StudyToCert

All certifications / SC-300 / Cheat sheet

SC-300 SC-300 (skills outline of April 27, 2026) cheat sheet

Every exam tip and key term from the free SC-300 lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: Implement and manage user identities (24%)

Exam tips

Key terms

Initial domain
The permanent tenantname.onmicrosoft.com domain created with every tenant; it cannot be removed.
Domain verification
Proving you own a custom domain by publishing a TXT or MX record with an Entra-supplied value in public DNS.
Primary domain
The verified domain used as the default UPN suffix when you create new users.
Tenant ID
The GUID that uniquely identifies a Microsoft Entra tenant, used by apps, scripts and federation settings.
Company branding
Customization of the sign-in page with your logos, background, colors and text, with optional per-language versions.
Role definition
A collection of permissions, either built-in or custom, that can be assigned to a principal.
Role scope
The boundary where a role applies: the tenant, an administrative unit, or a single resource.
Role-assignable group
A group created with isAssignableToRole set to true so it can receive Entra role assignments; the setting is fixed at creation.
Global Reader
A built-in read-only role that can view most settings and data without making changes.
Least privilege
Granting only the permissions, scope and duration a person needs to perform a task.
Administrative unit
A container of users, groups or devices used to scope Entra role assignments to a subset of the directory.
Restricted management AU
An administrative unit whose objects can be changed only by admins with roles scoped to that AU, not by tenant-scoped admins.
AU-scoped role assignment
A role assignment whose scope is an administrative unit, limiting the admin's power to objects in that AU.
Dynamic AU membership
An administrative unit whose user or device members are added and removed automatically by an attribute-based rule.
Security group
A group used to grant access to resources; can contain users, devices, service principals and nested groups.
Microsoft 365 group
A collaboration group that provisions a shared mailbox, calendar, SharePoint site and optional Team; contains users only.
Dynamic membership rule
An attribute-based expression that automatically adds and removes group members; requires Entra ID P1.
Assigned membership
Group membership managed manually by owners or administrators.
Soft delete
The 30-day window during which deleted users and Microsoft 365 groups can be restored.
Service plan
An individual service inside a license product that can be enabled or disabled per assignment.
Usage location
The user's country or region; required before a license can be assigned.
Group-based licensing
Assigning licenses to a group so members inherit them automatically; requires Entra ID P1.
Inherited license
A license a user holds because of group membership rather than direct assignment.
Reprocess
An action that retries license assignment for a group or user after you fix the cause of an error.
Microsoft Entra registered
A personal device with a work account added; used for BYOD scenarios on Windows, macOS, iOS and Android.
Microsoft Entra joined
An organization-owned Windows device joined directly to Entra ID, where users sign in with work accounts.
Microsoft Entra hybrid joined
