SC-900 Practice Question: Describe the concepts of security, compliance, and identity
Which THREE of the following are key concepts of identity management in Microsoft Entra ID?
⚠ Common exam trap
SC-900 often tests the boundary between authentication and authorization — candidates confuse 'who you are' with 'what you can do,' and may also incorrectly include encryption or least privilege as core identity concepts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Federation
Authentication (E) is a core identity-management concept in Microsoft Entra ID because it verifies a user's or service principal's identity through credentials such as passwords, certificate-based authentication, Windows Hello for Business, or FIDO2 security keys, and it underpins tokens issued by the Microsoft identity platform. Authorization (D) is equally fundamental: once Entra ID authenticates an identity, it determines what that identity may access through mechanisms like role-based access control (RBAC), OAuth 2.0 scopes, app roles, and conditional access policies. Federation (B) is also a key concept because Entra ID can trust external identity providers via protocols such as SAML 2.0, WS-Federation, and OpenID Connect, enabling single sign-on and delegated authentication for partner or on-premises identities. Encryption (A) is a security control used to protect data in transit and at rest, but it is not itself an identity-management concept. Least privilege (C) is an important security principle applied within authorization and access reviews, yet it is a guiding principle rather than one of the core identity-management concepts tested here.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Encryption
Why it's wrong here
Encryption is primarily a cryptographic technique used to protect data confidentiality and integrity, whether data is at rest or in transit. While it's crucial for securing communication channels and protecting sensitive identity data within an identity system, it is not one of the fundamental processes or concepts that define how identities are managed, verified, or authorized access to resources. Its role is data protection, not identity lifecycle or access control.
- ✓
Federation
Why this is correct
Federation is a key concept in modern identity management that establishes a trust relationship between multiple independent identity providers and service providers. It enables users to authenticate once with their home identity provider and then gain access to various applications and services across different organizational boundaries without re-authenticating. This facilitates single sign-on (SSO) and streamlines user experience by leveraging external identity sources.
- ✗
Least privilege
Why it's wrong here
Least privilege is a fundamental security principle dictating that users, programs, or processes should be granted only the minimum necessary permissions to perform their intended function. While identity management systems are designed to enforce least privilege through granular access controls, the principle itself describes a desired state of access rather than a core operational concept of identity verification, authorization, or trust establishment. It guides policy, but isn't a mechanism.
- ✓
Authorization
Why this is correct
Authorization is the process of determining whether an authenticated user or service principal is permitted to access a specific resource or perform a particular action. This decision is made based on predefined policies, roles, attributes, and permissions associated with the identity and the resource. It ensures that even after identity verification, access is strictly controlled according to established security rules and business requirements.
- ✓
Authentication
Why this is correct
Authentication is the crucial first step in identity management, involving the verification of a user's or system's claimed identity. This process typically relies on presenting credentials, such as passwords, multi-factor authentication (MFA) tokens, biometrics, or digital certificates, which are then validated against an authoritative identity store. Successful authentication confirms "who you are" before any access decisions can be made.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Self-Service Password Reset (SSPR)
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.