Exam objective

SC-900

Define identity concepts

This objective sits in Describe concepts of security, compliance, and identity, which carries 12% of the Security, Compliance, and Identity Fundamentals exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page ↗

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Describe concepts of security, compliance, and identity

Organization A configures its identity provider to trust Organization B's, so B's users can reach A's workspace with their own credentials. A's users then try to access a resource in B. What happens?

They sign in with their A credentials, as trust is mutualFederation trust is not automatically bidirectional; the unit says so directly.
They must first create guest accounts in Organization BFederation exists so users do not need separate accounts; the missing piece is the reverse trust, not an account.
They are denied until B configures a trust in ACorrect · your answerCorrect.
It depends on whether B uses the same vendor productFederation works across vendors through standard protocols; the vendor is not what blocks access here.

Correct.

Checked against learn.microsoft.com, September 2026

Concept

A trust between identity providers has a direction; setting it up one way says nothing about the other way.

Why C

The source says trust relationships are not automatically bidirectional: if A trusts B, B does not automatically trust A, and a two-way trust must be explicitly configured.

Source

An important point: trust relationships aren't automatically bidirectional. If Organization A trusts Organization B, that doesn't mean Organization B automatically trusts Organization A. A two-way trust must be explicitly configured if both organizations need to access each other's resources.

Describe the concept of federation, checked September 2026
#federation#trust#scenario

Now you: practice questions

No account needed. The explanation opens when you answer.

Sample question 1 of 2

Describe concepts of security, compliance, and identity

An organization removes standing administrator access to Exchange configuration settings. Admins must now request temporary elevated access only when performing a specific task. Which Zero Trust guiding principle does this practice best reflect?

Sample question 2 of 2

Describe concepts of security, compliance, and identity

A virtual machine needs to read from a storage account without any password or key being stored in its code or configuration. Which identity type fits?

Full Security, Compliance, and Identity Fundamentals question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Describe concepts of security, compliance, and identity