Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityHard
A global enterprise needs to manage the identities and access rights for its employees, contractors, and partners across various cloud services (e.g., Azure, Salesforce, Workday) and on-premises applications. They require a centralized system to provision, de-provision, and manage access consistently across all these disparate systems. Which identity concept provides this overarching capability?
- AIdentity Governance
- BMulti-Factor Authentication (MFA)
- CRole-Based Access Control (RBAC)
- DSingle Sign-On (SSO)
Show answer & explanationAnswer & explanation
Correct answer: A. Identity Governance
Identity Governance encompasses the processes and technologies for managing the lifecycle of digital identities and their access rights across an organization's systems. This includes provisioning, de-provisioning, access reviews, and entitlement management, which matches the need for consistent management across disparate systems.
Why the other options are wrong
- B. MFA is an authentication method, not a system for managing access rights across multiple platforms.
- C. RBAC is a method for assigning permissions based on roles within a single system or a set of integrated systems, not an overarching management concept for disparate systems.
- D. SSO allows users to log in once to access multiple applications, but doesn't cover the full lifecycle management of identities and access rights.
Identity Governance
A framework that ensures the right people have the right access to the right resources at the right time, managing the full lifecycle of identities and their access rights.
- Includes access reviews, entitlement management, and lifecycle management.
- Crucial for compliance and security.
- Often implemented with tools like Azure AD Identity Governance.
Memory trick: Identity Governance: 'The conductor of the identity orchestra, ensuring everyone plays their part correctly.'