SC-900 - Security, Compliance, and Identity Concepts - Section 1.2

Define identity concepts.

Define identity as the primary security perimeter and distinguish authentication from authorisation, explaining the role each plays in controlling access. Recognise how identity providers, directory services, Active Directory, and federation enable single sign-on across trust boundaries.

identity as the primary security perimeterauthenticationauthorizationidentity providersdirectory services and Active Directoryfederation

Practice question for this objective

Free sampleSecurity, Compliance, and Identity Conceptseasy

A consultant is explaining single sign-on and federation across organisational trust boundaries. Which TWO statements about these capabilities are correct? Select TWO.

  • ASingle sign-on lets a user authenticate once and then reach multiple applications without signing in again to each. Correct
  • BFederation requires every partner to use one shared password database that all of them administer jointly.
  • CFederation establishes trust between separate identity providers so users from one domain can access another's resources. Correct
  • DSingle sign-on means each application must store and verify its own copy of the user's credentials.
  • EFederation forces both organisations to migrate all accounts into a single combined directory service.
Single sign-on lets users authenticate once for many applications, while federation builds trust between separate identity providers so users can cross organisational boundaries. Single sign-on authenticates a user one time and reuses that session across applications that trust the same identity provider. Federation extends trust between distinct identity providers in different organisations, so a user authenticated in one domain can access resources in another without merging directories or sharing a password store. The distractors invert single sign-on or wrongly require a combined or shared directory.

Why A is correct: Single sign-on authenticates the user a single time and carries that session across trusting applications.

Why B is wrong: Tempting because federation links organisations, but each side keeps its own directory; no shared password store is required.

Why C is correct: Federation creates a trust relationship between identity providers, letting one domain accept the other's authentication.

Why D is wrong: This contradicts single sign-on, whose purpose is to remove per-application credential checks.

Why E is wrong: Tempting but wrong; federation works precisely so organisations need not merge directories to interoperate.

See more SC-900 practice questions, answers explained.

More in this domain

Back to all Security, Compliance, and Identity Concepts objectives, or the SC-900 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.