All certifications / SC-300 / Cheat sheet
SC-300 SC-300 (skills outline of April 27, 2026) cheat sheet
Domain 1: Implement and manage user identities (24%)
Exam tips
- Remember that verification uses a TXT (or MX) record, not a CNAME, and that the onmicrosoft.com domain can never be deleted. If a question asks why a domain can't be removed, look for users, groups or apps still using it.
- When a question asks for the least-privileged role, eliminate Global Administrator first, then choose the most narrowly focused role that still covers the task. Watch the difference between Authentication Administrator and Privileged Authentication Administrator: only the privileged one can manage methods for administrators.
- If a scenario says even Global Administrators should not be able to modify certain users by default, the answer is a restricted management administrative unit. If it only says to limit what a regional team can manage, a normal AU with a scoped role is enough.
- Exam questions love the limits: Microsoft 365 groups can't contain devices or nested groups, dynamic groups can't take manual members, one rule can't mix user and device attributes, and only Microsoft 365 groups (not security groups) can be restored after deletion.
- If a question says licenses won't assign to a brand-new user, check usage location first. If it says a user kept a license after leaving a group, look for a direct assignment that still exists alongside the inherited one.
- Personal device equals registered; company device with cloud only equals joined; company device still in on-premises AD equals hybrid joined. For requiring MFA when joining devices, the recommended answer is a Conditional Access policy on the Register or join devices user action.
- Know the four guest invite settings and the three guest access restriction levels. If a scenario wants guests to see only their own profile, pick the most restrictive guest access setting; if it wants only certain domains invited, use collaboration restrictions.
- If guests are being prompted to register MFA in your tenant even though they already did MFA at home, the fix is inbound trust settings. If the scenario mentions Teams shared channels without guest accounts, the answer is B2B direct connect, which both tenants must enable.
- Disconnected forests or a need for a lightweight, highly available agent point to Cloud Sync. Device sync for hybrid join, pass-through authentication, or complex custom sync rules point to Connect Sync. Remember Start-ADSyncSyncCycle -PolicyType Delta to force a sync.
- If the scenario needs on-premises policies like logon hours enforced at sign-in without storing hashes in the cloud, choose PTA. If it wants the least infrastructure or leaked credential detection, choose PHS. Seamless SSO never pairs with federation.
- Fix sync errors at the source of authority, not in the cloud. For a duplicate attribute error, find the other object holding the value; for a stopped sync with no errors, check whether the scheduler is disabled or the server is in staging mode.
Key terms
- Initial domain
- The permanent tenantname.onmicrosoft.com domain created with every tenant; it cannot be removed.
- Domain verification
- Proving you own a custom domain by publishing a TXT or MX record with an Entra-supplied value in public DNS.
- Primary domain
- The verified domain used as the default UPN suffix when you create new users.
- Tenant ID
- The GUID that uniquely identifies a Microsoft Entra tenant, used by apps, scripts and federation settings.
- Company branding
- Customization of the sign-in page with your logos, background, colors and text, with optional per-language versions.
- Role definition
- A collection of permissions, either built-in or custom, that can be assigned to a principal.
- Role scope
- The boundary where a role applies: the tenant, an administrative unit, or a single resource.
- Role-assignable group
- A group created with isAssignableToRole set to true so it can receive Entra role assignments; the setting is fixed at creation.
- Global Reader
- A built-in read-only role that can view most settings and data without making changes.
- Least privilege
- Granting only the permissions, scope and duration a person needs to perform a task.
- Administrative unit
- A container of users, groups or devices used to scope Entra role assignments to a subset of the directory.
- Restricted management AU
- An administrative unit whose objects can be changed only by admins with roles scoped to that AU, not by tenant-scoped admins.
- AU-scoped role assignment
- A role assignment whose scope is an administrative unit, limiting the admin's power to objects in that AU.
- Dynamic AU membership
- An administrative unit whose user or device members are added and removed automatically by an attribute-based rule.
- Security group
- A group used to grant access to resources; can contain users, devices, service principals and nested groups.
- Microsoft 365 group
- A collaboration group that provisions a shared mailbox, calendar, SharePoint site and optional Team; contains users only.
- Dynamic membership rule
- An attribute-based expression that automatically adds and removes group members; requires Entra ID P1.
