A user proves who they are with a fingerprint and a one-time code, and is then permitted to restart virtual machines but not to delete them. Which part of that is authentication, which is authorisation, and what provides the second part in Azure?
Microsoft Certified: Azure Fundamentals (AZ-900), objective architecture-and-services. Azure architecture and services easy
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
The options
Correct Proving identity is authentication; deciding what may be done is authorisation, and Azure role-based access control provides it by assigning a role to a principal at a scope
Correct. Authentication happens first and answers who; authorisation happens next and answers what — and on Azure resources, what is decided by role assignments.
Not correct Both are authentication, and role-based access control is a form of multifactor authentication
Wrong. Role-based access control never checks who anybody is. It begins with an already-authenticated principal and answers a completely different question about permissions.
Not correct Proving identity is authorisation, and the permissions are authentication
Wrong — the terms are the other way round. Authentication is the identity check, authorisation is the permission check, and they always happen in that order.
Not correct What may be done is decided by Conditional Access rather than role-based access control
Wrong. Conditional Access gates the sign-in itself — demanding multifactor authentication, requiring a compliant device, blocking a location. Which actions a principal may perform on which resources is role-based access control.
Why
Authentication asks who you are; authorisation asks what you may do. Azure separates them cleanly: Entra ID authenticates and issues the token, and role-based access control authorises each action against a role assignment made at some scope. Keeping the two words apart is worth marks on this exam, because several services live on one side of the line and are routinely offered as answers on the other.
Where this comes from
- Cited
- Microsoft AZ-900 study guide skill area architecture-and-services.identity-access-security
Practise this
Reading one question is not practice. The trainer will draw a set from objective architecture-and-services and space the ones you get wrong.
Practise Microsoft Certified: Azure Fundamentals (AZ-900)
More questions on this objective
- An image-resizing routine runs for about two seconds whenever a file lands in a storage container — perhaps two hundred times on a busy day, and not at all on a quiet one. The team wants to pay for the work done and maintain no servers. Which compute option fits? machine-checked
- A fifteen-year-old accounting application needs a kernel-level driver, a scheduled task that edits the registry, and a runtime version nobody supports any more. The business wants it running in Azure this quarter with as few code changes as possible. Where does it go? machine-checked
- A team runs nine small services, each with its own conflicting library versions. They want each one packaged with its dependencies, starting in seconds, several to a host, without a separate operating system per service. Which compute type are they describing? machine-checked
- Which TWO of these statements about Azure compute types are true? machine-checked
- A public website runs on four identical virtual machines behind a load balancer. Traffic triples while a television advert airs and falls back an hour later. The team wants instances added and removed automatically against CPU, all built from one image, with nobody clicking. Which option is designed for that? machine-checked
- Three virtual machines form a quorum-based cluster in a region that has no availability zones. You want them placed so that neither a single rack losing power nor a single batch of planned host maintenance can take all three at once. What do you configure? machine-checked