Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityHard

A consulting firm frequently collaborates with external partners on projects. They want to provide these partners with access to specific project-related resources in their Azure environment, but without creating full user accounts for them in their own corporate directory (Azure AD tenant). The partners should authenticate using their existing corporate identities from their own organizations. Which identity concept would facilitate this secure collaboration?

  1. APrivileged Identity Management (PIM)
  2. BFederated Identity
  3. CDevice Identity
  4. DManaged Identity
Show answer & explanation

Correct answer: B. Federated Identity

Federated identity allows users from one organization (identity provider) to authenticate and access resources in another organization (service provider) using their existing credentials, without needing to create new accounts in the service provider's directory. This perfectly matches the scenario where external partners use their 'existing corporate identities' to access resources in the consulting firm's tenant.

Why the other options are wrong

  • A. PIM manages temporary, elevated access for internal users, not external identity sharing.
  • C. Device Identity is about identifying and managing devices, not external user identities.
  • D. Managed Identity is for Azure resources to authenticate to other Azure services, not for external human users.

Federated Identity

A system that allows a user to access resources across different security domains using a single identity, typically managed by their home organization.

  • Enables Single Sign-On (SSO) across organizations.
  • Eliminates the need for external users to have multiple credentials.
  • Often implemented using standards like SAML, OAuth, or OpenID Connect.

Memory trick: Federated: Friends Exchange IDs.

More Describe the concepts of security, compliance, and identity questions