Manage Azure identities and governance Flashcards
AAD: Identity
an object that can be authenticated. The identity can be a user with a username and password. Identities can also be applications or other servers that require authentication by using secret keys or certificates. Azure AD is the underlying product that provides the identity service.
AAD: an identity that has data associated with it.
Account
Azure AD account
an identity that’s created through AAD or another Microsoft cloud services such as 365. Also referred to as a work/school account.
Azure Tenant (Directory)
A single dedicated and trusted instance of Azure AD.
AD DS
Active Directory Domain Services- remember this is for managing OU’s on premise
Communication used for Azure AD
HTTPS and HTTP, unlike standard AD which uses kerberos.
Does Azure AD have OU’s or GPO’s
NO
Is Azure AD a managed service
Yes: You only manage users, groups, and policies.
AAD Free tier
Single Sign on, B2B. Core identity and access management.
AAD 365 tier
Includes all on free tier + identity and access management for 365 apps
License type: Allows hybrid users, self services groups, dynamic groups
AAD P1
License Type: Identity Protection and Identity management
AAD P2
Changes the local state of your device to allow users to sign into the device by using an organizational work or school account instead of a personal account
Azure Join (device)
Azure register (device)
Azure AD device registration provides the device with an identity that’s used to authenticate the device when a user signs into Azure AD. BYOD is mentioned in regards to this as well.
What does SSPR (self service password reset) require?
Global Administration privileges
which 3 options are available for SSPR in terms of users enabled
All, Selected, None
MFA SSPR options?
Email, text, security code sent to mobile or office phone, Set of Security questions
Cloud Identity
a user account defined only in AAD.
Directory Synced Identity
A user whom originated in an on premise Active Directory and has been synced to azure via azure AD connect
Guest user
User added to ad tenant from outside organization
What types of users have rights to add or manage users in AAD
Global administrators or user administrators
What are the two types of groups you can create in AAD
Security groups and Microsoft 365 groups
Dynamic device
(Security groups only) Apply dynamic group rules to automatically add and remove devices in security groups. When device attributes change, Azure reviews the dynamic group rules for the directory. If the device attributes meet the rule requirements, the device is added to the security group. If the device attributes no longer meet the rule requirements, the device is removed.