Describe identity, governance, privacy, and compliance features (20- 25%) Flashcards
Explain the difference between authentication and authorization
Authentication is a user proving who their are.
Authorisation is what a user is permitted to do.
Describe the functionality and usage of Conditional Access, Multi-Factor Authentication (MFA), and Single Sign-On (SSO)
MFA, is 3FA something you know, something you have, something you are. Conditional access, is additional authentication level for unusual login attempts. E.g. IF out of office, THEN prompt MFA.
Describe the functionality and usage of Azure Active Directory
Secure, centralised identity provider, reduced development time, easier support
Define Azure Active Directory
Identity as a service. Complete solution for managing user, groups and roles.
Describe the functionality and usage of Role-Based Access Control (RBAC)
Roles have different permissions assigned, assign users to roles. Reader, Contributor, Owner.
Describe the Cloud Adoption Framework for Azure
Journey from on-prem to cloud adoption documentation, guidance and tools.
Describe the functionality and usage of Azure Blueprints
Templates that create users, roles and policies which can be assigned to NEW subscriptions.
Describe the functionality and usage of Azure Policy
Governance sets rules and policies over subscriptions. Eg. Allowed locations, allowed server versions, default tags, allowed virtual machines.
Describe the functionality and usage of tags
Resource tags, metadata which can be searched and acted upon with automation and for financial or other reasons.
Describe the functionality and usage of resource locks
Lock a resource, means read only and cannot delete.
Describe the Microsoft core tenets of Security, Privacy, and Compliance
TRUSTED CLOUD, Azure is built with security in mind, privacy, your data is your own. Compliance, following standards and ISOs.
Describe the purpose of the Microsoft Privacy Statement, Product Terms site, and Data Protection Addendum (DPA)
privacy.microsoft.com. Agreements and PERSONAL DATA THAT AZURE COLLECTS, Azure tells you what and why. TERMS OF SERVICE.
Describe the purpose of the Trust Center
Documentation for the Trusted Cloud.
Describe the purpose of the Azure compliance documentation
Documentation claims to be compliant with certain documentation. ISOs and GDPR etc.
Describe the purpose of Azure Sovereign Regions (Azure Government cloud services and Azure China cloud services)
Runs on different hardware and isolated datacentres for governments, Azure China etc.