01-Identity Flashcards

1
Q

What is Azure Active Directory

A

Cloud-based suite of IDENTITY MANAGEMENT capabilities.

Allows you to securely manage access to Azure services and resources for your users.

Provides application management, authentication, device management, and hybrid identity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How to authenticate to Azure Active Directory?

A
AUTH
SAML
Oauth
Open ID
WS-Federation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the common authentication set among Windows Server Active Directory and Azure Active Directory?

A

Users & Groups Authentication and Authorization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How to authenticate to Windows Server Active Directory?

A

AUTH
Kerberos
NTML

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is Identity

A

An object that can be authenticated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is Account

A

An identity that has data associated with it

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is Azure AD account

A

An identity created through Azure AD or another Microsoft cloud service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is Azure subscription

A

It is used to pay for Azure cloud services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is Azure AD tenant/directory

A

A dedicated and trusted instance of Azure AD, a Tenant is automatically created when your organization signs up for a Microsoft cloud service subscription

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is Tenant

A

It is a single instance of Azure AD representing a single organization.

The terms Tenants and Directory are often interchanged

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the underlying product that provides identity service

A

Azure AD is the underlying product that provides identity service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is Azure AD primary function

A

Identity solution, designed for HTTP and HTTPS communications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How is Azure AD queired

A

Using REST API over HTTP and HTTPS.

Unstead of LDAP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What HTTP and HTTPS protocols does Azure AD use

A

SAML
WS-Federation
OpenID Connect of authentication and OAuth for authorization.

Instead of Kerberos

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Does Azure AD include Federation services

A

Yes, and many 3rd party services, such as Facebook

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What structure are Azure AD users and groups are created

A

In a flat structure, i.e. no Organizational Units (OUs) or Group Policy Objects (GPOs)

17
Q

4 Azure Active Directory Editions

A
  1. Free
  2. Microsoft 365 Apps
  3. Premium P1
  4. Premium P2
18
Q

What is difference between Premium P1 and Premium P2 Azure Active Directory Editions

A

P2 has Identity Protection and Identity Governance

19
Q

What is Azure AD Join

A

User joins Azure AZ with their personal devices.

Facilitates Bring Your Own Device and makes sure personal device is compliant with the Organization’s network

Jist: for my users, their devices must be compliant BEFORE joining network

20
Q

What is Self-Service Password Reset

A

Avoid users having to call Help Desk when they forget their passwords.

You can choose the number of authentication methods required and the methods available (email, phone, questions)

You can require users to register for SSPR (same process as Multi Factor Authentication)

21
Q

Three ways Azure AD Identifies users

A

1 . Cloud Identities - created inside of Azure AD and accessed inside Azure AD

  1. Directory synchronized Identities - on-prem a/c/ synced with Azure AD
  2. Guest Identities - outside Azure AD, i.e. gmail, aol
22
Q

How can you create or manage Azure AD User Accounts

A

Single accounts or bulk accounts

23
Q

Who can manage Azure AD User Accounts

A

Global Admin or User Admin

24
Q

Two group types in Azure AD

A
  1. Security Groups

2. Microsoft 365 gROUPS

25
Q

Three assignment types in Azure AD

A
  1. Assigned
  2. Dynamic User
  3. Dynamic Device (Security groups only)
26
Q

What is Dynamic User

A

User is automatically added to group based on predefined rule, i.e. user belongs to “Finance”

27
Q

Is there parent-child relationship between organizations in Azure AD

A

No, they are Independent.

A peer is logically independent from the other Azure AD organizations you manage.

28
Q

What does Independence in Azure AD Include

A
  1. Resource Independence
  2. Administration Independence
  3. Synchronization Independence