What's changed: Revamped AZ-900 Chapter 4 to the new depth and added security coverage (Zero Trust/defense in depth/Defender for Cloud/RBAC/external ID) to the identity section
4.2Identity, Access, and Security
Centered on Microsoft Entra ID: authentication vs authorization, MFA/SSO/passwordless, Conditional Access, RBAC, external ID, Entra ID vs AD DS, plus security basics—Zero Trust, defense in depth, and Microsoft Defender for Cloud.
The foundation of secure cloud use is identity. We have shifted from defending at the perimeter (the corporate network) to "identity is the new perimeter." This section covers identity management (authentication, authorization, Entra ID, RBAC) and the surrounding security mindset (Zero Trust, defense in depth, Defender for Cloud) together.
4.2.1Authentication and authorization
Authentication (AuthN, "who you are") and authorization (AuthZ, "what you can access") are different concepts. The order is always authenticate → authorize: confirm identity first, then decide "may you act on this resource." Exams frequently swap these two terms in options.
| Aspect | Authentication | Authorization |
|---|---|---|
| Question | Who are you? | What can you do? |
| Means | Sign-in, MFA, passkeys | RBAC, role assignment |
| Order | First | Second |
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

