CompTIA SecurityX (CAS-005)Security EngineeringMedium
A security architect is designing an identity and access management (IAM) solution for a multi-cloud environment. The solution needs to provide centralized authentication and authorization for applications deployed across different cloud providers and on-premises infrastructure. The primary goal is to ensure consistent identity governance and streamline user provisioning and deprovisioning. Which IAM concept is BEST represented by this design?
- AHardware-Enforced Identity
- BIdentity Federation
- CDecentralized Identity
- DLocal Authentication
Show answer & explanationAnswer & explanation
Correct answer: B. Identity Federation
Identity federation is the process of linking a user's identity across multiple, disparate identity management systems. It enables single sign-on (SSO) and consistent access control across different domains (e.g., multiple cloud providers, on-premises), streamlining user management and ensuring centralized governance.
Why the other options are wrong
- A. Hardware-enforced identity refers to using hardware tokens or modules for identity verification, not the overarching concept of managing identities across disparate systems.
- C. Decentralized Identity (DID) focuses on user-centric control of identity data, which is different from centralizing authentication/authorization across multiple platforms.
- D. Local authentication means each application or system manages its own user identities, which is contrary to the goal of centralized authentication and streamlined provisioning across multiple environments.
Identity Federation
A system that allows users to use the same digital identity across multiple, disparate identity management systems, enabling single sign-on (SSO) and centralized identity governance.
- Links identities across different domains
- Enables Single Sign-On (SSO)
- Centralizes identity management and governance
Memory trick: Identity Federation: One identity, many domains, no more pain!