SC-300 logo
Focused certification exam prep
Start practice

SC-300 Exam Domains 2026: Complete Guide to All 4 Content Areas

TL;DR
  • SC-300 has exactly four domains; Domain 2 (authentication and access management) is weighted 25-30%.
  • Domains 1, 3, and 4 each carry 20-25%, so no single other domain can be safely skipped.
  • The exam runs 100 minutes inside a 120-minute appointment, delivered via Pearson VUE.
  • A passing result is 700 on a 1,000-point scale, not a fixed percentage of correct answers.

SC-300 Domain Overview: What Changed for 2026

Microsoft Certified: Identity and Access Administrator Associate is validated by a single exam, SC-300: Microsoft Identity and Access Administrator, delivered through Pearson VUE. Every version of the exam is organized around four content domains that Microsoft publishes in its official skills outline, and the version effective April 27, 2026 keeps that same four-domain structure. If you're mapping out a study plan, understanding exactly how these domains are weighted - and what each one actually tests - matters more than any generic exam-prep advice you'll find elsewhere.

This guide breaks down all four domains in detail, flags an unresolved discrepancy in how Microsoft itself describes the weighting of one domain, and gives you a domain-aware way to sequence your preparation. For a broader walkthrough of how to structure an entire study plan, see the SC-300 Study Guide 2026: How to Pass on Your First Attempt. If you want a distilled, printable version of the same domain facts, the SC-300 Cheat Sheet 2026: One-Page Review of Must-Know Facts is a useful companion.

Format Snapshot: SC-300 is a proctored, computer-based exam with an exam time of 100 minutes inside a standard 120-minute appointment. The exact total question count and the split between scored and unscored items are not disclosed by Microsoft, so treat any specific number you see elsewhere as an estimate, not a guarantee.

Domain 1: Implement and Manage User Identities (20-25%)

Domain 1 is the foundation of the exam and of the job itself. Before you can manage authentication, workload identities, or governance, you need to be fluent in how identities are created, synchronized, and administered inside Microsoft Entra ID (and, where relevant, hybrid environments touching Active Directory Domain Services).

Domain 1: Implement and Manage User Identities

Candidates must understand how to create and manage the full lifecycle of identity objects, and how identity data flows between on-premises AD DS and cloud directories.

  • Creating, configuring, and managing users and groups, including bulk operations
  • Managing licenses and administrative units
  • Implementing and managing hybrid identity, including directory synchronization concepts
  • Managing external/guest identities and B2B collaboration scenarios
  • Using PowerShell for identity-related administrative tasks

Because PowerShell and Azure familiarity are assumed rather than taught from scratch, Domain 1 questions often test whether you know which cmdlet or portal blade accomplishes a task, not just the underlying concept. If your background is heavier on Microsoft 365 admin work than on scripting, this is the domain where hands-on lab time pays off fastest. Candidates coming from help-desk or generalist IT roles frequently find this domain the most approachable starting point - for a broader discussion of who tends to find the exam easier or harder, see How Hard Is the SC-300 Exam? Complete Difficulty Guide 2026.

Domain 2: Implement Authentication and Access Management (25-30%)

Domain 2 is the largest single content area on SC-300 under Microsoft's official domain summary, and it's also the domain most closely tied to day-to-day security operations. This is where authentication methods, conditional access, and access management controls live.

Domain 2: Implement Authentication and Access Management

This domain covers how identities prove who they are and how access decisions get enforced across the tenant.

  • Planning and implementing multifactor authentication (MFA) and passwordless approaches
  • Managing and troubleshooting self-service password reset (SSPR)
  • Designing and implementing Conditional Access policies
  • Managing device registration and Microsoft Entra join scenarios
  • Configuring authentication methods policies and security defaults

Conditional Access is the single topic most likely to generate scenario-based questions in this domain - expect exam items that describe a business requirement (block legacy authentication, require compliant devices, enforce MFA for risky sign-ins) and ask you to pick the correct policy configuration rather than define a term. Because this domain touches both identity protection and access enforcement, it overlaps conceptually with parts of Domain 1 and Domain 4, so build your study notes to cross-reference rather than treat each domain as an isolated silo.

