SC-300 · Implement and manage user identities

Configure and manage a Microsoft Entra tenant

Objective 1.1 · Configure and manage a Microsoft Entra tenant.

3 learning blocksNext: about 12 minutes8 key conceptsPreview · not independently reviewed
ProgressNot started0/3 blocks learned and checked
Learn

Continue your lesson

Trace the identity, credential, token, assignment, policy decision, resource, and audit record for each access request.

0/3blocks complete
Block 1 of 3

Compare Company branding · Custom domain name

Current · 12 min
Learn with your providerOpen a provider lesson below, then return to try four related questions.
Optional concept notes

Custom domain name

Lets tenant identities use an organization's verified DNS domain instead of the initial tenant name.

Company branding

Customizes supported Microsoft Entra sign-in pages with organizational visual elements and text.

Your sessionabout 12 minutes

Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.

Block 2 of 3

Compare Administrative unit · Microsoft Entra built-in role · Microsoft Entra custom role · Effective role permissions

18 min
Optional concept notes

Administrative unit

Scopes selected directory administration to a defined set of users groups or devices.

Microsoft Entra built-in role

Grants a fixed Microsoft-defined set of directory permissions for a common administrative task.

Microsoft Entra custom role

Combines supported directory permissions into an organization-defined administrative role.

Effective role permissions

Show the combined directory permissions an administrator receives through current assignments.

Your sessionabout 18 minutes

Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.

Block 3 of 3

Compare Tenant properties · Tenant user group and device settings

12 min
Optional concept notes

Tenant properties

Store directory-wide details such as display name contacts and privacy statement links.

Tenant user group and device settings

Control directory-wide defaults and allowed behavior for users groups and devices.

Your sessionabout 12 minutes

Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.

No setup required

Practice the reasoning here

Use a fictional tenant. Draw one access path, apply least privilege, test an exception, and name the logs that would confirm the result.

  1. State the expected result before changing or testing anything.
  2. Name the observation, command, log, or report that would confirm it.
  3. Explain why the closest alternative does not fit the same requirement.
Your next milestone

Check the whole objective

This unlocks objective 1.1 for recall. The latest checkpoint needs 70% or higher; a lower result puts the lesson back near the front of your timeline.

One lesson at a time.Your block checks prepare you for this milestone. A score of 70% or higher advances the course; finishing a practice session completes your daily goal.
Official blueprint references
Official Identity and Access Administrator certification overviewMicrosoft ↗Official SC-300 study guideMicrosoft ↗