Azure AD Flashcards
What is the main auth protocol used by Azure AD?
OAUTH, SAML, OPEN ID
Is Azure AD like Windows AD?
No, Azure AD is a multi Tennant, global service
What do we use Azure AD for?
Identity Management - Identity Management, users, groups, ect. - User names, passwords - Domain name Enterprise Access - Single sign-on - Device management Identity and access security - Just in time access - MFA
What is a tenant?
A tenant represents an organization in Azure Active Directory. It’s a dedicated Azure AD service instance that an organization receives and owns when it signs up for a Microsoft cloud service such as Azure, Microsoft Intune, or Microsoft 365. Each Azure AD tenant is distinct and separate from other Azure AD tenants.
What must each tenant have?
a unique domain name
I wnat to add a custom domain to my tenant, how can i do this?
You have the option to add a custom domain to a tenant.
What is an AD association?
This is where we associate a subscription with an AD tenant.
Is an AD tenant global?
No, it is like USA.
I would like to give my users the ability to self service reset there passwords, how can I do this?
Azure has Serf-service password reset (SSPR)
What auth options do i have available for Azure has Serf-service password reset (SSPR) ?
- SMS
- Phone (Voice)
- Mobile app
- Security passwords
What is Azure has Serf-service password reset (SSPR)?
It provides a portal you can use as a user to reset the password, its a service provided by Azure.
I have an AD group that has access to a custom web application, I want to ensure people in the AD group still use the application and remove them form the group if they are not needing access, what options do i have?
You can use AD Access Review, the enables you to create a review process where either the owner of the group or it members get to select if the still require access.
What is Azure AD Access Review?
It enables you to have the owners or users of an AD group validate through email if they still requires access to the AD group and then automatically remove people, that do not need accessor did not respond.
What is Azure Identity protection?
Enables the detection and remediation of identity-based risks. It used Microsoft cyber security (both human and AI) to detect password suite breaches or issues, like password been available on dark web
When using Azure Identity protection, is it at the subscription or tenant level?
It a tenant or subscription solution?