A device joined to on-premises AD and also registered in Entra ID, configured through Entra Connect.
Service connection point (SCP)
An AD object that tells domain-joined computers which Entra tenant to register with for hybrid join.
Windows LAPS with Entra
A feature that rotates each device's local administrator password and backs it up to Entra ID.
B2B collaboration
Inviting external users to use your resources with their own identities, represented as user objects in your tenant.
Redemption
The step where an invited external user accepts the invitation and links their home identity to the guest object.
Email one-time passcode
A sign-in method for guests without a supported identity provider, where a code is emailed at each sign-in.
Guest Inviter
A built-in role allowing a user to invite external users when invitations are restricted to admins.
Collaboration restrictions
An allow list or deny list of domains that controls where invitations can be sent.
Inbound access
Cross-tenant settings controlling which external users and apps can reach your tenant's resources.
Outbound access
Cross-tenant settings controlling which of your users can access other tenants' resources.
Inbound trust settings
Options to accept MFA, compliant device and hybrid joined device claims from a partner's home tenant.
B2B direct connect
Mutual trust that lets external users access resources such as Teams shared channels without a guest object in your tenant.
Cross-tenant synchronization
A provisioning job from a source tenant that creates and maintains B2B users in a target tenant.
Microsoft Entra Connect Sync
An on-premises sync engine on Windows Server with a SQL database, supporting the broadest hybrid feature set.
Microsoft Entra Cloud Sync
A cloud-managed sync service that uses lightweight provisioning agents; configured in the Entra admin center.
Staging mode
A Connect Sync server that imports and syncs but does not export, used for failover and testing.
Delta sync
A sync cycle that processes only changes since the last run.
Accidental deletes threshold
A Connect Sync safeguard that blocks exports deleting more than a set number of objects.
Password hash synchronization
Syncing a salted, re-hashed version of the on-premises password hash so Entra ID can authenticate users in the cloud.
Pass-through authentication
Cloud sign-in where on-premises agents validate passwords against AD DS in real time.
Federation
Delegating authentication to a separate identity provider such as AD FS that issues tokens Entra trusts.
Seamless SSO
Kerberos-based silent sign-in for domain-joined devices on the corporate network, used with PHS or PTA.
Staged rollout
Moving selected groups from federated to cloud authentication before converting the whole domain.
Microsoft Entra Connect Health
A monitoring service with on-premises agents that reports health, alerts and sync errors for Connect Sync, AD FS and AD DS.
Duplicate attribute error
A sync error when two objects share a value such as UPN or proxyAddresses that must be unique.
Hard match
Matching an on-premises object to a cloud object by sourceAnchor (immutableId).
Soft match
Matching an on-premises object to an existing cloud object by primary SMTP address or UPN.
IdFix
A tool that scans on-premises AD for data problems such as duplicates and invalid characters before synchronization.

