Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium
A financial institution is implementing a new security system. They need to ensure that when a user logs into their internal banking application, their identity is verified by a trusted third-party identity provider, rather than the banking application itself. This allows users to use their existing corporate credentials without creating new ones for each application. Which identity concept does this scenario describe?
- ASingle Sign-On (SSO)
- BFederated Identity
- CPrivileged Identity Management (PIM)
- DMulti-Factor Authentication (MFA)
Show answer & explanationAnswer & explanation
Correct answer: B. Federated Identity
Federated Identity enables identity information to be shared and trusted across different security domains, allowing users to authenticate with one identity provider (e.g., their corporate network) and gain access to resources in another domain (e.g., the banking application) without re-authenticating.
Why the other options are wrong
- A. SSO allows access to multiple apps with one login, but doesn't necessarily involve a *third-party* identity provider across *different security domains*.
- C. PIM manages temporary, elevated access for administrative roles, which is not the core concept here.
- D. MFA adds extra verification steps, not the concept of trusting external identity providers.
Federated Identity
A system that allows users to authenticate with one identity provider and gain access to resources managed by other service providers without needing to create separate credentials for each service. It establishes trust between disparate identity systems.
- Enables single sign-on across different organizations.
- Relies on trusted identity providers.
- Simplifies user access and reduces credential sprawl.
Memory trick: Federated Identity: Your identity is like a passport, accepted across different countries (domains).