Manage identities and governance in Azure Flashcards

1
Q

What cloud service model does Microsoft Entra ID fall under?

A

Platform as a service (PaaS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the function of Microsoft Entra ID?

A

Microsoft-managed directory service in the cloud.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the advantages of Microsoft Entra ID compared to AD DS?

A

MFA, SSO, identity protection, and self-service password reset.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How does Microsoft Entra ID differ to AD DS?

A

Focused on providing IAM services to web-based apps, unlike AD DS, which is more focused on on-premises apps.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is an Entra ID domain referred to as?

A

A tenant.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Are organizations able to create multiple Entra ID tenants under a single subcription?

A

Yes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Must an Azure subscription be associated with an Entra tenant?

A

Yes; Every Azure subscription must be associated with only one Microsoft Entra tenant.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Can a single Entra tenant be associated with multiple Azure subscirptons?

A

Yes; Allows you to use the same users, groups, and applications to manage resources across multiple Azure subscriptions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Does an Entra tenant have a DNS name?

A

Yes; Each Microsoft Entra tenant is assigned the default DNS name, consisting of a unique prefix.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the prefix of an Entra tenant DNS name?

A

The prefix is the name derived from the Microsoft account used to create an Azure subscription or provided explicitly when creating an Entra tenant.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the full DNS naming convention of an Entra tenant?

A

prefix.onmicrosoft.com”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the purpose of Entra ID?

A

Acts as a security boundary and a container for Microsoft Entra objects such as users, groups, and applications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Describe the structure of Entra ID

A

Users and groups are created in a flat structure not a hierarchy, and there are no OUs or GPOs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What protocol(s) does Entra ID use for communication and authentication/authorizatoin?

A

HTTP/HTTPs via SAML, OAuth, etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How is the Entra ID directory service queried?

A

Uses the REST API over HTTP and HTTPS instead of LDAP(s)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Aside from the free instances of Entra ID that come with O365, what are the two versions of Entra ID?

A

Microsoft Entra ID P1 or P2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What are the two ways an organization can implement an Entra ID license?

A

You can procure it as an extra license or as a part of the Microsoft Enterprise Mobility + Security.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Define ‘Microsoft Identity Manager (MIM)’

A

Hybrid identity solution; Can bridge on-premises authentication stores such as AD DS, LDAP, Oracle, etc., with Microsoft Entra ID.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

How does Entra ID P2 differ from P1?

A
  1. Microsoft Entra ID Protection
  2. Microsoft Entra Privileged Identity Management
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What SLA does Microsoft guarantee for Entra ID?

A

Guaranteed at least 99.9% availability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Define ‘Microsoft Entra ID Protection’

A

Provides enhanced functionalities for monitoring and protecting user accounts; Define user risk policies and sign-in policies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Define Microsoft Entra Privileged Identity Management.’

A

Lets you configure additional security levels for privileged users such as administrators.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What are the 3 types of supported user accounts in Entra ID?

A
  1. Cloud identity
  2. Directory-synchronized identity
  3. Guest user
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Define a ‘Cloud identity’ user account type

A

A user account defined only in Microsoft Entra ID.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Define a ‘Directory-synchronized identity’ user account type

A

User accounts that are initially defined in an on-premises Active Directory synchronized through Entra Connect.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Define a ‘Guest user’ account type

A

Defined outside Azure.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

What is the purpose of a guest user?

A

Useful when external vendors or contractors need access to your Azure resources.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

Where is info and settings that describe a user stored?

A

In the user account profile.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

What are the two types of groups used to organize user accounts?

A
  1. Security groups
  2. Microsoft 365 groups
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

Define a ‘Microsoft 365 group’

A

Provide collaboration opportunities; Access to a shared mailbox, calendar, files, SharePoint site, and more.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

Describe a ‘Security group’ and its purpose

A

Used to manage access to resources based on user/device membership.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

What is best practice for configuring user access to resources?

A

Use security groups to set permissions for all group members at the same time, rather than adding permissions to each member individually.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

What is best practice for configuring guest access to resrouces?

A

Add Microsoft 365 groups to enable group access for guest users.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

What are the 3 access designation methods that can be used to determine user/device group membership?

A
  1. Assigned
  2. Dynamic user
  3. Dynamic device
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

Define an ‘assigned’ access right

A

Members of a group must be assigned manually.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

Define a ‘dynamic user’ access right

A

Dynamic membership rules automatically add and remove group members based on user attributes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

Define a ‘dynamic device’ access right

A

Dynamic membership rules automatically add and remove group members devices based on user attributes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

Can a dynamic device membership rule be applied to a Microsoft 365 group?

A

No; Security groups only.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

What is the purpose of an administrative unit?

A

For the division of roles and responsibilities.

40
Q

Define a ‘region’

A

A geographical area on the planet containing at least one, but potentially multiple datacenters.

41
Q

How many Azure regions are there?

A

Over 60

42
Q

What is Azure’s preferred distance between region pairs?

A

At least 300 miles.

43
Q

What Azure services don’t require a region/location?

A

Microsoft Entra ID, Microsoft Azure Traffic Manager, and Azure DNS.

44
Q

When deploying a service, what is to be considered when selecting a region?

A

Some services or Azure Virtual Machines features are available only in certain regions.

45
Q

Define an ‘Azure subscripton’

A

A logical unit of Azure services that’s linked to an Azure account.

46
Q

Can subscriptions have different billing and payment configurations?

A

Yes.

47
Q

Can multiple Azure accounts be linked to the same subscription?

A

Yes.

48
Q

What are the 3 ways to procure an Azure subscription?

A
  1. Enterprise agreement (EA)
  2. Microsoft reseller
  3. Microsoft partner
49
Q

What are the most common subscription types?

A

Free, Pay-As-You-Go, Enterprise Agreement, and Student.

50
Q

Define an ‘Enterprise agreement’

A

Suited for large organizations; Provides flexibility to buy cloud services and software licenses under one agreement; Comes with discounts and Software Assurance.

51
Q

What does a resource tag consist of?

A

Each resource tag has a name and a value.

52
Q

What is the max number of tags a resource/resource group can have?

A

Maximum of 50 tag name/value pairs.

53
Q

Are tags applied to a resource group inherited by the resources in the group?

A

No.

54
Q

Define ‘Azure Policy’

A

Service in Azure that enables you to create, assign, and manage policies to control or audit your resources.

55
Q

What is the purpose of Azure Policy?

A

Enforce different rules over your resource configurations so the configurations stay compliant with corporate standards and SLAs.

56
Q

What is the purpose of an Azure management group?

A

Provide a governance scope above subscriptions; Manage access, policy, and compliance across your subscriptions.

57
Q

When a new subscription is procured, where is it logically located?

A

By default, all new subscriptions are allocated to the root management group.

58
Q

Are policies inherited within a management group?

A

Yes; All subscriptions within a management group automatically inherit the conditions applied to that management group.

59
Q

Is a management group hierarchal?

A

Yes; A management group tree can support up to six levels of depth.

60
Q

How are management groups identified?

A

A management group has a directory unique identifier (ID) and a display name.

61
Q

Can the UID for a management group be changed?

A

No.

62
Q

Can Azure Policy perform remediation?

A

Yes; Conduct real-time remediation, and remediation on your existing resources.

63
Q

Define a ‘policy definition’

A

The compliance conditions for a resource, and the actions to complete when the conditions are met.

64
Q

Define an ‘initiative definition’

A

A set of policy definitions that help you track your resource compliance state to meet a larger goal.

64
Q

What are the 3 steps to create an azure policy?

A
  1. Create policy definitions
  2. Create an initiative definition
  3. Define the scope of initiative definition
64
Q

What are the two policy definition offerings?

A
  1. built-in policy definitions
  2. new/created policy definitions
65
Q

To satisfy the finance team’s request for billing by department, multiple resource groups have been created and the resource tags applied. What’s the next step?

A

Create an Azure policy; An Azure policy requires that a resource tag is applied before the resource is created.

66
Q

Define a ‘Security principal’

A

An object that requests access to resources; User, group, service principal.

67
Q

Define a ‘Role definition’

A

A set of permissions that lists the allowed operations; Reader, Contributor, Owner, User Access Administrator.

68
Q

Define an ‘RBAC scope’

A

The boundary for the requested level of access, or “how much” access is granted; Management group, subscription, resource group, resource

69
Q

What does a ‘role definition’ consist of?

A

Sets of permissions that are defined in a JSON file; Each permission set has its own name.

70
Q

What does an asterisk in in a role definition JSON file represent?

A

The asterisk “*” wildcard means “all” permissions.

71
Q

What built-in role has the highest level of access in Azure?

A

Owner

72
Q

In a role definition JSON file, how is effective permissions determined?

A

The system subtracts NotActions permissions from Actions permissions.

73
Q

In a role definition JSON file, what permission set determines granted access?

A

Actions.

74
Q

In a role definition JSON file, what permission set determines denied access?

A

NotActions.

75
Q

In a role definition JSON file, what permission set defines the scope; where the role definition is applied?

A

The AssignableScopes permission set; Can be management groups, subscriptions, resource groups, or resources.

76
Q

Define ‘role assignment’

A

The process of scoping a role definition to limit permissions for a requestor, such as a user, group, service principal, or managed identity.

77
Q

Define ‘Microsoft Entra admin roles’

A

Used to manage resources in Microsoft Entra ID, such as users, groups, and domains.

78
Q

Define ‘Azure RBAC roles’

A

Provide more granular access management for Azure resources.

79
Q

Define the contributor RBAC

A

The Contributor role can create and manage all types of Azure resources. This role can’t grant access to others.

80
Q

Define the User Access Administrator RBAC

A

The User Access Administrator role can manage user access to Azure resources.

81
Q

Define a member user

A

Native member of the Microsoft Entra organization that has a set of default permissions.

82
Q

What is the Azure CLI command to create a new user?

A

az ad user create

83
Q

What is the PowerShell command to create a new user?

A

New-MgUser

84
Q

What is the Azure CLI command to delete a user?

A

az ad user delete

85
Q

What is the PowerShell command to delete a new user?

A

Remove-MgUser

86
Q

What are the 3 ways to assign access rights?

A
  1. Direct assignment: Assign a user the required access
  2. Group assignment: Assign a group the required access rights
  3. Rule-based assignment
87
Q

By default, who can grant guest user access?

A

Users and administrators in Microsoft Entra ID can invite guest users, but the Global Administrator can limit or disable this ability.

88
Q

What is the advantage of Microsoft Entra B2B instead of federation?

A

With Microsoft Entra B2B, you don’t take on the responsibility of managing and authenticating partners’ credentials and identities.

89
Q

How do Azure subscriptions manage access?

A

The subscriptions use Microsoft Entra ID for single sign-on (SSO) and access management.

90
Q

What is Azure RABC built on?

A

An authorization system built on Azure Resource Manager that provides fine-grained access management for resources in Azure.

91
Q

What is the inheritance order for scope in Azure?

A

Management group, Subscription, Resource group, Resource.

92
Q

Suppose a team member can’t view resources in a resource group. Where would the administrator go to check the team member’s access?

A

Go to the resource group and select Access control (IAM) > Check Access.

93
Q

When is a user considered registered for SSPR?

A

When they’ve registered at least the number of methods that you’ve required to reset a password.