Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
SC-300 Case Studies: Identity and Access Admin Exam Prep

SC-300 Case Studies: Identity and Access Admin Exam Prep

10 full-length case studies, 80 exam-style questions, and pattern-based reasoning for the SC-300 exam
Created byjh Pickering
Last updated 7/2026
English

What you'll learn

  • Work through 10 full-length SC-300 case studies covering all four exam domains (User Identities, Authentication & Access, Workload Identities, and Identity Gov)
  • Answer 80 exam-style multiple-choice questions and understand exactly why each correct answer is right and every distractor is wrong
  • Recognize the 50 recurring patterns that repeat across Microsoft identity and access exam scenarios — from PIM break-glass rules to Global Secure Access
  • Reason through Business, Security, and Technical Requirements together to select the correct solution in multi-constraint scenarios, like real exams test you
  • Build the case-study reasoning skill the SC-300 exam's scenario-based questions demand, rather than relying on isolated fact recall
  • Work through realistic existing-environment scenarios

Course content

1 section10 lectures6h 51m total length
  • Case Study 1: Fabrikam Healthcare -- Identity Governance, PIM & Shared Devices40:26

    Walk through the full Fabrikam Healthcare case study — a hybrid hospital network dealing with shared ward workstations, ungoverned Global Admin access, and a partner merger that needs proper external identity governance. You'll see the complete company background, existing environment, and Business/Security/Technical Requirements very similar to style of the real exam, followed by 8 exam-style questions covering PIM break-glass configuration, phishing-resistant MFA, hybrid SSPR with writeback, and dynamic group design.

    As well as some tips and tricks that I wish I knew before attempting the exam

  • Case Study 2: Contoso Financial -- Risk Policies, PIM Hours & Insider Risk47:12

    Work through the Contoso Financial Services case study — an investment bank responding to a credential-theft incident, a stale contractor account, and a lack of automated risk response. This case study leans into Conditional Access risk-based policies, PIM activation hour limits, insider risk integration with Purview, and the classic "check your existing licence before buying more" trap that shows up repeatedly on the real exam.

  • Case Study 3: Alpine University -- B2B, Cross-Tenant Sync & Entitlement Mgmt41:24

    Work through the Alpine University case study — a research university juggling three very different types of external relationships: permanent government research partners, project-based corporate sponsors, and public online students. This case study is built specifically to test whether you can tell apart the three external identity mechanisms Microsoft loves to blur together on the exam — B2B invitation, Cross-Tenant Synchronization, and Entitlement Management access packages — plus Terms of Use enforcement via Conditional Access and Access Review configuration for guest governance at scale.

  • Case Study 4: Pacific Government -- GSA, Phishing-Resistant MFA & CBA33:40

    Work through the Pacific Government Agency case study — a government department replacing a flat-network VPN with Zero Trust Network Access after repeated lateral-movement incidents. This case study is heavily focused on Global Secure Access, new content that trips up a lot of SC-300 candidates: Private Access vs. Internet Access, the connector's outbound-only architecture, Remote Network Connectivity for branch offices, and the Compliant Network Conditional Access condition. It also drills the classic exam trap of number matching versus genuine phishing-resistant MFA, and the difference between single-factor and multi-factor certificate-based authentication.

  • Case Study 5: Northwind Retail -- Dynamic Groups, SSPR & Privilege Creep42:38

    Work through the Northwind Retail Group case study — a 28,000-employee retail chain with 35% annual turnover, drowning in stale accounts and manual identity processes their 8-person IT team can't keep up with. This case study is built around one core exam lesson: at scale, manual solutions always fail. You'll drill dynamic group design, group-based licensing, Workday SCIM provisioning, SSPR with Conditional Access enforcement, and the classic exam trap where dynamic groups alone don't actually prevent privilege creep — Lifecycle Workflows with a remove-before-assign sequence are what the exam wants instead.

