Execute Device Enrolment Flashcards
True or False: Windows Home edition supports joining a domain
False
True or False: Devices can only be joined to one AD-DS domain
True
What does being registered in Entra ID mean for a device?
It can access cloud and Azure-based resources using SSO
What user types would an Eduational Institution have in Entra ID?
Faculty and Student
Describe Entra ID joining
A device joined only to Microsoft Entra ID requiring organizational account to sign in to the device
Describe Entra ID registering
A device registered to Microsoft Entra ID without requiring organizational account to sign in to the device - for BYOD
What is the difference between Entra ID joined and Entra ID registered?
Entra ID Registered devices don’t need an organisational login to access the device itself
Entra ID joined devices require an organisational login before the device can be logged on
Should a BYOD device be Entra ID joined or registered?
Entra ID Registered
True or False: an Entra ID registered device using a personal account requires Entra ID credentials to access cloud resources
True
Why would an Educational Facility create Student accounts in Entra ID?
-Short-term org members
-More Students than Faculty members = burden of the directory can be stored in cloud rather than on prem
True or false: Entra ID allows device joining by default
False - it must be enabled first
Which Windows OS numbered versions support Entra hybrid join?
Windows 11, Windows 10, Windows 8.1
(but not Home Edition)
Which Windows Server versions support Entra hybrid join?
-Windows Server 2008/R2
-Windows Server 2012/R2
-Windows Server 2016
-Windows Server 2019
-Windows Server 2022
What is a down-level device?
A device with an older OS (e.g. Windows 7)
What must be installed to use Entra Hybrid Join for devices older than Windows 10?
Microsoft Workplace Join for non-Windows 10 computers
True or false: you can’t use Entra Hybrid Join if your environment consists of a single forest that syncs identity data to more than one Entra tenant
True
What does WS-Fed stand for and what does it do?
Web Services Federation
An identity protocol that allows users to sign in to multiple resources and services with SSO
What does WS-Trust stand for and what does it do?
Web Services Trust
A standard that enables the exchange of security tokens between web applications, APIs, and devices
As a prerequisite for Entra Join, what are the minimum versions for WS-Trust?
1.3 OR 2005
True or false: Entra-joined devices can access SSO even when disconnected from the domain network
True
What does STS stand for and what does it mean?
Secure Token Service
Issues, validates, renews, and cancels security tokens for users, resources, and systems that request access to a federation
What is Microsoft’s on-prem STS server?
AD-FS
True or false: Using Entra Domain Services, Group Policy can manage smartphones and tablets
False
True or false: Entra Domain Services is not enabled by default
True - it must be configured manually