- SC-300 Domain Overview: What Changed for 2026
- Domain 1: Implement and Manage User Identities (20-25%)
- Domain 2: Implement Authentication and Access Management (25-30%)
- Domain 3: Plan and Implement Workload Identities (20-25%)
- Domain 4: Plan and Automate Identity Governance (20-25%)
- The Domain 2 Weighting Question, Explained
- How to Sequence Your Study Around the Domains
- Frequently Asked Questions
- SC-300 has exactly four domains; Domain 2 (authentication and access management) is weighted 25-30%.
- Domains 1, 3, and 4 each carry 20-25%, so no single other domain can be safely skipped.
- The exam runs 100 minutes inside a 120-minute appointment, delivered via Pearson VUE.
- A passing result is 700 on a 1,000-point scale, not a fixed percentage of correct answers.
SC-300 Domain Overview: What Changed for 2026
Microsoft Certified: Identity and Access Administrator Associate is validated by a single exam, SC-300: Microsoft Identity and Access Administrator, delivered through Pearson VUE. Every version of the exam is organized around four content domains that Microsoft publishes in its official skills outline, and the version effective April 27, 2026 keeps that same four-domain structure. If you're mapping out a study plan, understanding exactly how these domains are weighted - and what each one actually tests - matters more than any generic exam-prep advice you'll find elsewhere.
This guide breaks down all four domains in detail, flags an unresolved discrepancy in how Microsoft itself describes the weighting of one domain, and gives you a domain-aware way to sequence your preparation. For a broader walkthrough of how to structure an entire study plan, see the SC-300 Study Guide 2026: How to Pass on Your First Attempt. If you want a distilled, printable version of the same domain facts, the SC-300 Cheat Sheet 2026: One-Page Review of Must-Know Facts is a useful companion.
Domain 1: Implement and Manage User Identities (20-25%)
Domain 1 is the foundation of the exam and of the job itself. Before you can manage authentication, workload identities, or governance, you need to be fluent in how identities are created, synchronized, and administered inside Microsoft Entra ID (and, where relevant, hybrid environments touching Active Directory Domain Services).
Domain 1: Implement and Manage User Identities
Candidates must understand how to create and manage the full lifecycle of identity objects, and how identity data flows between on-premises AD DS and cloud directories.
- Creating, configuring, and managing users and groups, including bulk operations
- Managing licenses and administrative units
- Implementing and managing hybrid identity, including directory synchronization concepts
- Managing external/guest identities and B2B collaboration scenarios
- Using PowerShell for identity-related administrative tasks
Because PowerShell and Azure familiarity are assumed rather than taught from scratch, Domain 1 questions often test whether you know which cmdlet or portal blade accomplishes a task, not just the underlying concept. If your background is heavier on Microsoft 365 admin work than on scripting, this is the domain where hands-on lab time pays off fastest. Candidates coming from help-desk or generalist IT roles frequently find this domain the most approachable starting point - for a broader discussion of who tends to find the exam easier or harder, see How Hard Is the SC-300 Exam? Complete Difficulty Guide 2026.
Domain 2: Implement Authentication and Access Management (25-30%)
Domain 2 is the largest single content area on SC-300 under Microsoft's official domain summary, and it's also the domain most closely tied to day-to-day security operations. This is where authentication methods, conditional access, and access management controls live.
Domain 2: Implement Authentication and Access Management
This domain covers how identities prove who they are and how access decisions get enforced across the tenant.
- Planning and implementing multifactor authentication (MFA) and passwordless approaches
- Managing and troubleshooting self-service password reset (SSPR)
- Designing and implementing Conditional Access policies
- Managing device registration and Microsoft Entra join scenarios
- Configuring authentication methods policies and security defaults
Conditional Access is the single topic most likely to generate scenario-based questions in this domain - expect exam items that describe a business requirement (block legacy authentication, require compliant devices, enforce MFA for risky sign-ins) and ask you to pick the correct policy configuration rather than define a term. Because this domain touches both identity protection and access enforcement, it overlaps conceptually with parts of Domain 1 and Domain 4, so build your study notes to cross-reference rather than treat each domain as an isolated silo.
Key Takeaway
Spend proportionally more practice-question time on Conditional Access scenarios than on any other single topic - Domain 2's weighting alone justifies it, and its policy logic shows up indirectly in governance questions too.
Domain 3: Plan and Implement Workload Identities (20-25%)
Workload identities cover applications, services, and automated processes that need to authenticate - as distinct from human user identities in Domain 1. This domain is where app registrations, service principals, and managed identities live, and it tends to be the least familiar territory for candidates whose background is primarily on the Microsoft 365 admin side rather than the developer or infrastructure side.
Domain 3: Plan and Implement Workload Identities
Expect questions on securing non-human identities used by applications and automated services.
- Registering and configuring applications in Microsoft Entra ID
- Configuring app permissions, consent, and admin consent workflows
- Implementing and managing managed identities for Azure resources
- Planning and troubleshooting workload identity federation
- Monitoring and securing service principal activity
If you haven't previously registered an app or configured a managed identity in the Azure portal, this domain deserves dedicated lab time rather than passive reading. The concepts around permissions and consent (delegated vs. application permissions, admin consent) are also commonly tested with distractor answers designed to catch candidates who confuse the two permission types.
Domain 4: Plan and Automate Identity Governance (20-25%)
Governance is the domain most likely to trip up candidates who are strong on hands-on configuration but haven't spent time in Microsoft Entra ID's governance and entitlement features. This domain is about lifecycle policy and oversight rather than one-time setup.
