*Manage Azure Identities and governance Important Info* Flashcards
Important things to know about
Create users and groups:
- There are 3 different types of users
Need to know what are they and when to use them
Cloud
Hybrid
Guest
- Know the portal and entra.micorsoft.com portal as well
Manage Licenses in microsoft Entra ID
-Know the licenses of entra
-PIM/indentity protection you need a p2 license
-Self service password reset you need a p1 license
Manage external users
-When a guest is invited:
-Know how to invite , what happens with the guest account , what is considered a guest.
-IE anyone that’s not part of the tenant
Manage built in Azure roles
Owner
Contributor
User access admin
^Know the difference between these ones specifically^
-Reader
-Backup operator
-Security reader
VM contributor
Know that there are custom roles you can create and you use the json format
Assign roles at different scopes(Hierarchy)
-Know at what levels you can scope your permissions and policy.
!!Know that it is inherited and you can not break it!!
-When you scope your permissions or policy management group , subscription , resource group or role you cant break that!
Know that you get Azure(Entra) roles and Azure Entra AD roles
Azure(Entra ) roles more of your resource type roles
Azure( Entra AD) roles - Your administrator roles
^Know the scoping of that as well^
Implement and manage azure policy
- Know that there is a difference between Policy initiative and a initiative definition
-initiative definition - Is a grouping of policies and a policy is single
Configure Resource locks
There is 2 resource locks:
-Delete: Authorized users can still read and modify a resource , but they cant delete the resource
-Read only: Authorized users can read a resource but they cant delete or update the resource
Manage resource groups
-Know that it cant be nested flat structure
-All resources need to be part of a resource
can be part of more than one region
resources can be moved between resource groups
Manage subscriptions
Know the different types of subscriptions
For invoicing all about the billing capability
Manage costs by using alerts , budgets , and advisor recommendations:
Know the Cost optimization tool
-They can ask things like how you create a budget which is part of the optimization tool
-
Configure management groups
- this is if you have more than 1 subscription
-Great for security and policy
-Know tagging
Know interpret access management
-Manage users and group properties
Know sefl service password reset - requires a p1 license