Key Takeaway

Spend proportionally more practice-question time on Conditional Access scenarios than on any other single topic - Domain 2's weighting alone justifies it, and its policy logic shows up indirectly in governance questions too.

Domain 3: Plan and Implement Workload Identities (20-25%)

Workload identities cover applications, services, and automated processes that need to authenticate - as distinct from human user identities in Domain 1. This domain is where app registrations, service principals, and managed identities live, and it tends to be the least familiar territory for candidates whose background is primarily on the Microsoft 365 admin side rather than the developer or infrastructure side.

Domain 3: Plan and Implement Workload Identities

Expect questions on securing non-human identities used by applications and automated services.

  • Registering and configuring applications in Microsoft Entra ID
  • Configuring app permissions, consent, and admin consent workflows
  • Implementing and managing managed identities for Azure resources
  • Planning and troubleshooting workload identity federation
  • Monitoring and securing service principal activity

If you haven't previously registered an app or configured a managed identity in the Azure portal, this domain deserves dedicated lab time rather than passive reading. The concepts around permissions and consent (delegated vs. application permissions, admin consent) are also commonly tested with distractor answers designed to catch candidates who confuse the two permission types.

Common Gap: Candidates who focus their study time heavily on end-user identity and Conditional Access sometimes underinvest in workload identities simply because it feels less "identity administrator" and more "developer." Domain 3's weighting means that gap can cost real points.

Domain 4: Plan and Automate Identity Governance (20-25%)

Governance is the domain most likely to trip up candidates who are strong on hands-on configuration but haven't spent time in Microsoft Entra ID's governance and entitlement features. This domain is about lifecycle policy and oversight rather than one-time setup.

Domain 4: Plan and Automate Identity Governance

This domain tests whether you can design processes that keep access appropriate over time, not just correct at the moment it's granted.

  • Planning and implementing entitlement management (access packages, catalogs)
  • Planning, implementing, and managing access reviews
  • Planning and implementing Privileged Identity Management (PIM) for Entra roles and Azure resources
  • Monitoring and maintaining Microsoft Entra ID using logs and reports
  • Configuring and managing entitlement lifecycle workflows

PIM is the topic to prioritize inside this domain - expect scenario questions about time-bound role activation, approval workflows, and justifications, since these mechanics come up repeatedly on the real exam format. Access reviews and entitlement management are the second-highest priority; understand not just how to configure them but why an organization would choose one governance control over another for a given compliance requirement.

DomainWeight (Official Summary)Core Focus
1. User Identities20-25%Creation, lifecycle, hybrid sync, guests
2. Authentication & Access Management25-30%MFA, SSPR, Conditional Access, device registration
3. Workload Identities20-25%App registrations, managed identities, federation
4. Identity Governance20-25%Entitlement management, access reviews, PIM

The Domain 2 Weighting Question, Explained

There's a detail worth flagging directly: Microsoft's own materials show a discrepancy in how Domain 2 is weighted. The official domain summary lists Implement Authentication and Access Management at 25-30%, making it the largest domain - but the detailed heading within the same outline shows 20-25% instead. This guide uses the official summary figure (25-30%) as the primary reference throughout, since that's the number Microsoft presents as the headline weighting, but candidates should be aware that Microsoft's source documents have not fully reconciled this internally.

Practically speaking, this doesn't change your study strategy much either way - whether Domain 2 sits at the top of a 25-30% range or the top of a 20-25% range, it's still tied for the most heavily weighted (or the single most heavily weighted) domain on the exam, and authentication/Conditional Access content deserves proportionally more of your practice time than any one of the other three domains individually.

