Entra IDTraining path

Training path: Microsoft Entra ID for administrators (SC-300 study plan)

A six-stage study plan for exam SC-300, mapped to the official Microsoft Learn learning paths, with hands-on labs for Conditional Access, authentication methods, PIM, access reviews, apps and Entra Connect.

SC-300 is the exam behind the Microsoft Certified: Identity and Access Administrator Associate certification, and it's the natural next step for anyone who already manages users, MFA and Conditional Access in Microsoft Entra ID. In this post I'll lay out a six-stage plan built on Microsoft's own learning paths, with a lab for every stage so you learn by configuring things in a test tenant rather than only reading about them.

Study roadmap: Who it's for → The exam at a glance → Stage 1 → Stage 2 → Stage 3 → Stage 4 → Stage 5 → Stage 6 → Hands-on practice → Exam day → After the examRoadmap of the training path in order: Who it's for; The exam at a glance; Stage 1 (weeks 1–2): Tenant foundations and identities; Stage 2 (weeks 3–4): Hybrid identity; Stage 3 (weeks 5–6): Authentication; Stage 4 (weeks 7–8): Conditional Access, ID Protection and Global Secure Access; Stage 5 (weeks 9–10): Applications and workload identities; Stage 6 (weeks 11–12): Governance, monitoring and review; Hands-on practice; Exam day; After the exam.1Who it's for2The exam at a glanceStage 1weeks 1–2Tenantfoundations and…Stage 2weeks 3–4Hybrid identityStage 3weeks 5–6AuthenticationStage 4weeks 7–8ConditionalAccess, ID Prote…Stage 5weeks 9–10Applications andworkload identit…Stage 6weeks 11–12Governance,monitoring and r…3Hands-on practice4Exam day5After the examStudy roadmap: Who it's for → The exam at a glance → Stage 1 → Stage 2 → Stage 3 → Stage 4 → Stage 5 → Stage 6 → Hands-on practice → Exam day → After the examRoadmap of the training path in order: Who it's for; The exam at a glance; Stage 1 (weeks 1–2): Tenant foundations and identities; Stage 2 (weeks 3–4): Hybrid identity; Stage 3 (weeks 5–6): Authentication; Stage 4 (weeks 7–8): Conditional Access, ID Protection and Global Secure Access; Stage 5 (weeks 9–10): Applications and workload identities; Stage 6 (weeks 11–12): Governance, monitoring and review; Hands-on practice; Exam day; After the exam.1Who it's for2The exam at a glanceStage 1 · weeks 1–2Tenant foundations and identitiesStage 2 · weeks 3–4Hybrid identityStage 3 · weeks 5–6AuthenticationStage 4 · weeks 7–8Conditional Access, ID Protection and Global Secur…Stage 5 · weeks 9–10Applications and workload identitiesStage 6 · weeks 11–12Governance, monitoring and review3Hands-on practice4Exam day5After the exam
At a glance: how this study path is organised · 6 stages over 12 weeks

Who this path is for#

This plan suits Microsoft 365 and Intune administrators who touch Entra ID every day, helpdesk engineers moving into identity, and Active Directory admins who now run a hybrid environment. Microsoft's audience profile expects familiarity with Azure, Microsoft 365 workloads and Active Directory Domain Services, plus some comfort with PowerShell and Kusto Query Language (KQL). You don't need to be a developer, but you do need to understand what an app registration is.

Prerequisites for the labs: a test tenant where you hold the Global Administrator role and can break things safely, a small lab Active Directory (one domain controller in a VM is enough) for the hybrid topics, and licensing for the premium features. PIM, access reviews, entitlement management and risk-based policies need Microsoft Entra ID P2 or Microsoft Entra ID Governance licences in that tenant.

The exam at a glance#

ItemDetail
ExamSC-300: Microsoft Identity and Access Administrator
Certification earnedMicrosoft Certified: Identity and Access Administrator Associate
Duration and passing score100 minutes; a score of 700 or greater is required to pass (per Microsoft Learn)
LanguagesEnglish, German, Spanish, French, Italian, Japanese, Korean, Portuguese (Brazil), Chinese (Simplified and Traditional)
RenewalEvery 12 months through a free online assessment on Microsoft Learn

The skills measured, as published in Microsoft's study guide (version applying from October 28, 2026), are:

DomainWeight
Implement and manage user identities20–25%
Implement authentication and access management25–30%
Plan and implement workload identities20–25%
Plan and automate identity governance20–25%

Note: Microsoft updates this exam periodically; the English version changed on October 28, 2026 and the study guide's change log describes those edits as minor. Re-check the study guide before you book, and remember that most questions cover generally available features, with preview features appearing only when they're widely used.

