DECK 1 Flashcards

1
Q

Simplest Cloud Authentication?

What requires Password Hash Sync?

Entra Domain Services lets users sign in with corporate credentials

A

Password Hash Sync (sign in to cloud apps and on prem same time)

Entra Domain Services managed domain

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What two roles required to host Entra Domain?

This authentication immediately enforces on prem user password policies

Federated auth uses a separate trusted system, such as on prem Active Directory Fed Services

A

-Application and Groups Admins

-Pass through auth

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Entra ID can handle sign in without relying on on-prem

Pass through needs light weight agents installed on premises

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Display name and user name are required when adding several users at once with a…

Bulk creation forms are found in 365 admin center> users > all users > bulk operations. Also in Entra too

A

-csv file

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Global admins can do EVERYTHING

Least permissive roles for resetting passwords would be roles like password admin or…

Admins who make purchases and make support tickets and manage subscriptions

A

-helpdesk admin

-billing admins

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Exchange admins view/manage inboxes

Only role that adds/manages domains and unblocks global admins

Global readers see what global admins can but can’t make changes

A

-global admins

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Group admins manage settings across different admin centers for their groups

Helpdesk admins can monitor and manage service request/health. Can only help non-admin users

Helpdesk admins can also help other helpdesk and readers (except global)

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

….admins assign/remove licenses to users and groups

Role that reads privacy and security messages. Can see data privacy messages, like a Global admin

password admins reset passwords for who?

A

license

-message center privacy reader

-non admins and other password admins

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Reports readers view usage/activity reports in 365, access Power BI adoption content pack, and access sign in reports in Entra ID

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

-Role that creates and manage search results

Role that can be added to user or admins to open/manage service requests, share message center post, an monitor service health

User admins can reset passwords for other user admins and non users

A

-Search admin

-Service Support

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

SETTING UP DNS MANUALLY

-Connect page > More options > Add your own DNS records. Can add what two files?

when adding domains, first custom domain is the default

A

-Zone or csv file

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

SERVICE TAB SETTINGS

-Adoption Score (manage privacy levels and exclude/include users)

-Azure Speech (disabled by default)

Bookings (choose whether available, can share externally or restrict data collection)

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

SERVICE TAB SETTINGS (Found in Org settings > Services

-Briefing email from VIVA (enabled by default; users can unsubscribe)

-Directory sync (link for AD Connect sync tool)

-Teams settings (enable or disable teams org wide, allow/disallow guest access)

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

SERVICE TAB SETTINGS

-……..(allow PII to be shared internally and whether to make data available to 365

-SHAREPOINT (enable/disable….

A

-REPORTS

-external sharing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

SECURITY/PRIVACY TAB IN ORG SETTINGS

-can configure idle timeout and….

-Can also create privacy profile

-also has link to SSPR in Azure

A

-password expiry policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

ORG PROFILE TAB IN ORG SETTINGS

-usually informational or to manage

A

-aspects of user experience

17
Q

SHAREPOINT

-if Guest sharing disabled/restricted in Entra ID, it overrides settings where?

what settings need to be verified to ensure you can share SHAREPOINT w/guest?

Make sure the domains of guest aren’t blocked. What else can you limit?

A

-in 365

-B2B external collaboration settings in Microsoft Entra ID (aka Azure Active Directory)

-Guest seeing other guest in the directory

18
Q

SHAREPOINT

-Modern sharepoint uses 365 Groups to control access

-Sharepoint settings are in 365 admin >……..>Org settings > 365 Groups

Sharepoint Admin center also used to enable sharing. Can also set these settings at….

HIEARCHY: Entra ID B2B settings > 365 Group settings > Sharepoint Org settings > individual site level settings

A

-settings

-the site level

19
Q

What 2 roles other than Global Admins that can create mail contacts? And where can they create?

Remove-MailContact= removes contact

New-MailContact= creates contact

A

-Exchange Admin and Directory Writers. Both in 365 admin

20
Q

SERVICE HEALTH (365 amin > Health > service health. What notifications can you set here?

Usage reports show metrics on #of files in Sharepoint/exchange and….

Cloud users can be assigned to any verified domain that is in MANAGE mode, except FEDERATED domains (must be provisioned in on prem system)

A

-email

-general usage of all kinds of services