Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium

A university has multiple disparate systems for student registration, library access, and course management. They want to implement a solution where students can use a single set of credentials (username and password) to access all these different systems without re-entering their credentials for each one. Which identity solution would best achieve this goal?

  1. AJust-in-Time (JIT) Access
  2. BRole-Based Access Control (RBAC)
  3. CMulti-Factor Authentication (MFA)
  4. DSingle Sign-On (SSO)
Show answer & explanation

Correct answer: D. Single Sign-On (SSO)

Single Sign-On (SSO) is an authentication scheme that allows a user to log in with a single ID and password to gain access to multiple related, yet independent, software systems. The scenario directly describes this functionality: 'single set of credentials... to access all these different systems without re-entering'.

Why the other options are wrong

  • A. JIT access grants temporary, elevated permissions only when needed, which is unrelated to accessing multiple systems with one credential set.
  • B. RBAC manages what a user can do, not how they log into multiple systems.
  • C. MFA strengthens authentication by requiring multiple factors, but doesn't inherently enable access to multiple systems with one login.

Single Sign-On (SSO)

An authentication process that allows a user to access multiple independent software systems with a single set of login credentials.

  • Improves user experience by reducing login fatigue.
  • Can improve security by centralizing credential management.
  • Commonly implemented with protocols like SAML or OAuth.

Memory trick: SSO: Single Key, Many Doors Open.

More Describe the concepts of security, compliance, and identity questions