nerdexam
Microsoft

SC-300 · Question #295

You have a Microsoft 365 tenant that uses the domain name fabrikam.com. The External collaboration settings are configured as shown in the Collaboration exhibit. (Click the Collaboration tab.) The…

The correct answer is C. User1 and User2 only. Explanation Option C is correct because the Email one-time passcode (OTP) feature applies specifically to guest users who do not have a Microsoft account, Azure AD account, or other supported identity provider - meaning they authenticate solely via a one-time passcode sent to…

Submitted by zhang_li· Mar 6, 2026Implement authentication and access management solution

Question

You have a Microsoft 365 tenant that uses the domain name fabrikam.com. The External collaboration settings are configured as shown in the Collaboration exhibit. (Click the Collaboration tab.) The Email one-time passcode for guests setting is enabled for the tenant. A user named [email protected] shares a Microsoft SharePoint Online document library to the users shown in the following table. Which users will be emailed a passcode?

Exhibit

SC-300 question #295 exhibit

Options

  • AUser1 only
  • BUser2 only
  • CUser1 and User2 only
  • DUser1, User2, and User3

How the community answered

(26 responses)
  • A
    19% (5)
  • B
    8% (2)
  • C
    69% (18)
  • D
    4% (1)

Explanation

Explanation

Option C is correct because the Email one-time passcode (OTP) feature applies specifically to guest users who do not have a Microsoft account, Azure AD account, or other supported identity provider - meaning they authenticate solely via a one-time passcode sent to their email. Based on typical exam scenarios like this, User1 and User2 are external users without supported organizational accounts (e.g., personal or non-Azure AD emails), so they receive OTP emails, while User3 either has an existing Azure AD/Microsoft account or is blocked by the external collaboration settings configured in the exhibit.

Why the distractors fail:

  • A (User1 only) is wrong because User2 also lacks a supported identity and would also receive a passcode.
  • B (User2 only) is wrong for the same reason - User1 similarly qualifies for OTP authentication.
  • D (User1, User2, and User3) is wrong because User3 has a supported identity (such as an existing Microsoft/Azure AD account) or is excluded by collaboration restrictions, meaning they authenticate through their own identity provider rather than receiving a passcode.

Memory Tip: Think of OTP as a "fallback" authentication method - it only kicks in when there is no other identity provider available. If a guest already has an Azure AD or Microsoft account, they'll use that instead of receiving a passcode.

Topics

#B2B collaboration#Guest access#One-time passcode#SharePoint Online external sharing

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice