Identity, Governance, Privacy and Compliance- 20-25% Flashcards
Azure Identity Services - Objective Domain
- Explain the difference between authentication and authorization
- Define Azure Active Directory
- Describe the functionality and usage of Azure Active Directory
- Describe the functionality and usage of Conditional Access, Multi-Factor Authentication (MFA), and Single Sign-On (SSO)
Azure Multi-Factor Authentication?
Azure Multi-Factor Authentication
Provides additional security for your identities by requiring two or more elements for full authentication.
• Something you know → Something you possess → Something you are
Azure Active Directory (AAD)?
Azure Active Directory (AAD)
Azure Active Directory (AAD) is Microsoft Azure’s cloud-based identity and access
management service.
• Authentication (employees sign-in to access resources).
• Single sign-on (SSO).
• Application management.
• Business to Business (B2B).
• Business to Customer (B2C) identity services.
• Device management.
Conditional Access?
Conditional Access Conditional Access is used by Azure Active Directory to bring signals together, to make decisions, and enforce organizational policies. • User or Group Membership • IP Location • Device • Application • Risk Detection
Walkthrough - Manage access with RBAC Assign roles?
Walkthrough - Manage access with RBAC Assign roles and view activity logs.
- View and assign roles.
- View the activity log and remove a role assignment.
Azure Governance Methodologies - Objective Domain
Describe the functionality and the usage of: • Role-Based Access Control (RBAC) • Resource locks • Tags • Azure Policy • Azure Blueprints • Cloud Adoption Framework for Azure
Explore Role-based access control (RBAC)?
Fine-grained accessmanagement.
• Segregatedutieswithintheteamand grant only the amount of access to users that they need to perform their jobs.
• EnablesaccesstotheAzureportaland controlling access to resources.
Resource locks?
Resource locks
• Protect your Azure resources from accidental deletion or modification.
• Manage locks at subscription, resource group, or individual resource levels within Azure Portal.
Walkthrough - Manage Resource Locks?
Walkthrough - Manage Resource Locks
Create a resource group add a lock and test deletion, test deleting a resource in the resource group.
1. Create a resource group.
2. Add a resource lock to prevent deletion of a resource group.
3. Test deleting a member of the resource group.
4. Remove the resource lock.
Tags??
Tags
• ProvidesmetadataforyourAzure resources.
• Logicallyorganizesresourcesintoa taxonomy.
• Consistsofaname-valuepair.
• Veryusefulforrollingupbilling information.
Azure Policy
?
Azure Policy helps to enforce organizational standards and to assess compliance at- scale. Provides governance and resource consistency with regulatory compliance, security, cost, and management.
• Evaluates and identifies Azure resources that do not comply with your policies.
• Provides built-in policy and initiative definitions, under categories such as Storage, Networking, Compute, Security Center, and Monitoring.
Walkthrough - Create an Azure Policy?
Create an Azure Policy to restrict deployment of Azure resources to a specific location.
- Create a policy assignment.
- Test the allowed location policy.
- Delete the policy assignment.
Azure Blueprints ?
Azure Blueprints makes it possible for development teams to rapidly build and stand up new environments. Development teams can quickly build trust through organizational compliance with a set of built-in components (such as networking) in order to speed up development and delivery. • Role Assignments • Policy Assignments • Azure Resource Manager Templates • Resource Groups
Cloud Adoption Framework?
The One Microsoft approach to cloud adoption in Azure.
• Best practices from Microsoft employees, partners, and customers.
• Tools, guidance, and narratives for strategies and outcomes.
Privacy, Compliance, and Data Protection - Objective Domain
Describe the purpose of the:
• Microsoft core tenants of Security, Privacy, and Compliance
• Microsoft Privacy Statement, Online Services Terms (OST) and Data Protection
Amendment (DPA)
• Trust Center
• Azure compliance documentation
• Azure Sovereign Regions (Azure Government cloud services and Azure China cloud services)