Manage Azure Identities and Governance Flashcards

1
Q

What are the two primary types of users in Azure AD ?

A

Cloud-only users

Users synchronized from an on-premises directory

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

When you create a new group for users, what are the two different types of groups ?

A

Security

Microsoft 365

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What kind of role must one have in order to enable, disable, or delete devices from Azure AD ?

A

Global administrator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the three options for associating devices with Azure AD ?

A

Registering a device
Joining a device
Using hybrid AD joined

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

…. are joined to your on-premises Active Directory and are registered with your Azure AD tenant.

Registered devices
Joined devices
Hybrid AD joined devices

A

Hybrid AD joined devices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

When a device is a …………………………., users can sign in to the device using an organizational account instead of a personal account.

Registered device
Azure AD Joined device
Hybrid AD - Joined device

A

Azure AD–Joined

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

……. is good for personal devices, where as ……. is good for corporate devices.

Registering a device
Joining a device
Using hybrid AD joined

A

Registering a device

Joining a device

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

…………. a device with Azure AD allows you to manage a device’s identity by implement- ing features like single sign on (SSO) and securing access using conditional access.

A

Associating

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Match the device with the right method for associating with Azure AD

A) Personal device
B) Corporate or Enterprise device
C) On premise Active Directory device

1) Joining Azure AD
2) Registering
3) Joining Hybrid Azure AD

A

A - 2
B - 1
C - 3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

The …………………. is one of the highest cost-incurring activities for many organizations, and many organizations have dedicated front-line help desks to handle such requests.

A

Password reset

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What three possible values for Membership Types when defining a new group ?

Which ones are only available with Azure AD Premium ?

A

Assigned
Dynamic user
Dynamic Device

Dynamic user and Dynamic device are only available with Azure AD Premium

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the four foundational built in roles in Azure RBAC role assignments ?

Are roles customizable ?

A

Reader
Contributor
Owner
User Access Administrator

Yes, you can customize them

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

When managing Azure RBAC, what are the four possible different scopes ?

A

An individual resource
A resource group
A subscription
A management group

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

………….. are used to manage access and allow or restrict users to Azure resources, while …………………….. are used to allow or restrict admins to perform identity tasks, such as creating new users, reset- ting the users’ passwords, and so on.

A

RBAC roles

Azure AD administrative roles

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

True or false : RBAC roles and Azure AD administrative roles are identical in Azure

A

False, not the same thing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

True of false : It is possible to create a management group under a root management group

A

True, a single tenant in Azure can support up to 10,000 management groups

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Granting a user access to the Owner role at the management group scope will grant that user Owner rights to all the subscriptions under the management group that is inclusive of all the resource groups and resources within them.

What is this principal called ?

A

RBAC inheritance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What is understood by “security principal” when speaking about managing RBAC in Azure ? (List the 4 possibilities)

A

A user
A group of users
A service principal
A managed identity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

To make an RBAC role assignment, what three dimensions must you define?

A

The role
The security principal
The scope

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is the limit of role assignments per subscription ?

A

2000

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What is the limit of role assignments per management group ?

A

500

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

In the Azure Portal, which blade is used to manage access to resources as well as role assignments ?

A

the Access Control (IAM) blade

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

True or false : The Deny Assignments tab of the Access Control (IAM) blade is used to make or alter deny assignments.

A

False - Deny assignments are set and controlled by applying a resource lock for resources created through Azure Blueprints.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

How you can set deny assignments ?

A

By applying a resource lock for resources created through Azure Blueprints

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

……………………. is a default deny mechanism with an explicit allow mechanism, whereas ……………………. is a default allow mechanism with an explicit deny system.

A

Azure RBAC

Policy

26
Q

True or false: When configuring the scope while assigning a Policy or an Initiative, it is possible to exclude a subscope.

A

True

27
Q

…………………………. are a collection of Policy definitions that are focused on the same goal. They allow for a set of policies to be grouped as a single item.

A

Initiative definitions

28
Q

What are the two types of resource locks ?

A

CanNotDelete

ReadOnly

29
Q

A CanNotDelete lock is applied to a resource within a resource group.

Can you delete this resource by deleting the resource group ?

Can you delete the resource group ?

A

No

No

30
Q

True or false : Tags applied at the resource group scope are inherited by child resources.

