SC-300試験無料問題集「Microsoft Identity and Access Administrator 認定」
You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains an Azure AD enterprise application named App1.
A contractor uses the credentials of [email protected].
You need to ensure that you can provide the contractor with access to App1. The contractor must be able to authenticate as [email protected].
What should you do?
A contractor uses the credentials of [email protected].
You need to ensure that you can provide the contractor with access to App1. The contractor must be able to authenticate as [email protected].
What should you do?
正解:D
解答を投票する
解説: (GoShiken メンバーにのみ表示されます)
You have a Microsoft Entra tenant that contains the users shown in the following table.

The tenant contains the Microsoft 365 groups shown in the following table.

You create an access review named Access1 that has the following settings:
* Select what to review: Teams + Groups
* Review scope: All Microsoft groups with guest users
* Scope: Guest users only
* Select reviewers: Users review their own access
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.


The tenant contains the Microsoft 365 groups shown in the following table.

You create an access review named Access1 that has the following settings:
* Select what to review: Teams + Groups
* Review scope: All Microsoft groups with guest users
* Scope: Guest users only
* Select reviewers: Users review their own access
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

正解:

Explanation:

You have a Microsoft 365 tenant that has 5,000 users. One hundred of the users are executives. The executives have a dedicated support team.
You need to ensure that the support team can reset passwords and manage multi-factorauthentication (MFA) settings for only the executives. The solution must use the principle of least privilege.
Which object type and Azure Active Directory (Azure AD) role should you use? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You need to ensure that the support team can reset passwords and manage multi-factorauthentication (MFA) settings for only the executives. The solution must use the principle of least privilege.
Which object type and Azure Active Directory (Azure AD) role should you use? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

正解:

Explanation:
Object type: An administrative unit
Role: Authentication administrator
In Azure AD Identity and Access Administration, Administrative units (AUs) let you scope delegated admin privileges to a subset of users. The study materials describe AUs as a way to "delegate administration to a subset of users by using administrative units," ensuring the support team's privileges apply only to the executives and not tenant-wide. You would place the 100 executives in a dedicated AU and then assign the support team a suitable role scoped to that AU , satisfying least-privilege principles.
For the required tasks- reset passwords and manage MFA settings -the correct least-privileged role is Authentication administrator . The role capabilities are documented as allowing you to "view, set, and reset authentication method information for non-administrators" and to "require users to re-register for MFA," which covers managing MFA settings for the executives. By contrast, Password administrator is limited to
"reset passwords for non-administrators" and does not include managing authentication methods/MFA, and Helpdesk administrator focuses on basic user help tasks and password resets without full MFA method management. Therefore, assigning Authentication administrator scoped to an Administrative unit containing only the executives meets the scenario and adheres to least privilege.
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it as a result, these questions will not appear in the review screen.
You have an Amazon Web Services (AWS) account, a Google Workspace subscription, and a GitHub account.
You deploy an Azure subscription and enable Microsoft 365 Defender
You need to ensure that you can monitor OAuth authentication requests by using Microsoft Defender for Cloud Apps.
Solution: From the Microsoft 365 Defender portal, you add the Microsoft Azure app connector.
Does this meet the goal?
After you answer a question in this section, you will NOT be able to return to it as a result, these questions will not appear in the review screen.
You have an Amazon Web Services (AWS) account, a Google Workspace subscription, and a GitHub account.
You deploy an Azure subscription and enable Microsoft 365 Defender
You need to ensure that you can monitor OAuth authentication requests by using Microsoft Defender for Cloud Apps.
Solution: From the Microsoft 365 Defender portal, you add the Microsoft Azure app connector.
Does this meet the goal?
正解:A
解答を投票する
解説: (GoShiken メンバーにのみ表示されます)
Task 1
You need to deploy multi factor authentication (MFA). The solution must meet the following requirements:
* Require MFA registration only for members of the Sg-Finance group.
* Exclude Debra Berger from having to register for MFA.
* Implement the solution without using a Conditional Access policy.
You need to deploy multi factor authentication (MFA). The solution must meet the following requirements:
* Require MFA registration only for members of the Sg-Finance group.
* Exclude Debra Berger from having to register for MFA.
* Implement the solution without using a Conditional Access policy.
正解:
See the Explanation for the complete step by step solution.
Explanation:
To deploy Multi-Factor Authentication (MFA) for only the members of the Sg-Finance group, excluding Debra Berger, and without using a Conditional Access policy, you can follow these steps:
Open the Microsoft Entra admin center:
Sign in as a Security Administrator or Global Administrator.
Navigate to MFA settings:
Go to Users > Active users.
On the Active users page, select Multi-factor authentication.
Manage user settings:
Find and select the Sg-Finance group.
Enable MFA for this group by setting the requirement status to Enabled.
Exclude a user from MFA:
In the Multi-factor authentication page, search for Debra Berger.
Set her MFA status to Disabled to exclude her from MFA registration.
Verify the configuration:
Ensure that all members of the Sg-Finance group have MFA enabled except for Debra Berger.
Communicate the change:
Inform the Sg-Finance group members about the MFA requirement and provide instructions on how to register for MFA.
Monitor the setup:
Check the sign-in logs to confirm that MFA is being prompted for the Sg-Finance group members and not for Debra Berger.
Explanation:
To deploy Multi-Factor Authentication (MFA) for only the members of the Sg-Finance group, excluding Debra Berger, and without using a Conditional Access policy, you can follow these steps:
Open the Microsoft Entra admin center:
Sign in as a Security Administrator or Global Administrator.
Navigate to MFA settings:
Go to Users > Active users.
On the Active users page, select Multi-factor authentication.
Manage user settings:
Find and select the Sg-Finance group.
Enable MFA for this group by setting the requirement status to Enabled.
Exclude a user from MFA:
In the Multi-factor authentication page, search for Debra Berger.
Set her MFA status to Disabled to exclude her from MFA registration.
Verify the configuration:
Ensure that all members of the Sg-Finance group have MFA enabled except for Debra Berger.
Communicate the change:
Inform the Sg-Finance group members about the MFA requirement and provide instructions on how to register for MFA.
Monitor the setup:
Check the sign-in logs to confirm that MFA is being prompted for the Sg-Finance group members and not for Debra Berger.
You have an Azure subscription that contains an Azure Automation account named Automation1.
You need to grant Automation1 access to Azure resources. The solution must meet the following requirements:
* Ensure that any permissions granted to Automation1 are removed when the account is deleted.
* Minimize administrative effort.
What should you use?
You need to grant Automation1 access to Azure resources. The solution must meet the following requirements:
* Ensure that any permissions granted to Automation1 are removed when the account is deleted.
* Minimize administrative effort.
What should you use?
正解:A
解答を投票する
You need to implement the planned changes and technical requirements for the marketing department.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

