Describe access management capabilities of Microsoft Entra ID Flashcards

1
Q

Conditional access

A

analyses signals including user, location, device, application, and risk to automate decisions for authorizing access to resources (apps and data).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

t or f

Conditional Access policies at their simplest are if-then statements

A

true

ex. Conditional Access policy might state that if a user belongs to a certain group, then they’re required to provide multifactor authentication to sign in to an application.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

A conditional access policy in Microsoft Entra ID consists of two components

A

assignments
access controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

t or f

When creating a conditional access policy, admins can determine which signals to use through assignments

A

true

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Assignment portion of the policy controls:

A

who
what
where
when

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

users and groups

A

assign who the policy will include or exclude

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

cloud apps or actions

A

include or exclude cloud applications, user actions, authentication contexts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

conditions

A

define where and when the policy will apply.
sign in risk
user risk
device platform
IP location info
client apps
filters for devices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

access control

A

decision to block access, grant access, grant access with extra verification, or apply a session control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

grant access

A

Administrators can grant access without any additional control, or they can choose to enforce one or more controls when granting access.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

session

A

administrator can make use of session controls to enable limited experiences within specific cloud applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

RBAC - role based access control

A

managing access using roles

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Does Microsoft Entra have built in and custom roles?

A

yes. these are consider a form of RBAC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Built in roles

A

global administrator
user administrator
billing administrator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Global administrator

A

users with this role have access to all administrative features in Microsoft Entra.

The person who signs up for the Microsoft Entra tenant automatically becomes a global administrator.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

User administrator

A

users with this role can create and manage all aspects of users and groups.

This role also includes the ability to manage support tickets and monitor service health.

17
Q

billing administrator

A

users with this role make purchases, manage subscriptions and support tickets, and monitor service health.

18
Q

Custom roles

A

a collection of permissions that you choose from a preset list

19
Q

t or f

Granting permission using custom Microsoft Entra roles is a two-step process

A

true

20
Q

what is the first step for granting permission using custom Microsoft Entra roles

A

eating a custom role definition, consisting of a collection of permissions that you add from a preset list

21
Q

what is the second step for granting permission using custom Microsoft Entra roles

A

assign that role to users or groups by creating a role assignment

22
Q

t or f

Microsoft Entra ID is an available service if you subscribe to any Microsoft Online business offer, such as Microsoft 365 and Azure.

A

true

23
Q

Microsoft Entra built in roles can be used in

A

Microsoft Entra specific roles
Service specific roles
Cross service roles

24
Q

Microsoft Entra RBAC

A

control access to Microsoft Entra resources such as users, groups, and applications.

25
Q

Azure RBAC

A

control access to Azure resources such as virtual machines or storage using Azure Resource Management.

26
Q

An organization plans to implement Conditional Access. What do admins need to do?

A

Create policies that enforce organizational rules.

27
Q

Sign-in risk is a signal used by Conditional Access policies to decide whether to grant or deny access. What is sign-in risk?

A

The probability that the authentication request isn’t authorized by the identity owner.

28
Q

IT admins have been asked to review Microsoft Entra roles assigned to users, to improve organizational security. Which of the following should they implement?

A

Replace global admin roles with specific Microsoft Entra roles