Domain 2: Implement authentication and access management (28%)

Exam tips

Key terms

Authentication methods policy
The unified Entra policy that enables and targets methods for sign-in, MFA and SSPR.
Number matching
An Authenticator push feature requiring the user to enter a number shown on the sign-in screen, blocking MFA fatigue approvals.
Passkey (FIDO2)
A phishing-resistant credential using a device-held private key bound to the sign-in domain.
Temporary Access Pass
A time-limited passcode issued by an admin for onboarding or recovery, used to register stronger methods.
Certificate-based authentication
Signing in to Entra ID with an X.509 certificate validated against uploaded certificate authorities.
Combined security info registration
One registration experience for MFA and SSPR methods, reached from the My Security Info page.
Registration campaign
A sign-in prompt (nudge) that asks users on weaker methods to register Microsoft Authenticator or another targeted method.
System-preferred MFA
Entra behavior that prompts for the strongest registered method rather than the user's chosen default.
Register security information user action
A Conditional Access target used to control when and where users can register authentication methods.
SSPR
Self-service password reset, letting users reset passwords or unlock accounts using registered methods.
Password writeback
Writing passwords changed or reset in Entra ID back to on-premises AD for synchronized users.
Number of methods required
The SSPR setting (one or two) that controls how many verification methods a user must pass to reset.
Admin SSPR policy
The fixed, stronger policy for administrator roles that requires two methods and disallows security questions.
Global banned password list
A Microsoft-maintained, non-editable list of weak passwords applied to all Entra users.
Custom banned password list
An admin-defined list of organization-specific terms that Entra blocks in passwords; requires P1.
Smart lockout
Entra sign-in protection that locks out attackers after failed attempts while distinguishing familiar and unfamiliar locations.
DC agent
The Password Protection component installed on every domain controller to enforce the banned list on-premises.
Proxy service
The Password Protection component on a member server that relays policy between Entra ID and the DC agents.
Security defaults
Free, preconfigured identity protections that enforce MFA registration, admin MFA and legacy auth blocking with no customization.
Conditional Access
A P1 policy engine that grants or blocks access based on signals such as user, app, device, location and risk.
Emergency access account
A cloud-only, highly privileged break-glass account used only when normal admin access is lost.
Legacy authentication
Older protocols such as basic authentication for POP, IMAP and SMTP that can't perform MFA.
Assignments
The users, workload identities and target resources that a Conditional Access policy applies to.
Conditions
Additional signals such as risk, device platform, network location, client app and device filters that narrow a policy.
Grant controls
The access decision: block, or grant while requiring MFA, compliant device, authentication strength and similar.
Session controls
Controls applied after access is granted, such as sign-in frequency, app enforced restrictions and App Control.
Filter for devices
A rule on device attributes that includes or excludes specific devices from a policy.
Named location
An administrator-defined IP range or set of countries used in Conditional Access network conditions.
Trusted location
A named IP location marked as trusted, which can be excluded from policies and lowers risk evaluation.
Authentication strength
A Conditional Access control that specifies which authentication method combinations satisfy a policy.
Sign-in frequency
A session control setting how long before users must reauthenticate, or requiring it every time.
Token protection
A session control that binds tokens to the issuing device to prevent replay of stolen tokens.
Report-only mode
A Conditional Access policy state that evaluates and logs results without enforcing them.
What If tool
A Conditional Access tool that simulates a sign-in to show which policies would apply and why.
Sign-in log
A record of each authentication with user, app, device, location, methods and Conditional Access results.
Correlation ID
An identifier linking the events of one sign-in request, used for troubleshooting and support cases.
Sign-in risk
The probability that a specific authentication request was not performed by the legitimate user.
User risk
The probability that an identity is compromised, based on accumulated detections such as leaked credentials.
Risk detection
A signal of suspicious activity, such as atypical travel or leaked credentials, that contributes to risk levels.
Self-remediation
Users clearing their own risk by completing MFA (sign-in risk) or a secure password change (user risk).
Confirm user compromised
An admin action that sets user risk to high and trains the detection model.
Continuous access evaluation
A mechanism letting services revoke access in near real time when critical events or policy changes occur.
Critical event
A change such as account disablement, password reset or token revocation that CAE-capable services act on.
Claims challenge
A response telling the client its token is no longer accepted and it must reauthenticate to Entra ID.
Strict location enforcement
A CAE setting that makes resources enforce location policy against the IP address they observe.
Revoke sessions
An admin action that invalidates a user's refresh tokens and session cookies.
Security service edge (SSE)
Cloud-delivered network security that applies identity-aware policy to user traffic.
Microsoft Entra Internet Access
The Global Secure Access service securing internet, SaaS and Microsoft 365 traffic with filtering and tenant restrictions.
Microsoft Entra Private Access
The Global Secure Access service providing Zero Trust access to private apps without a traditional VPN.
Traffic forwarding profile
A setting (Microsoft, Private Access or Internet Access) that determines which traffic is acquired and tunneled.
Universal tenant restrictions
A control that prevents users from accessing unapproved external tenants using corporate devices.

Domain 3: Plan and implement workload identities (24%)