Domain 4: Plan and Automate Identity Governance
This domain tests whether you can design processes that keep access appropriate over time, not just correct at the moment it's granted.
- Planning and implementing entitlement management (access packages, catalogs)
- Planning, implementing, and managing access reviews
- Planning and implementing Privileged Identity Management (PIM) for Entra roles and Azure resources
- Monitoring and maintaining Microsoft Entra ID using logs and reports
- Configuring and managing entitlement lifecycle workflows
PIM is the topic to prioritize inside this domain - expect scenario questions about time-bound role activation, approval workflows, and justifications, since these mechanics come up repeatedly on the real exam format. Access reviews and entitlement management are the second-highest priority; understand not just how to configure them but why an organization would choose one governance control over another for a given compliance requirement.
| Domain | Weight (Official Summary) | Core Focus |
|---|---|---|
| 1. User Identities | 20-25% | Creation, lifecycle, hybrid sync, guests |
| 2. Authentication & Access Management | 25-30% | MFA, SSPR, Conditional Access, device registration |
| 3. Workload Identities | 20-25% | App registrations, managed identities, federation |
| 4. Identity Governance | 20-25% | Entitlement management, access reviews, PIM |
The Domain 2 Weighting Question, Explained
There's a detail worth flagging directly: Microsoft's own materials show a discrepancy in how Domain 2 is weighted. The official domain summary lists Implement Authentication and Access Management at 25-30%, making it the largest domain - but the detailed heading within the same outline shows 20-25% instead. This guide uses the official summary figure (25-30%) as the primary reference throughout, since that's the number Microsoft presents as the headline weighting, but candidates should be aware that Microsoft's source documents have not fully reconciled this internally.
Practically speaking, this doesn't change your study strategy much either way - whether Domain 2 sits at the top of a 25-30% range or the top of a 20-25% range, it's still tied for the most heavily weighted (or the single most heavily weighted) domain on the exam, and authentication/Conditional Access content deserves proportionally more of your practice time than any one of the other three domains individually.
How to Sequence Your Study Around the Domains
Rather than studying the domains in numerical order, sequence them by how much unfamiliar territory each one typically represents for a given background. A simple domain-aware sequence over four weeks looks like this:
Domain 1: User Identities
- Practice bulk user/group operations and license assignment in a trial tenant
- Review hybrid identity and directory sync concepts
- Drill PowerShell cmdlets for identity administration
Domain 2: Authentication & Access Management
- Build and test Conditional Access policies for multiple scenarios
- Configure MFA, passwordless, and SSPR end to end
- Work through device registration and join scenarios
Domain 3: Workload Identities
- Register apps and configure delegated vs. application permissions
- Set up managed identities and test federation scenarios
- Review service principal monitoring options
Domain 4: Identity Governance + Full Review
- Configure PIM role activation and approval workflows
- Build an access package and run an access review
- Take full-length practice exams covering all four domains
This sequencing front-loads the domain most candidates already have some exposure to (Domain 1) and ends with a full-domain review week using timed practice questions from a dedicated practice test platform, which is far more useful for catching domain-level weak spots than re-reading notes. If you'd rather see a more general week-by-week framework not tied to domain order, the SC-300 Study Guide 2026 covers that approach in more depth.
Using Domain Weighting to Prioritize Practice Questions
Once you understand the four domains, the next decision is how to allocate practice-question time. A reasonable approach is to weight your practice sessions roughly in line with exam weighting: slightly more repetitions on Domain 2 scenarios than on Domains 1, 3, or 4, but not so heavily skewed that you neglect the other three, since each still represents 20-25% of the exam individually - enough to swing a borderline result relative to the 700/1000 passing score. Running full-length practice sets through SC-300 Exam Prep's practice tests lets you see which domain you're weakest in before exam day, rather than guessing.
It's also worth understanding what "passing" actually means numerically before you start tracking practice scores against it - the scaled scoring model isn't a simple percentage-correct calculation. That distinction is explained fully in SC-300 Passing Score 2026: Exactly What You Need to Pass.
For candidates weighing whether the time investment across all four domains is worth it relative to career outcomes, it helps to look at who actually hires for this credential and what roles it supports - identity and access administrators, security engineers, and Microsoft 365/Entra specialists most commonly. That broader context, along with realistic earnings discussion, is covered in SC-300 Salary Guide 2026: Complete Earnings Analysis and Is the SC-300 Certification Worth It? Complete ROI Analysis 2026.
Frequently Asked Questions
Four: Implement and Manage User Identities, Implement Authentication and Access Management, Plan and Implement Workload Identities, and Plan and Automate Identity Governance.
Implement Authentication and Access Management is listed at 25-30% in Microsoft's official domain summary, making it the largest under that source - though the detailed outline heading shows 20-25% instead, so treat it as tied for largest rather than definitively largest.
No. Domains 1, 3, and 4 each still represent up to a quarter of the exam individually, and with a 700/1000 passing score, gaps in any one domain can be enough to miss passing.
Microsoft updates the outline periodically; the version referenced in this guide is the English outline effective April 27, 2026. Always check the current official outline before your test date.
Yes - the exam includes interactive, scenario-style components, and Domains 2, 3, and 4 in particular (Conditional Access, app registrations, PIM) are difficult to master through reading alone.
Ready to pass your SC-300 exam?
Put this into practice with free SC-300 questions across every exam domain.