正解:

Explanation:

According to the Microsoft SC-300: Identity and Access Administrator official study guide and Microsoft Learn modules on Azure AD Identity Governance , the correct way to manage user access-especially for scenarios involving both internal and external users-is through Entitlement Management in Azure AD Identity Governance .
Entitlement Management uses access packages to define and automate how users obtain access to resources such as groups, SharePoint sites, and applications. Access packages contain policies that specify who can request access (internal users, external users, or both) and how that access is approved and periodically reviewed. The guide clearly states:
"Access packages provide a structured method to configure and automate access for users, ensuring that access assignments follow the organization's policy and compliance requirements." To enable external collaboration with another organization (such as fabrikam.com ), Microsoft documentation emphasizes that you must create a connected organization . A connected organization represents an external directory or domain whose users can be invited to request access packages or participate in identity governance workflows. The connected organization defines trust boundaries for cross- tenant collaboration, without requiring domain federation or acceptance.
In summary:
* Access packages configure and automate user access.
You have an Azure Active Directory (Azure AD) tenant that contains three users named User1, User1, and User3, You create a group named Group1. You add User2 and User3 to Group1.
You configure a role in Azure AD Privileged identity Management (PIM) as shown in the application administrator exhibit. (Click the application Administrator tab.)

Group1 is configured as the approver for the application administrator role.
You configure User2to be eligible for the application administrator role.
For User1, you add an assignment to the Application administrator role as shown in the Assignment exhibit.
(Click Assignment tab)

For each of the following statement, select Yes if the statement is true, Otherwise, select No.
NOTE: Each correct selection is worth one point.

You configure a role in Azure AD Privileged identity Management (PIM) as shown in the application administrator exhibit. (Click the application Administrator tab.)

Group1 is configured as the approver for the application administrator role.
You configure User2to be eligible for the application administrator role.
For User1, you add an assignment to the Application administrator role as shown in the Assignment exhibit.
(Click Assignment tab)

For each of the following statement, select Yes if the statement is true, Otherwise, select No.
NOTE: Each correct selection is worth one point.

正解:

Explanation:
< Statement 1 # No
Statement 2 # No
Statement 3 # Yes
According to the Microsoft SC-300: Microsoft Identity and Access Administrator study guide and Azure AD Privileged Identity Management (PIM) documentation, roles in PIM can be configured for eligible or active assignments.
* User1 is assigned automatically - No The "Add assignments" screen shows User1's assignment type as Eligible, not Active. Eligible assignments mean the user is not automatically granted the role; they must activate it manually when needed. Therefore, User1 is not assigned automatically to the Application Administrator role.
* When User2 requests role assignment, only User3 can approve - No The Role setting details show that approval is required to activate and that the approver is listed as Group1. Because both User2 and User3 are members of Group1, any member of the group can approve the request, not only User3. Hence, the statement that only User3 can approve is incorrect.
* User1's approval on January 31, 2021, at 23:00 - Yes The configuration shows an activation maximum duration of 5 hours. Therefore, if User1's request is approved at 23:00 on January 31, the role remains active for 5 hours - until 04:00 on February 1, 2021. This aligns precisely with the parameters displayed in the exhibit.
As confirmed in Microsoft documentation ( "Configure role settings in Azure AD PIM" ), activation settings define how long a user can remain active after approval, and group approvers allow any member of that group to approve activations.
