Explore Identity Synchronization Flashcards

1
Q

Define cloud-only identities

A

The user identity only exists in the cloud. All password management and policy control are done through Azure AD.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What Azure AD authentication option uses a software agent running on an on-premises server to validate the user in Active Directory?

A

Pass-Through Authentication (PTA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

True or false: With PTA, users can only sign into their Microsoft 365 resources using their on-premises account and password?

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What synchronization service does SSO work with to provide authentication?

A

Active Directory Federation Services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the key difference between PTA and SSO?

A

SSO requires another proxy server because AD FS Server isn’t allowed to accept public connections.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the primary purpose of on-premises Active Directory?

A

Scalable, secure, and manageable infrastructure for user and resource management using access control at the object level.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is an Azure AD resource?

A

Any logical object: permissions, apps, services, Sharepoint sites, on-premises resources, etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Whether on-premises, cloud, or hybrid what are the default permissions provided to a new user?

A

The least amount of privilege, especially no administrator privileges.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

List the three types of user provisioning.

A
  1. On-premise only
  2. Cloud-only
  3. Hybrid
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What technology facilitates hybrid user provisioning?

A

Azure AD Connect

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which Microsoft 365 provisioning option do companies prefer when they want more administrative versatility and another disaster recovery backup option?

A

Hybrid

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Explain Azure AD write back

A

The process of directory synchronization that begins in the cloud and synchs “down” to the on-premises directory.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What was Azure AD Connect called before?

A
  • Windows Azure AD Synchronization

- DirSync

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Three parts of ____________

  1. Synchronization services
  2. ADFS (optional)
  3. Monitoring
A

Azure AD Connect

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

True or False:

Licenses are automatically assigned in Microsoft 365 when Azure AD connect synchronizes objects from Active Directory?

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Are all Active Directory attributes synchronized to Microsoft 365 through Azure AD Connect?

A

No

17
Q

Scenarios supported by ____________

  1. Multiple Active Directory forests
  2. Multiple Exchange organizations to one 365 tenant
A

Azure AD Connect

18
Q

What is the single source of authority when using Azure AD Connect?

A

Active Directory on-premises

19
Q

Explain this Azure AD Connect feature:

Exchange hybrid deployment.

A

Used to implement an Exchange hybrid deployment with one or multiple on-premises Exchange organizations.

20
Q

Explain this Azure AD Connect feature:

Exchange mail-enabled public folders

A

Synchronizes mail-enabled public folder objects from on-premises Active Directory to Azure AD.

21
Q

Azure AD Connect provides which of the following features?

  • Migrates Exchange public folders from your on-premises organization to Exchange Online
  • Password writeback that enables your users to change and reset their passwords in the cloud and have your on-premises password policy applied
  • Determines the on-premises domain suffixes, identifies whether any domains are already verified with Microsoft 365, and validates the appropriate DNS records
A

Password writeback that enables your users to change and reset their passwords in the cloud and have your on-premises password policy applied

22
Q

Azure AD Connect includes an optional group writeback feature. Group writeback writes groups from Azure AD to on-premises Active Directory. Which type of groups can be written back from Azure AD to your on-premises Active Directory?

A

Microsoft 365 groups