SC-300 SC-300 Skills measured April 27, 2026 Workload identities Runs in your browser · no setup Preview · not independently reviewed

Repair an application identity and consent design

Choose the correct workload identity, permission type, and credential path.

Estimated15 min
DifficultyAdvanced
Points10
Scenario brief

An Azure-hosted inventory job reads a protected API without a signed-in user. The current app registration uses a client secret stored in a deployment file and requests a delegated permission.

Content record

Preview · not independently reviewed

Mapped to Microsoft SC-300 objectives · Internal validation 2026-08-16 · Available as preview practice, but a named independent subject-matter expert has not yet verified the question and answer key.

Community review →
3.1Plan and implement identities for applications and Azure workloads. 3.2Plan, implement, and monitor the integration of enterprise applications. 3.3Plan and implement app registrations.
Show review record and official sources

Method: Mapped to SC-300 objectives 3.1, 3.2, and 3.3; scenario logic and answer feedback checked against current Microsoft Learn documentation.

Current-profile check: 2026-08-16 · Next review due 2027-02-12

01

Inspect the evidence

Use only the information provided to complete the tasks.

Current configuration

table
ItemValue
RuntimeAzure Function
User presentNo
CredentialClient secret in deployment settings
PermissionInventory.Read delegated
ConsentUser consent attempted
02

Complete the response

Partial credit is available for matching, ordering, and multi-select tasks.

01
single choice

Which identity design removes the stored secret with the least lifecycle overhead?

3 pts
Need a hint?

Restate the exact outcome or failure the prompt asks about before comparing choices.

Show another hint

Eliminate choices that solve a nearby problem, change more than requested, or do not fit the evidence.

02
matching

Match each access case to the correct permission or consent model.

3 pts
Need a hint?

Start with the row and choice that have the most distinctive purpose, then use that pair to narrow the rest.

Show another hint

For each remaining pair, explain the relationship in one sentence before selecting it.

03
ordering

Order the identity repair steps.

4 pts

Drag the rows or use the arrow buttons to reorder.

  1. 1 Remove and revoke the exposed client secret
  2. 2 Grant the managed identity the least required API access
  3. 3 Enable the managed identity on the Function
  4. 4 Test token acquisition and API authorization
Need a hint?

Identify the prerequisite that must happen first and the verification or documentation that belongs last.

Show another hint

For the middle steps, ask what must already be true before each action can safely happen.

Ready to check your work?Submit to finish this session and review your feedback. Extra practice is optional.
Persistent progress

Attempt history

Every submission is retained. Starting another attempt never replaces or unlocks the previous one.

No attempts yet

Your first submitted score and detailed answer review will appear here.

Community quality control

Question or answer look wrong?

Proposals and votes help staff prioritize review. They never change the scoring key automatically.

Full review queue
No community corrections yet

Be the first to flag unclear wording, an answer-key issue, or a source that needs another look.

Propose a correction