SC-300 remains Microsoft’s identity-and-access administration exam for professionals who design, implement, and operate identity solutions with Microsoft Entra. The current study guide measures skills as of April 27, 2026 and keeps the role centered on identity lifecycle, authentication, authorization, workload identities, application access, privileged access, governance, monitoring, and Zero Trust. This is not a narrow “create users and groups” certification. It expects candidates to reason across people, devices, applications, Azure resources, hybrid identity, and external collaboration.
The current SC-300 blueprint has four weighted groups: implement and manage user identities at 20–25%, implement authentication and access management at 25–30%, plan and implement workload identities at 20–25%, and plan and automate identity governance at 20–25%. The certification page identifies the credential as Microsoft Certified: Identity and Access Administrator Associate, an intermediate security role that renews annually. The exam page currently lists a $165 U.S. price, with local pricing varying by region.
User identity management begins at the tenant boundary
The first domain starts with tenant configuration, built-in and custom Microsoft Entra roles, administrative units, effective permissions, domains, company branding, and tenant, user, group, and device settings. These objectives establish the administrative boundary before individual identities are created. A candidate should understand not only how to grant a role but also how the scope of that role changes the effective authority of the administrator.
Administrative units are especially useful when a large organization wants delegated administration without granting tenant-wide authority. Study them as a scoping mechanism rather than as another directory container. The question is always which administrators should manage which identities and whether the role assignment actually creates the intended least-privilege boundary.
Identity lifecycle includes users, groups, devices, licenses, and custom attributes
Microsoft expects candidates to create and manage users and groups, work with custom security attributes, automate bulk operations, manage device join and registration, and assign or report on licenses. These tasks are connected because identity is not static. A user changes department, joins groups, receives devices, gains applications, and eventually leaves the organization.
Strong preparation treats lifecycle events as a chain. When a user joins, which attributes and groups are created? When the user changes role, which permissions should change automatically? When employment ends, which sessions, devices, licenses, and application assignments need to be removed? That operational view is more valuable than memorizing the location of individual settings.
External identity is about controlled collaboration across organizational boundaries
The current guide includes external collaboration settings, guest invitations, external-account management, cross-tenant access settings, cross-tenant synchronization, and external identity providers such as SAML or WS-Fed. These objectives reflect modern organizations that collaborate with partners rather than keeping every user inside one tenant.
The key distinction is between making collaboration easy and keeping the boundary intentional. Cross-tenant synchronization can automate user representation across tenants, while cross-tenant access settings influence trust and access behavior. Candidates should know where lifecycle ownership remains and which tenant controls authentication, access, and removal.
Hybrid identity remains part of the role even as cloud-first patterns expand
SC-300 still expects knowledge of Microsoft Entra Connect Sync, Cloud Sync, password hash synchronization, pass-through authentication, seamless SSO, migration away from AD FS, and Connect Health. A cloud identity administrator therefore needs enough Active Directory Domain Services context to understand where identities originate and how authentication flows from on-premises systems into Microsoft Entra.
Study hybrid identity by comparing source-of-authority and authentication models. Password hash synchronization and pass-through authentication solve different operational problems. Cloud Sync and Connect Sync have different capabilities and deployment characteristics. Migration away from AD FS should be understood as an authentication modernization project, not just a switch of one endpoint.
Authentication and Conditional Access form the largest weighted domain
The 25–30% authentication and access-management group includes certificate-based authentication, Temporary Access Pass, OAuth 2.0 tokens, Microsoft Authenticator, passkeys using FIDO2, MFA settings, SSPR, Windows Hello for Business, account/session revocation, password protection, and Microsoft Entra Kerberos for hybrid identities. Candidates need to match authentication methods to user experience, security, and recovery requirements.
Conditional Access is equally central. Planning assignments and controls, testing policies, session management, device-enforced restrictions, continuous access evaluation, authentication context, protected actions, and templates all appear in the guide. A focused review of Conditional Access can reinforce the idea that access decisions combine identity, risk, device, location, application, and session context rather than relying on one static MFA rule.
Identity Protection and Global Secure Access extend access decisions into risk and network context
The current blueprint expects candidates to manage user risk, sign-in risk, MFA-registration campaigns, risky users, risky sign-ins, and risky workload identities. Risk is therefore an input to access decisions, not merely a report. A risky sign-in can trigger controls, while remediation can change the user’s state or require stronger authentication.
