Microsoft 365 FundamentalsDescribe core Microsoft 365 services and conceptsHard

A global enterprise is adopting Microsoft 365 and needs to ensure that users can log in securely from anywhere, on any device, and that access to resources is protected based on user context. Which core Microsoft 365 component provides the identity and access management foundation for these requirements?

  1. AAzure Active Directory (Azure AD)
  2. BMicrosoft Intune
  3. CMicrosoft Exchange Online
  4. DMicrosoft Defender for Endpoint
Show answer & explanation

Correct answer: A. Azure Active Directory (Azure AD)

Azure Active Directory (Azure AD) is the cloud-based identity and access management service that provides single sign-on, multifactor authentication, and conditional access to protect user access to Microsoft 365 and other cloud apps.

Why the other options are wrong

  • B. Microsoft Intune is for mobile device and application management, not the core identity provider.
  • C. Microsoft Exchange Online is the email service, unrelated to identity and access management.
  • D. Microsoft Defender for Endpoint is an enterprise endpoint security platform, not an identity management service.

Azure Active Directory (Azure AD)

Microsoft's cloud-based identity and access management service that helps employees sign in and access resources.

  • Provides Single Sign-On (SSO) for Microsoft 365 and thousands of SaaS apps.
  • Enables Multifactor Authentication (MFA).
  • Supports Conditional Access policies for granular control over resource access.

Memory trick: Azure AD is the ID card, Intune is the bouncer, Defender is the guard dog.

More Describe core Microsoft 365 services and concepts questions