Microsoft Identity and Access Administrator - SC-300 FREE EXAM DUMPS QUESTIONS & ANSWERS

You need to resolve the issue of the guest user invitations. What should you do for the Azure AD tenant?
Correct Answer: C Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
Task 5
You need to assign a Windows 10/11 Enterprise E3 license to the Sg-Retail group.
Correct Answer:
See the Explanation for the complete step by step solution.
Explanation:
To assign a Windows 10/11 Enterprise E3 license to the Sg-Retail group, you can follow these steps:
Sign in to the Microsoft Entra admin center:
Make sure you have the role of Global Administrator or License Administrator.
Navigate to the licensing page:
Go toBilling > Licenses1.
Find the Windows 10/11 Enterprise E3 license:
Look for the Windows 10/11 Enterprise E3 license in the list of available products.
Assign licenses to the group:
Select the license and then choose Assign licenses.
Search for and select the Sg-Retail group.
Confirm the assignment and make sure that the correct number of licenses is available for the group.
Review and confirm the assignment:
Ensure that the licenses have been properly assigned to the Sg-Retail group without affecting other groups or users.
Monitor the license status:
Check the license usage and status to ensure that the Sg-Retail group members can utilize the Windows 10/11 Enterprise E3 features.
By following these steps, the Sg-Retail group should now have the Windows 10/11 Enterprise E3 licenses assigned to them.
You have an Azure Active Directory (Azure AD) tenant that contains a user named User1.
An administrator deletes User1.
You need to identity the following:
* How many days after the account of User1 is deleted can you restore the account?
* Which is the least privileged role that can be used to restore User1?
What should you identify? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
Correct Answer:

Explanation:

As per the Microsoft Identity and Access Administrator (SC-300) official study guide, and confirmed by Microsoft Learn documentation on "Restore a deleted user in Azure Active Directory", when a user account is deleted from Azure Active Directory (Azure AD), it is not permanently removed immediately. Instead, the deleted user object is retained in a " soft-deleted " state for 30 days. During this retention period, administrators can restore the user account, including its associated group memberships and licenses. After 30 days, the user object is permanently deleted and cannot be recovered.
From the Microsoft documentation:
"When a user is deleted, the account is retained in a deleted state for up to 30 days. You can restore the user within this period using the Azure portal, PowerShell, or Microsoft Graph." Regarding the minimum role required, the same documentation and SC-300 guide state that the User Administrator role is the least privileged built-in Azure AD role that can manage users - including restoring deleted accounts. Higher roles, such as Global Administrator, also have this capability, but the principle of least privilege applies.
"The User Administrator role can create, update, delete, and restore user accounts and reset passwords for non- administrators." Therefore, the correct configuration is:
* Number of days: 30
* Role: User Administrator
Your company has an Azure AD tenant that contains the users shown in the following table.

You have the app registrations shown in the following table.

A company policy prevents changes to user permissions.
Which user can create appointments in the calendar of each user at the company?
Correct Answer: C Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
A user named User1 attempts to sign in to the tenant by entering the following incorrect passwords:
Pa55w0rd12
Pa55w0rd12
Pa55w0rd12
Pa55w.rd12
Pa55w.rd123
Pa55w.rd123
Pa55w.rd123
Pa55word12
Pa55word12
Pa55word12
Pa55w.rd12
You need to identify how many sign-in attempts were tracked for User1, and how User1 can unlock her account before the 300-second lockout duration expires.
What should identify? To answer, select the appropriate
NOTE:Each correct selection is worth one point.
Correct Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-sspr-deployment
You have a Microsoft 365 tenant.
In Azure Active Directory (Azure AD), you configure the terms of use.
You need to ensure that only users who accept the terms of use can access the resources in the tenant. Other users must be denied access.
What should you configure?
Correct Answer: C Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
You have an Azure Active Directory (Azure AD) tenant that has an Azure Active Directory Premium Plan 2 license. The tenant contains the users shown in the following table.

You have the Device Settings shown in the following exhibit.

