Microsoft SC-300 External Identities and Cross-Tenant Collaboration Practice Test
Topic 03 covers external identities and cross-tenant collaboration for the Microsoft Certified: Identity and Access Administrator Associate certification. These original practice questions apply the verified SC-300 objectives to practical decisions and troubleshooting. Select one answer unless a fixed number is requested. For broader preparation, visit the SC-300 Exam Dumps page. Each option includes an explanation of the relevant behavior and scenario constraints.
Question 1
A workforce tenant allows invitations only from users assigned to the specific administrator roles permitted by its guest-invite policy. Partner-domain and cross-tenant policies already permit the invitations. A procurement employee must invite partners but must not receive general user-management authority. Which change meets the requirement?
Correct Answer: A
Correct Answer
Answer A is correct because Guest Inviter is explicitly permitted under this policy and supplies invitation authority without the broader user-management capabilities of User Administrator.
Incorrect Answers
Answer B is incorrect because group ownership is not the specific invitation-role exception allowed by the configured policy. It does not establish the required tenant invitation authority.
Answer C is incorrect because this would enable invitations but also grants broader user administration. It exceeds the explicitly limited procurement responsibility.
Answer D is incorrect because domain eligibility and inviter authority are separate requirements. An allowed destination domain does not authorize this employee to issue invitations.
Answer E is incorrect because this broadens invitation eligibility across the tenant rather than delegating it to the designated employee.
Question 2
Security requires B2B guests to see only their own directory-object properties and memberships. A guest must still use an application already shared with them. Which setting addresses the directory-visibility requirement without treating it as an application access revocation?
Correct Answer: E
Correct Answer
Answer E is correct because this is the most restrictive documented directory-visibility setting. It controls directory reads; application authorization remains a separate consideration.
Incorrect Answers
Answer A is incorrect because that would prevent the required application access rather than narrowly limiting what guests can inspect in the directory.
Answer B is incorrect because invitation eligibility controls onboarding. It does not narrow the directory visibility of an already existing guest.
Answer C is incorrect because this expands default visibility and conflicts with the own-object-only requirement. The scenario requires the narrower Microsoft Entra behavior described in the stem.
Answer D is incorrect because this revokes the business access that must remain. It does not implement the requested directory-visibility boundary.
Question 3
A tenant blocks invitations from partner.example after two partners were invited. One already redeemed the invitation; the other’s invitation is still pending. No account or access-policy change accompanies the new domain restriction. Which TWO outcomes follow from the documented invitation-list behavior? Choose TWO.
Correct Answers: C, D
Correct Answers
Answer C is correct because Microsoft applies the configured restriction to a pending invitation when the user attempts redemption. An earlier invitation does not guarantee later redemption.
Answer D is correct because the allow/block list does not apply retroactively to users who already redeemed. Continued access must be assessed through account and resource-access controls.
Incorrect Answers
Answer A is incorrect because the list does not automatically revoke existing redeemed-user access. Group membership is a separate administrative state.
Answer B is incorrect because the invitation policy is not a directory deletion operation. The described change does not remove those objects.
Answer E is incorrect because the documentation specifically states that pending redemption can fail after the domain becomes blocked.
Answer F is incorrect because the policy also affects attempts to redeem pending invitations. Limiting it to message transport understates its documented effect.
Question 4
SharePoint B2B integration is enabled. A partner tenant is allowed in organization-specific cross-tenant access settings, but native SharePoint invitations to that partner still fail. The resource tenant’s external collaboration allow list excludes the partner’s email domain. What should the administrator correct?
Correct Answer: C
Correct Answer
Answer C is correct because Microsoft documents this additional requirement for native SharePoint and OneDrive sharing with B2B integration. Cross-tenant permission alone does not override the invitation-domain restriction.
Incorrect Answers
Answer A is incorrect because changing the local relationship classification does not fix the blocked invitation domain. It also changes permissions unnecessarily.