- Assigned membership
- Group membership managed manually by owners or administrators.
- Soft delete
- The 30-day window during which deleted users and Microsoft 365 groups can be restored.
- Service plan
- An individual service inside a license product that can be enabled or disabled per assignment.
- Usage location
- The user's country or region; required before a license can be assigned.
- Group-based licensing
- Assigning licenses to a group so members inherit them automatically; requires Entra ID P1.
- Inherited license
- A license a user holds because of group membership rather than direct assignment.
- Reprocess
- An action that retries license assignment for a group or user after you fix the cause of an error.
- Microsoft Entra registered
- A personal device with a work account added; used for BYOD scenarios on Windows, macOS, iOS and Android.
- Microsoft Entra joined
- An organization-owned Windows device joined directly to Entra ID, where users sign in with work accounts.
- Microsoft Entra hybrid joined
- A device joined to on-premises AD and also registered in Entra ID, configured through Entra Connect.
- Service connection point (SCP)
- An AD object that tells domain-joined computers which Entra tenant to register with for hybrid join.
- Windows LAPS with Entra
- A feature that rotates each device's local administrator password and backs it up to Entra ID.
- B2B collaboration
- Inviting external users to use your resources with their own identities, represented as user objects in your tenant.
- Redemption
- The step where an invited external user accepts the invitation and links their home identity to the guest object.
- Email one-time passcode
- A sign-in method for guests without a supported identity provider, where a code is emailed at each sign-in.
- Guest Inviter
- A built-in role allowing a user to invite external users when invitations are restricted to admins.
- Collaboration restrictions
- An allow list or deny list of domains that controls where invitations can be sent.
- Inbound access
- Cross-tenant settings controlling which external users and apps can reach your tenant's resources.
- Outbound access
- Cross-tenant settings controlling which of your users can access other tenants' resources.
- Inbound trust settings
- Options to accept MFA, compliant device and hybrid joined device claims from a partner's home tenant.
- B2B direct connect
- Mutual trust that lets external users access resources such as Teams shared channels without a guest object in your tenant.
- Cross-tenant synchronization
- A provisioning job from a source tenant that creates and maintains B2B users in a target tenant.
- Microsoft Entra Connect Sync
- An on-premises sync engine on Windows Server with a SQL database, supporting the broadest hybrid feature set.
- Microsoft Entra Cloud Sync
- A cloud-managed sync service that uses lightweight provisioning agents; configured in the Entra admin center.
- Staging mode
- A Connect Sync server that imports and syncs but does not export, used for failover and testing.
- Delta sync
- A sync cycle that processes only changes since the last run.
- Accidental deletes threshold
- A Connect Sync safeguard that blocks exports deleting more than a set number of objects.
- Password hash synchronization
- Syncing a salted, re-hashed version of the on-premises password hash so Entra ID can authenticate users in the cloud.
- Pass-through authentication
- Cloud sign-in where on-premises agents validate passwords against AD DS in real time.
- Federation
- Delegating authentication to a separate identity provider such as AD FS that issues tokens Entra trusts.
- Seamless SSO
- Kerberos-based silent sign-in for domain-joined devices on the corporate network, used with PHS or PTA.
- Staged rollout
- Moving selected groups from federated to cloud authentication before converting the whole domain.
- Microsoft Entra Connect Health
- A monitoring service with on-premises agents that reports health, alerts and sync errors for Connect Sync, AD FS and AD DS.
- Duplicate attribute error
- A sync error when two objects share a value such as UPN or proxyAddresses that must be unique.
- Hard match
- Matching an on-premises object to a cloud object by sourceAnchor (immutableId).
- Soft match
- Matching an on-premises object to an existing cloud object by primary SMTP address or UPN.
- IdFix
- A tool that scans on-premises AD for data problems such as duplicates and invalid characters before synchronization.
Domain 2: Implement authentication and access management (28%)
Exam tips
- Phishing-resistant means passkeys/FIDO2, Windows Hello for Business and certificate-based authentication, not Authenticator push or SMS. When a user has no methods and must set up passwordless sign-in, the answer is Temporary Access Pass.
