2V0-21.23 Question 112
Single answerA company is deploying a new VMware vSphere environment and wants to integrate it with their existing corporate identity provider for centralized user authentication and single sign-on (SSO). They want to ensure that administrators can manage access across multiple systems without creating and maintaining separate credentials for vSphere. Which use case would justify the implementation of identity federation in this scenario?
- A
Ensure that users can log in to vSphere using their corporate credentials.
- B
Enforce multi-factor authentication (MFA) for vSphere access.
- C
Standardize password policies across all vSphere users.
- D
Allow administrators to create and manage local vSphere accounts for all users.
Show answer and explanation
Correct answer: A
Explanation
The primary use case for identity federation is to integrate vSphere with an external corporate identity provider, enabling users to authenticate with their existing corporate credentials. This reduces administrative overhead by centralizing user management and eliminates the need for managing separate local accounts in vSphere. In this scenario, the company’s requirement to use corporate credentials for authentication directly aligns with the purpose of identity federation.
- A. Correct.
Correct. Identity federation allows users to authenticate using their corporate credentials, ensuring centralized authentication and reducing the need for separate account management.
- B. Incorrect.
Incorrect. While identity federation can enable MFA integration as part of the corporate identity provider, enforcing MFA is an additional feature and not the primary use case for federation.
- C. Incorrect.
Incorrect. Password policies are typically managed by the corporate identity provider but standardizing password policies is not the primary purpose of identity federation.
- D. Incorrect.
Incorrect. Identity federation eliminates the need for creating and managing local accounts in vSphere by leveraging the corporate identity provider for authentication.