Active Directory Flashcards
What does Active Directory provide?
Single sign-on (SSO) and Multi-factor authentication (MFA)
What are the 4 pricing tiers for AD?
Free, Office 365 Apps, Premium P1, and Premium P2
What pricing tier do you need to provide ‘Identity Protection’ and ‘Identity Governance’?
Premium P2
What is the acronym RBAC stand for?
Role Based Access Control
What 3 things to you need to specify when creating a role?
Security Principal, Role Definition, Scope
Name the different types of Service Principals
User, managed identity, service principal, group
How long are RBAC Activity Logs stored by default?
90 days
What is the workaround for the RBAC activity log storage limitation?
Use Azure Event Hub
How many RBAC Activity Log categories are there?
8
List the RBAC Activity Log categories
Administrative, Service Health, Resource Health, Alert, Autoscale, Recommendation, Security, Policy
What are the 3 methods for achieving Hybrid Identity?
Password Hash Synchronisation (PHS), Pass-through authentication (PTA), Federation
What is PHS?
Password Hash Synchronisation. Sync the hash of the hashed password to Azure
What is PTA?
Pass-through authentication. Use the same password as on-premise. Validates directly with On-premise AD. Password never stored on Azure
What is Federation Hybrid Identity?
Collections of domain trust each other for shared access of resources
What does the acronym SAML stand for?
Security Assertion Markup Language
What does the acronym MFA stand for?
Multi-Factor Authentication
What types of MFA are there?
Password, SMS, Voice Call, Email, App, Security questions, App passwords, OAUTH hardware token
What is Azure AD B2B used for?
To allow external partners access to Azure. No need for external accounts and passwords or syncing accounts. Invite guest user via email
What is Azure AD B2C used for?
To control how customers use apps
What identity methods are there for Azure B2C?
Identity Providers, Users, Other systems, Local Directory
What is Self-service Password reset (SSPR)?
Allows users to reset their own passwords
What SSPR functionality is provided in the BASIC AD license?
Only allows CLOUD USERS to reset their passwords
What AD licenses provide full SSPR functionality?
AD Premium P1 and P2
What is SAS used for?
Provided delegated access to Azure Resources with granular control
What are the 3 types of SAS for storage accounts?
User delegation SAS, Service SAS, Account SAS
What is User delegation SAS?
Use AD to create SAS
What resource is User Delegation SAS limited to?
Blob Storage
What is Service SAS?
Use Storage Account key to create SAS
What are the limitations of Service SAS?
Can only access ONE storage account type
What are the limitations of Account SAS?
Use the Account Key to create SAS
Are there any limitations to using Account SAS?
No. You can give access to one or more storage account types
What 3 benefits does Azure AD Identity Protection provide?
1) Get summary of flagged users and detected risk events. 2) Set risk-based conditional access policies 3) Get suggested vulnerabilities to act on