Microsoft · Free Practice Questions · Last reviewed May 2026
6real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
An organization uses Microsoft Entra ID and needs to create external user accounts for contractors. The contractors should be invited by a select group of non-administrator employees without granting them full User Administrator privileges. Which administrative role should you assign to these employees?
User Administrator
Guest Inviter
The Guest Inviter role specifically empowers non-administrative users to invite external B2B guests into the Microsoft Entra tenant without granting broader directory management permissions, perfectly balancing administrative delegation and operational security.
Helpdesk Administrator
Directory Readers
Your company, Fabrikam, Inc., has acquired another firm. You need to invite 500 external contractors to your Microsoft Entra ID tenant to access specific applications. You want to ensure that these users are categorized as guests and cannot browse the full directory. Which feature should you configure first to enforce these restrictions tenant-wide?
Guest user access restrictions
Configuring guest user access to the most restrictive setting ensures that external users cannot perform directory lookups or see other users in the tenant. This is a foundational security step when onboarding large numbers of contractors who only require access to specific resource endpoints rather than the broader organizational structure.
Administrative Units
Conditional Access policies
Entitlement Management
You have a large Microsoft Entra ID tenant with 10,000 users. You need to delegate the ability to reset passwords for users in the 'Seattle' office to a local IT lead, without granting them administrative rights over users in other offices. What should you create?
A new Custom Role with a scope of the entire directory
A Dynamic Security Group containing the Seattle users
A Conditional Access policy targeting the Seattle location
An Administrative Unit containing the Seattle users
An Administrative Unit allows you to group specific users and then assign a Helpdesk Administrator role scoped specifically to that unit. This ensures the IT lead can only reset passwords for the Seattle-based users, fulfilling the requirement for regional delegation while following the security principle of least privilege.
You need to store specialized metadata for users in Microsoft Entra ID that is not available in the standard user profile attributes. This metadata must be accessible via the Microsoft Graph API and must support fine-grained access control so only specific administrators can read or write the data. Which THREE steps are required to implement Custom Security Attributes?
Assign the Attribute Definition Administrator role
To create and manage the structure of custom security attributes, a user must have the Attribute Definition Administrator role. This role is distinct from Global Administrator, ensuring that attribute schema management is a delegated, specific task that follows the principle of least privilege within the Microsoft Entra ID environment.
Configure a new Schema Extension using the Azure AD Graph API
Define an Attribute Set
An Attribute Set is a mandatory grouping for custom security attributes. It serves as the container for related attributes and, more importantly, provides the boundary for assigning permissions. You cannot create an individual attribute without first defining the set it belongs to, which organizes the metadata logically.
Create a new Directory Extension in Microsoft Entra Connect
Add Attribute Definitions to the Attribute Set
After creating the set, you must define the specific attributes (definitions) that will store the data. This includes naming the attribute and selecting its data type (e.g., Boolean, Integer, or String). This step establishes the actual fields that will be available on the user objects for data entry.
A company wants to implement advanced identity management features for their users. You are evaluating the differences between Microsoft Entra ID P1 and P2 licenses. Which TWO features are ONLY available with the Microsoft Entra ID P2 license?
Self-Service Password Reset (SSPR) for cloud users
Conditional Access based on user location and device state
Microsoft Entra ID Protection (Risk-based Conditional Access)
Identity Protection, which includes the ability to trigger policies based on 'User Risk' and 'Sign-in Risk' levels (High, Medium, Low), is a premium feature exclusive to the P2 license. It uses machine learning to detect compromised credentials and anomalous sign-in patterns to automatically protect the organization's identities.
Application Proxy for accessing on-premises web applications
Privileged Identity Management (PIM)
Privileged Identity Management (PIM) is a P2-exclusive feature that allows for 'just-in-time' administrative access. It minimizes the risk of standing privileges by requiring administrators to request and justify the activation of their roles, often requiring MFA or approval before permissions are temporarily granted to their account.
You accidentally delete a cloud-only user account from the Microsoft Entra admin center. You need to restore the user and their associated group memberships. Within how many days must you perform the restoration before the user is permanently deleted?
14 days
30 days
Microsoft Entra ID retains deleted users in a soft-deleted state for exactly 30 days. During this time, the account can be restored with its original SID, properties, and group memberships intact. After 30 days, the user is permanently removed from the directory and the data becomes unrecoverable.
60 days
90 days
Want more Implement and Manage User Identities practice?
Practice this domainThe SC-300 exam has 60–90 questions and must be completed in 120 minutes. The passing score is 700/1000.
Identity scenario questions covering Microsoft Entra ID, SSO, MFA, conditional access, hybrid identity, and entitlement management.
The exam covers 1 domain: Implement and Manage User Identities. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Microsoft SC-300 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.