Microsoft Azure Fundamentals (AZ-900)Describe Azure identity, security, and networkingEasy

A company is planning to deploy several applications to Azure. They need a service that can manage and secure access to these applications for both internal employees and external partners, ensuring single sign-on (SSO) capabilities. Which Azure identity service should they choose?

  1. AAzure Active Directory (Azure AD)
  2. BAzure Active Directory Domain Services (Azure AD DS)
  3. CAzure DNS
  4. DAzure Firewall
Show answer & explanation

Correct answer: A. Azure Active Directory (Azure AD)

Azure Active Directory (Azure AD) is a cloud-based identity and access management service that provides single sign-on, multifactor authentication, and conditional access for applications in the cloud and on-premises.

Why the other options are wrong

  • B. Azure AD DS provides managed domain services like traditional Active Directory, not primarily for application access management and SSO.
  • C. Azure DNS is a hosting service for DNS domains, unrelated to identity and access management.
  • D. Azure Firewall is a managed, cloud-based network security service that protects Azure Virtual Network resources, not an identity service.

Azure Active Directory (Azure AD)

A cloud-based identity and access management service that helps employees sign in and access resources.

  • Provides single sign-on (SSO)
  • Supports multi-factor authentication (MFA)
  • Manages access to cloud and on-premises applications

Memory trick: Azure AD is the 'key' to 'all doors' in the 'cloud'.

More Describe Azure identity, security, and networking questions