User1 has the devices shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE:Each correct selection is worth one point.
Correct Answer:

Explanation:
< User1 can join four additional Windows 10 devices to Azure AD. # No
2# # Admin1 can set "Devices to be Azure AD joined or Azure AD registered require Multi-Factor Authentication" to Yes. # Yes
3# # Admin2 is a local administrator on Device3. # No
This scenario draws from Module: Manage device identities in Azure Active Directory in the Microsoft SC-
300 Official Study Guide and Microsoft Learn content.
In the Device Settings, the "Maximum number of devices per user" is configured as 5. User1 already has one Azure AD joined device (Device1) and three Azure AD registered devices (Device2, Device3, Device4).
Since both Azure AD joined and Azure AD registered devices count toward the same limit, User1 has already registered 4 devices. This means they can add only one more, not four additional Windows 10 devices.
Therefore, the statement is No.
Microsoft documentation states: "The maximum number of devices per user setting applies collectively to all Azure AD-joined and Azure AD-registered devices." The Cloud Device Administrator role (Admin1's role) has the delegated permissions to manage device settings in Azure AD, including enforcing MFA requirements for device registration and join operations. The role allows management of the Azure AD device configuration blade, including toggling settings like MFA for join/register, join limits, and device ownership policies. Therefore, Admin1 can enable the MFA requirement for device join/registration.
As per Microsoft Learn: "Cloud Device Administrator can manage all aspects of device settings, including device join and registration MFA requirements." Admin2 holds the Device Administrator role. However, per Microsoft's documentation, only Azure AD- joined Windows 10 devices grant local administrator rights to users in the Device Administrator role. Azure AD-registered devices (such as Device3) are personal devices that do not have local administrator assignment through Azure AD roles. Since Device3 is Azure AD registered, not joined, Admin2 is not a local admin on it.
Microsoft guidance clarifies: "Users assigned to the Device Administrator role are added as local administrators only on Azure AD-joined devices, not on Azure AD-registered or hybrid devices."
You have an Azure Active Directory (Azure AD) tenant.
For the tenant. Users can register applications Is set to No.
A user named Admin1 must deploy a new cloud app named App1.
You need to ensure that Admin1 can register App1 in Azure AD. The solution must use the principle of least privilege.
Which role should you assign to Admin1?
Correct Answer: A Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
You have an Azure AD tenant that contains a user named User1. User1 is assigned the User Administrator role.
You need to configure External collaboration settings for the tenant to meet the following requirements: |
*Guest users must be prevented from querying staff email addresses.
*Guest users must be able to access the tenant only if they are invited by User1.
Which three settings should you configure? To answer, select the appropriate settings in the answer area.
Correct Answer:

Explanation:
According to the Microsoft SC-300 Study Guide, Exam Ref SC-300, and Microsoft Entra External Collaboration (B2B) documentation, the configuration of External collaboration settings in Azure AD determines how guest users can access directory data and who can invite them into the tenant.
Let's analyze each requirement in context:
"Guest users must be prevented from querying staff email addresses."
To achieve this, Azure AD provides the setting Guest user access restrictions, which defines what a guest can see in the directory. The most restrictive setting ensures that guest users can only see their own profile details and no other users or groups.
# Therefore, select:
"Guest user access is restricted to properties and memberships of their own directory objects (most restrictive)." This prevents guests from discovering internal directory data such as email addresses of staff members or group memberships.
"Guest users must be able to access the tenant only if they are invited by User1." User1 has the User Administrator role. This role is included among the "specific admin roles" allowed to invite guest users when the setting is configured appropriately.
To meet the requirement that only User1 (or other admins) can invite guests, you must configure:
# "Only users assigned to specific admin roles can invite guest users." This restricts invitation privileges to admin roles (such as Global Administrator, User Administrator, etc.) and prevents ordinary users or guests from inviting others.
"Guests should not be able to self-enroll."
Azure AD B2B allows self-service sign-up through user flows (Identity Experience Framework). Enabling this feature would let external users sign up themselves - which violates the condition that guests must be invited by User1 only.
# Therefore, set Enable guest self-service sign-up via user flows = No.
Setting
Value
Guest user access restrictions
Guest user access is restricted to properties and memberships of their own directory objects (most restrictive) Guest invite restrictions Only users assigned to specific admin roles can invite guest users Enable guest self-service sign-up via user flows No
# Microsoft Official Documentation Reference (SC-300 Content):
"To prevent guests from seeing other users in the directory, configure guest user access restrictions to 'most restrictive.' To control who can invite guests, use the setting that limits invitations to users with admin roles.
To disallow self-service guest access, disable user flows for external sign-up."
You have two Microsoft Entra tenants named contoso.com and fabrikam.com. Contoso.com contains the identities shown in the following table.

You configure cross-tenant synchronization from contoso.com to fabrikam.com. Which identities will sync with fabrikam.com?
Correct Answer: B Vote an answer
0
0
0
10