Answer B is incorrect because the invitation is being issued to external users for resource-tenant collaboration. The identified domain exclusion remains regardless of that unrelated outbound change.
Answer D is incorrect because MFA trust affects whether authentication evidence is accepted. It does not make an excluded invitation domain pass the collaboration allow list.
Answer E is incorrect because a partner outbound permission does not remove the resource tenant’s external-collaboration invitation restriction. The identified domain block would still apply.
Question 5
A supplier sends a roster of external employees who will keep using their own supported identity providers. An operator proposes bulk creating internal members with initial passwords. The approved onboarding process instead requires B2B invitations and the supplier’s existing credentials. Which workflow should be used?
Correct Answer: B
Correct Answer
Answer B is correct because this creates the intended B2B invitation flow. Bulk internal-user creation would establish a different account and credential model.
Incorrect Answers
Answer A is incorrect because this creates local workforce credentials rather than federating the external identities. It conflicts with the approved authentication model.
Answer C is incorrect because licensing is not an identity onboarding operation. It does not create a B2B invitation or bind the supplier’s authentication identity.
Answer D is incorrect because UserType describes the relationship to the organization. Changing it does not replace newly created local credentials with the intended external B2B identity binding.
Answer E is incorrect because a contact entry is not an invited B2B user identity. It does not establish the required sign-in and redemption flow.
Question 6
An invitation CSV contains the correct external email addresses, but its Redirection URL points to an obsolete portal. Guests successfully accept their invitations and then land on that obsolete page. The replacement portal’s access assignments are already correct. What should be corrected for subsequent invitations?
Correct Answer: A
Correct Answer
Answer A is correct because this field controls where the user is forwarded after acceptance. The observed timing isolates the problem from authentication and app assignment.
Incorrect Answers
Answer B is incorrect because the guests successfully authenticate and accept. An issuer change would not correct the post-acceptance destination specified in the invitation.
Answer C is incorrect because authorization is already correct. More permissions do not replace the obsolete URL in the invitation flow.
Answer D is incorrect because redemption order selects the authentication provider. The guests already authenticate successfully; it does not replace the post-acceptance destination URL.
Answer E is incorrect because relationship classification does not define the invitation’s redirect destination. It would introduce an unrelated permissions change.
Question 7
A bulk invitation job succeeds, and its guest objects appear in the directory. Several objects still show Pending acceptance, and automatic redemption is not enabled. The onboarding dashboard reports all suppliers as having completed their first-time consent. Which TWO changes would make the report defensible? Choose TWO.
Correct Answers: A, D
Correct Answers
Answer A is correct because successful invitation processing proves that the invitations were created. Pending acceptance shows that the user-dependent redemption step is not yet complete.
Answer D is correct because completion must be tied to the actual user step being measured. Directory-object existence alone is insufficient for a claim about first-time consent.
Incorrect Answers
Answer B is incorrect because pending redemption is compatible with successful invitation creation. Deletion is not justified by that status alone.
Answer C is incorrect because the job does not perform each external user’s interactive authentication and consent. Its success has a narrower meaning.
Answer E is incorrect because an application assignment can exist before the guest redeems. It establishes authorization intent, not completion of the first-time user action.
Answer F is incorrect because the guest object and its UPN can exist before redemption. That identifier does not establish completion of the user’s acceptance step.
Question 8
A B2B guest remains Pending acceptance and reports losing the invitation email. The guest’s email address and intended identity provider have not changed. The team wants to preserve the existing guest object. What should support do first?
Correct Answer: E
Correct Answer
Answer E is correct because the administration workflow exposes Resend invitation for pending acceptance. It restores the delivery path without replacing the existing object.
Incorrect Answers
Answer A is incorrect because the requested identity information has not changed. Creating a second object is unnecessary and conflicts with preserving the existing guest lifecycle.
