IAM & AAD Flashcards

1
Q

Azure Tenant

A

Identity Security Boundary
Can contain one or more subscriptions via a trust relationship
Azure AD: Subscription = 1: N

Contains IAM Resources (via AAD)

Active Directory Tenant > root account owner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

AAD Groups

A

Security Group
Users/computer access to shared resources/groups

O365 Groups
Access to shared mailbox, calendar, SP and OneDrive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

AAD Group Membership Types

A

Assigned - manual

Dynamic User
- Rules to auto add/remove users, dependent on member attribute

Dynamic Device
- Rules, Auto add/remove, device attributes for devices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Azure AD Specific Toles

A

Azure AD Specific Roles
– Tenant Level Scope
– Only applicable to AD specific resources
— user/groups/billing/passwords

  • Global Administrator
  • Security Administrator
  • User Administrator
  • Application Developer
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Azure B2C

A

AWS Cognito

Allows 3rd party OIDC providers to connect to Azure App’s

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Azure AAD Licenses

A

Azure AD Free
Azure AD Premium
- P1
- P2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Conditional Access - AAD Licenses

A

P1 and P2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Dynamic Groups - AAD Licenses

A

P1 & P2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Identity Protection - AAD Licenses

A

P1

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Azure AD Groups

A

AAD Groups > Membership Types > Dynamic Users
> Add Dynamic Querry > Add Expressions

user.country -eq “India”

Takes times for SYNC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Azure RBAC Roles

v/s Azure AD Roles

A

Azure RBAC Roles
– Access Control to Azure Resources
– Multiple Levels
- Subscriptions
- Resource Groups
- Resources

Prebuilt Roles
- Owner
- Contributor (everything else, but no IAM changes)
- Reader
- User Access Administrator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Administrative Unit

A

Used to restrict scope of roles
Default Scope: Tenant Level

AAD > Administrative Unit > Limited Set of Roles

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

IAM - Different Entities

A

User Principal
Service Principal
Managed Identity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Azure AD Privileged Identity Management

A

Tool that will allow you to see who has elevated permissions within your environment.

You can examine the history of that access, and whether they use those permissions.
Also you can ask users to justify the need for those elevated permissions in a security review.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly