Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium

A multinational corporation uses several cloud-based applications, some hosted in Azure, others by third-party vendors. They want to enable their employees to use their existing corporate credentials to access all these applications without needing to create separate accounts for each. Which identity concept facilitates this seamless access across different service providers?

  1. AFederated Identity
  2. BSingle Sign-On (SSO)
  3. CRole-Based Access Control (RBAC)
  4. DManaged Identities
Show answer & explanation

Correct answer: A. Federated Identity

Federated Identity allows users to authenticate once with their home identity provider and then access multiple service providers (like different cloud applications) without re-authenticating, using a trust relationship between the providers.

Why the other options are wrong

  • B. SSO allows a single login for multiple applications within the same domain or ecosystem, but Federated Identity extends this across different, independent service providers.
  • C. RBAC defines permissions for resources but doesn't handle cross-domain authentication.
  • D. Managed Identities are for Azure resources to authenticate to Azure AD, not for human users accessing multiple cloud applications.

Federated Identity

Federated Identity is a system that allows users to use a single set of credentials (from an identity provider) to access multiple applications and services (from different service providers) across various security domains.

  • Establishes trust between identity and service providers.
  • Enables cross-domain authentication.
  • Users authenticate once with their home identity provider.

Memory trick: Federation links identity kingdoms.

More Describe the concepts of security, compliance, and identity questions