Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityHard
A large enterprise uses various cloud services and on-premises applications. They want to ensure that access permissions for employees are automatically provisioned and de-provisioned based on their employment status and role changes within the company. This automation should also extend to integrating with their Human Resources (HR) system. Which identity management capability is most relevant here?
- ASelf-service password reset
- BPrivileged Identity Management (PIM)
- CConditional Access
- DIdentity Governance
Show answer & explanationAnswer & explanation
Correct answer: D. Identity Governance
Identity Governance focuses on managing the identity lifecycle, including provisioning, de-provisioning, and access reviews, to ensure that users have appropriate access based on their roles and compliance requirements. Its integration with HR systems for automated lifecycle management is a key aspect.
Why the other options are wrong
- A. Self-service password reset allows users to reset their own passwords, which is a feature but not the core capability described.
- B. PIM manages elevated access for critical roles, which is a subset of identity management but doesn't cover general user lifecycle management.
- C. Conditional Access evaluates conditions at login to grant or deny access, which is a control mechanism, not a lifecycle management capability.
Identity Governance
The framework that ensures the right individuals have the right access to the right resources at the right time, managing the full identity lifecycle from provisioning to de-provisioning, often integrating with HR systems.
- Automates user provisioning and de-provisioning.
- Ensures compliance with access policies.
- Includes access reviews and separation of duties.
Memory trick: Governance: The boss managing all identity rules.