
Microsoft Identity and Access Administrator SC-300 Exam Guide
Master every domain of the SC-300 exam and become the identity security expert your organization needs. This comprehensive guide covers Azure AD architecture, Conditional Access, Privileged Identity Management, and hybrid identity from the ground up. Walk into exam day — and your next role — fully prepared to design, implement, and govern enterprise identity solutions.
What you will learn:
Configure multi-factor authentication, passwordless methods, and self-service password reset policies.
Design and enforce Conditional Access policies using risk signals, device compliance, and named locations.
Implement Privileged Identity Management to control just-in-time access to Azure AD and resource roles.
Deploy hybrid identity solutions using Azure AD Connect, cloud sync, and directory synchronization monitoring.
Manage application registrations, enterprise SSO, API permissions, and automated SCIM provisioning.
Build an identity governance program with Entitlement Management, access reviews, and lifecycle workflows.
How you study in practice Microsoft Identity and Access Administrator SC-300 Exam Guide
How you practice Microsoft Identity and Access Administrator SC-300 Exam Guide
For companies that want to train their team
With Dedika for Business, the course includes exercises and examples tailored to your own business and the way your company needs.
Course content
8 Chapters • 35 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsIdentity and Access Management Foundations
Identity and Access Management Foundations
Lesson 1 • Azure AD Licensing and Service Tiers
Compares Free, P1, and P2 feature sets and maps features to exam objectives. Enables accurate feature selection when designing identity solutions.
Lesson 2 • Azure Active Directory Architecture
Explains Azure AD tenants, directories, subscriptions, and object types. Connects directory structure to access control decisions made throughout the course.
Lesson 3 • Microsoft Identity Platform Overview
Surveys the Microsoft identity platform, OAuth 2.0, and OpenID Connect flows. Grounds students in the protocols that underpin all Azure AD authentication scenarios.
Lesson 4 • Core IAM Concepts and Terminology
Defines authentication, authorization, identity providers, and trust models. Provides the vocabulary needed for every subsequent SC-300 domain.
Chapter 2HideHide detailsSee detailsImplementing and Managing Azure AD Identities
Implementing and Managing Azure AD Identities
Lesson 1 • Identity Lifecycle Automation
Implements HR-driven provisioning and lifecycle workflows using Azure AD and Lifecycle Workflows. Reduces manual effort and enforces consistent joiner-mover-leaver processes.
Lesson 2 • External Identities and B2B Collaboration
Configures guest user invitations, cross-tenant access settings, and B2B direct connect. Extends secure collaboration beyond organizational boundaries.
Lesson 3 • Administrative Units and Delegated Management
Uses administrative units to scope admin roles to subsets of users and groups. Supports least-privilege delegation in large, multi-department tenants.
Lesson 4 • Group Types and Dynamic Membership
Covers security groups, Microsoft 365 groups, and dynamic membership rules. Enables automated group population based on user attributes.
Lesson 5 • User Account Creation and Management
Demonstrates bulk and individual user provisioning via portal, PowerShell, and Microsoft Graph. Directly supports the SC-300 objective on managing Azure AD users.
Chapter 3HideHide detailsSee detailsHybrid Identity and Directory Synchronization
Hybrid Identity and Directory Synchronization
Lesson 1 • Monitoring and Troubleshooting Synchronization
Uses Azure AD Connect Health, sync logs, and error reports to diagnose sync failures. Maintains directory consistency and minimizes identity-related service disruptions.
Lesson 2 • Azure AD Cloud Sync Deployment
Deploys the lightweight cloud sync agent for multi-forest and disconnected scenarios. Complements Azure AD Connect where full agent deployment is impractical.
Lesson 3 • Hybrid Identity Architecture and Options
Compares password hash sync, pass-through authentication, and federation topologies. Guides architecture decisions based on security, availability, and compliance requirements.
Lesson 4 • Azure AD Connect Installation and Configuration
Walks through express and custom installation, filtering, and attribute mapping. Produces a functional sync environment aligned with organizational directory structure.
Chapter 4HideHide detailsSee detailsAuthentication Methods and Passwordless Security
Authentication Methods and Passwordless Security
Lesson 1 • Passwordless Authentication Methods
Deploys FIDO2 security keys, Microsoft Authenticator passwordless, and Windows Hello for Business. Eliminates password-based attack surfaces for high-value accounts.
Lesson 2 • Authentication Method Policies and Monitoring
Manages the Authentication Methods policy blade and migration from legacy MFA settings. Provides centralized control and audit visibility over all authentication methods.
Lesson 3 • Self-Service Password Reset Setup
Configures SSPR authentication methods, registration campaigns, and writeback to on-premises AD. Reduces helpdesk load while maintaining secure password recovery.
Lesson 4 • Multi-Factor Authentication Configuration
Enables and configures per-user MFA, security defaults, and Conditional Access-based MFA. Balances security requirements with user experience across diverse workforces.
