Manage identity and access Flashcards

1
Q

What is Microsoft Entra ID?

A

a cloud based identity and access management service that enables your employees access external resources.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Resources that employees can access with Microsoft Entra ID

A

Microsoft 365
Azure portal
SaaS applications

apps on corporate intranet
cloud apps developed for you own organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Who uses Microsoft Entra ID?

A

IT admins

App Developers

Microsoft 365, Office 356, Azure, or Dynamics CRM Online subscribers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are Microsoft Entra ID licenses?

A

add paid features by upgrading to P1 or P2 licenses.

licenses provide self-service, enhanced monitoring, security reporting, and secure access for mobile users

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

T or f

If you subscribe to any Microsoft Online business service, you automatically get access to Microsoft Entra ID Free

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

T or F

To enhance your Microsoft Entra implementation, you can also add paid features by upgrading to Microsoft Entra ID P1 or Premium P2 licenses

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

T or F

Microsoft Entra paid licenses are built on top of your existing free directory

A

true

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Microsoft Entra ID Free

A

user and group management
on premises directory synchronization
basic reports
self service password change for cloud users
single sign on across Azure
Microsoft 365
many SaaS apps

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Microsoft Entra ID P1

A

in addition to the free features -

lets hybrid users access both on premises and cloud resources

supports advanced administration - such as dynamic groups, self-service group management, Microsoft Identity Manager, and cloud write-back capabilities which allow self-service password reset for your on-premises user

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Microsoft Entra ID P2

A

In addition to the Free and P1 features

offers Microsoft Entra ID Protection to help provide risk-based Conditional Access to your apps and critical company data and Privileged Identity Management to help discover, restrict, and monitor administrators and their access to resources and to provide just-in-time access when needed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Pay as you go - feature licenses

A

such as Business-to-Customer (B2C).

B2C can help you provide identity and access management solutions for your customer-facing apps.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Which features work in Microsoft Entra ID?

A

Application management

Authentication

Microsoft Entra ID for developers

B2B

B2C

Conditional Access

Device Management

Domain Services

Enterprise Users

Hybrid Identity

Identity governance

Identity protection

Managed identities for Azure resources

Privileged identity management (PIM)

Monitoring and health

Workload identities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

T or F

Microsoft Entra ID allows you to create several types of users in your tenant, which provides greater flexibility in how you manage your organization’s users.

A

true

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

t or f

Global Administrator can create users and assign roles

A

true

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

t or f

The required role of least privilege varies based on the type of user you’re adding and if you need to assign Microsoft Entra roles at the same time

A

true

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Microsoft Entra users:

Task - create a new user.

What is the role?

A

role - User Administrator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Microsoft Entra users:

Task - Invite an external guest

What is the role?

A

role - Guest Inviter

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Microsoft Entra users:

Task - Assign Microsoft Entra roles

What is the role?

A

role - Privileged Role Administrator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Type of users

A

Internal member

internal guest

external member

external guest

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Internal member

A

most likely full time employees

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Internal guest

A

account in your tenant but have guest level privileges

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

External member

A

authenticate using an external account but have member access to your tenant.

  • common in multitenant organizations
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

External guest

A

true guest of your tenant who authenticate using an external method and who have guest level privileges

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

t or f

Internal guest and members have credentials in your Microsoft Entra tenant that can be managed by administrators

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

T or F

External members authenticate to their home Microsoft

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

How to create a new user in Microsoft Entra ID

A

sign in to the Microsoft Entra admin center as a USER Administrator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

T or F

With Microsoft Entra you can grant access and permissions to a group of users instead of each individual

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

The groups that can’t be managed in the Azure portal

A

Groups synced from on-premises Microsoft Entra ID can be managed only in on-premises Microsoft Entra ID.

Distribution lists and mail-enabled security groups are managed only in Exchange admin center or Microsoft 365 admin center. You must sign in to Exchange admin center or Microsoft 365 admin center to manage these groups.

29
Q

Microsoft Entra ID lets you use groups to manage access to applications, data, and resources. Resources can be:

A

Part of the Microsoft Entra organization, such as permissions to manage objects through roles in Microsoft Entra ID

External to the organization, such as for Software as a Service (SaaS) apps

Azure services

SharePoint sites

On-premises resources

30
Q

How many group types are there?

A

2

Security - used to manage user and computer access to shared resources

Microsoft 365 - provides collaboration opportunities by giving group members access to shared mailbox, calendar, files, SharePoint sites, and more

31
Q

How many group membership types are there?

A

3

Assigned - Lets you add specific users as members of a group and have unique permissions

Dynamic user - Lets you use dynamic membership rules to automatically add and remove members

Dynamic device - Lets you use dynamic group rules to automatically add and remove devices

32
Q

t of f

Each application, resource, and service that requires access permissions needs to be managed separately.

A

true

permissions for one may not be the same for the other

33
Q

How access management in Microsoft Entra ID works

A

Microsoft Entra ID helps you give access to your organization’s resources by providing access rights to a single user or to an entire Microsoft Entra group

34
Q

Ways to assign access rights

A

Direct assignment
Group assignment
Rule based assignment
External authority assignment

35
Q

T or F

The group owner can let users find their own groups to join, instead of assigning them

A

True

36
Q

T or F

the owner can set up the group to automatically accept all users that join or to require approval

A

true

37
Q

Recommend when to use external identities

A

B2B collaboration - with Microsoft Entra External ID you can invite guest users to collaborate with your organization

38
Q

T or F

With Microsoft Entra B2B, the partner uses their own identity management solution, so there’s no external administrative overhead for your organization

A

True

The partner uses their own identities and credentials, whether or not they have a Microsoft Entra account.

