
An independent study guide for Microsoft Certified: Identity and Access Administrator Associate · by Tony Rough
Know which Microsoft Entra setting, role or licence fits the requirement, and why.
Due on Amazon in November 2026, in Kindle and paperback editions.
This independent study guide for the Microsoft Certified: Identity and Access Administrator Associate exam distils what SC-300 really expects you to understand into the comparisons, configuration choices, licence requirements and traps that identity decisions turn on, with short PowerShell and KQL examples throughout.
Twelve chapters, each readable on its own and together covering all four SC-300 skill areas:
Microsoft Entra changes quickly. This edition reflects Microsoft's documentation as of October 2026 and uses the current names: Microsoft Entra ID (formerly Azure Active Directory), Microsoft Entra Connect Sync (formerly Azure AD Connect), Microsoft Entra ID Protection (formerly Azure AD Identity Protection), PIM for Groups (formerly Privileged Access Groups) and target resources (formerly cloud apps or actions).
This book contains no exam questions. It explains the knowledge the exam expects, so you can answer questions you have never seen and apply the same judgement to real identity platforms.
Written by Tony Rough, a cloud architect with more than twenty years in IT infrastructure who holds the Azure Solutions Architect Expert, Azure Administrator and Azure Security Engineer certifications.
Part of the Ultra Transcenders series from Distilled Press. An independent publication, not affiliated with, sponsored by or endorsed by Microsoft Corporation.
Every skill area in Microsoft's SC-300 outline (as of October 28, 2026), and the chapters that cover it.
| Skill area | Weight | Chapters |
|---|---|---|
| Implement and manage user identities | 20–25% | 1, 2, 3, 4 |
| Implement authentication and access management | 25–30% | 5, 6, 7 |
| Plan and implement workload identities | 20–25% | 8, 9 |
| Plan and automate identity governance | 20–25% | 10, 11, 12 |
Plus an appendix glossary of 400+ terms, each linked to Microsoft Learn, with the same terms explained free online for print readers.



Some sections of the book, free to read online:
How the two hybrid sync engines differ in capability and limits, and where each sign-in method checks the password.
The three ways to switch on MFA across a tenant, compared by licence, flexibility and what each one enforces.
What a TAP is for, its lifetime and length settings, and which role can create one for which users.
Which events and location changes revoke a still-valid token, how long-lived CAE tokens behave, and where CAE falls back to one-hour tokens.
The difference between the two risk types, real-time versus offline detections, and which detections need P2.
How default and per-organisation settings control B2B collaboration and B2B direct connect, and when MFA and device claims are trusted.
How the two managed identity types differ in lifecycle and sharing, when to choose each, and the Azure roles needed to manage them.
Why every app has a global definition and a per-tenant instance, the three service principal types, and what happens when you change or delete one.