AZ-900 - Describe Azure Architecture and Services (36% of the exam) - Section 2.4

Describe Azure identity, access, and security including Microsoft Entra ID, authentication methods, conditional access, RBAC, and defence in depth.

Describe Microsoft Entra ID as Azure's cloud identity provider and explain how multi-factor authentication and Conditional Access policies protect sign-in. Distinguish Azure role-based access control (RBAC) for authorising resource actions from identity-level controls, and apply the defence-in-depth and Zero Trust principles to identify the appropriate layer for a given security control.

Microsoft Entra IDmulti-factor authenticationConditional AccessAzure RBACdefence in depth and Zero Trust

Practice question for this objective

Free sampleDescribe Azure Architecture and Serviceseasy

An organisation wants a cloud-based identity and access management service that lets users sign in to Microsoft cloud apps and to applications the organisation develops itself. Which service provides this?

  • AMicrosoft Entra Domain Services, a managed domain
  • BAzure Key Vault, the secret storage service
  • CMicrosoft Defender for Cloud, a posture tool
  • DMicrosoft Entra ID, the cloud identity service Correct
Microsoft Entra ID is the cloud identity and access management service for signing in to Microsoft and custom cloud apps. Microsoft Entra ID is Microsoft's cloud-based identity and access management service that lets users sign in and access both Microsoft cloud applications and applications the organisation develops, which is exactly the described need.

Why A is wrong: Microsoft Entra Domain Services provides a managed domain with domain join and LDAP, but it is not the cloud directory that signs users in to cloud apps.

Why B is wrong: Azure Key Vault securely stores secrets, keys, and certificates, but it is a storage service and does not act as the cloud identity directory.

Why C is wrong: Microsoft Defender for Cloud assesses security posture and detects threats, but it does not provide identity sign-in or manage cloud app access.

Why D is correct: Correct. Microsoft Entra ID is Microsoft's cloud-based identity and access management service that lets users sign in and access both Microsoft cloud applications and applications the organisation develops, which is exactly the described need.

See more AZ-900 practice questions, answers explained.

Exam traps in Describe Azure Architecture and Services

Answers that look right on this material and are not. Each one is a distractor from a different question in the AZ-900 bank for this domain.

  • Active Directory Domain Services, an on-premises role

    Why it is wrong: Active Directory Domain Services is the on-premises Windows directory role, a separate product that was never the cloud service's former name.

  • They are the same control under two different names doing identical work

    Why it is wrong: This treats them as interchangeable, but Conditional Access governs sign-in based on signals while RBAC governs resource permissions, so they are distinct mechanisms.

  • Conditional Access evaluating the request

    Why it is wrong: Conditional Access decides at sign-in whether to allow, block, or challenge a request using signals, but it does not grant a verified identity permissions on a resource scope.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.