SC-300 domain - 25% of the exam

Implement and Manage User Identities

Implement and Manage User Identities is 25% of the Microsoft Identity and Access Administrator (SC-300) (SC-300) exam. These are the objectives it covers, each with practice questions and worked explanations.

Objectives in this domain

Sample question from this domain

Free sampleImplement and Manage User Identitieshard

A company has three disconnected Active Directory forests acquired through mergers, each managed by a separate IT team, and wants to synchronise all of them to one Microsoft Entra tenant. The architecture team requires a lightweight, Microsoft-managed provisioning service that avoids deploying a full synchronisation server per forest. Which synchronisation technology meets this requirement?

  • ADeploy Microsoft Entra Cloud Sync with a lightweight provisioning agent in each forest, because the service is Microsoft-managed and supports disconnected multi-forest topologies. Correct
  • BDeploy Microsoft Entra Connect Sync on a server in each forest, because only the full sync engine can read objects from multiple disconnected Active Directory forests.
  • CDeploy a single Microsoft Entra Connect Sync server with a custom rule set that reaches across all three disconnected forests over the public internet.
  • DDeploy Microsoft Entra Connect Health agents in each forest, because the health service can provision identities from disconnected forests into the tenant.
Microsoft Entra Cloud Sync uses lightweight Microsoft-managed agents and is the preferred choice for synchronising disconnected multi-forest Active Directory environments. Cloud Sync places a lightweight provisioning agent in each forest and performs the synchronisation logic in a Microsoft-managed cloud service, so disconnected forests with no trust between them are supported without a full sync server per forest. Connect Sync requires a server and network reachability, and Connect Health only monitors.

Why A is correct: Cloud Sync uses lightweight agents that report to a Microsoft-managed cloud service and natively supports disconnected forests, matching the lightweight multi-forest requirement exactly.

Why B is wrong: Connect Sync can serve multiple forests, but it requires a full synchronisation server and is not the lightweight Microsoft-managed agent service the architecture team asked for.

Why C is wrong: Disconnected forests have no shared trust path for one Connect Sync server to reach them, and reaching across forests over the internet is not a supported synchronisation design.

Why D is wrong: Connect Health only monitors the health and performance of identity synchronisation; it does not provision or synchronise any directory objects into the tenant.

Other domains in this exam

See also the SC-300 cert hub, the study guide, and the cheat sheet.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.