam Guide
More than 2 million learners worldwide

Microsoft Identity and Access Administrator SC-300 Exam Guide

Master every domain of the SC-300 exam and become the identity security expert your organization needs. This comprehensive guide covers Azure AD architecture, Conditional Access, Privileged Identity Management, and hybrid identity from the ground up. Walk into exam day — and your next role — fully prepared to design, implement, and govern enterprise identity solutions.

Dedika for businesses

What you will learn:

  • Configure multi-factor authentication, passwordless methods, and self-service password reset policies.

  • Design and enforce Conditional Access policies using risk signals, device compliance, and named locations.

  • Implement Privileged Identity Management to control just-in-time access to Azure AD and resource roles.

  • Deploy hybrid identity solutions using Azure AD Connect, cloud sync, and directory synchronization monitoring.

  • Manage application registrations, enterprise SSO, API permissions, and automated SCIM provisioning.

  • Build an identity governance program with Entitlement Management, access reviews, and lifecycle workflows.

How you study in a practical way Microsoft Identity and Access Administrator SC-300 Exam Guide

How you practice Microsoft Identity and Access Administrator SC-300 Exam Guide

For companies who want to train their team

With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.

Click here

Course content

8 Chapters • 35 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Identity and Access Management Foundations

  • Lesson 1 • Azure AD Licensing and Service Tiers

    Compares Free, P1, and P2 feature sets and maps features to exam objectives. Enables accurate feature selection when designing identity solutions.

  • Lesson 2 • Azure Active Directory Architecture

    Explains Azure AD tenants, directories, subscriptions, and object types. Connects directory structure to access control decisions made throughout the course.

  • Lesson 3 • Microsoft Identity Platform Overview

    Surveys the Microsoft identity platform, OAuth 2.0, and OpenID Connect flows. Grounds students in the protocols that underpin all Azure AD authentication scenarios.

  • Lesson 4 • Core IAM Concepts and Terminology

    Defines authentication, authorization, identity providers, and trust models. Provides the vocabulary needed for every subsequent SC-300 domain.

Chapter 2See details

Implementing and Managing Azure AD Identities

  • Lesson 1 • Identity Lifecycle Automation

    Implements HR-driven provisioning and lifecycle workflows using Azure AD and Lifecycle Workflows. Reduces manual effort and enforces consistent joiner-mover-leaver processes.

  • Lesson 2 • External Identities and B2B Collaboration

    Configures guest user invitations, cross-tenant access settings, and B2B direct connect. Extends secure collaboration beyond organizational boundaries.

  • Lesson 3 • Administrative Units and Delegated Management

    Uses administrative units to scope admin roles to subsets of users and groups. Supports least-privilege delegation in large, multi-department tenants.

  • Lesson 4 • Group Types and Dynamic Membership

    Covers security groups, Microsoft 365 groups, and dynamic membership rules. Enables automated group population based on user attributes.

  • Lesson 5 • User Account Creation and Management

    Demonstrates bulk and individual user provisioning via portal, PowerShell, and Microsoft Graph. Directly supports the SC-300 objective on managing Azure AD users.

Chapter 3See details

Hybrid Identity and Directory Synchronization

  • Lesson 1 • Monitoring and Troubleshooting Synchronization

    Uses Azure AD Connect Health, sync logs, and error reports to diagnose sync failures. Maintains directory consistency and minimizes identity-related service disruptions.

  • Lesson 2 • Azure AD Cloud Sync Deployment

    Deploys the lightweight cloud sync agent for multi-forest and disconnected scenarios. Complements Azure AD Connect where full agent deployment is impractical.

  • Lesson 3 • Hybrid Identity Architecture and Options

    Compares password hash sync, pass-through authentication, and federation topologies. Guides architecture decisions based on security, availability, and compliance requirements.

  • Lesson 4 • Azure AD Connect Installation and Configuration

    Walks through express and custom installation, filtering, and attribute mapping. Produces a functional sync environment aligned with organizational directory structure.

Chapter 4See details

Authentication Methods and Passwordless Security

  • Lesson 1 • Passwordless Authentication Methods

    Deploys FIDO2 security keys, Microsoft Authenticator passwordless, and Windows Hello for Business. Eliminates password-based attack surfaces for high-value accounts.

  • Lesson 2 • Authentication Method Policies and Monitoring

    Manages the Authentication Methods policy blade and migration from legacy MFA settings. Provides centralized control and audit visibility over all authentication methods.

  • Lesson 3 • Self-Service Password Reset Setup

    Configures SSPR authentication methods, registration campaigns, and writeback to on-premises AD. Reduces helpdesk load while maintaining secure password recovery.

