Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium
A global enterprise needs to manage access for its 100,000 employees across various cloud services and on-premises applications. They want a centralized system that stores user identities and attributes, allowing these services to authenticate users against a single, authoritative source. Which identity service best fits this requirement?
- ADirectory Services
- BFederated Identity
- CMulti-Factor Authentication (MFA)
- DConditional Access
Show answer & explanationAnswer & explanation
Correct answer: A. Directory Services
Directory Services, such as Azure Active Directory, provide a centralized repository for user identities and attributes, enabling authentication and authorization across multiple applications and services from a single source.
Why the other options are wrong
- B. Federated Identity allows users to use credentials from one identity provider to access resources in another, but a Directory Service is the core component that stores these identities.
- C. MFA adds an extra layer of security to authentication but doesn't provide centralized identity management for a large enterprise.
- D. Conditional Access defines policies for accessing resources based on conditions but relies on an underlying identity service.
Directory Services
Directory Services are centralized, hierarchical databases that store information about network resources, such as users, groups, computers, and services, making them discoverable and manageable.
- Central repository for identity information.
- Enables authentication and authorization.
- Examples include Active Directory and Azure Active Directory.
Memory trick: Directories organize identities like a phone book for access.