Skip to content
Getting Digital
Microsoft certificationsMicrosoft · exam SC-300

Microsoft Certified: Identity and Access Administrator Associate

Identity and Access Administrator covers who exists, what they may reach, and how that is proven: directory objects, authentication methods, conditional access, entitlement management and the governance around all of it.

A hundred minutes, no prerequisite, twelve months of validity.

Exam facts

Exam code
SC-300
Level
Associate
Field
Cybersecurity
Duration
100 minutes
Questions
about 40 to 60, including case studies and drag-and-drop items; labs possible
Passing score
700 of 1,000 (scaled)
Languages
English, German, French, Spanish, Italian, Portuguese, Japanese, Korean, ChineseThe badges group regional variants: Chinese (Simplified and Traditional) count as one language here, so the vendor lists ten exam editions where this page shows nine.
Price
165 USD (read 8 September 2026)
Validity
1 year, renewable
Exam delivery
Pearson VUE (test centre or online proctored); students through Certiport

Prerequisites: No required certification. Microsoft expects familiarity with Azure, Microsoft 365 services, Active Directory Domain Services, PowerShell and Kusto Query Language.

Renewal: Free yearly renewal through an online assessment on Microsoft Learn, available from six months before expiry

Source: exam page at Microsoft · Price: Priced by the country where the exam is proctored: 165 USD in the United States, 126 EUR in Germany and Austria (Microsoft Learn country selector, read 2026-09-08)

How to prepare

  1. 1. The vendor's free learning path

    Microsoft publishes the exam objectives and a learning path free of charge — the authoritative source for scope and weighting. Open the learning path (opens in a new tab)

  2. 2. Online courses

    Courses and practice questions from the directory that target exactly this exam — details, price and the provider link (affiliate) are on the course page.

  3. 3. A practice test in the exam format

    MeasureUp sells a practice test for SC-300 with questions in the exam format, an explanation for every answer and a timed mode; the price shows in your currency on the shop page. Affiliate link.

    Practice test for SC-300 at MeasureUp (opens in a new tab)
  4. Book the exam

    Delivered by Pearson VUE (test centre or online proctored); students through Certiport. Schedule with Microsoft (opens in a new tab)

Affiliate disclosure: the course and practice-test links above are affiliate links — buying through them may earn us a commission at no extra cost to you. The vendor's learning path and booking links carry no commission.

Of the security certificates Microsoft offers, this is the one we would choose if forced to hold only one. Identity is where the majority of real incidents begin, it is the control plane every other product depends on, and unlike detection tooling it changes slowly. A conditional access policy written today will still be recognisable in three years, which cannot be said of the console around it. The exam also spreads its weighting evenly across the four areas rather than concentrating it, so there is no section to skip.

Do not treat Entra as a domain controller in the cloud

The single most reliable way to lose marks here is to reason from on-premise Active Directory. Group policy has no counterpart, the trust model is different, and synchronisation moves some attributes on schedules that differ from others. Candidates with deep directory experience often score worse than expected precisely because the familiar mental model keeps producing plausible wrong answers.

  • Conditional access carries more practical weight than its share of the syllabus, because almost every scenario resolves into a policy decision.
  • Entitlement management and access reviews are the governance half, and the half administrators least often touch before an audit.
  • Privileged access appears throughout: who can elevate, for how long, and who approved it.
  • Hybrid identity is where synchronisation questions live, and where on-premise instincts mislead most often.
  • External identities round it out, and are increasingly the part organisations get wrong in public.

Four areas, no soft one

Skill areaShareThe question underneath
Implement and manage user identities20 to 25 %Who exists, how they got there, and what happens when they leave
Implement authentication and access management25 to 30 %How a sign-in is proven, and which policy decides whether it proceeds
Plan and implement workload identities20 to 25 %The identities that are not people: applications, services, and what they may call
Plan and implement identity governance20 to 25 %Who reviews access, who approves elevation, and how you prove it later

The near-even split is unusual for Microsoft, whose other security papers lean hard on one area, and it changes preparation: there is no domain to triage away. Workload identities are the area candidates most often meet cold, because most administrators have spent their careers on people and have never had to reason about an application that authenticates on its own behalf. Governance is the area that decides audits and is examined as procedure, not as product knowledge: who requested, who approved, when it was reviewed, and where the evidence sits.

A year, then fifteen minutes at your desk

The sitting runs 100 minutes, or longer when a lab appears, over a question count Microsoft states only as a range; 700 scaled passes; nine editions include German; Pearson VUE delivers; and the fee follows the country of sitting. The certificate lasts twelve months and renews free through an online assessment on Microsoft Learn that opens six months before expiry. That renewal is the reason the twelve-month term is less punishing than it reads: the assessment is short, unproctored and taken at your desk, and the only way to lose the certificate is to forget the date.

