Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraHard
An organization wants to implement a solution where users can verify their identity using a decentralized, verifiable credential issued by a trusted third party, rather than relying solely on a centralized identity provider. This credential would then be used to access certain applications. Which Microsoft Entra capability supports this approach?
- AMicrosoft Entra Verified ID
- BMicrosoft Entra Conditional Access
- CMicrosoft Entra Identity Protection
- DMicrosoft Entra Privileged Identity Management
Show answer & explanationAnswer & explanation
Correct answer: A. Microsoft Entra Verified ID
Microsoft Entra Verified ID enables organizations to issue, hold, and verify decentralized digital identities (verifiable credentials). This allows users to present a verifiable credential from a trusted issuer to access resources, moving beyond traditional centralized identity models.
Why the other options are wrong
- B. Conditional Access enforces policies based on centralized identity signals, not decentralized credentials.
- C. Identity Protection detects risks in centralized identities, not decentralized credentials.
- D. PIM manages privileged access within a centralized directory, not verifiable credentials.
Microsoft Entra Verified ID
A decentralized identity solution that enables organizations to issue, hold, and verify verifiable credentials. It allows individuals to own and control their digital identities.
- Based on open standards for decentralized identifiers (DIDs) and verifiable credentials (VCs).
- Increases trust, privacy, and security by empowering users with self-sovereign identity.
- Used for various scenarios like secure onboarding, remote identity verification, and access to resources.
- Reduces reliance on centralized identity providers and data stores.
Memory trick: Entra's got IDs for all, from central hubs to decentralized calls.