Create, Configure, and Manage Identities Flashcards
Access to ________ workloads is controlled using two methods:
- Provide a definitive identity for each user for every service.
- Ensuring just enough access to do job.
Cloud-based Workloads
What is Microsoft’s cloud-based identity and management service?
Azure Active Directory (Azure AD)
After authentication, what does Azure use to determine what resources the user can access?
Access Token
What Dashboard can be used to switch between Azure AD directories?
Directory + Subscription
What user only exists in Azure AD?
Cloud identities
What are two Sources of cloud identities in Azure AD?
- Azure Active Directory
2. External Azure Active Directory
What user exists in an on-premises Active Directory?
Directory-synchronized identities
What is the Source of Directory-synchronized identities?
Windows Server AD
What user exists outside of Azure AD?
Guest users
What is the Source of a Guest user?
Invited user
On what blade can you create a new user and a security group in Azure?
Azure Active Directory blade
How long is a user in a suspended state after deletion?
30 days
Which roles will allow you to restore or permanently delete users?
- Global Administrator
- Partner Tier 1 Support
- Partner Tier 2 Support
- User Administrator
On what blade in Azure AD can you assign Licenses?
Marketing blade
On what blade in Azure AD can you restore deleted Users?
Users
What two types of user groups are defined in Azure AD?
- Security Groups
- Microsoft 365 Groups
What type of group manages member and computer access to shared resources for a group of users?
Security Group
What type of group provides collaboration by giving members access to a shared mailbox, calendar, Sharepoint site, and more?
Microsoft 365 Group
What two Membership types are available for Azure AD groups?
- Assigned
- Dynamic
Group membership generated by a formula each time the group is used including any recipient in Active Directory that matches its filter.
Dynamic Licensing
Eliminating the need for Powershell to adjust licensing on a per-user basis, what feature of Azure AD ensures that licenses are dynamically assigned based on group membership?
Group-based licensing