- The nudge moves users to Authenticator; system-preferred MFA makes Entra ask for the strongest method already registered. To stop attackers registering methods with a stolen password, use a Conditional Access policy on the Register security information user action.
- If synced users can reset in the cloud but their on-premises password doesn't change, the answer is password writeback (P1, enabled in the sync tool and in the portal). Remember admins always get the two-method policy and can't use security questions.
- DC agents go on every domain controller and need no internet; the proxy goes on member servers with outbound internet access. For hybrid lockout, keep Entra's threshold below AD's and its duration above AD's.
- Security defaults and Conditional Access are mutually exclusive; if a question needs exclusions, locations or per-app rules, the answer is Conditional Access with P1. Break-glass accounts are cloud-only, onmicrosoft.com, Global Administrator, excluded from lockout-risk policies and monitored with alerts.
- All applicable policies are combined, and block always wins. Device platform is a convenience condition, not a security boundary; use compliant device or filters for devices for real device control. Require one versus require all changes the meaning of multiple grant controls.
- Phishing-resistant strength means passkeys, Windows Hello for Business and CBA; Authenticator push does not qualify. Persistent browser session only works when the policy targets all cloud apps.
- Report-only shows what real sign-ins would have done; What If simulates a sign-in that hasn't happened yet. Report-only policies that require a compliant device can still cause a device check prompt on some platforms, so read the documentation notes before relying on them for all users.
- Sign-in risk pairs with require MFA; user risk pairs with require password change. Leaked credential detection for synced users needs password hash sync. ID Protection risk-based policies need P2.
- Know the list of critical events and that CAE-capable clients get tokens lasting up to 28 hours. Apps that don't support CAE still honor revocation only when their current access token expires.
- Private Access equals VPN replacement for private apps using connectors; Internet Access equals web filtering and tenant restrictions for internet and Microsoft 365. Quick Access is broad; per-app access is granular and supports app-specific Conditional Access.
Key terms
- Authentication methods policy
- The unified Entra policy that enables and targets methods for sign-in, MFA and SSPR.
- Number matching
- An Authenticator push feature requiring the user to enter a number shown on the sign-in screen, blocking MFA fatigue approvals.
- Passkey (FIDO2)
- A phishing-resistant credential using a device-held private key bound to the sign-in domain.
- Temporary Access Pass
- A time-limited passcode issued by an admin for onboarding or recovery, used to register stronger methods.
- Certificate-based authentication
- Signing in to Entra ID with an X.509 certificate validated against uploaded certificate authorities.
- Combined security info registration
- One registration experience for MFA and SSPR methods, reached from the My Security Info page.
- Registration campaign
- A sign-in prompt (nudge) that asks users on weaker methods to register Microsoft Authenticator or another targeted method.
- System-preferred MFA
- Entra behavior that prompts for the strongest registered method rather than the user's chosen default.
- Register security information user action
- A Conditional Access target used to control when and where users can register authentication methods.
- SSPR
- Self-service password reset, letting users reset passwords or unlock accounts using registered methods.
- Password writeback
- Writing passwords changed or reset in Entra ID back to on-premises AD for synchronized users.
- Number of methods required
- The SSPR setting (one or two) that controls how many verification methods a user must pass to reset.
- Admin SSPR policy
- The fixed, stronger policy for administrator roles that requires two methods and disallows security questions.
- Global banned password list
- A Microsoft-maintained, non-editable list of weak passwords applied to all Entra users.
- Custom banned password list
- An admin-defined list of organization-specific terms that Entra blocks in passwords; requires P1.
- Smart lockout
- Entra sign-in protection that locks out attackers after failed attempts while distinguishing familiar and unfamiliar locations.
- DC agent
- The Password Protection component installed on every domain controller to enforce the banned list on-premises.
- Proxy service
- The Password Protection component on a member server that relays policy between Entra ID and the DC agents.
- Security defaults
- Free, preconfigured identity protections that enforce MFA registration, admin MFA and legacy auth blocking with no customization.
- Conditional Access
- A P1 policy engine that grants or blocks access based on signals such as user, app, device, location and risk.
- Emergency access account
- A cloud-only, highly privileged break-glass account used only when normal admin access is lost.
- Legacy authentication
- Older protocols such as basic authentication for POP, IMAP and SMTP that can't perform MFA.
