Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityEasy
A global organization is implementing a new security policy that requires all users to provide two different forms of verification before accessing sensitive internal applications. Which security concept is this organization primarily implementing?
- ALeast Privilege
- BSingle Sign-On (SSO)
- CConditional Access
- DMulti-Factor Authentication (MFA)
Show answer & explanationAnswer & explanation
Correct answer: D. Multi-Factor Authentication (MFA)
Multi-Factor Authentication (MFA) requires users to provide two or more verification factors to gain access to a resource, significantly increasing security by making it harder for unauthorized users to gain access.
Why the other options are wrong
- A. Least Privilege focuses on granting users only the necessary permissions, not on the number of authentication factors.
- B. Single Sign-On (SSO) allows users to access multiple applications with one set of credentials, which is different from requiring multiple factors for a single login.
- C. Conditional Access defines access policies based on conditions, but the core concept of requiring two forms of verification is MFA.
Multi-Factor Authentication (MFA)
A security system that requires users to provide two or more verification factors to gain access to a resource.
- Enhances security by requiring multiple proofs of identity.
- Combines different types of authentication factors (e.g., something you know, something you have, something you are).
- Significantly reduces the risk of unauthorized access.
Memory trick: Many Factors Secure Access