Courseiva
Implement and Manage User IdentitiesmediumMultiple ChoiceObjective-mapped

SC-300 Implement and Manage User Identities Practice Question

Your company, Fabrikam, Inc., has acquired another firm. You need to invite 500 external contractors to your Microsoft Entra ID tenant to access specific applications. You want to ensure that these users are categorized as guests and cannot browse the full directory. Which feature should you configure first to enforce these restrictions tenant-wide?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Guest user access restrictions

External collaboration settings within Microsoft Entra ID allow administrators to define the level of access guest users have to the directory. By default, guests have limited permissions, but these can be further restricted to prevent them from seeing any directory information outside of their own profile. This ensures data privacy and limits the potential for internal discovery by external entities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Guest user access restrictions

    Why this is correct

    Configuring guest user access to the most restrictive setting ensures that external users cannot perform directory lookups or see other users in the tenant. This is a foundational security step when onboarding large numbers of contractors who only require access to specific resource endpoints rather than the broader organizational structure.

  • Administrative Units

    Why it's wrong here

    Administrative units are primarily used for delegating administrative permissions over a subset of users, groups, or devices. While they help organize users, they do not natively restrict a guest user's ability to browse the global address list or view other tenant objects unless combined with complex custom roles and scoped permissions.

  • Conditional Access policies

    Why it's wrong here

    Conditional Access policies are used to enforce signals like location, device state, or risk during the authentication process. While they can block access to applications, they do not control the internal directory browsing permissions assigned to the guest user object itself within the Microsoft Entra ID directory settings or profile.

  • Entitlement Management

    Why it's wrong here

    Entitlement Management is used for automating the lifecycle of access for internal and external users through access packages. While it facilitates the invitation of contractors, the core restriction for directory-wide browsing is handled by the tenant-wide external collaboration settings rather than the access package workflow or the catalog settings.

About these practice questions

This SC-300 question is part of Courseiva's 17-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-300 exam.