- Assignments
- The users, workload identities and target resources that a Conditional Access policy applies to.
- Conditions
- Additional signals such as risk, device platform, network location, client app and device filters that narrow a policy.
- Grant controls
- The access decision: block, or grant while requiring MFA, compliant device, authentication strength and similar.
- Session controls
- Controls applied after access is granted, such as sign-in frequency, app enforced restrictions and App Control.
- Filter for devices
- A rule on device attributes that includes or excludes specific devices from a policy.
- Named location
- An administrator-defined IP range or set of countries used in Conditional Access network conditions.
- Trusted location
- A named IP location marked as trusted, which can be excluded from policies and lowers risk evaluation.
- Authentication strength
- A Conditional Access control that specifies which authentication method combinations satisfy a policy.
- Sign-in frequency
- A session control setting how long before users must reauthenticate, or requiring it every time.
- Token protection
- A session control that binds tokens to the issuing device to prevent replay of stolen tokens.
- Report-only mode
- A Conditional Access policy state that evaluates and logs results without enforcing them.
- What If tool
- A Conditional Access tool that simulates a sign-in to show which policies would apply and why.
- Sign-in log
- A record of each authentication with user, app, device, location, methods and Conditional Access results.
- Correlation ID
- An identifier linking the events of one sign-in request, used for troubleshooting and support cases.
- Sign-in risk
- The probability that a specific authentication request was not performed by the legitimate user.
- User risk
- The probability that an identity is compromised, based on accumulated detections such as leaked credentials.
- Risk detection
- A signal of suspicious activity, such as atypical travel or leaked credentials, that contributes to risk levels.
- Self-remediation
- Users clearing their own risk by completing MFA (sign-in risk) or a secure password change (user risk).
- Confirm user compromised
- An admin action that sets user risk to high and trains the detection model.
- Continuous access evaluation
- A mechanism letting services revoke access in near real time when critical events or policy changes occur.
- Critical event
- A change such as account disablement, password reset or token revocation that CAE-capable services act on.
- Claims challenge
- A response telling the client its token is no longer accepted and it must reauthenticate to Entra ID.
- Strict location enforcement
- A CAE setting that makes resources enforce location policy against the IP address they observe.
- Revoke sessions
- An admin action that invalidates a user's refresh tokens and session cookies.
- Security service edge (SSE)
- Cloud-delivered network security that applies identity-aware policy to user traffic.
- Microsoft Entra Internet Access
- The Global Secure Access service securing internet, SaaS and Microsoft 365 traffic with filtering and tenant restrictions.
- Microsoft Entra Private Access
- The Global Secure Access service providing Zero Trust access to private apps without a traditional VPN.
- Traffic forwarding profile
- A setting (Microsoft, Private Access or Internet Access) that determines which traffic is acquired and tunneled.
- Universal tenant restrictions
- A control that prevents users from accessing unapproved external tenants using corporate devices.
Domain 3: Plan and implement workload identities (24%)
Exam tips
- Shared identity across many resources or a lifecycle independent of the resource means user-assigned; a single resource whose identity should disappear with it means system-assigned. Permissions come from Azure RBAC at the smallest scope.
- App registrations show application objects; Enterprise applications show service principals. For pipelines in GitHub or Kubernetes with no secrets allowed, choose federated credentials. Between secrets and certificates, certificates are the more secure choice.
- No signed-in user means application permissions and admin consent. If users are blocked from consenting and need a way to ask, the answer is the admin consent workflow, not changing user consent to allow all apps.
- If a question says any user can sign in to an app but only certain users should, the answer is Assignment required set to Yes plus user or group assignments. Remember nested groups don't receive app role assignments.
- A SAML error saying the reply address doesn't match points to the Reply URL; an app not recognizing the issuer or audience points to the Identifier. Rotate signing certificates by adding the new one to the app before making it active in Entra.
- Assignment and scope decide who is provisioned; scoping filter clauses in one group are ANDed and groups are ORed. If a single user isn't appearing in the app, use provision on demand and then read the provisioning log entry for the reason.
- Connectors need only outbound 443, never inbound ports. For Integrated Windows Authentication SSO the answer is Kerberos constrained delegation. Choose Microsoft Entra ID pre-authentication whenever Conditional Access or MFA must protect the app.
