Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium

A global enterprise needs to manage access for its employees across various cloud services and on-premises applications. They want a centralized system that allows them to define user identities and their corresponding access rights uniformly, and then synchronize these identities and rights across all connected systems. Which identity concept best describes this requirement?

  1. APrivileged Identity Management (PIM)
  2. BIdentity Governance
  3. CDirectory Services
  4. DConditional Access
Show answer & explanation

Correct answer: C. Directory Services

Directory Services, such as Azure Active Directory (Azure AD), provide a centralized repository for user identities and their attributes, enabling uniform management and synchronization of access rights across diverse systems.

Why the other options are wrong

  • A. PIM manages elevated access for highly privileged roles, which is a specific aspect of identity management.
  • B. Identity Governance focuses on managing identity lifecycle, access reviews, and entitlement management, which builds upon directory services but isn't the core centralized system.
  • D. Conditional Access is a policy-based access control system, not a core identity management service.

Directory Services

A foundational identity concept that provides a centralized, hierarchical database for storing and managing information about network resources, including users, groups, devices, and their associated attributes and access permissions.

  • Central repository for identities and attributes.
  • Enables authentication and authorization.
  • Facilitates uniform management across various systems (on-prem & cloud).

Memory trick: Think of a 'Directory' as the phone book for all your digital identities.

More Describe the concepts of security, compliance, and identity questions