  • Case Study 6: Southland Manufacturing -- Hybrid Identity & AD FS Migration39:43

    Work through the Southland Manufacturing case study — a 12,000-employee industrial manufacturer stuck on an unreliable AD FS farm that's caused three separate Microsoft 365 outages. This case study is entirely about hybrid identity migration done correctly: why Password Hash Sync beats Pass-Through Authentication for both resilience and Identity Protection, how Staged Rollout lets you pilot cloud authentication without converting the domain, Seamless SSO for shared factory workstations, and the exact migration sequence the exam expects — PHS, then Seamless SSO, then Staged Rollout, then app migration, then domain conversion, and AD FS decommissioning last.

  • Case Study 7: TailwindTraders -- Managed IDs, SCIM, App Proxy & Delegated vs App49:50

    Work through the Tailwind Traders case study — an e-commerce platform with 67 apps hardcoding client secrets in source code and 34 apps carrying excessive API permissions. This case study covers the full breadth of Domain 3, the most conceptually distinct part of SC-300: the Managed Identity hierarchy (Azure-hosted workloads always use Managed Identity first, Key Vault second, never a hardcoded secret), the delegated-versus-application permission distinction that trips up almost everyone the first time, SCIM provisioning for SaaS gallery apps, when Application Proxy is the right call over Global Secure Access, and where Workload Identities Premium licensing fits into service principal risk monitoring.

  • Case Study 8: BlueSky Media -- Copilot Governance, Labels & Verified ID31:42

    Work through the BlueSky Media Group case study — a media company that deployed Microsoft 365 Copilot to all staff with zero governance, and paid for it within two weeks: a junior employee summarised a confidential acquisition document via inherited SharePoint access, a contractor leaked a talent contract through Copilot output, and 340 staff were caught using personal ChatGPT accounts. This is genuinely new SC-300 exam content, built around one core principle: Copilot inherits the user's permissions — fix the permissions, not Copilot. You'll drill Purview sensitivity labels for content protection, Conditional Access for blocking guest Copilot access, GSA Internet Access for shadow AI, and Microsoft Entra Verified ID for freelance identity verification without creating internal accounts.

  • Case Study 9: Woodgrove Health -- Access Reviews at Scale & KQL Monitoring40:00

    Work through the Woodgrove Health Network case study — a hospital system that hasn't run a single access review in 18 months, with 2,800 clinical accounts of uncertain legitimacy and 340 external partner users on direct group membership instead of proper entitlement packages. This case study drills Access Review configuration at genuine scale (reviewer type, fallback reviewers, auto-apply logic), Connected Organizations and access packages for healthcare partner governance, GSA Internet Access for clinical device web filtering, the correct order for Identity Secure Score remediation, and writing actual KQL queries against SignInLogs and AuditLogs to detect impossible travel and off-hours privileged activation.

  • SC-300 Case Study 10: The Final Boss — All 4 Domains Integrated44:27

    WELCOME TO THE FINAL BOSS (Case Study #10)


    In this ultimate capstone case study, we tackle Meridian Group—an 18,000-employee global enterprise facing a 90-day CISO mandate following three major security incidents.


    Unlike previous single-domain studies, Case Study #10 integrates ALL FOUR SC-300 exam domains simultaneously into a realistic, high-stakes enterprise scenario.


    ---


    WHAT YOU WILL LEARN & MASTER IN THIS VIDEO:


    • Domain 1 (Identity & Access): Cross-Tenant Synchronization for acquisitions (TechVentures) and automated Leaver Lifecycle Workflows triggered on employeeLeaveDateTime.

    • Domain 2 (Authentication & Access Control): Eliminating MFA fatigue, blocking high-risk sign-ins via modern Conditional Access, and securing remote workers with Global Secure Access (GSA).

    • Domain 3 (Workload Identities & Governance): Transitioning 23 compromised Azure apps from hardcoded credentials to Managed Identities and Azure Key Vault.

    • Domain 4 (Privileged Access & M365 Governance): Configuring PIM for Global Admins, protecting break-glass accounts, governing Copilot with Purview sensitivity labels, and blocking shadow IT via GSA Internet Access.


