Manage Identity and Access Flashcards
How many directory objects can you have in the free AD plan?
500.000
Which four editions does Azure AD come in?
Free, Microsoft 365 Apps, Premium 1, Premium 2
What are the different ways to query Azure AD and Active Directory Domain Services?
Azure Ad is designed for HTTP/Https and queried via REST APIs.. Active Directory Domain Services are queried via LDAP
Organizational Units (OU’s) and Group Policy (GPO’s) exist in Azure AD or Active Directory Domain Services
Organizational Units (OUs) and Group Policy Objects (GPOs are in Active Directory Domain Services.
Azure AD has a flat structure with users/groups.
Are both Azure AD and Active Directory Domain Services for cloud?
No Active Directory Domain Services are for On-premises
What AD service supports Kerberos authentication?
Active Directory Domain Services.
Where can user permissions be changed?
The default user permissions can be changed only in user settings in Azure AD
Which role can read and modify every administrative setting in your Azure AD org?
Global administrator role
Which role can set or reset any auth method for non-admins and some other roles?
Authentication Administrator
Explain the traditional vs new security preimeter and who is responsible for securing?
Traditionally entrance and exit points of a network was the primary security perimeter.
With the rise of the internet the privileged administrative accounts are now effectively in control of this new security perimeter
What is LDAP?
Lightweight Directory Access Protocol
Azure AD DS is compatible with what?
Windows Service Active Directory
Explain how Azure AD DS can work with on-premise or cloud
It automatically replicates identity information from Azure AD or it can be synchronized with an on-prem Azure AD DS env.
Which three Azure AD identities exist?
Cloud identities (exist only in Cloud), Directory-synced identities (exist in on-prem AD) and Guest ussers (Exist outside of azure for example other cloud providers)
How are on-prem users synced with Azure AD?
Occurs via Azure AD Connect