Microsoft Azure Fundamentals (AZ-900)Describe Azure identity, security, and networkingEasy
A company is planning to deploy several applications to Azure. They need a service that can manage and secure access to these applications for both internal employees and external partners, ensuring single sign-on (SSO) capabilities. Which Azure identity service should they choose?
- AAzure Active Directory (Azure AD)
- BAzure Active Directory Domain Services (Azure AD DS)
- CAzure DNS
- DAzure Firewall
Show answer & explanationAnswer & explanation
Correct answer: A. Azure Active Directory (Azure AD)
Azure Active Directory (Azure AD) is a cloud-based identity and access management service that provides single sign-on, multifactor authentication, and conditional access for applications in the cloud and on-premises.
Why the other options are wrong
- B. Azure AD DS provides managed domain services like traditional Active Directory, not primarily for application access management and SSO.
- C. Azure DNS is a hosting service for DNS domains, unrelated to identity and access management.
- D. Azure Firewall is a managed, cloud-based network security service that protects Azure Virtual Network resources, not an identity service.
Azure Active Directory (Azure AD)
A cloud-based identity and access management service that helps employees sign in and access resources.
- Provides single sign-on (SSO)
- Supports multi-factor authentication (MFA)
- Manages access to cloud and on-premises applications
Memory trick: Azure AD is the 'key' to 'all doors' in the 'cloud'.