A

False - Tags are not inherited

31
Q

To apply tags to a subscription, resource group, or resource, the user applying the tag must have ……………………. to the resource

A

write access

32
Q

Which Azure service allows automatic tagging ?

A

Azure Policy

33
Q

Why is the location of a resource group important for compliance ?

A

Because the location specifies where the metadata for the resource group is stored

34
Q

True or false : All resources in Azure must be placed in resource groups

A

False
Taken from docs.microsoft.com

“Some resources can exist outside of a resource group. These resources are deployed to the subscription, management group, or tenant. Only specific resource types are supported at these scopes.”

35
Q

What are the three classic administrator roles ?

A

Account Administrator

Service Administrator

Service Co-Administrator

36
Q

What is the difference between a Service Administrator and a Service Co-Administrator ?

A

The Service Administrator and the Service Co-Administrator have the same level access in a subscription, except that the Service Co-Administrator cannot change the association of subscriptions to Azure directories

37
Q

What RBAC role are Services Administrators and Service Co-Administrators assigned at the subscription scope ?

A

Owner

38
Q

What two main types of quotas that can be applied to a subscription ?

A

Resource quotas (limits)

Spending quotas

39
Q

Which type of quota would block a user from deploying a VM ?

A

Resource quotas (limits)

40
Q

Which type of quota would not block actions from users, but send an alert once a certain threshold has been breached ?

A

Spending quotas (limits)

41
Q

How can you raise a service limit (resource quota) ?

A

Open a support ticket specifying the request to Microsoft

42
Q

True or False : Budgets are only applied at a subscription level

A

False : They are by default set at a subscription level, but you can also apply them to a management group level

43
Q

True or false : breaking threshold for a budget will stop services from running

A

False - it will send an alert, but services will continue to run

44
Q

For Azure billing and cost management, what are the three portals available ?

A

EA Portal - Only customers with an EA agreement

Account Portal - Account owners can access this

Azure Portal / Azure cost management - All subscriptions can access this

45
Q

What is a simple way to safely allow BYOD ?

A

Register Windows 10 as a device in Azure AD

46
Q

An administrator whats to manage corporate devices, independently of users. What method should he use for Azure AD ?

A

Azure AD Join enables administrators to manage device identity independently of users.

For example, dynamic security groups can be created based on device attributes and then conditional access policies could be applied to those groups.

47
Q

…………… is a feature of Azure AD which allows administrators to control access to cloud applications through additional checks such as user location, the device the user is accessing the cloud app from, and more.

A

Conditional Access

48
Q

Each tag needs … (2 things)

A

A name

A value pair

49
Q

True or false : Tags can be applied to resources, resource groups, subscriptions, and management groups

A

False : They cannot be applied to management groups

50
Q

Within a(n) ……………………………….. , an administrator can make use of session controls to enable limited experiences within specific cloud applications.

A

Conditional Access policy

51
Q

An administrator can make use of …………………… to enable limited experiences within specific cloud applications.

A

Session controls

52
Q

In conditional access, what is the difference between grant controls and session controls ?

A

Grant controls determine who gets access to the ressources (either granting or blocking)

Session controls enable limited experiences within specific cloud applications

53
Q

What are three approaches to creating a custom RBAC role ?

A

Clone a built - in RBAC role and modify it

Start from Scratch

Start from JSON and declare permissions

54
Q

When defining a custom RBAC role, what are the four “actions” that define the permissions of the role ?

A

Actions
NotActions
DataActions
NotDataActions

55
Q

When moving resources between groups or subscriptions, what is the maximum number of resources that can be done in a single move operation ?

A

800

56
Q

True or false : It is possible to move resources between subscriptions that have different Azure AD tenants

A

False, you need to first transfer ownership of the subscription to another account.

57
Q

What are three necessary conditions for moving resource between subscriptions ?

A
  1. The subscriptions must be in the same Azure AD tenant
  2. The source resource must be registered in the target subscription
  3. Dependant resource must be in the same resource group
58
Q

True or false : During a move operation, Write and Delete actions are blocked, but the underlying services will continue to function

A

True

59
Q

True or false : During a move operation, Write and Delete actions are blocked and all services cease to function

A

False

60
Q

When transferring a subscription to a different Azure AD tenant, what is the major risk one should be attention to ?

A

Unexpected effects on RBACs associated with either the services or subscription being moved