Microsoft Cybersecurity Architect (SC-100)Design security for infrastructureMedium
A multinational corporation is implementing a Zero Trust architecture across its hybrid cloud environment. They need to ensure that all access requests, regardless of origin (on-premises or cloud), are rigorously authenticated, authorized, and continuously verified. The solution must integrate with existing on-premises identity providers and provide granular access control to Azure resources. Which Azure identity and access management service is foundational to achieving this Zero Trust principle?
- AAzure AD Connect
- BAzure AD B2C
- CAzure Active Directory Domain Services (Azure AD DS)
- DAzure Active Directory (Azure AD)
Show answer & explanationAnswer & explanation
Correct answer: D. Azure Active Directory (Azure AD)
Azure Active Directory (Azure AD) is the foundational identity and access management service in Azure. It enables robust authentication, authorization, and continuous verification for users, devices, and applications, which are core tenets of Zero Trust. It also supports integration with on-premises identity providers.
Why the other options are wrong
- A. Azure AD Connect synchronizes identities from on-premises AD to Azure AD, it's a tool, not the foundational identity service itself.
- B. Azure AD B2C is for customer-facing applications, not the primary corporate identity for Zero Trust.
- C. Azure AD DS provides managed domain services for legacy applications, but Azure AD is the primary identity store for Zero Trust.
Azure Active Directory (Azure AD)
Microsoft's cloud-based identity and access management service, providing identity for users, groups, and applications.
- Central component for Zero Trust implementation in Azure.
- Supports single sign-on (SSO), multi-factor authentication (MFA), and conditional access.
- Integrates with on-premises Active Directory.
Memory trick: Zero Trust: Never Trust, Always Verify, Constantly Monitor.