Exam tips

Key terms

Managed identity
An automatically managed Entra identity for an Azure resource, with no credentials for you to store or rotate.
System-assigned managed identity
An identity enabled on one resource and deleted with it.
User-assigned managed identity
A standalone identity resource that can be attached to multiple Azure resources and has its own lifecycle.
Azure RBAC role assignment
Granting a role to a principal at a scope such as a resource, resource group or subscription.
DefaultAzureCredential
An Azure SDK credential class that automatically uses a managed identity when running in Azure.
Application object
The global definition of an app in its home tenant, managed under App registrations.
Service principal
The local instance of an app in a tenant, which receives permissions and assignments; managed under Enterprise applications.
Client secret
A password-like string used by an app to authenticate; simple but prone to leaks and expiry.
Certificate credential
A public key registered on the app whose private key signs authentication assertions; preferred over secrets.
Federated identity credential
A trust with an external identity provider that lets a workload exchange its token for an Entra token without secrets.
Delegated permission
A permission used by an app acting on behalf of a signed-in user, limited by that user's own access.
Application permission
An app-only permission used without a signed-in user; always requires admin consent.
Admin consent
Tenant-wide approval by an authorized admin that grants an app its requested permissions for all users.
Admin consent workflow
A process letting users request admin approval for apps they can't consent to, reviewed by designated reviewers.
Illicit consent grant
An attack that tricks users into granting permissions to a malicious app, giving it access to their data.
App role
A named role defined on an app registration that can be assigned to users, groups or applications.
Roles claim
A token claim listing the app role values assigned to the signed-in user or calling app.
Assignment required
An enterprise app property that, when Yes, allows only assigned users, groups and apps to get tokens.
Allowed member types
The app role setting deciding whether a role can be assigned to users and groups, applications, or both.
Visible to users
An enterprise app property controlling whether the app appears in My Apps, without affecting access.
Identifier (Entity ID)
The unique name of a SAML service provider that must match between Entra and the app.
Reply URL (ACS URL)
The app endpoint where Entra ID posts the SAML response after sign-in.
SAML signing certificate
The certificate Entra uses to sign SAML assertions, which the app uses to verify them.
NameID
The SAML claim that uniquely identifies the user to the app, by default the user principal name.
OpenID Connect
An identity protocol on top of OAuth 2.0 that issues ID tokens in JWT format to identify users.
SCIM
System for Cross-domain Identity Management, a standard REST protocol for provisioning users and groups.
Attribute mapping
The rule that maps an Entra attribute or expression to a target app attribute.
Scoping filter
Attribute-based clauses that limit which assigned users or groups are provisioned.
Provision on demand
Provisioning a single user immediately to test and troubleshoot configuration.
Quarantine
A provisioning job state entered after repeated failures, where it runs less often until fixed.
Application proxy
An Entra service that publishes on-premises web apps to remote users with Entra authentication and no inbound ports.
Private network connector
A lightweight Windows service with outbound-only connections that relays traffic for application proxy and Private Access.
Connector group
A set of connectors assigned to specific published apps, used for location and availability.
Pre-authentication
Requiring Microsoft Entra ID sign-in before traffic reaches the internal app; the alternative is Passthrough.
Kerberos constrained delegation
Allowing the connector to request Kerberos tickets on behalf of users for Integrated Windows Authentication SSO.
CASB
Cloud access security broker, a service providing visibility and control over cloud app use.
Cloud discovery
Analysis of traffic logs or endpoint signals to identify cloud apps in use and their risk.
Sanctioned app
A cloud app approved for use; unsanctioned apps can be flagged or blocked.
App governance
Defender for Cloud Apps capability that monitors and controls OAuth apps' permissions and behavior.
Session policy
A Conditional Access app control policy that monitors or restricts actions such as downloads during a session.
Workload identity
An identity used by software, such as a service principal or managed identity.
Workload ID Premium
A license adding Conditional Access, risk detection, access reviews and recommendations for workload identities.
Conditional Access for workload identities
Policies targeting single-tenant service principals that block access by location or service principal risk.
Risky workload identity
A service principal flagged by ID Protection with detections such as leaked credentials or anomalous activity.
Service principal sign-in log
The sign-in log tab that records authentication by apps using their own credentials.
Unused application
An app registration or enterprise app with no recent sign-ins, a candidate for disabling and removal.
Overprivileged application
An app granted permissions broader than it needs, such as tenant-wide read/write access.
Credential expiry
The end date of a client secret or certificate after which the app can no longer authenticate with it.
Enabled for users to sign-in
An enterprise app property that, when set to No, blocks all sign-ins to that app.
Microsoft Entra recommendations
Tenant-specific guidance listing actions such as removing unused apps or renewing expiring credentials.

Domain 4: Plan and automate identity governance (24%)