Global Secure Access adds Private Access, Internet Access, Microsoft 365 Internet Access, and client deployment. These objectives connect identity with network access in a Zero Trust architecture. The broader principles in Zero Trust are useful here: verify explicitly, use least privilege, and assume breach. SC-300 applies those principles specifically through Microsoft Entra controls.
Workload identities require a different mental model from user identities
The third domain asks candidates to choose among managed identities, service principals, user accounts, and managed service accounts for applications and Azure workloads. It also includes creating and assigning managed identities and using them to access other Azure resources. The security advantage of managed identity is that code can authenticate without embedding a long-lived secret that developers must rotate manually.
Workload identities also include enterprise applications and app registrations. Candidates need to understand app-level and tenant-level settings, Application Proxy for on-premises applications, SaaS integration, user and group assignments, app roles, consent, API permissions, and application authentication. The distinction between an app registration and the enterprise-application representation in a tenant is especially important during troubleshooting.
Defender for Cloud Apps adds discovery and session controls to application governance
The exam includes cloud discovery, connected apps, application-enforced restrictions, Conditional Access app control, access and session policies, OAuth-app policies, and the cloud app catalog. This extends identity administration into visibility and control of application use, including unsanctioned or risky cloud services.
Do not study Defender for Cloud Apps as a disconnected security product. Its value in SC-300 comes from the way it consumes identity and session context and can enforce controls after sign-in. A user can be authenticated successfully yet still have a restricted session because the application or device context requires tighter controls.
Identity governance closes the lifecycle with entitlement, review, privilege, and evidence
The final 20–25% domain covers entitlement management, catalogs, access packages, requests, terms of use, external-user lifecycle, connected organizations, access reviews, Privileged Identity Management, break-glass accounts, sign-in and audit logs, diagnostic settings, KQL in Log Analytics, workbooks, reporting, and Identity Secure Score. These are the controls that keep access from accumulating indefinitely.
The best preparation is to connect governance to real lifecycle questions. Who approves access? How long should it last? Who reviews it? Which privileged role should be eligible rather than permanent? How is emergency access protected? Which logs prove what happened? The broader SC-300 identity blueprint is useful for revising those connections without reducing them to isolated features.
The current exam is an identity lifecycle under Zero Trust
A strong readiness test is to trace one identity from creation to retirement. Add authentication, Conditional Access, risk, application assignment, external access if needed, privileged access, access reviews, monitoring, and eventual removal. Then repeat the same exercise for an application or workload identity.
Microsoft’s current change log is also useful because it shows that the April 2026 update did not replace the architecture of the exam. The four major skill groups remain stable, while authentication, risk, Defender for Cloud Apps, privileged access, and monitoring received minor objective changes. Candidates using older 2025 material can still reuse much of the conceptual foundation, but they should verify current terminology and newer objectives such as passkeys, risky workload identities, and the current Global Secure Access coverage against the live guide.
Role separation is another recurring theme. Identity administrators collaborate with security, application, cloud, Microsoft 365, and Active Directory teams. That means SC-300 scenarios may present a symptom whose root cause is adjacent to identity administration even though the candidate is not expected to become the owner of every platform. Good preparation includes knowing where the identity administrator’s responsibility ends and which evidence should be handed to another team.
Licensing also matters conceptually because some Entra capabilities require specific subscription levels, but the exam is not best approached as a licensing memorization exercise. Focus on the functional relationship among Identity Protection, PIM, access reviews, Conditional Access, Global Secure Access, and Defender for Cloud Apps. In real deployments, availability of a feature is checked against licensing and tenant configuration before the design is committed.
PowerShell and KQL appear in the audience profile because identity operations have to scale beyond manual portal work. Candidates should be comfortable reading simple automation and query patterns even when the exam does not ask them to become developers. Bulk identity changes, reporting, log investigation, and repeatable administrative tasks are more reliable when the engineer can move between graphical tools and scriptable interfaces.
One final current-scope note is that Microsoft continues to expect familiarity with Azure, Microsoft 365, Active Directory Domain Services, PowerShell, and KQL. Those are supporting skills rather than separate exam domains, but they explain why some scenarios cross portal, hybrid, and log-analysis boundaries.
Within the wider Microsoft certifications landscape, SC-300 is distinctive because identity is the control plane connecting users, applications, and cloud resources. Candidates who understand the lifecycle and evidence behind each access decision will be better prepared than candidates who memorize portal locations.