Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium
A global enterprise needs to manage access for its 100,000 employees across various cloud services and on-premises applications. They require a centralized system to store user identities, authenticate users, and manage access rights efficiently. Which identity concept is essential for this requirement?
- AFederated Identity
- BDirectory Services
- CMulti-Factor Authentication (MFA)
- DConditional Access
Show answer & explanationAnswer & explanation
Correct answer: B. Directory Services
Directory Services provide the centralized repository for user identities and attributes, crucial for managing a large user base across diverse applications and enabling authentication and authorization.
Why the other options are wrong
- A. Federated Identity allows identities from one system to be trusted by another, but doesn't provide the centralized repository itself.
- C. MFA adds a layer of security to authentication but doesn't provide the core identity management system.
- D. Conditional Access uses identity information to make access decisions but relies on an underlying directory service.
Directory Services
A centralized, hierarchical database that stores information about network resources and users, enabling efficient management and access control.
- Examples include Active Directory and Azure Active Directory.
- Provides a single source of truth for user identities.
- Facilitates authentication and authorization across an organization's resources.
Memory trick: Directory is the phone book of users