How to Sequence Your Study Around the Domains

Rather than studying the domains in numerical order, sequence them by how much unfamiliar territory each one typically represents for a given background. A simple domain-aware sequence over four weeks looks like this:

Week 1

Domain 1: User Identities

  • Practice bulk user/group operations and license assignment in a trial tenant
  • Review hybrid identity and directory sync concepts
  • Drill PowerShell cmdlets for identity administration
Week 2

Domain 2: Authentication & Access Management

  • Build and test Conditional Access policies for multiple scenarios
  • Configure MFA, passwordless, and SSPR end to end
  • Work through device registration and join scenarios
Week 3

Domain 3: Workload Identities

  • Register apps and configure delegated vs. application permissions
  • Set up managed identities and test federation scenarios
  • Review service principal monitoring options
Week 4

Domain 4: Identity Governance + Full Review

  • Configure PIM role activation and approval workflows
  • Build an access package and run an access review
  • Take full-length practice exams covering all four domains

This sequencing front-loads the domain most candidates already have some exposure to (Domain 1) and ends with a full-domain review week using timed practice questions from a dedicated practice test platform, which is far more useful for catching domain-level weak spots than re-reading notes. If you'd rather see a more general week-by-week framework not tied to domain order, the SC-300 Study Guide 2026 covers that approach in more depth.

Before You Register: Confirm you meet the expected background - Microsoft doesn't require a degree, prior certification, or a specific number of training hours, but familiarity with Azure, Microsoft 365, AD DS, PowerShell, and KQL is assumed. Details on what actually qualifies as "ready" are covered in SC-300 Requirements 2026: Eligibility, Prerequisites & How to Qualify.

Using Domain Weighting to Prioritize Practice Questions

Once you understand the four domains, the next decision is how to allocate practice-question time. A reasonable approach is to weight your practice sessions roughly in line with exam weighting: slightly more repetitions on Domain 2 scenarios than on Domains 1, 3, or 4, but not so heavily skewed that you neglect the other three, since each still represents 20-25% of the exam individually - enough to swing a borderline result relative to the 700/1000 passing score. Running full-length practice sets through SC-300 Exam Prep's practice tests lets you see which domain you're weakest in before exam day, rather than guessing.

It's also worth understanding what "passing" actually means numerically before you start tracking practice scores against it - the scaled scoring model isn't a simple percentage-correct calculation. That distinction is explained fully in SC-300 Passing Score 2026: Exactly What You Need to Pass.

For candidates weighing whether the time investment across all four domains is worth it relative to career outcomes, it helps to look at who actually hires for this credential and what roles it supports - identity and access administrators, security engineers, and Microsoft 365/Entra specialists most commonly. That broader context, along with realistic earnings discussion, is covered in SC-300 Salary Guide 2026: Complete Earnings Analysis and Is the SC-300 Certification Worth It? Complete ROI Analysis 2026.

Frequently Asked Questions

How many domains does SC-300 have, and what are they called?

Four: Implement and Manage User Identities, Implement Authentication and Access Management, Plan and Implement Workload Identities, and Plan and Automate Identity Governance.

Which SC-300 domain has the highest weighting?

Implement Authentication and Access Management is listed at 25-30% in Microsoft's official domain summary, making it the largest under that source - though the detailed outline heading shows 20-25% instead, so treat it as tied for largest rather than definitively largest.

Is it safe to skip a domain that's only 20-25% weighted?

No. Domains 1, 3, and 4 each still represent up to a quarter of the exam individually, and with a 700/1000 passing score, gaps in any one domain can be enough to miss passing.

Does the SC-300 domain list change often?

Microsoft updates the outline periodically; the version referenced in this guide is the English outline effective April 27, 2026. Always check the current official outline before your test date.

Do I need hands-on lab experience for every domain?

Yes - the exam includes interactive, scenario-style components, and Domains 2, 3, and 4 in particular (Conditional Access, app registrations, PIM) are difficult to master through reading alone.

Ready to pass your SC-300 exam?

Put this into practice with free SC-300 questions across every exam domain.