Exam tips

Key terms

Catalog
A container of resources and access packages with its own delegated owners.
Access package
A bundle of resource roles (groups, apps, sites) with policies governing who can get them and for how long.
Assignment policy
Rules in an access package defining who can request, approval steps, expiration and reviews.
Separation of duties
Access package settings listing incompatible packages or groups to prevent conflicting access.
Automatic assignment policy
A policy that assigns an access package to users matching an attribute rule without a request.
Connected organization
An external organization, identified by Entra tenant or domain, that can request access packages.
Configured state
A connected organization an admin created or approved, included in the all configured connected organizations scope.
Proposed state
A connected organization created automatically after an approved request from a new organization.
Sponsor
An internal or external contact for a connected organization who can act as an approver.
External user lifecycle
Entitlement management settings to block and later remove guests whose last assignment ends.
Access review
A scheduled or one-time campaign in which reviewers approve or deny continued access.
Self-review
An access review where users attest to whether they still need their own access.
Auto apply results
A completion setting that automatically removes access that reviewers denied.
If reviewers don't respond
The setting deciding the outcome for unreviewed users: no change, remove, approve or take recommendations.
Inactive-user recommendation
A decision helper suggesting denial for users who have not signed in within a defined period.
Lifecycle workflow
An automated set of tasks in Entra ID triggered by joiner, mover or leaver events.
employeeHireDate
The user attribute holding the start date, used to trigger onboarding workflows.
employeeLeaveDateTime
The user attribute holding the departure date and time, used to trigger offboarding workflows.
Execution conditions
The scope rule that determines which users a lifecycle workflow applies to.
Custom task extension
A workflow task that calls an Azure Logic App to perform actions outside the built-in tasks.
Terms of use
An Entra feature that presents PDF documents users must accept, enforced through Conditional Access.
Require users to expand
A terms of use setting forcing users to open the document before they can accept it.
Expire consents
A setting that requires all users to reaccept on a recurring schedule from a start date.
Duration before re-acceptance
A setting that requires each user to reaccept a set number of days after their own acceptance.
Terms of use grant control
The Conditional Access grant option requiring acceptance of a specific terms of use.
Privileged Identity Management
An Entra service providing just-in-time, time-bound and approval-based privileged role access.
Eligible assignment
A role assignment the user must activate before gaining the role's permissions.
Active assignment
A role assignment that grants permissions immediately without activation.
Activation
The just-in-time step where an eligible user turns on a role for a limited duration, meeting any required checks.
PIM alert
A warning about risky privileged access configuration, such as too many Global Administrators.
PIM for Groups
Just-in-time eligible membership or ownership of security or Microsoft 365 groups.
PIM for Azure resources
Just-in-time eligible assignment of Azure RBAC roles at management group, subscription, resource group or resource scope.
Discovery and onboarding
The step that brings Azure subscriptions or resources under PIM management.
Eligible member
A user who can activate group membership for a limited time through PIM.
Role inheritance
Azure RBAC behavior where a role assigned at a higher scope applies to all child scopes.
Sign-in logs
Records of authentication events, split into interactive, non-interactive, service principal and managed identity sign-ins.
Audit logs
Records of directory changes showing the activity, initiator, target and modified properties.
Provisioning logs
Records of actions taken by provisioning services in target systems.
Diagnostic setting
A configuration that exports selected Entra log categories to Log Analytics, storage, Event Hubs or a partner.
Event Hub
An Azure streaming service used to forward logs in near real time to external SIEM tools.
Workbook
An interactive, customizable report built on Log Analytics data, with Entra templates for common scenarios.
KQL
Kusto Query Language, used to query Log Analytics tables such as SigninLogs and AuditLogs.
SigninLogs
The Log Analytics table containing interactive user sign-in events exported from Entra ID.
Identity Secure Score
A percentage measuring alignment with Microsoft identity security best practices, with improvement actions.
Microsoft Entra recommendations
Tenant-specific, prioritized actions with status tracking and impacted resources.
Microsoft Entra ID Free
The included edition with directory, sync, SSO, B2B and security defaults, but no Conditional Access.
Microsoft Entra ID P1
The paid edition adding Conditional Access, dynamic groups, group licensing, SSPR writeback, app proxy and more.
Microsoft Entra ID P2
P1 plus ID Protection, Privileged Identity Management, access reviews and entitlement management.
Microsoft Entra ID Governance
An add-on for P1 or P2 that adds lifecycle workflows and advanced governance features.
Workload ID Premium
A license adding Conditional Access and risk detection for workload identities.
Study SC-300 for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the SC-300 study plan