Answer B is incorrect because UserType describes the relationship to the organization. It does not perform invitation acceptance or authenticate the guest.
Answer C is incorrect because this changes both the object and the authentication model. It is unnecessary when the only issue is the missing invitation message.
Answer D is incorrect because there is no reported provider change or authentication failure. Reconfiguring trust is not a targeted response to a missing email.
Question 9
A partner user’s home account was deleted and recreated. The resource tenant must bind the guest to the replacement identity while preserving its object ID, group memberships and application assignments. Which supported operation addresses that requirement?
Correct Answer: C
Correct Answer
Answer C is correct because Microsoft supports this operation for a recreated home account. It allows a new identity binding while retaining the existing resource-tenant object’s ID and assignments.
Incorrect Answers
Answer A is incorrect because a display-name edit does not rebind the guest’s external authentication identity. The scenario requires the narrower Microsoft Entra behavior described in the stem.
Answer B is incorrect because a recreated guest is not guaranteed to retain the original object identity and assignments. This discards the preservation benefit explicitly required.
Answer D is incorrect because an application assignment changes authorization, not the external identity binding that failed after home-account recreation.
Answer E is incorrect because the guest authenticates using the external identity provider. A local password-reset approach does not perform the required external identity rebinding.
Question 10
An administrator changes a B2B collaborator’s UserType from Guest to Member because the partner is now part of a larger corporate organization. The Identities property still points to the external provider. The user continues to authenticate there. Which interpretation is correct?
Correct Answer: D
Correct Answer
Answer D is correct because UserType and Identities are independent. Editing the former does not automatically move credentials or authentication into the resource tenant.
Incorrect Answers
Answer A is incorrect because relationship classification and role assignments are distinct properties. The update does not by itself assign an administrative role.
Answer B is incorrect because authentication can remain external after the relationship classification changes. The observed sign-in is compatible with the new UserType.
Answer C is incorrect because external members are supported. Member is not a universal statement about credential storage or authentication location.
Answer E is incorrect because Microsoft documents external members. Deleting a valid external account would unnecessarily disrupt the intended collaboration.
Question 11
A redeemed B2B guest cannot authenticate because the password for their home organization’s account has expired. The resource tenant’s guest object uses ExternalAzureAD and has no local credential. What is the appropriate recovery path?
Correct Answer: A
Correct Answer
Answer A is correct because the home identity provider owns the credential used for this guest’s authentication. Resource-tenant authorization changes cannot repair an expired home password.
Incorrect Answers
Answer B is incorrect because a resource directory role does not transfer administration of the partner’s password store. The credential still belongs to the home provider.
Answer C is incorrect because a redemption reset can rebind identities, but it does not change the password state at the home provider. The identified credential problem remains.
Answer D is incorrect because the scenario explicitly has no local credential for this external authentication relationship. This is not the home provider’s password-reset mechanism.
Answer E is incorrect because local account enablement and home password validity are different conditions. Toggling the guest cannot make the expired home password valid.
Question 12
An app-only automation tries to reset redemption for a guest that has a directory role assignment. The API does not permit the reset for that target. The role assignment is legitimate and must remain. Which response follows the documented operation boundary?
Correct Answer: A
Correct Answer
Answer A is correct because Microsoft documents that app-only redemption reset cannot be used when the target has role assignments. A supported delegated path addresses the operation without removing required access.
Incorrect Answers
Answer B is incorrect because a duplicate identity does not rebind the existing role-bearing guest. It also abandons continuity of the target object.
Answer C is incorrect because a broader application grant does not remove the documented app-only target restriction. The invocation model remains unsupported for this target.
Answer D is incorrect because UserType is not the documented condition causing the restriction. The target still has a directory role assignment.
Answer E is incorrect because the scenario requires that legitimate assignment to remain. Permanently removing it would violate the operational constraint.
