SC-300 Implement and Manage User Identities Practice Question
You need to delegate the ability to reset passwords for users in the 'Sales' department to a local helpdesk lead. You want to ensure the helpdesk lead cannot manage users in any other department. What should you create?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An Administrative Unit (AU) and add the Sales users to it.
Administrative Units (AUs) provide a way to define a boundary for administrative delegation within a Microsoft Entra tenant. This is vital for large organizations that need to distribute management tasks to regional or departmental IT staff without granting them broad permissions across the entire directory, adhering to the principle of least privilege.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A dynamic security group containing all Sales users.
Why it's wrong here
While a dynamic group can automatically group the users, it does not provide a scope for administrative delegation. Assigning a role to a user over a group allows them to manage the group itself, but it does not grant them the permission to manage the individual user objects contained within that group.
- ✓
An Administrative Unit (AU) and add the Sales users to it.
Why this is correct
Administrative Units are the correct tool for this requirement. By placing the Sales users into an AU, you can then assign the 'Password Administrator' role to the helpdesk lead scoped specifically to that AU. This limits their authority strictly to the members of that unit, protecting other users.
- ✗
A Custom Role with the 'microsoft.directory/users/password/update' permission.
Why it's wrong here
A custom role defines *what* a user can do, but on its own, it does not define *who* they can do it to. Without being scoped to an Administrative Unit, a user with this role would either have no targets or would have permission to reset passwords for every user in the tenant.
- ✗
An Access Package in Entra ID Governance.
Why it's wrong here
Access Packages are used for automated access requests and lifecycle management for users to gain access to groups, sites, or apps. They are not designed for delegating administrative permissions like password resets, which are managed through the Role-Based Access Control (RBAC) and Administrative Unit systems.
About these practice questions
This SC-300 question is part of Courseiva's 17-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-300 exam.