Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium
A global enterprise needs to manage access for its 100,000 employees across various cloud services and on-premises applications. They require a centralized system to store user attributes, groups, and device information, which can then be used by different applications for authentication and authorization. Which identity concept is most relevant here?
- APrivileged Identity Management (PIM)
- BIdentity Protection
- CDirectory Services
- DCertificate-Based Authentication
Show answer & explanationAnswer & explanation
Correct answer: C. Directory Services
Directory Services, such as Azure Active Directory or traditional Active Directory, provide a centralized repository for storing and managing user, group, and device information. This information is then used by applications to authenticate users and determine their authorization levels, perfectly aligning with the scenario's requirements for central management and use by various applications.
Why the other options are wrong
- A. PIM focuses on managing temporary, just-in-time access for privileged roles, not general identity storage.
- B. Identity Protection detects and remediates identity-based risks, not primarily a storage and management system.
- D. Certificate-Based Authentication is an authentication method, not a system for managing all identity attributes.
Directory Services
A network service that stores information about network resources and provides access to that information for users and applications.
- Centralized repository for identities (users, groups, devices).
- Enables authentication and authorization for applications.
- Examples include Active Directory and Azure Active Directory.
Memory trick: Directory Services is the master contact list for everyone and everything in your digital world.