Question 13
A user from HomeTenant accesses an application hosted in ResourceTenant. ResourceTenant permits the user’s organization through inbound B2B collaboration settings, and the application assignment is valid. HomeTenant’s outbound policy blocks access to ResourceTenant. Which policy change is needed for the approved access path?
Correct Answer: B
Correct Answer
Answer B is correct because the home tenant governs its users’ outbound access to external organizations. The resource tenant’s inbound allowance cannot override the home tenant’s block.
Incorrect Answers
Answer A is incorrect because the application assignment is already valid. An additional assignment cannot override the stated outbound block.
Answer C is incorrect because the requested journey is outbound from HomeTenant. Its inbound setting concerns external users accessing HomeTenant’s resources.
Answer D is incorrect because automatic redemption addresses the consent experience. It does not override an explicit cross-tenant access denial.
Answer E is incorrect because that direction governs ResourceTenant users accessing HomeTenant resources. It does not authorize the HomeTenant user’s outbound journey.
Question 14
A resource tenant blocks external access by default. An administrator adds a partner to Organizational settings and expects the act of adding it to allow one partner group to one internal application. The new organization’s settings still show Inherited from default. What should the administrator configure?
Correct Answer: C
Correct Answer
Answer C is correct because adding an organization initially inherits defaults. An organization-specific inbound configuration is needed to create the intended narrow exception.
Incorrect Answers
Answer A is incorrect because trust determines which authentication claims can be accepted. It does not supply the missing inbound access allowance.
Answer B is incorrect because both relevant user and resource scopes must permit the journey. A user-only exception is incomplete while the intended application remains blocked.
Answer D is incorrect because this would create a much broader exception than the one partner, group and application specified.
Answer E is incorrect because the requested path involves partner users entering the resource tenant. An outbound exception in the resource tenant addresses the opposite direction.
Question 15
A resource tenant requires MFA for ordinary B2B collaborators. A trusted partner’s users already satisfy MFA in their home Entra tenant, and the resource tenant wants to accept that evidence while keeping its MFA requirement. These users are not using GDAP. Which configuration addresses the requirement?
Correct Answer: D
Correct Answer
Answer D is correct because this allows the resource tenant’s policy to accept the partner’s home-tenant MFA claim. It preserves the MFA requirement while changing which evidence can satisfy it.
Incorrect Answers
Answer A is incorrect because the partner users are entering the resource tenant. The relevant decision is the resource tenant’s inbound trust of the partner’s claims.
Answer B is incorrect because device compliance and MFA are different claim categories. Trusting the device does not enable acceptance of the home MFA claim.
Answer C is incorrect because automatic redemption suppresses a consent prompt in a supported bilateral setup. It is not the setting that establishes MFA-claim trust.
Answer E is incorrect because that removes the stated MFA requirement rather than accepting verified home-tenant evidence under it.
Question 16
A resource application’s Conditional Access policy requires a compliant device. Partner users arrive with valid home-tenant compliant-device claims, but the resource tenant does not trust those claims. Security approves trusting compliance from this partner only. Which configuration directly addresses the missing trust?
Correct Answer: B
Correct Answer
Answer B is correct because this is the documented setting for accepting the partner’s compliance claims. Organization-specific scope limits trust to the approved partner.
Incorrect Answers
Answer A is incorrect because this would weaken the required access condition. The approved change is to trust the partner’s evidence, not eliminate the requirement.
Answer C is incorrect because this broadens the trust relationship beyond the organization approved by security. A partner-specific setting is sufficient.
Answer D is incorrect because hybrid join and compliance are distinct claims. Trusting hybrid join alone does not satisfy a policy that specifically requires compliance.
Answer E is incorrect because MFA establishes a different aspect of authentication. It does not make a home-tenant compliant-device claim trusted.
Question 17
An organization is configuring one-way synchronization of internal user accounts from SourceTenant to TargetTenant within the same Microsoft cloud. Licensing and administrator permissions are ready, but no synchronization configuration or consent settings exist. Which THREE setup actions belong to the documented user-synchronization workflow? Choose THREE.
