SC-300 Implement and Manage User Identities Practice Question
You are configuring External Collaboration settings in Microsoft Entra ID. You want to ensure that only specific partner domains can be invited as guests, and that guest users have the most restricted access to the directory. Which THREE settings should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set 'Guest user access is restricted to properties and memberships of their own directory objects'.
Securing external identities involves a multi-layered approach that controls both who can be invited and what those individuals can see once they are in the tenant. These settings are found in the External Collaboration settings and are vital for preventing data leakage and ensuring that guest access aligns with organizational security policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Set 'Guest user access is restricted to properties and memberships of their own directory objects'.
Why this is correct
This setting provides the highest level of restriction for guest users, preventing them from searching the directory or viewing memberships of groups they do not belong to. It ensures that guests only see information relevant to their own account, significantly reducing the risk of internal directory harvesting.
- ✓
Enable 'Allow invitations only to the specified domains (most restrictive)'.
Why this is correct
By implementing an allowlist for domains, you ensure that employees can only invite guests from approved partner organizations. This prevents users from inviting individuals from personal email providers or unverified third parties, maintaining a strict boundary on who can enter the corporate identity environment.
- ✓
Set 'Guest invite restrictions' to 'Only users assigned to specific admin roles can invite guest users'.
Why this is correct
Restricting invitation capabilities to specific administrative roles ensures that guest creation is a controlled process. This prevents standard users from independently inviting external parties, ensuring that all guest accounts are vetted or created according to the organization's formal identity lifecycle and governance policies.
- ✗
Disable the 'External user' account type in the User Settings blade.
Why it's wrong here
There is no single toggle to 'disable' the external user account type in the User Settings blade that would achieve the desired restrictions. Managing external access is done through the External Collaboration settings and Cross-tenant access policies rather than a global account type disablement in user settings.
- ✗
Enable 'Self-service sign-up via user flows' for all external users.
Why it's wrong here
Enabling self-service sign-up is the opposite of a restrictive policy, as it allows external users to join the tenant without a direct invitation from an administrator. This is typically used for B2C scenarios or broad B2B applications and would undermine the goal of limiting access to specific partners.
About these practice questions
One of 17 original SC-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-300 exam.