No certificate is required first. Microsoft expects familiarity with Azure, Microsoft 365, Active Directory Domain Services, PowerShell and the Kusto Query Language, and that last item surprises people: the sign-in logs are queried, and a candidate who cannot read a query cannot answer the questions that ask what the logs show. Pair it with the operations analyst certificate if incidents are your work; pair it with the Microsoft 365 administrator certificate if tenants are; hold it alone if you may keep only one, because it is the one that will still describe your job when the products around it have been renamed.

What a question looks like

Written by us in the exam's style. It is not a real question from any question bank, and we do not publish those.

Contractors must reach one application from unmanaged devices, staff must reach everything from managed ones, and neither group should be prompted for extra verification on the corporate network. Which combination of policy conditions and controls achieves this without blocking either group?

Conditional access questions are logic puzzles wearing product names. Several combinations satisfy two of the three clauses and quietly lock out one population, which the exam counts as wrong even though the policy would deploy. Candidates who have written these policies and watched somebody get locked out read them far more carefully than those who have not.

What it costs to get and to keep

ItemAmountNote
Exam fee165 USDUnited States figure; Microsoft prices by the country of proctoring (read 12 September 2026)
Exam fee, Germany and Austria126 EURfrom the Microsoft Learn country selector (read 8 September 2026)
Annual renewalnot publishedfree and unproctored on Microsoft Learn, in the six-month window before expiry only (read 12 September 2026)
Renewal after lapsing165 USDthe full proctored exam at full price (read 12 September 2026)

How much preparation, from where you are

You administer Entra already
The governance sections are usually the gap: access reviews, entitlement packages and privileged access, which many organisations configure once and never revisit.
You come from on-premise Active Directory
Budget time for unlearning. The vocabulary overlaps enough to be dangerous, and the questions are built around exactly the places where the two models diverge.
You are a security generalist
The concepts will be familiar and the policy engine will not. Conditional access in particular rewards hands-on time in a trial tenant more than any amount of reading.

What passing this does not prove

  • Whether your access model matches how the organisation actually works.
  • The politics of removing somebody's standing administrative rights, which is the real obstacle.
  • Identity outside Microsoft's ecosystem, beyond the federation standards it speaks.
  • Whether anyone reviewed the access reviews.

Against the alternatives

SC-200Microsoft Certified: Security Operations Analyst Associate
Operations rather than identity, and a natural pair. Most incidents an analyst investigates started as an account problem, so holding both covers a real workflow rather than two hobbies.
MS-102Microsoft 365 Certified: Administrator Expert
Broader and retiring in November 2026. If identity is the part that interests you, this certificate is the one with a future.
CISSPCertified Information Systems Security Professional (CISSP)
A management credential with an experience requirement, not a technical one. They answer entirely different questions about a candidate and are not alternatives.

SC-300 — quick answers

Why pick this over the other security exams?

Because identity underpins the rest and ages more slowly than the tooling around it. Detection products are replaced and renamed; the questions of who exists, what they may reach and how that is proven persist. If you will only maintain one annual renewal, this is the one we would keep.

Is Active Directory experience an advantage?

Partly, and it is also the commonest trap. The vocabulary is similar enough that on-premise instincts feel right, and this paper deliberately targets precisely those points where the cloud model parts company. Treat the overlap as a starting point rather than a shortcut.

Do I need SC-900 first?

No. Nothing gates this exam, and the fundamentals paper introduces products rather than teaching administration. Technical candidates routinely start here.

How much hands-on time is realistic?

Enough to have built a conditional access policy, applied it, and watched it do something you did not intend. Microsoft offers trial tenants for this purpose, and the difference between candidates who used one and candidates who did not is visible in their scores.

What are workload identities, and why a quarter of the paper?

Identities that belong to software rather than people: an application that calls an API, a service that reads a mailbox, an automation that rotates its own secret. They outnumber human accounts in most tenants and are governed worse, which is why the exam gives them a full skill area and why administrators who have only ever managed users find that area the hardest.

What comes next

Concepts this exam draws on

Glossary entries with the reason each one matters for SC-300.

  • SSL/TLS

    Identity protection, conditional access and secure authentication.

  • IAM

    The exam is this concept applied to one vendor's directory.

  • Authentication

    Authentication methods and their configuration are a quarter of the paper.

  • MFA

    Conditional access policies demanding a stronger factor are the exam's recurring scenario.

  • Zero Trust

    The exam's design assumptions are the model: verify explicitly, least privilege, assume breach.

  • Least Privilege

    Privileged identity management and access reviews implement it.

A vendor certificate — not a degree and not an accredited qualification. Facts are from the vendor's exam page on the date shown; prices are list prices that vary by country and tax.

Last reviewed 12 September 2026 · Getting Digital