Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium

A global financial institution needs to implement a security solution that allows its employees to access various internal applications and cloud services using a single set of credentials. This solution must also simplify user management and improve the overall user experience. Which identity concept best fits these requirements?

  1. AMulti-Factor Authentication (MFA)
  2. BSingle Sign-On (SSO)
  3. CFederated Identity
  4. DRole-Based Access Control (RBAC)
Show answer & explanation

Correct answer: B. Single Sign-On (SSO)

Single Sign-On (SSO) allows users to authenticate once and gain access to multiple independent software systems without re-entering credentials, which directly addresses the need for a single set of credentials across various applications and services, simplifying user management and improving user experience.

Why the other options are wrong

  • A. MFA adds an extra layer of security but doesn't simplify access to multiple applications with a single login.
  • C. Federated Identity allows identities to be shared across different security domains, but SSO is the specific mechanism for single login across applications within or across domains when trust is established.
  • D. RBAC manages permissions based on roles but doesn't enable single credential access across disparate systems.

Single Sign-On (SSO)

An authentication scheme that allows a user to log in with a single ID and password to gain access to multiple related but independent software systems.

  • Simplifies user experience by reducing login prompts.
  • Improves security by reducing password fatigue.
  • Requires a central identity provider.

Memory trick: SSO: One key opens many doors.

More Describe the concepts of security, compliance, and identity questions