SC-300
Microsoft Certified: Identity and Access Administrator Associate
Entra ID deployment, conditional access, privileged access, identity governance.
› Quality score
Four-axis SecProve rubric, each 0–10. SecProve editorial assessment — each axis carries a written justification so you can push back on any single call without dismissing the whole score.
› Market signals
public, citable inputs to the recognition scoreMicrosoft doesn't publish per-cert counts; widely cited on Entra ID / IAM listings.
› Built for these roles
› Exam format
40–60 questions over 100 minutes (case studies + MCQ), English plus several other languages. Online proctored or test center.
24h wait after first fail; 14 days between subsequent attempts. Max 5 attempts per 12 months.
› Recertification
Free online renewal assessment available 6 months before expiry. Pass to extend by another year — no exam fee.
› NICE Framework work roles
The NIST NICE work-role IDs this cert maps to. NICCS lookup.
› Core domains covered
The 2 domains this cert is centrally about. Passing the exam demonstrates working knowledge of each.
AuthN/AuthZ, SSO, MFA, PAM, RBAC/ABAC, identity governance, FIDO2/passkeys, plus non-human identity: service accounts, workload identity, agent / plugin identities.
Zero trust principles, micro-segmentation, NIST SP 800-207, ZTNA, continuous verification, BeyondCorp.
› Also touched
Present in the blueprint but not the primary focus — you’ll be introduced but shouldn’t expect depth.
› Prerequisites
Intermediate Entra ID experience; familiarity with M365 admin and conditional access.
- Entra ID (Azure AD) identity lifecycle
- Conditional access and PIM
- Identity governance and lifecycle workflows
› Progression
requiredrecommendedWhere this cert fits in the typical learning path. Required edges are vendor-gated; recommended edges reflect de facto industry progression.
No vendor-gated prereqs.
No certs require this one.
› Study materials
Curated starting points. Not exhaustive — vet each against your learning style and the current exam version.
- Microsoft Learn SC-300 Learning Path (FREE) — Microsoft
- Exam Ref SC-300 Microsoft Identity and Access Administrator — Microsoft Press
- Microsoft Learn (free)
- John Savill SC-300 Study Cram (YouTube)
- MeasureUp Official SC-300 Practice Test
- Microsoft Learn SC-300 modules (free)
› Version & lifecycle
› Salary signal
Identity / IAM engineer (Azure AD / Entra ID), US, 3–5 years.
Robert Half Salary Guide + Glassdoor 'Identity Engineer' aggregations · 2024 · US base only · p25–p75 range
› How it compares
AZ-500 is the broader Azure-security cert; SC-300 is identity-specialized.
↔ Compare side-by-sideVendor-specific identity certs — pick by your IdP (Entra ID = SC-300, Okta = OCP).
↔ Compare side-by-side› Careers that commonly pursue this cert
Design and operate the identity fabric that every other control inherits. Federated identity, MFA/passkeys, PAM, identity governance, and the policy glue between them.
See this cert’s domains highlighted on the interactive map, or compare it against the rest of the catalog.