Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium

A multinational corporation uses several cloud-based applications, some hosted in Azure, others by third-party providers. They want to provide a seamless login experience for their employees, where users can log in once with their corporate credentials and access all approved applications without re-entering their password. This also helps centralize user management. Which identity concept is being implemented?

  1. AFederated Identity
  2. BMulti-Factor Authentication (MFA)
  3. CConditional Access
  4. DSingle Sign-On (SSO)
Show answer & explanation

Correct answer: D. Single Sign-On (SSO)

Single Sign-On (SSO) allows users to authenticate once with a single set of credentials and gain access to multiple independent software systems without re-authenticating.

Why the other options are wrong

  • A. Federated Identity allows identities from one domain to be trusted by another, often a component of SSO across organizations, but SSO is the direct 'single login' experience.
  • B. MFA requires multiple authentication factors, but doesn't inherently provide a single login for multiple apps.
  • C. Conditional Access defines policies for access based on conditions, not the 'one login for all apps' experience.

Single Sign-On (SSO)

An authentication scheme that allows a user to log in with a single ID and password to gain access to multiple connected systems.

  • Improves user experience and productivity.
  • Reduces password fatigue.
  • Centralizes identity management.

Memory trick: SSO: one key opens all doors.

More Describe the concepts of security, compliance, and identity questions