Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityHard
A multinational corporation uses several cloud-based applications, some hosted in Azure, others by third-party providers. They need a system where employees can use their corporate credentials to access all these applications without re-entering their username and password for each. Which identity concept is best suited for this scenario?
- AMulti-Factor Authentication (MFA)
- BRole-Based Access Control (RBAC)
- CIdentity Governance
- DFederated Identity
Show answer & explanationAnswer & explanation
Correct answer: D. Federated Identity
Federated Identity allows users to authenticate once with their primary identity provider (e.g., corporate directory) and then access multiple services from different providers without re-authenticating, which is ideal for a multinational corporation using various cloud applications.
Why the other options are wrong
- A. MFA adds security but doesn't solve the problem of multiple logins across different providers.
- B. RBAC manages permissions within a single system, not authentication across disparate cloud applications.
- C. Identity Governance focuses on managing the lifecycle and access rights of identities, not cross-domain authentication.
Federated Identity
A system that allows users to authenticate with one identity provider and then access services from multiple, independent service providers without re-authenticating.
- Enables Single Sign-On (SSO) across different organizations or cloud platforms.
- Relies on trust relationships between identity providers and service providers.
- Protocols like SAML and OpenID Connect are commonly used.
Memory trick: Federated = Friends with other providers