Explore Identity Synchronization Flashcards
Define cloud-only identities
The user identity only exists in the cloud. All password management and policy control are done through Azure AD.
What Azure AD authentication option uses a software agent running on an on-premises server to validate the user in Active Directory?
Pass-Through Authentication (PTA)
True or false: With PTA, users can only sign into their Microsoft 365 resources using their on-premises account and password?
False
What synchronization service does SSO work with to provide authentication?
Active Directory Federation Services
What is the key difference between PTA and SSO?
SSO requires another proxy server because AD FS Server isn’t allowed to accept public connections.
What is the primary purpose of on-premises Active Directory?
Scalable, secure, and manageable infrastructure for user and resource management using access control at the object level.
What is an Azure AD resource?
Any logical object: permissions, apps, services, Sharepoint sites, on-premises resources, etc.
Whether on-premises, cloud, or hybrid what are the default permissions provided to a new user?
The least amount of privilege, especially no administrator privileges.
List the three types of user provisioning.
- On-premise only
- Cloud-only
- Hybrid
What technology facilitates hybrid user provisioning?
Azure AD Connect
Which Microsoft 365 provisioning option do companies prefer when they want more administrative versatility and another disaster recovery backup option?
Hybrid
Explain Azure AD write back
The process of directory synchronization that begins in the cloud and synchs “down” to the on-premises directory.
What was Azure AD Connect called before?
- Windows Azure AD Synchronization
- DirSync
Three parts of ____________
- Synchronization services
- ADFS (optional)
- Monitoring
Azure AD Connect
True or False:
Licenses are automatically assigned in Microsoft 365 when Azure AD connect synchronizes objects from Active Directory?
False