Azure Developer Associate (YT) - Azure AD Flashcards

1
Q

Wat is Azure AD?

A

Cloud based identity and access management service.
External Resources
* MS office 365 / Azure Portal / SaaS apps
Interal Resources
* Applications binnen je netwerk
* Access to workstations on-premise

Gebruik Azure AD om gebruik te maken van Single-Sign On (SSO)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Wat is Azure Active Directory (Azure AD)?

A

Identity as a Service (IDaaS) van Azure AD

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Welke Azure AD versies zijn er?

A

Free
MFA, SSO, Basic security * reports, usermanagement
Office 365 Apps
Company branding, SLA, Two-Sync tussen on-premise&cloud
Premium 1
Hybrid Architecture, Advanced Group Access, Conditional Access
Premium 2
Identity Protection, Identity Governance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Azure AD - Use Cases

A

Azure AD Connect > On-premise
App Registrations > Web application
External Indentities > facebook, Google
Cloud Applications > Office 365, Azure Microsoft

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Azure AD Terminology

A

Domain > logical grouping of AD object on a network
Domain controller (DC) > server that authenticates user and authorizes their access
Domain Computer > Computer tat is registered with central authentication database (also an AD Object)
AD Object > Basic element of AZ AD > Users, Groups, Printers, Computers, Shared dirs
Group Policy Object (GPO) > Virtual Collection of policy settins. Controls what AD Objects have access to
Organization Units (OU) > Subdivision in AD to place User/Groups/Computers
Directory Service > provides the methods for storing directory data and making is available to network users and admins. DS runs on DC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Active Directory Tenant

A

Tenant stelt een organizatie voor en is dedicated Azure AD Service Instance
Dit zijn groepen om de users mee te isoleren binnen Azure AD. Elke tenant heeft een eigen service plan

maak je automatisch aan wanneer je signed voor MS Azure/Intune/365

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Waarom een custom AZ AD domain controller?

A

Wanneer je wilt migreren naar AZ AD
Azure Active Directory Domain Service (AD DS) regelt
* domain joins
* Group policies
* lightWeight directory access protocol (LDAP)
* kerberos / NTLM Authentication

migratie = lift-and-shift

Dit kun je ook gebruiken zonder iets te maken

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Wat is Azure AD Connect?

A

Gebruik je voor een Single Sign on op je on-premise PC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Wat zijn de 4 manieren om een toegang te geven?

Assign Access Rights

A

Assigment types
* direct > owner stelt user in
* Group > owner stelt de Azure AD group in
* Rule-based > “iedereen die uit NL komt” > vanaf Premium V1
* External Authority > bijv onpremise SaaS app

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Wat is Azure Active Directory (Azure AD)?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Welke Azure Roles heb je?

A

Classic subscription admin role
original role system
Azure Roles
Role-Based Access Controls (RBAC) authorization system built on top of Azure Resource Manager
Azure AD Roles
Used to manage Azure AD resources in a directory

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Wat is een identity Access Management (IAM)?

A

Azure Roles
* BuiltInRole > standaard rollen
* CustomRole

Azure BluePrints > Enige manier hoe je Deny Assignments kunt doen

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Opties voor de Classis administrator

A
  • Account Admin > billing owner. Geen Access tot de Portal
  • Service Admin > Zelfde als de Owner Role. Volledige Access tot de Portal
  • Co-Admin > Zelfde Access als de persoon die hem die role heeft gegeven

Gebruik de nieuwe RBAC zoveel mogelijk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Hoe gebruik je Role-Bases Access Control (RBAC)?

A

Helpt je te managen wie toegang tot welke resouce
3 elementen voor Role Assignments
* security principal/role > User, Group, Service, Managed Identity
* role definition > read, write, delete?
* scope

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Wat zijn de 4 Azure built in roles en wat mogen ze?

A

Owner: read, grant, CRUD
Contributer: read, CRUD
Reader: read
User Access Admin: grant

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Wat zijn Azure AD Roles?

A

used to manage Azure AD resources.
Roles you should know:
* Global admin
* User admin
* Billing admin

voor custom roles moet je Premium P1 of P2 hebben

17
Q

Verschil tussen Azure Policies & Azure Roles

A

Policies > ensures complaince of resource
Roles > control access to Azure Resource

Dus een gebruiker kan toegang hebben tot een resource, maar doe Policy geblocked worden

18
Q

Azure AD Roles vs Azure Roles

A

AD Roles > control access of AD Resources
Roles