- Blocking downloads from unmanaged devices in real time is a session policy in Conditional Access app control, enabled by the Use Conditional Access App Control session control. Finding unapproved apps is cloud discovery; policing risky OAuth apps is app governance.
- Conditional Access for workload identities supports only single-tenant service principals, not managed identities, and its grant control is block (by location or risk). Anything beyond basic workload identity features points to the Workload ID Premium license.
- Disable before delete: set Enabled for users to sign-in to No to test the impact safely. For credential expiry questions, think owners, notifications, the expiring credentials recommendation and preferring certificates or federated credentials.
Key terms
- Managed identity
- An automatically managed Entra identity for an Azure resource, with no credentials for you to store or rotate.
- System-assigned managed identity
- An identity enabled on one resource and deleted with it.
- User-assigned managed identity
- A standalone identity resource that can be attached to multiple Azure resources and has its own lifecycle.
- Azure RBAC role assignment
- Granting a role to a principal at a scope such as a resource, resource group or subscription.
- DefaultAzureCredential
- An Azure SDK credential class that automatically uses a managed identity when running in Azure.
- Application object
- The global definition of an app in its home tenant, managed under App registrations.
- Service principal
- The local instance of an app in a tenant, which receives permissions and assignments; managed under Enterprise applications.
- Client secret
- A password-like string used by an app to authenticate; simple but prone to leaks and expiry.
- Certificate credential
- A public key registered on the app whose private key signs authentication assertions; preferred over secrets.
- Federated identity credential
- A trust with an external identity provider that lets a workload exchange its token for an Entra token without secrets.
- Delegated permission
- A permission used by an app acting on behalf of a signed-in user, limited by that user's own access.
- Application permission
- An app-only permission used without a signed-in user; always requires admin consent.
- Admin consent
- Tenant-wide approval by an authorized admin that grants an app its requested permissions for all users.
- Admin consent workflow
- A process letting users request admin approval for apps they can't consent to, reviewed by designated reviewers.
- Illicit consent grant
- An attack that tricks users into granting permissions to a malicious app, giving it access to their data.
- App role
- A named role defined on an app registration that can be assigned to users, groups or applications.
- Roles claim
- A token claim listing the app role values assigned to the signed-in user or calling app.
- Assignment required
- An enterprise app property that, when Yes, allows only assigned users, groups and apps to get tokens.
- Allowed member types
- The app role setting deciding whether a role can be assigned to users and groups, applications, or both.
- Visible to users
- An enterprise app property controlling whether the app appears in My Apps, without affecting access.
- Identifier (Entity ID)
- The unique name of a SAML service provider that must match between Entra and the app.
- Reply URL (ACS URL)
- The app endpoint where Entra ID posts the SAML response after sign-in.
- SAML signing certificate
- The certificate Entra uses to sign SAML assertions, which the app uses to verify them.
- NameID
- The SAML claim that uniquely identifies the user to the app, by default the user principal name.
- OpenID Connect
- An identity protocol on top of OAuth 2.0 that issues ID tokens in JWT format to identify users.
- SCIM
- System for Cross-domain Identity Management, a standard REST protocol for provisioning users and groups.
- Attribute mapping
- The rule that maps an Entra attribute or expression to a target app attribute.
- Scoping filter
- Attribute-based clauses that limit which assigned users or groups are provisioned.
- Provision on demand
- Provisioning a single user immediately to test and troubleshoot configuration.
- Quarantine
- A provisioning job state entered after repeated failures, where it runs less often until fixed.
- Application proxy
- An Entra service that publishes on-premises web apps to remote users with Entra authentication and no inbound ports.
- Private network connector
- A lightweight Windows service with outbound-only connections that relays traffic for application proxy and Private Access.
- Connector group
- A set of connectors assigned to specific published apps, used for location and availability.
- Pre-authentication
- Requiring Microsoft Entra ID sign-in before traffic reaches the internal app; the alternative is Passthrough.
- Kerberos constrained delegation
- Allowing the connector to request Kerberos tickets on behalf of users for Integrated Windows Authentication SSO.
- CASB
- Cloud access security broker, a service providing visibility and control over cloud app use.