You don’t need to manage external accounts or passwords.

You don’t need to sync accounts or manage account lifecycles.

39
Q

With B2B collaboration with other Microsoft Entra organizations you can control and manage settings such as

A

managed inbound and outbound B2B collab

scope access to specific users, group, and applications

MFA

cross tenant access

device claims

40
Q

t or F

You can use external collaboration settings to define who can invite external users, allow or block B2B specific domains, and set restrictions on guest user access to your directory.

A

True

41
Q

t or f

Use Microsoft cloud settings to establish mutual B2B collaboration between the Microsoft Azure global cloud and Microsoft Azure Government or Microsoft Azure operated by 21Vianet.

A

True

42
Q

What is self-service sign up

A

a self-service sign-up user flow, you can create a sign-up experience for external users who want to access your apps

43
Q

t or f

You can delegate guest user management to application owners so that they can add guest users to any app

A

True

44
Q

t or f

Non-administrators use their Access Panel to add guest users to applications or groups.

A

true

45
Q

t or f

Administrators set up self-service app and group management.

A

true

46
Q

how do non administrators add guest users to applications or groups?

A

Access panel

47
Q

How to customize the onboarding experience for B2B guest users

A

Use Microsoft Entra entitlement management to configure policies that manage access for external users.

Use the B2B collaboration invitation APIs to customize your onboarding experiences.

48
Q

Integrate with identity providers

A

external users can sign in with their existing social or enterprise accounts instead of creating a new account just for your application

49
Q

Integrate with SharePoint and OneDrive

A

to share files, folders, list items, document libraries, and sites with people outside your organization, while using Azure B2B for authentication and management

50
Q

Secure external identities

A

managed access with Microsoft Entra ID or Microsoft Entra B2C

51
Q

the following capabilities make up External Identities

A

B2B collab

B2B direct connect

Microsoft Entra B2C

Microsoft Entra multitenant organization

52
Q

B2B collaboration

A

Collaborate with external users by letting them use their preferred identity to sign in to your Microsoft applications or other enterprise applications

  • typically guest users
53
Q

B2B direct connect

A

Establish a mutual, two-way trust with another Microsoft Entra organization for seamless collaboration

54
Q

Microsoft Enter B2C

A

Publish modern SaaS apps or custom-developed apps (excluding Microsoft apps) to consumers and customers, while using Microsoft Entra B2C for identity and access management

55
Q

Microsoft Entra multitenant organization

A

Collaborate with multiple tenants in a single Microsoft Entra organization via cross-tenant synchronization

56
Q

T or F

With B2B collaboration you can invite anyone to sign in to your Microsoft Entra organization using their own credentials

A

True

57
Q

Ways to add external users to your organization for B2B collaboration

A

invite users with them using their Microsoft Entra accounts

use self service sign up

Microsoft Entra entitlement management

58
Q

Microsoft Entra Identity protection

A

helps organizations detect, investigate, and remediate identity based risks

59
Q

Detect risks from?

A

Active Directory
Microsoft Accounts
gaming - Xbox

60
Q

Identity Protection provides three key reports for administrators to investigate risks and take action:

A

Risk detections - Each risk detected is reported as a risk detection

Risky sign ins - A risky sign-in is reported when there are one or more risk detections reported for that sign-in.

Risky users - A Risky user is reported when either or both of the following are true:
The user has one or more Risky sign-ins.
One or more risk detections have been reported.

61
Q

Automatic remediation

A

Risk-based Conditional Access policies can be enabled to require access controls such as providing a strong authentication method, perform multifactor authentication, or perform a secure password reset based on the detected risk level. If the user successfully completes the access control, the risk is automatically remediated.

62
Q

Manual remediation

A

When user remediation isn’t enabled, an administrator must manually review them in the reports in the portal, through the API, or in Microsoft 365 Defender.

Administrators can perform manual actions to dismiss, confirm safe, or confirm compromise on the risks.

63
Q

making use of the data

A

Data from Identity Protection can be exported to other tools for archive, further investigation, and correlation.

64
Q

A company wants to collaborate with a vendor outside of their organization. Which capability of Microsoft Entra External ID should they use?

A

b2b collab

65
Q

An organization wants to enable automatic remediation for identity-based risks detected by Microsoft Entra ID Protection. What access controls can be required based on the detected risk level?

A

Providing a strong authentication method, performing multifactor authentication, or performing a secure password reset

66
Q

A User Administrator wants to add a new user to their Microsoft Entra ID organization. What steps should they follow?

A

Sign in to the Azure portal in the User Administrator role, navigate to Microsoft Entra ID Users, and select either Create new user or Invite external user from the menu.

67
Q

A company wants to manage identity and access for external users at scale by automating access request workflows, access assignments, reviews, and expiration. Which feature should they use?

A

Microsoft Entra entitlement management

68
Q

A company wants to create a sign-up experience for external users who want to access their apps. What options can they provide as part of the sign-up flow?

A

Providing options for different social or enterprise identity providers.