    ---

    KEY EXAM PATTERNS COVERED:


    1. Cross-Tenant Sync = Internal/Acquisition member appearance at scale.

    2. Lifecycle Workflows = employeeLeaveDateTime trigger for automated 1-hour offboarding.

    3. Legacy ID Protection Portal = WRONG when technical requirements specify modern CA policies.

    4. Workload Identity Rule = Azure-hosted → Managed Identity; External/Unsupported → Key Vault.

    5. PIM Break-Glass Standard = EXACTLY 2, permanent, .onmicrosoft.com, excluded from ALL CA.

    6. Copilot Protection = Guest blocking via CA Policy + Document protection via Purview Sensitivity Labels.


    ---


    PRACTICE RESOURCES:

    Be sure to pause the video at each question to attempt the scenario yourself before reviewing the GIDEON answer breakdown and pattern explanation!

Requirements

  • A basic understanding of Microsoft Entra ID (formerly Azure AD) is helpful but not required — key concepts are explained as they come up in each case study
  • No prior experience with case-study or scenario-based exam questions is necessary; the format is introduced progressively across the course
  • General familiarity with IT security fundamentals is useful if you're completely new to identity and access management, but not mandatory
  • Access to a free Microsoft Entra tenant is helpful if you want to follow along hands-on, but is not required to complete the course
  • Some foundational security knowledge is recommended before starting — CompTIA Security+, Microsoft's SC-900 (Security, Compliance, and Identity Fundamentals), or equivalent hands-on experience
  • Basic familiarity with Microsoft Entra ID concepts is expected; this course applies that knowledge to realistic scenarios rather than teaching it from scratch

Description

This course covers the newest SC-300 content, updated for 2026 — including Global Secure Access (Private Access, Internet Access, and the Compliant Network Conditional Access condition), Microsoft Copilot governance and sensitivity labels, Verified ID, and the latest identity governance patterns Microsoft has added to the exam. If you've seen older SC-300 prep material that doesn't mention GSA or Copilot, it's already out of date — this course was built against the current exam.

Master the SC-300 Exam Through 10 Full-Length, Exam-Realistic Case Studies

  • Work through 10 complete case studies modeled on real SC-300 exam scenarios — denser and more challenging than what you'll actually face on exam day

  • Answer 80 exam-style multiple-choice questions with full reasoning for every correct answer and every distractor

  • Learn to recognize the 50 recurring patterns that repeat across Microsoft's identity and access exam scenarios

  • Build the case-study reasoning skill the real SC-300 exam demands — not just isolated fact recall

  • Study Business, Security, and Technical Requirements the way they actually interact in a real scenario, not as disconnected flashcards

Most SC-300 prep courses give you scattered practice questions. This course gives you something closer to the real exam experience: full company scenarios, existing environments, and layered requirements you have to reason through — the same format the actual exam uses, but with more volume and depth than you'll see on exam day itself. If you can work through these ten scenarios confidently, the real exam's case studies will feel manageable by comparison.

Each case study includes:

  • A realistic company scenario with a full existing-environment breakdown

  • Business, Security, and Technical Requirements exactly as they'd appear on the real exam

  • 8 scored questions with detailed explanations for every answer choice

  • Cross-referenced patterns that show up again and again across Microsoft's identity exams

I'm an IAM consultant currently completing my own Microsoft SC-300 certification, and I built this course using the exact case study method I'm using to prepare for it myself. I already hold Microsoft Certified: Security, Compliance, and Identity Fundamentals and Azure Fundamentals, and I run GIDEON, a free open-source identity exam-prep tool with real hands-on lab experience across Entra ID, Conditional Access, and Privileged Identity Management

Who this course is for:

  • IT professionals studying for the Microsoft SC-300 (Identity and Access Administrator) certification who want exam-realistic case study practice beyond basic flashcard-style questions
  • IAM practitioners and analysts who want to sharpen the scenario-based reasoning skills used in real identity governance work
  • Security professionals moving into or already working in Microsoft identity administration roles
  • Candidates who've sat SC-300 before, found the case-study questions were their weak point, and want deeper, more realistic practice before retaking it
  • Consultants and administrators preparing to implement Conditional Access, PIM, Global Secure Access, or Identity Governance in a real Microsoft Entra environment