- Cloud discovery
- Analysis of traffic logs or endpoint signals to identify cloud apps in use and their risk.
- Sanctioned app
- A cloud app approved for use; unsanctioned apps can be flagged or blocked.
- App governance
- Defender for Cloud Apps capability that monitors and controls OAuth apps' permissions and behavior.
- Session policy
- A Conditional Access app control policy that monitors or restricts actions such as downloads during a session.
- Workload identity
- An identity used by software, such as a service principal or managed identity.
- Workload ID Premium
- A license adding Conditional Access, risk detection, access reviews and recommendations for workload identities.
- Conditional Access for workload identities
- Policies targeting single-tenant service principals that block access by location or service principal risk.
- Risky workload identity
- A service principal flagged by ID Protection with detections such as leaked credentials or anomalous activity.
- Service principal sign-in log
- The sign-in log tab that records authentication by apps using their own credentials.
- Unused application
- An app registration or enterprise app with no recent sign-ins, a candidate for disabling and removal.
- Overprivileged application
- An app granted permissions broader than it needs, such as tenant-wide read/write access.
- Credential expiry
- The end date of a client secret or certificate after which the app can no longer authenticate with it.
- Enabled for users to sign-in
- An enterprise app property that, when set to No, blocks all sign-ins to that app.
- Microsoft Entra recommendations
- Tenant-specific guidance listing actions such as removing unused apps or renewing expiring credentials.
Domain 4: Plan and automate identity governance (24%)
Exam tips
- Resources go into catalogs, catalogs hold access packages, and policies decide who, approval and duration. When a question describes time-limited, approved, bundled access, the answer is an access package; for preventing conflicting access, it's incompatible packages or groups.
- Proposed connected organizations are not included when a policy targets all configured connected organizations. To have Entra clean up guests automatically, configure the external user lifecycle settings in entitlement management, which only affect guests brought in through it.
- Auto apply only acts on decisions; the If reviewers don't respond setting decides what happens to users nobody reviewed. Role reviews for Entra roles and Azure resource roles are created through PIM.
- Time-based triggers use a date attribute plus an offset. Onboarding pairs with employeeHireDate, offboarding with employeeLeaveDateTime, and setting employeeLeaveDateTime needs special permission. Lifecycle workflows need Microsoft Entra ID Governance licensing.
- Terms of use are enforced only through a Conditional Access grant control, so if acceptance isn't being prompted, check the policy's assignments. Expire consents resets everyone on a schedule; duration before re-acceptance is per user from their own acceptance date.
- Eligible means must activate; active means has it now. Settings like MFA, justification, ticket and approval apply at activation and are configured per role. Maximum activation duration is 1 to 24 hours.
- PIM for Groups doesn't support dynamic or on-premises synced groups. Azure resources must be discovered before they can be managed in PIM. Owner and User Access Administrator are the Azure roles most worth making eligible.
- Default retention: 7 days free, 30 days P1/P2. Long-term archive means storage account; SIEM streaming means Event Hub; KQL, workbooks and alerts mean Log Analytics. Non-interactive sign-ins are a separate category you must select explicitly.
- Workbooks and KQL need logs in a Log Analytics workspace via diagnostic settings. In SigninLogs, ResultType 0 means success. Identity Secure Score measures posture as a percentage; recommendations list concrete fixes with statuses you can postpone or dismiss.
- Memorize the split: P1 is Conditional Access and hybrid conveniences; P2 is risk and privileged access plus basic governance; ID Governance is lifecycle workflows and advanced governance. When a question asks for the minimum license, choose the lowest tier that contains every feature mentioned.
Key terms
- Catalog
- A container of resources and access packages with its own delegated owners.
- Access package
- A bundle of resource roles (groups, apps, sites) with policies governing who can get them and for how long.
- Assignment policy
- Rules in an access package defining who can request, approval steps, expiration and reviews.
- Separation of duties
- Access package settings listing incompatible packages or groups to prevent conflicting access.
- Automatic assignment policy
- A policy that assigns an access package to users matching an attribute rule without a request.
- Connected organization
- An external organization, identified by Entra tenant or domain, that can request access packages.
- Configured state
- A connected organization an admin created or approved, included in the all configured connected organizations scope.
