Implement Authentication and Access Management

Plan and implement user authentication methods, Conditional Access policies, identity protection risk policies, and Global Secure Access.

This is the highest-weighted domain on the SC-300 exam. It covers planning, implementing, and managing Microsoft Entra user authentication — authentication methods (certificate-based, temporary access pass, OAUTH tokens, Microsoft Authenticator, passkey/FIDO2), tenant-wide MFA settings, self-service password reset, Windows Hello for Business, account disabling and session revocation, password protection, and Microsoft Entra Kerberos for hybrid identities. Candidates must plan, implement, and manage Conditional Access policies including assignments, controls, testing and troubleshooting, session management, device-enforced restrictions, continuous access evaluation, authentication context, protected actions, and policy templates. The domain also covers managing risk using Microsoft Entra ID Protection — user risk and sign-in risk policies, MFA registration policy, monitoring and remediating risky users, sign-ins, and workload identities. Additionally, it addresses implementing Global Secure Access including client deployment, Private Access, Internet Access, and Internet Access for Microsoft 365. (25–30% of exam)
5 minutes 5 Questions

Implementing Authentication and Access Management is a core responsibility of the Microsoft Identity and Access Administrator. This involves configuring and managing how users prove their identity and what resources they can access within an organization's Microsoft ecosystem. **Authentication Met…

Concepts covered: Authentication Methods Planning and Implementation, Microsoft Authenticator and Passkey (FIDO2), Self-Service Password Reset Configuration, Account Disabling and Session Revocation, Tenant-Wide Multifactor Authentication Settings, Conditional Access Policy Planning and Templates, Conditional Access Assignments and Controls, Authentication Context and Protected Actions, MFA Registration Policy and Risky User Remediation, Global Secure Access Client and Private Access, Certificate-Based Authentication and OAUTH Tokens, Temporary Access Pass and Passwordless Methods, Windows Hello for Business Implementation, Microsoft Entra Password Protection and Kerberos, Conditional Access Testing and Troubleshooting, Session Management and Continuous Access Evaluation, User Risk and Sign-In Risk Policies, Risky Workload Identity Monitoring, Internet Access and Microsoft 365 Access Configuration

Test mode:
More Implement Authentication and Access Management questions
855 questions (total)