Correct Answers: A, B, D
Correct Answers
Answer A is correct because the target must permit the source organization to synchronize users into it. Source-side configuration alone does not grant that inbound permission.
Answer B is correct because the source controls which of its identities are provisioned into the target. Creating the source-side configuration establishes the intended direction.
Answer D is correct because the documented setup requires this bilateral relationship setting. Configuring only one side does not satisfy the workflow’s automatic-consent requirements.
Incorrect Answers
Answer C is incorrect because the permission is required where users will be created. Granting it in the source does not authorize provisioning into the target.
Answer E is incorrect because that creates the opposite direction and does not implement SourceTenant-to-TargetTenant provisioning. The scenario requires the narrower Microsoft Entra behavior described in the stem.
Answer F is incorrect because direct connect and cross-tenant user synchronization are distinct mechanisms. Direct connect alone does not create the requested synchronized user population.
Question 18
A cross-tenant synchronization administrator changes the default matching attribute to an email-based attribute. The validation log reports schemaInvalid and identifies the matching-attribute change as unsupported. The documented matching attribute, alternativeSecurityIds using AltSecIdFromNetId, was previously unchanged. Which correction addresses this failure?
Correct Answer: C
Correct Answer
Answer C is correct because Microsoft documents that this matching attribute cannot be changed or supplemented. The error follows the unsupported matching-schema modification.
Incorrect Answers
Answer A is incorrect because recreating the job does not change its supported schema. Carrying forward the rejected matching changes reproduces the defect.
Answer B is incorrect because the documentation also excludes adding matching attributes. Expanding the unsupported configuration does not resolve schemaInvalid.
Answer D is incorrect because normalization might help supported value comparisons, but it does not make this service-controlled matching field replaceable. The schema restriction remains.
Answer E is incorrect because editing target data does not make the unsupported matching-schema definition valid. The service rejects the configuration before such matching can solve it.
Question 19
A source tenant’s cross-tenant synchronization configuration includes internal employees and an externally authenticated B2B guest. The team expects the guest to be copied onward simply because it changed the guest’s UserType to Member. The external identity provider is unchanged. What should the administrator conclude?
Correct Answer: D
Correct Answer
Answer D is correct because cross-tenant synchronization supports internal users, not external users. UserType and identity origin are independent, so the label change does not establish eligibility.
Incorrect Answers
Answer A is incorrect because group assignment selects candidate objects. It does not change their identity-provider relationship or supported source type.
Answer B is incorrect because Microsoft distinguishes external members from internal users. UserType alone does not prove the source authentication origin.
Answer C is incorrect because another assignment or job does not change the user’s external origin. The unsupported source identity type remains.
Answer E is incorrect because a target relationship label does not convert the source’s authentication origin. Eligibility must be established for the source identity itself.
Question 20
A cross-tenant synchronization relationship is being retired. Scope is Sync only assigned users and groups, and all previously provisioned users must be deprovisioned from the target before the relationship is removed. Which TWO actions support that sequence? Choose TWO.
Correct Answers: A, C
Correct Answers
Answer A is correct because this removes the configured provisioning population and triggers deprovisioning in subsequent cycles. It is different from merely severing the relationship.
Answer C is correct because the service needs the relationship to process the removals. Microsoft explicitly requires retaining this permission until the cleanup finishes.
Incorrect Answers
Answer B is incorrect because submission is not proof of completed deprovisioning. Removing permission prematurely can interrupt remaining cleanup work.
Answer D is incorrect because preventing the service from operating can stop the requested cleanup from propagating. It reverses the needed sequence.
Answer E is incorrect because that change does not remove the provisioning scope or instruct the service to deprovision the users.
Answer F is incorrect because severing the relationship does not itself change previously managed target users. This can leave the population in place.