  • Lesson 4 • Multi-Factor Authentication Configuration

    Enables and configures per-user MFA, security defaults, and Conditional Access-based MFA. Balances security requirements with user experience across diverse workforces.

Chapter 5See details

Conditional Access and Identity Protection

  • Lesson 1 • Monitoring and Reporting Access Decisions

    Analyzes sign-in logs, Conditional Access insights, and Identity Protection reports. Validates policy effectiveness and identifies gaps in access control coverage.

  • Lesson 2 • Conditional Access Policy Design

    Builds policies using users, cloud apps, conditions, and grant controls. Translates business security requirements into enforceable access rules.

  • Lesson 3 • Advanced Conditional Access Scenarios

    Implements authentication strength, continuous access evaluation, and token protection. Addresses sophisticated attack vectors beyond basic MFA enforcement.

  • Lesson 4 • Azure AD Identity Protection Configuration

    Configures user risk and sign-in risk policies, risk detections, and remediation workflows. Automates response to compromised credentials and anomalous sign-in behavior.

Chapter 6See details

Application Registration and Enterprise App Management

  • Lesson 1 • Enterprise Application SSO Configuration

    Configures SAML, OIDC, and password-based SSO for gallery and non-gallery apps. Delivers seamless user access while centralizing authentication control.

  • Lesson 2 • Application Registration in Azure AD

    Creates app registrations, configures redirect URIs, and manages certificates and secrets. Establishes the identity foundation for custom and third-party applications.

  • Lesson 3 • Application Governance and Access Reviews

    Applies app governance policies, consent phishing detection, and access reviews for apps. Reduces overprivileged application access and enforces periodic recertification.

  • Lesson 4 • App Provisioning with SCIM

    Configures automatic user provisioning to SaaS apps using the SCIM protocol. Synchronizes identity lifecycle events from Azure AD to connected applications.

  • Lesson 5 • API Permissions and Consent Framework

    Configures delegated and application permissions, admin consent, and consent policies. Controls what data applications can access on behalf of users or as themselves.

Chapter 7See details

Identity Governance and Privileged Access

  • Lesson 1 • Privileged Identity Management for Azure AD Roles

    Activates, assigns, and audits eligible Azure AD role assignments using PIM. Enforces just-in-time access and approval gates for privileged directory roles.

  • Lesson 2 • Terms of Use and Conditional Access Integration

    Creates terms-of-use policies and enforces acceptance via Conditional Access. Provides legal and compliance documentation of user consent to access conditions.

  • Lesson 3 • PIM for Azure Resource Roles

    Extends PIM governance to Azure subscription and resource roles. Applies just-in-time and time-bound access controls to cloud infrastructure permissions.

  • Lesson 4 • Entitlement Management and Access Packages

    Creates catalogs, access packages, and policies for automated access request and approval. Enables self-service access while enforcing approval workflows and expiration.

  • Lesson 5 • Access Reviews Design and Operation

    Configures recurring access reviews for groups, applications, and Azure AD roles. Ensures continuous validation of access rights and supports audit compliance.

Chapter 8See details

Monitoring, Reporting, and Exam Readiness

  • Lesson 1 • SC-300 Exam Scenario Practice

    Applies all SC-300 domains through end-to-end scenario labs and practice questions. Consolidates knowledge and identifies remaining gaps before the certification exam.

  • Lesson 2 • Identity Secure Score and Recommendations

    Interprets the Identity Secure Score and prioritizes improvement actions. Provides a measurable baseline for continuous identity security posture improvement.

  • Lesson 3 • Azure AD Audit and Sign-In Log Management

    Configures diagnostic settings to route logs to Log Analytics, Storage, and Event Hubs. Enables long-term retention and cross-service correlation of identity events.

  • Lesson 4 • Microsoft Sentinel Identity Threat Detection

    Connects Azure AD data connectors to Sentinel and enables UEBA and analytics rules. Automates detection of identity-based threats across the Microsoft security stack.

Certification

Your valid completion certificate

This course is for you:

  • IT generalist: ready to specialize in Microsoft cloud identity security.

  • Systems administrator: managing Active Directory and exploring Azure migration paths.

  • Security analyst: wanting formal credentials to validate identity threat response skills.

  • Cloud engineer: building Azure solutions who needs deeper identity governance knowledge.

  • Help desk professional: aiming to move into an identity or IAM-focused role.

  • Career changer: coming from networking or dev and pivoting toward cloud security.

What our students say

Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to change platforms... I thank you for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can switch chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the way videos are presented and transcribed, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.
André Felipe
André FelipePrompt Engineering Student

Top trainings

FAQs

Who is Dedika?

Is the certificate valid in the Philippines?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course