Chapter 5HideHide detailsSee detailsConditional Access and Identity Protection
Conditional Access and Identity Protection
Lesson 1 • Monitoring and Reporting Access Decisions
Analyzes sign-in logs, Conditional Access insights, and Identity Protection reports. Validates policy effectiveness and identifies gaps in access control coverage.
Lesson 2 • Conditional Access Policy Design
Builds policies using users, cloud apps, conditions, and grant controls. Translates business security requirements into enforceable access rules.
Lesson 3 • Advanced Conditional Access Scenarios
Implements authentication strength, continuous access evaluation, and token protection. Addresses sophisticated attack vectors beyond basic MFA enforcement.
Lesson 4 • Azure AD Identity Protection Configuration
Configures user risk and sign-in risk policies, risk detections, and remediation workflows. Automates response to compromised credentials and anomalous sign-in behavior.
Chapter 6HideHide detailsSee detailsApplication Registration and Enterprise App Management
Application Registration and Enterprise App Management
Lesson 1 • Enterprise Application SSO Configuration
Configures SAML, OIDC, and password-based SSO for gallery and non-gallery apps. Delivers seamless user access while centralizing authentication control.
Lesson 2 • Application Registration in Azure AD
Creates app registrations, configures redirect URIs, and manages certificates and secrets. Establishes the identity foundation for custom and third-party applications.
Lesson 3 • Application Governance and Access Reviews
Applies app governance policies, consent phishing detection, and access reviews for apps. Reduces overprivileged application access and enforces periodic recertification.
Lesson 4 • App Provisioning with SCIM
Configures automatic user provisioning to SaaS apps using the SCIM protocol. Synchronizes identity lifecycle events from Azure AD to connected applications.
Lesson 5 • API Permissions and Consent Framework
Configures delegated and application permissions, admin consent, and consent policies. Controls what data applications can access on behalf of users or as themselves.
Chapter 7HideHide detailsSee detailsIdentity Governance and Privileged Access
Identity Governance and Privileged Access
Lesson 1 • Privileged Identity Management for Azure AD Roles
Activates, assigns, and audits eligible Azure AD role assignments using PIM. Enforces just-in-time access and approval gates for privileged directory roles.
Lesson 2 • Terms of Use and Conditional Access Integration
Creates terms-of-use policies and enforces acceptance via Conditional Access. Provides legal and compliance documentation of user consent to access conditions.
Lesson 3 • PIM for Azure Resource Roles
Extends PIM governance to Azure subscription and resource roles. Applies just-in-time and time-bound access controls to cloud infrastructure permissions.
Lesson 4 • Entitlement Management and Access Packages
Creates catalogs, access packages, and policies for automated access request and approval. Enables self-service access while enforcing approval workflows and expiration.
Lesson 5 • Access Reviews Design and Operation
Configures recurring access reviews for groups, applications, and Azure AD roles. Ensures continuous validation of access rights and supports audit compliance.
Chapter 8HideHide detailsSee detailsMonitoring, Reporting, and Exam Readiness
Monitoring, Reporting, and Exam Readiness
Lesson 1 • SC-300 Exam Scenario Practice
Applies all SC-300 domains through end-to-end scenario labs and practice questions. Consolidates knowledge and identifies remaining gaps before the certification exam.
Lesson 2 • Identity Secure Score and Recommendations
Interprets the Identity Secure Score and prioritizes improvement actions. Provides a measurable baseline for continuous identity security posture improvement.
Lesson 3 • Azure AD Audit and Sign-In Log Management
Configures diagnostic settings to route logs to Log Analytics, Storage, and Event Hubs. Enables long-term retention and cross-service correlation of identity events.
Lesson 4 • Microsoft Sentinel Identity Threat Detection
Connects Azure AD data connectors to Sentinel and enables UEBA and analytics rules. Automates detection of identity-based threats across the Microsoft security stack.
Your valid completion certificate
This course is for you:
IT generalist: ready to specialize in Microsoft cloud identity security.
Systems administrator: managing Active Directory and exploring Azure migration paths.
Security analyst: wanting formal credentials to validate identity threat response skills.
Cloud engineer: building Azure solutions who needs deeper identity governance knowledge.
Help desk professional: aiming to move into an identity or IAM-focused role.
Career changer: coming from networking or dev and pivoting toward cloud security.
What our students say
Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to switch platforms... I thank you for everything you do, I've already recommended you to other people...

I like how the lessons are straight to the point and how I can switch chapters and skip content I don't need.

I like the content and the presentation style and video transcription, which speeds up the process!

The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.

Top trainings
FAQ
Who is Dedika?
Is the certificate valid in the United States?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course




