Question 21
A partner uses a WS-Fed identity provider. Its users have addresses in partner.example, but its passive authentication endpoint is https://login.partner-host.example/adfs, outside that email domain. The federation setup requires proof linking the domains. What should the partner configure?
Correct Answer: E
Correct Answer
Answer E is correct because Microsoft requires this DNS association when the passive endpoint is outside the target domain. It links the partner’s email domain to the separate authentication endpoint.
Incorrect Answers
Answer A is incorrect because the resource tenant does not need to take ownership of the partner’s email namespace. This would not provide the partner-side federation association.
Answer B is incorrect because mail routing is not the documented federation endpoint proof. Changing MX would affect email without supplying the required TXT association.
Answer C is incorrect because the issuer must identify the actual identity provider. Changing it to mimic the email domain does not provide the documented endpoint-domain proof and can introduce a trust mismatch.
Answer D is incorrect because metadata supplies provider configuration and signing information. It is not a substitute for the documented DNS association when the passive endpoint is outside the email domain.
Question 22
A partner configures a new SAML federation in 2026. Its IdP expects the old global issuer value urn:federation:MicrosoftOnline, but the request from Entra uses a tenant-specific issuer endpoint. Sign-in fails at the partner’s relying-party validation. What should be corrected?
Correct Answer: B
Correct Answer
Answer B is correct because Microsoft recommends the tenanted endpoint for new federations and documents failure when a new setup expects the old global issuer. The validation mismatch is at the partner IdP.
Incorrect Answers
Answer A is incorrect because NameID formatting concerns the represented identity. It does not correct the relying party’s mismatch with the tenant-specific request issuer.
Answer C is incorrect because response destination and request issuer are different trust settings. Adjusting the destination does not resolve the identified issuer validation failure.
Answer D is incorrect because a new signing certificate does not make the old global issuer expectation match the tenant-specific request. The diagnosed trust setting still needs correction.
Answer E is incorrect because the local relationship classification does not change the SAML request issuer expected by the external IdP.
Question 23
A domain-based external SAML federation receives a correctly signed assertion but rejects it with AADSTS5000819, indicating that the email claim is missing or does not match the external realm. The setup is not using a domainless federation feature. What should the administrator verify first?
Correct Answer: B
Correct Answer
Answer B is correct because the error specifically identifies the identity claim or its domain alignment. A valid signature alone does not prove that the assertion contains the required identity information.
Incorrect Answers
Answer A is incorrect because the assertion’s signature is already verified. Changing the certificate does not address the stated missing or mismatched email claim.
Answer C is incorrect because navigation after redemption is not the source of the assertion’s email claim. The IdP claim configuration still needs verification.
Answer D is incorrect because rebinding the guest does not add a missing claim or align its domain in the external assertion. The IdP configuration would continue producing the same failure.
Answer E is incorrect because signature validation establishes integrity and issuer trust, not that every required claim and domain condition is satisfied.
Question 24
A partner rotates its SAML/WS-Fed signing certificate before the old certificate expires. The resource tenant has a metadata URL configured, but sign-ins fail after the early rotation. The partner confirms the new certificate. What should the administrator do under the documented renewal behavior?
Correct Answer: D
Correct Answer
Answer D is correct because Microsoft documents that early rotation can require a manual update even when a metadata URL exists. The confirmed new certificate addresses the changed trust material.
Incorrect Answers
Answer A is incorrect because the documentation explicitly distinguishes early rotation from automatic renewal at expiration. Waiting prolongs the present outage.
Answer B is incorrect because removing metadata does not make the old certificate validate assertions signed by the new key. It also removes future automatic-renewal assistance.
Answer C is incorrect because audience validation and signature-key validation are distinct. Altering the audience does not allow the old configured key to validate assertions signed after rotation.
Answer E is incorrect because redemption rebinding does not make the configured old signing key validate the partner’s new signatures. The trust configuration needs correction.
Popular posts
Recent Posts
