Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium
A large enterprise uses various cloud services and on-premises applications. They want to ensure that all employees have appropriate access rights to resources based on their job roles, and that these rights are regularly reviewed and certified. Additionally, they need to manage the lifecycle of identities from onboarding to offboarding. Which identity concept best describes this comprehensive approach?
- AFederated Identity
- BSingle Sign-On (SSO)
- CDirectory Services
- DIdentity Governance
Show answer & explanationAnswer & explanation
Correct answer: D. Identity Governance
Identity Governance is a policy-based approach to managing all digital identities and their access rights across an organization. It includes managing the full identity lifecycle, access reviews, and role-based access to ensure compliance and security.
Why the other options are wrong
- A. Federated Identity allows identities from one domain to be used in another, which is a component but not the full scope described.
- B. SSO simplifies login for users but doesn't cover access rights management or lifecycle.
- C. Directory Services store identity information, but don't inherently manage access reviews or lifecycle.
Identity Governance
The framework of policies and processes that manages digital identities and access rights throughout their lifecycle to ensure compliance and security.
- Manages entire identity lifecycle (onboarding, changes, offboarding).
- Includes access reviews and certifications.
- Ensures 'least privilege' and compliance.
Memory trick: Governance Guides Identity's Journey