Courseiva

Authentication vs Authorization: What's the Difference?

A company implements a sign-in process where a user must provide their password and then enter a temporary code sent to their mobile phone. Which security principle is this process primarily enforcing?

Quick Answer

The answer is authentication. This process is primarily enforcing authentication because it verifies the user’s identity through multi-factor authentication (MFA), combining something they know (the password) with something they have (the temporary code sent to their phone). On the Microsoft SC-900 exam, understanding the distinction between authentication and authorization is critical: authentication confirms who you are, while authorization determines what you can access. A common trap is confusing the two when a scenario includes both steps, but the key is to identify which principle is being directly enforced by the sign-in flow itself. Remember, authentication always comes first—it’s the gatekeeper that checks your ID before you can even ask for permission. A simple memory tip: “AuthN before AuthZ”—think of authentication as proving your name, and authorization as showing your ticket.

⚠ Common exam trap

Many candidates confuse authentication (proving identity) with authorization (granting permissions), especially when the question describes a multi-step sign-in process that seems to 'allow access' — but the core principle being enforced is identity verification, not access control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Authentication

The process of verifying a user's identity by requiring both a password (something they know) and a temporary code sent to their mobile phone (something they have) is a classic implementation of multi-factor authentication (MFA). Authentication is the security principle that confirms the identity of a user, device, or system before granting access. This sign-in flow directly enforces authentication by combining two distinct factors to prove the user is who they claim to be.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Authorization

    Why it's wrong here

    Authorization determines what resources a user can access, not how they prove their identity.

    When this WOULD be correct

    A question asking: 'After a user logs in, the system checks whether they can access a specific file. Which security principle is being applied?' — here Authorization is correct because it controls access rights after identity is verified.

  • Authentication

    Why this is correct

    Authentication verifies identity. Multi-factor authentication requires two or more forms of verification, such as a password and a code from a phone.

  • Accounting

    Why it's wrong here

    Accounting involves tracking user activities for auditing and logging purposes, not verifying identity at sign-in.

    When this WOULD be correct

    A question that asks: 'Which security principle is primarily enforced when an organization logs user access times, data modifications, and resource usage for auditing purposes?' would make Accounting the correct answer.

  • Non-repudiation

    Why it's wrong here

    Non-repudiation ensures that a user cannot deny an action (e.g., digitally signing a document), but it is not the primary principle being enforced during sign-in.

    When this WOULD be correct

    An exam question might ask: 'A company uses digital signatures on all financial transactions to ensure that employees cannot deny authorizing payments. Which security principle is this?' In that case, non-repudiation would be correct because it provides proof of origin and integrity.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

AuthenticationCorrect answer

Why this is correct

Authentication verifies identity. Multi-factor authentication requires two or more forms of verification, such as a password and a code from a phone.

AuthorizationWrong answer — click to see why

Why this is wrong here

The process described (password + temporary code) is about verifying identity, not granting permissions. Authorization determines what an authenticated user is allowed to do, not how they prove who they are.

★ When this WOULD be the correct answer

A question asking: 'After a user logs in, the system checks whether they can access a specific file. Which security principle is being applied?' — here Authorization is correct because it controls access rights after identity is verified.

Why candidates choose this

Candidates may confuse authentication (proving identity) with authorization (granting permissions), especially when the scenario involves multiple steps and they think the code is 'authorizing' access.

AccountingWrong answer — click to see why

Why this is wrong here

The sign-in process described (password + temporary code) is a method of verifying identity, which is authentication. Accounting refers to tracking user activities and resource usage, not verifying identity.

★ When this WOULD be the correct answer

A question that asks: 'Which security principle is primarily enforced when an organization logs user access times, data modifications, and resource usage for auditing purposes?' would make Accounting the correct answer.

Why candidates choose this

Candidates may confuse 'accounting' with 'authentication' because both are part of AAA (Authentication, Authorization, Accounting) and the term 'account' appears in both contexts, leading to a mix-up.

Non-repudiationWrong answer — click to see why

Why this is wrong here

Non-repudiation ensures that a party cannot deny having performed an action, typically through digital signatures or audit trails. The described sign-in process (password + temporary code) is about verifying identity (authentication), not preventing denial of actions.

★ When this WOULD be the correct answer

An exam question might ask: 'A company uses digital signatures on all financial transactions to ensure that employees cannot deny authorizing payments. Which security principle is this?' In that case, non-repudiation would be correct because it provides proof of origin and integrity.

Why candidates choose this

Candidates may confuse authentication with non-repudiation because both involve identity verification. However, non-repudiation goes further by providing evidence that can be used to prove an action occurred, which is not the primary goal of the sign-in process described.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A user logs into the company's network using their username and password. After successful login, the user attempts to open a financial report but receives an access denied message because they are not a member of the 'Finance' security group. Which security concept is best illustrated by the access denial?

easy
  • A.Authentication
  • B.Authorization
  • C.Accounting
  • D.Non-repudiation

Why B: The access denial occurs because the user lacks the necessary permissions to open the financial report, even though their identity was verified. This is the core function of authorization, which determines what resources an authenticated user can access. In this scenario, the user is authenticated but not authorized to access the report due to missing group membership.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.