SC-900 - Security, Compliance, and Identity Concepts (13% of the exam) - Section 1.2

Define identity concepts.

Define identity as the primary security perimeter and distinguish authentication from authorisation, explaining the role each plays in controlling access. Recognise how identity providers, directory services, Active Directory, and federation enable single sign-on across trust boundaries.

identity as the primary security perimeterauthenticationauthorizationidentity providersdirectory services and Active Directoryfederation

Practice question for this objective

Free sampleSecurity, Compliance, and Identity Conceptseasy

A consultant is explaining single sign-on and federation across organisational trust boundaries. Which TWO statements about these capabilities are correct? Select TWO.

  • ASingle sign-on lets a user authenticate once and then reach multiple applications without signing in again to each. Correct
  • BFederation requires every partner to use one shared password database that all of them administer jointly.
  • CFederation establishes trust between separate identity providers so users from one domain can access another's resources. Correct
  • DSingle sign-on means each application must store and verify its own copy of the user's credentials.
  • EFederation forces both organisations to migrate all accounts into a single combined directory service.
Single sign-on lets users authenticate once for many applications, while federation builds trust between separate identity providers so users can cross organisational boundaries. Single sign-on authenticates a user one time and reuses that session across applications that trust the same identity provider. Federation extends trust between distinct identity providers in different organisations, so a user authenticated in one domain can access resources in another without merging directories or sharing a password store. The distractors invert single sign-on or wrongly require a combined or shared directory.

Why A is correct: Single sign-on authenticates the user a single time and carries that session across trusting applications.

Why B is wrong: Tempting because federation links organisations, but each side keeps its own directory; no shared password store is required.

Why C is correct: Federation creates a trust relationship between identity providers, letting one domain accept the other's authentication.

Why D is wrong: This contradicts single sign-on, whose purpose is to remove per-application credential checks.

Why E is wrong: Tempting but wrong; federation works precisely so organisations need not merge directories to interoperate.

See more SC-900 practice questions, answers explained.

Exam traps in Security, Compliance, and Identity Concepts

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-900 bank for this domain.

  • Because firewalls and VPN gateways have been completely removed from the environment the moment an organisation begins to adopt cloud and software-as-a-service applications.

    Why it is wrong: Cloud adoption does not remove network controls; it erodes their sufficiency, which is why identity becomes the boundary rather than the firewall disappearing.

  • It encrypts the network traffic between the user's browser and the application so that credentials cannot be intercepted.

    Why it is wrong: Encrypting traffic protects data in transit; it is not the role of an identity provider, which manages identities and verifies credentials.

  • Authentication and authorisation are interchangeable terms for the single act of typing a password.

    Why it is wrong: Tempting because both happen at sign-in, but they are distinct stages and neither is just typing a password.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.