nerdexam
Microsoft

SC-300 · Question #44

Drag and Drop Question You have an on-premises Microsoft Exchange organization that uses an SMTP address space of contoso.com. You discover that users use their email address for self-service…

The correct answer is Create a self-signed user account in the Azure AD tenant.; Sign in to the Microsoft 365 admin center.; Respond to the Become the admin message.; Create a TXT record in the contoso.com DNS zone. To perform an IT Pro takeover of an unmanaged Azure AD tenant created by self-service sign-up, you must first create a self-signed user account in that tenant (using the contoso.com domain), then sign in to the Microsoft 365 admin center with that account, add the contoso.com…

Submitted by olafpl· Mar 6, 2026Manage Azure Active Directory identities and governance - specifically performing an IT Pro (internal) admin takeover of an unmanaged Azure AD tenant created through self-service sign-up, aligning with Microsoft 365 identity management and hybrid identity scenarios.

Question

Drag and Drop Question You have an on-premises Microsoft Exchange organization that uses an SMTP address space of contoso.com. You discover that users use their email address for self-service sign-up to Microsoft 365 services. You need to gain global administrator privileges to the Azure Active Directory (Azure AD) tenant that contains the self-signed users. Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order. Answer:

Answer Area

Drag items

Sign in to the Microsoft 365 admin center.Create a self-signed user account in the Azure AD tenant.From the Microsoft 365 admin center, add the domain name.Respond to the Become the admin message.From the Microsoft 365 admin center, remove the domain name.Create a TXT record in the contoso.com DNS zone.

Correct arrangement

  • Create a self-signed user account in the Azure AD tenant.
  • Sign in to the Microsoft 365 admin center.
  • Respond to the Become the admin message.
  • Create a TXT record in the contoso.com DNS zone.

Explanation

To perform an IT Pro takeover of an unmanaged Azure AD tenant created by self-service sign-up, you must first create a self-signed user account in that tenant (using the contoso.com domain), then sign in to the Microsoft 365 admin center with that account, add the contoso.com domain name to trigger the takeover process, and finally respond to the 'Become the admin' verification message (which requires proving domain ownership via a DNS TXT record). This sequence follows Microsoft's internal domain takeover process, where domain ownership verification grants global administrator rights over the unmanaged tenant.

Topics

#Azure AD Tenant Takeover#Self-Service Sign-Up#Microsoft 365 Administration#Unmanaged Tenant Management

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice