Manage Identities and Access Flashcards

1
Q

Azure Active Directory - Users with leadked credentials

What is the risk level and detection type?

A

Azure Active Directory - Users with leadked credentials

What is the risk level and detection type?

Risk Level: High

Detection Type: Offline

Categories: What is risk? Azure AD Identity Protection | Microsoft Docs

Investigate risk Azure Active Directory Identity Protection | Microsoft Docs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Azure Active Directory - sign-ins from anonymous IP addresses

What is the risk level and detection type?

A

Azure Active Directory - sign-ins from anonymous IP addresses

What is the risk level and detection type?

Risk Level: Medium

Detection Type: Real-time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Azure Active Directory - Impossible travel to atypical locations

What is the risk level and detection type?

A

Azure Active Directory - Impossible travel to atypical locations

What is the risk level and detection type?

Risk Level: Medium

Detection Type: Offline

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Azure Active Directory - Sign-ins from infected devices

What is the risk level and detection type?

A

Azure Active Directory - Sign-ins from infected devices

What is the risk level and detection type?

Risk Level: Low

Detection Type: Offline

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Azure Active Directory - Sign-ins from unfamiliar locations

What is the risk level and detection type?

A

Azure Active Directory - Sign-ins from unfamiliar locations

What is the risk level and detection type?

Risk Level: Medium

Detection Type: Real-time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Azure Active Directory - Sign-ins from IP addresses with suspicious activity

What is the risk level and detection type?

A

Azure Active Directory - Sign-ins from IP addresses with suspicious activity

What is the risk level and detection type?

Risk Level: Low

Detection Type: Real-time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Authentication Methods - Decision Tree

Password Hash Sync + Seamless SSO

A

Authentication Methods - Decision Tree

Password Hash Sync + Seamless SSO

  • Scenario 1
    • Azure AD to handle sign-ins

Flow Diagram

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Authentication Methods - Decision Tree

Pass-through Auth + Seamless SSO

A

Authentication Methods - Decision Tree

Pass-through Auth + Seamless SSO

  • Scenario 1
    • Azure AD to handle sign-ins
    • Enforcing Azure Directory security policies
  • Scenario 2
    • Sign-ins handled on-premise (not in the cloud)

Flow Diagram

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Authentication Methods - Decision Tree

Pass-through Auth + Seamless SSO with Password Hash Sync

A

Authentication Methods - Decision Tree

Pass-through Auth + Seamless SSO with Password Hash Sync

  • Scenario 1
    • Azure AD to handle sign-ins
    • Enforcing Azure Directory security policies
    • Disaster recovery needed or credential reports needed
  • Scenario 2
    • Sign-ins handled on-premise (not in the cloud)
    • Disaster recovery needed or credential reports needed

Flow Diagram

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Authentication Methods - Decision Tree

Federation

A

Authentication Methods - Decision Tree

Federation

  • Scenario 1
    • Azure AD to handle sign-ins
    • Sign-in requirement no supported by Azure
  • Scenario 2
    • Azure AD to handle sign-ins
    • Enforcing Azure Directory security policies
    • Sign-in requirement no supported by Azure
  • Scenario 3
    • Sign-ins handled on-premise (not in the cloud)
    • Integration with Federation provider

Flow Diagram

Note: If disaster recovery or credential reports is needed, then Federation with Password Hash Sync is required.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Authentication Methods - Decision Tree

Federation with Password Hash Sync

A

Authentication Methods - Decision Tree

Federation with Password Hash Sync

  • Scenario 1
    • Azure AD to handle sign-ins
    • Sign-in requirement no supported by Azure
    • Disaster recovery needed or credential reports needed
  • Scenario 2
    • Azure AD to handle sign-ins
    • Enforcing Azure Directory security policies
    • Sign-in requirement no supported by Azure
    • Disaster recovery needed or credential reports needed
  • Scenario 3
    • Sign-ins handled on-premise (not in the cloud)
    • Integration with Federation provider
    • Disaster recovery needed or credential reports needed

Flow Diagram

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly