Manage Microsoft Entra Identities Flashcards

1
Q

What does RBAC stand for?

A

Role-Based Access Control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

True or false: Entra ID supports management via GPO settings

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which Entra ID tier includes self-service group management and PIM?

A

Entra ID Premium P2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How can Entra users access Entra apps using the web portal?

A

myapps.microsoft.com

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the 3 built-in roles that the Azure RBAC mechanism is built on?

A

Owner / Contributor / Reader

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Why is it recommended to use organisational accounts to manage an Entra tenant?

A

To avoid mixing authentication methods

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What type of Entra group can be used as an email distribution list?

A

Microsoft 365 Group

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

True or false: groups from on-prem AD-DS with dynamic membership don’t sync with Entra ID

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which version of Powershell is recommended for use with the MS Graph Powershell SDK?

A

Powershell 7

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the Powershell command to install the Graph SDK?

A

Install-Module -Name Microsoft.Graph -Scope CurrentUser

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What cmdlet is used to connect the Powershell Graph SDK to Entra?

A

Connect-MgGraph

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

For which Entra ID tiers is on-prem directory sync only one-directional?

A

Entra ID Free/Basic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

True or false: By default, Entra connect syncs all users and groups

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is pass-through authentication in the context of directory sync?

A

True SSO: Entra ID uses cloud identities to verify validity, and passes authentication to Entra Connect.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is a synchronised password in the context of directory sync?

A

When an AD-DS User password syncs with the entity in Entra ID

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is is a separate cloud password in the context of directory sync?

A

When a user identity is synced but not its password, requiring a separate unique password for the cloud-based user

17
Q

What are federated identities in the context of directory sync?

A

AD-FS performs authentication on-prem instead of using Entra Connect, providing claims-based authentication that multiple cloud-based apps can use

18
Q

True or false: a computer running Entra Connect requires inbound internet connectivity

A

False - Entra Connect initiates all communication

19
Q

When installing Entra connect, should an organisation syncing a single AD-DS forest with an Entra tenant use Express or Custom settings?

A

Express

20
Q

When installing Entra Connect using Express settings, what settings are configured? (6)

A

-SQL server Express is installed
-All identities in the forest are synced
-All attributes are synced
-Password sync is enabled
-An initial sync is performed immediately after install
-Automatic upgrade is enabled

21
Q

When installing Entra Connect with Custom settings, what settings are available? (5)

A

-Pass-through authentication
-Federation with AD-FS
-Filtering based on OUs or attributes
-Exchange Hybrid
-Password, group and device writeback

22
Q

What is Pass-through authentication?

A

When users sign in to applications by validating their passwords directly against on-premises Active Directory

23
Q

What is Exchange Hybrid?

A

Extending on-prem Exchange servers to Exchange Online

24
Q

True or false: Entra connect automatically assigns licenses for MS365 services from on-prem AD to synced Entra ID objects

A

False

25
Q

True or false: not all on-prem AD attributes sync with Entra ID

A

True

26
Q

True or false: existing user, group and contact objects that are deleted from on-prem AD are deleted from Entra ID

A

True

27
Q

True or false: existing user objects that are disabled on-prem are disabled in Azure

A

True (but licenses aren’t automatically unassigned).