Which approach is commonly used to provide single sign-on (SSO) between on-premises Active Directory and cloud identities?

Study for the CompTIA Cloud+ exam. Enhance your skills with flashcards and multiple choice questions, each supported by hints and explanations. Prepare effectively for your certification!

Multiple Choice

Which approach is commonly used to provide single sign-on (SSO) between on-premises Active Directory and cloud identities?

Explanation:
Federation using SAML or OpenID Connect (OIDC) is the common approach to provide single sign-on between on-premises Active Directory and cloud identities. By establishing a trust relationship between your local identity provider and the cloud service, users authenticate once to the IdP and receive a token that cloud apps trust, enabling seamless access across both environments without re-entering credentials. This standard-based setup also supports additional security controls like MFA and conditional access. Other options don’t establish the same cross-cloud trust: using SMS-only codes isn’t a federated SSO mechanism, Kerberos over VPN binds authentication to a VPN session rather than cloud access, and static local accounts require separate credentials for each service, which breaks SSO and increases risk.

Federation using SAML or OpenID Connect (OIDC) is the common approach to provide single sign-on between on-premises Active Directory and cloud identities. By establishing a trust relationship between your local identity provider and the cloud service, users authenticate once to the IdP and receive a token that cloud apps trust, enabling seamless access across both environments without re-entering credentials. This standard-based setup also supports additional security controls like MFA and conditional access. Other options don’t establish the same cross-cloud trust: using SMS-only codes isn’t a federated SSO mechanism, Kerberos over VPN binds authentication to a VPN session rather than cloud access, and static local accounts require separate credentials for each service, which breaks SSO and increases risk.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy