certslothcertsloth
SC-900/Topic 02

Microsoft / Foundational

Entra Identity, Authentication and Governance

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Prove who, decide what, review why access continues.

Must remember

Entra ID provides cloud identity and access management. AD DS provides traditional domain services; hybrid identity connects supported on-premises and cloud identity processes. Federation trusts another identity provider for authentication. People, devices, applications and workloads can all have identities with different lifecycles.

Authentication proves identity; authorization decides actions. MFA combines independent proof factors; passwordless methods can use keys or device-bound credentials. Password Protection and self-service reset address different parts of credential management. No method removes the need to secure enrollment and recovery.

Conditional Access evaluates configured signals and applies access/session controls. Entra roles manage directory tasks; Azure RBAC manages Azure resource access. Identity Protection identifies user/sign-in risk; it does not mean every detection is confirmed compromise.

Identity Governance manages access lifecycle. Access reviews check continuing need; entitlement management organizes requestable access; PIM supports temporary controlled privileged activation. Least privilege and timely offboarding reduce standing exposure.

Choose under exam pressure

Requirement Choice and reason
Require stronger sign-in under a condition Conditional Access.
Temporary administrator elevation PIM.
Periodic confirmation of access Access reviews.

Traps

  • Authentication is not authorization.
  • Entra ID is not simply a cloud VM running AD DS.

Active recall

1. What is federation?

Trusting another identity provider for authentication assertions.

2. Why use MFA?

To reduce reliance on one compromised proof factor.

3. What does PIM reduce?

Unnecessary standing privileged access.

4. What does an access review ask?

Whether existing access remains justified.

5. User identity versus workload identity?

A person’s access principal versus software/service access.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.