Stage-by-stage plan#

Stage 1 (weeks 1–2): Tenant foundations and identities#

Study: the learning path Implement an identity management solution using Microsoft Entra ID, which covers initial tenant configuration, users and groups, external identities and hybrid identity. Practise: add and verify a custom domain, configure company branding, create administrative units and delegate a scoped role, compare built-in roles with a custom role, and bulk-create users with the admin center and the Microsoft Graph PowerShell SDK. Invite a guest, then review cross-tenant access settings and external collaboration settings.

Stage 2 (weeks 3–4): Hybrid identity#

Study: the Implement and manage hybrid identity module from the same learning path. Practise: install Microsoft Entra Connect in your lab with password hash synchronization and seamless SSO, filter by OU, trigger Start-ADSyncSyncCycle -PolicyType Delta, and read a synchronization error in Synchronization Service Manager. Then install Microsoft Entra Cloud Sync in parallel on a second server so you can explain when each tool fits, and enable Microsoft Entra Connect Health.

Stage 3 (weeks 5–6): Authentication#

Study: the first two modules of Implement an authentication and access management solution: Secure Microsoft Entra users with multifactor authentication and Manage user authentication. Practise: in Entra ID › Authentication methods › Policies enable Microsoft Authenticator, passkeys (FIDO2) and Temporary Access Pass; register a passkey yourself; configure SSPR for a pilot group; set up Microsoft Entra password protection with a custom banned password list; and run a registration campaign. If your lab has a domain, deploy Microsoft Entra Kerberos and Windows Hello for Business with cloud Kerberos trust.

Stage 4 (weeks 7–8): Conditional Access, ID Protection and Global Secure Access#

Study: the remaining modules of that learning path: Plan, implement, and administer Conditional Access, Manage Microsoft Entra Identity Protection, Implement access management for Azure resources and Deploy and Configure Microsoft Entra Global Secure Access. Practise: create policies from the templates in report-only mode, read the report-only results in the sign-in logs, test with the What If tool, then switch one policy on for a pilot group. Build an authentication strength, an authentication context and a protected action. Configure sign-in and user risk policies and walk through the risky users report. Assign a managed identity to an Azure resource and grant it an RBAC role.

Stage 5 (weeks 9–10): Applications and workload identities#

Study: the learning path Implement access management for apps (enterprise app SSO, app registration, monitoring). Practise: add a SAML gallery app and assign users and app roles; create an app registration with delegated and application API permissions, grant admin consent and review the consent settings; publish an internal web app with Microsoft Entra application proxy; and look at Defender for Cloud Apps discovery and OAuth app policies if you have access.

Stage 6 (weeks 11–12): Governance, monitoring and review#

Study: the learning path Plan and implement an identity governance strategy. Practise: configure PIM for an Entra role with approval and justification, activate it, then review the audit history; create an access review for a group and complete it; build a catalog and an access package with an approval stage and a connected organization; publish terms of use; create two emergency access accounts and exclude them from your policies. Send sign-in and audit logs to a Log Analytics workspace, write a few KQL queries and open the built-in workbooks and Identity Secure Score. Finish with Microsoft's free practice assessment and re-study anything under 70%.

Hands-on practice#

These exercises map directly to objectives in the study guide. Keep a notebook of portal paths and setting names as you go; the exam rewards precise knowledge.

  • Conditional Access: a Require MFA for all users policy in report-only mode, then enforced for a pilot group with a break-glass exclusion; a device-compliance policy for Microsoft 365; a sign-in frequency session control.
  • Authentication methods: onboard a brand-new user with a Temporary Access Pass and a passkey, then verify the methods on their Authentication methods page.
  • PIM: eligible assignment, activation with MFA, approval by a second account, and an alert for permanent Global Administrator assignments.
  • Access reviews and entitlement management: a recurring review of guest users, and an access package that grants a group, a Teams team and an app with a 90-day expiry.
  • Apps: an app registration consumed by a PowerShell script using a certificate rather than a client secret.
  • Hybrid: break a sync on purpose (duplicate proxyAddresses) and fix it from the Connect Health error report.

Exam-day tips#

  • Expect scenario questions that ask for the least privileged role or the solution with the least administrative effort; eliminate options that work but are heavier than needed.
  • Know which features need P1, P2 or ID Governance licensing, and which need Defender for Cloud Apps.
  • Use the exam sandbox on Microsoft Learn beforehand so the question formats hold no surprises, and register with a personal Microsoft account so your record stays with you if you change employers.
  • If you don't pass, you can retake the exam 24 hours after the first attempt; later retakes have longer waits.

After the exam#

Role-based associate certifications expire after 12 months. You renew for free by passing an online assessment on Microsoft Learn before the expiry date, so put a reminder in your calendar when your badge arrives. Natural next steps are SC-100 (Cybersecurity Architect Expert, which lists identity exams among its prerequisites; check the current requirements), MD-102 if you also run Intune, and SC-200 if you lean towards security operations.

References#

Training path

Everything for SC-300 on this site

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)