certslothcertsloth
SC-100/Topic 02

Microsoft / Expert

Identity, agents and privileged access

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Identity is a boundary; privilege has an expiry.

Must remember

  • Design workforce, external and workload identities separately. Entra ID, hybrid AD DS and B2B access have different lifecycle, authentication and trust requirements; decentralized identity addresses particular verification scenarios rather than replacing every account.
  • Conditional Access combines user/workload context, device, risk and application requirements. Continuous access evaluation can improve supported revocation behavior; test emergency access and avoid blanket assumptions about token lifetime.
  • Agent identities, including supported Entra Agent ID capabilities, need ownership, scope and policy. An agent should not inherit an unrestricted human administrator credential for every user request.
  • Privileged Identity Management enables eligible/time-bound role activation with supported controls. Entitlement management and access reviews govern access packages and continued need; they are not substitutes for runtime authorization.
  • Use the enterprise access model to protect administration across cloud tenants and on-premises systems. Secure privileged workstations, reduce standing privilege, harden AD DS and audit delegation.
  • Manage secrets, keys and certificates with controlled lifecycle and recovery. Evaluate excessive cloud entitlements, external collaboration and dormant identities continuously, with accountable resource owners.

Choose under exam pressure

Requirement Choice and reason
Administrators need occasional production elevation Eligible scoped roles through PIM with appropriate approval and audit.
An agent acts for many users A dedicated constrained identity plus supported user-context authorization where required.

Traps

  • MFA does not make every endpoint or session trustworthy.
  • An access review identifies continued need; it does not replace a resource’s permission checks.

Active recall

1. How does authentication differ from authorization?

Authentication establishes identity; authorization determines allowed actions.

2. Why protect administrative workstations?

Compromised endpoints can steal or misuse highly privileged sessions.

3. What is standing privilege?

Privileged access continuously assigned even when no privileged task is being performed.

4. Why review B2B access?

External users’ business need and employment status can change outside your organization.

5. What should agent ownership include?

Responsible owner, allowed resources/actions, lifecycle, audit and incident response.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.