Courseiva
Implement and Manage User IdentitiesmediumMultiple ChoiceObjective-mapped

SC-300 Implement and Manage User Identities Practice Question

You need to delegate the ability to reset passwords for users in the 'Sales' department to a local helpdesk lead. You want to ensure the helpdesk lead cannot manage users in any other department. What should you create?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

An Administrative Unit (AU) and add the Sales users to it.

Administrative Units (AUs) provide a way to define a boundary for administrative delegation within a Microsoft Entra tenant. This is vital for large organizations that need to distribute management tasks to regional or departmental IT staff without granting them broad permissions across the entire directory, adhering to the principle of least privilege.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A dynamic security group containing all Sales users.

    Why it's wrong here

    While a dynamic group can automatically group the users, it does not provide a scope for administrative delegation. Assigning a role to a user over a group allows them to manage the group itself, but it does not grant them the permission to manage the individual user objects contained within that group.

  • An Administrative Unit (AU) and add the Sales users to it.

    Why this is correct

    Administrative Units are the correct tool for this requirement. By placing the Sales users into an AU, you can then assign the 'Password Administrator' role to the helpdesk lead scoped specifically to that AU. This limits their authority strictly to the members of that unit, protecting other users.

  • A Custom Role with the 'microsoft.directory/users/password/update' permission.

    Why it's wrong here

    A custom role defines *what* a user can do, but on its own, it does not define *who* they can do it to. Without being scoped to an Administrative Unit, a user with this role would either have no targets or would have permission to reset passwords for every user in the tenant.

  • An Access Package in Entra ID Governance.

    Why it's wrong here

    Access Packages are used for automated access requests and lifecycle management for users to gain access to groups, sites, or apps. They are not designed for delegating administrative permissions like password resets, which are managed through the Role-Based Access Control (RBAC) and Administrative Unit systems.

About these practice questions

This SC-300 question is part of Courseiva's 17-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-300 exam.