- Proposed state
- A connected organization created automatically after an approved request from a new organization.
- Sponsor
- An internal or external contact for a connected organization who can act as an approver.
- External user lifecycle
- Entitlement management settings to block and later remove guests whose last assignment ends.
- Access review
- A scheduled or one-time campaign in which reviewers approve or deny continued access.
- Self-review
- An access review where users attest to whether they still need their own access.
- Auto apply results
- A completion setting that automatically removes access that reviewers denied.
- If reviewers don't respond
- The setting deciding the outcome for unreviewed users: no change, remove, approve or take recommendations.
- Inactive-user recommendation
- A decision helper suggesting denial for users who have not signed in within a defined period.
- Lifecycle workflow
- An automated set of tasks in Entra ID triggered by joiner, mover or leaver events.
- employeeHireDate
- The user attribute holding the start date, used to trigger onboarding workflows.
- employeeLeaveDateTime
- The user attribute holding the departure date and time, used to trigger offboarding workflows.
- Execution conditions
- The scope rule that determines which users a lifecycle workflow applies to.
- Custom task extension
- A workflow task that calls an Azure Logic App to perform actions outside the built-in tasks.
- Terms of use
- An Entra feature that presents PDF documents users must accept, enforced through Conditional Access.
- Require users to expand
- A terms of use setting forcing users to open the document before they can accept it.
- Expire consents
- A setting that requires all users to reaccept on a recurring schedule from a start date.
- Duration before re-acceptance
- A setting that requires each user to reaccept a set number of days after their own acceptance.
- Terms of use grant control
- The Conditional Access grant option requiring acceptance of a specific terms of use.
- Privileged Identity Management
- An Entra service providing just-in-time, time-bound and approval-based privileged role access.
- Eligible assignment
- A role assignment the user must activate before gaining the role's permissions.
- Active assignment
- A role assignment that grants permissions immediately without activation.
- Activation
- The just-in-time step where an eligible user turns on a role for a limited duration, meeting any required checks.
- PIM alert
- A warning about risky privileged access configuration, such as too many Global Administrators.
- PIM for Groups
- Just-in-time eligible membership or ownership of security or Microsoft 365 groups.
- PIM for Azure resources
- Just-in-time eligible assignment of Azure RBAC roles at management group, subscription, resource group or resource scope.
- Discovery and onboarding
- The step that brings Azure subscriptions or resources under PIM management.
- Eligible member
- A user who can activate group membership for a limited time through PIM.
- Role inheritance
- Azure RBAC behavior where a role assigned at a higher scope applies to all child scopes.
- Sign-in logs
- Records of authentication events, split into interactive, non-interactive, service principal and managed identity sign-ins.
- Audit logs
- Records of directory changes showing the activity, initiator, target and modified properties.
- Provisioning logs
- Records of actions taken by provisioning services in target systems.
- Diagnostic setting
- A configuration that exports selected Entra log categories to Log Analytics, storage, Event Hubs or a partner.
- Event Hub
- An Azure streaming service used to forward logs in near real time to external SIEM tools.
- Workbook
- An interactive, customizable report built on Log Analytics data, with Entra templates for common scenarios.
- KQL
- Kusto Query Language, used to query Log Analytics tables such as SigninLogs and AuditLogs.
- SigninLogs
- The Log Analytics table containing interactive user sign-in events exported from Entra ID.
- Identity Secure Score
- A percentage measuring alignment with Microsoft identity security best practices, with improvement actions.
- Microsoft Entra recommendations
- Tenant-specific, prioritized actions with status tracking and impacted resources.
- Microsoft Entra ID Free
- The included edition with directory, sync, SSO, B2B and security defaults, but no Conditional Access.
- Microsoft Entra ID P1
- The paid edition adding Conditional Access, dynamic groups, group licensing, SSPR writeback, app proxy and more.
- Microsoft Entra ID P2
- P1 plus ID Protection, Privileged Identity Management, access reviews and entitlement management.
- Microsoft Entra ID Governance
- An add-on for P1 or P2 that adds lifecycle workflows and advanced governance features.
- Workload ID Premium
- A license adding Conditional Access and risk detection for workload identities.
Study SC-300 for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the SC-300 study planLessons, quizzes, exam simulations and hands-on labs.