A user proves who they are with a fingerprint and a one-time code, and is then permitted to restart virtual machines but not to delete them. Which part of that is authentication, which is authorisation, and what provides the second part in Azure?

Microsoft Certified: Azure Fundamentals (AZ-900), objective architecture-and-services. Azure architecture and services easy

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

The options

Correct Proving identity is authentication; deciding what may be done is authorisation, and Azure role-based access control provides it by assigning a role to a principal at a scope

Correct. Authentication happens first and answers who; authorisation happens next and answers what — and on Azure resources, what is decided by role assignments.

Not correct Both are authentication, and role-based access control is a form of multifactor authentication

Wrong. Role-based access control never checks who anybody is. It begins with an already-authenticated principal and answers a completely different question about permissions.

Not correct Proving identity is authorisation, and the permissions are authentication

Wrong — the terms are the other way round. Authentication is the identity check, authorisation is the permission check, and they always happen in that order.

Not correct What may be done is decided by Conditional Access rather than role-based access control

Wrong. Conditional Access gates the sign-in itself — demanding multifactor authentication, requiring a compliant device, blocking a location. Which actions a principal may perform on which resources is role-based access control.

Why

Authentication asks who you are; authorisation asks what you may do. Azure separates them cleanly: Entra ID authenticates and issues the token, and role-based access control authorises each action against a role assignment made at some scope. Keeping the two words apart is worth marks on this exam, because several services live on one side of the line and are routinely offered as answers on the other.

Where this comes from

Cited
Microsoft AZ-900 study guide skill area architecture-and-services.identity-access-security

Practise this

Reading one question is not practice. The trainer will draw a set from objective architecture-and-services and space the ones you get wrong.

Practise Microsoft Certified: Azure Fundamentals (AZ-900)

More questions on this objective

All questions on Azure architecture and services