Manage Microsoft Entra identities Flashcards

1
Q

What operational model does Microsoft Entra ID follow?

A

SaaS operational model

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does Microsoft Entra ID lack support for?

A

Computer objects and management capabilities via Group Policy settings

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

List 5 admin built-in roles available in Microsoft Entra ID.

A
  • Global Administrator
  • Billing Administrator
  • Service Administrator
  • User Administrator
  • Password Administrator
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Who is assigned as the Global Administrator by default?

A

Account Administrator of the subscription hosting the Microsoft Entra instance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What can be delegated in Microsoft Entra ID?

A

Permissions to applications to act on behalf of users and groups

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which edition of Microsoft Entra ID allows dynamic group membership based on user attributes?

A

Microsoft Entra ID P1 edition

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What features does the Premium P2 edition of Microsoft Entra ID introduce?

A
  • Self-service group management
  • Privileged Identity Management (PIM)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How can users access Microsoft Entra applications?

A

Using the web-based portal, My Apps, at https://myapps.microsoft.com

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a benefit of using the My Apps portal?

A

Support for SSO (Single Sign-On)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What three built-in roles does the Azure delegation model utilize?

A
  • Owner
  • Contributor
  • Reader
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a limitation of Microsoft Entra ID regarding object arrangement?

A

Doesn’t include the OU class for hierarchical arrangement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What types of accounts can be used with Microsoft Entra ID?
3

A
  • Organizational account created by tenant administrator
  • Account referencing an organizational account in other Microsoft Entra instances
  • Microsoft account
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What role must you have to manage Microsoft Entra ID?

A

Global Administrator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Who can sign in to the Azure portal?

A

Tenant administrator or co-administrator configured by the tenant administrator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What role do tenant administrators and co-administrators automatically receive?

A

Global Administrator role in the Active Directory instance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What access does the Global Administrator role provide?

A

Access to all administrative features and settings

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What can the Password Administrator role do?

A

Reset passwords for users and manage service requests

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What role can manage billing information in Microsoft Entra ID?

A

Billing Administrator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Which role can manage user accounts and groups?

A

User Administrator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Which role is responsible for managing compliance settings?

A

Compliance Administrator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What is the default role in Microsoft Entra ID?

A

User

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Which security roles can be configured using Privileged Identity Management?

A
  • Security reader
  • Security administrator
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What can you manage using the Entra portal?

A

Microsoft Entra users, groups, and devices

This includes adding users to a directory and groups.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What are the two types of user accounts you can create on the Entra portal?

A
  • Member users
  • Guest users

Member users are managed by your Microsoft Entra tenant, while guest users are not.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

What are member users?

A

Accounts that your Microsoft Entra tenant manages

Member users are the most commonly created user type.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

What are guest users?

A

Accounts that your Microsoft Entra tenant doesn’t manage, but permissions are assigned

Guest users can be members from another Microsoft Entra tenant or a Microsoft account.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

How are guest user accounts often created?

A

Automatically when users share content with external users

For example, sharing a OneDrive file creates a guest user account.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

What are the two ways to create and manage users?

A
  • As cloud identities using Microsoft Entra ID
  • As directory-synchronized identities using an on-premises directory service

The second method requires synchronization software.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

What is the quickest method to create users in Microsoft Entra?

A

As cloud identities using only Microsoft Entra ID

This method is straightforward.

30
Q

What does the directory-synchronized identity method involve?

A

Using an on-premises directory service to synchronize with Microsoft Entra ID

This method is more complex due to synchronization software.

31
Q

What does the Azure portal provide for user management?

A

A simple web interface for creating and managing users, groups, and devices

This interface simplifies the management process.

32
Q

What do Microsoft Entra groups streamline?

A

Access management

33
Q

What happens when directory synchronization is enabled?

A

On-premises AD DS groups can be synchronized to Microsoft Entra ID

34
Q

What remains consistent between AD DS and Microsoft Entra ID?

A

Group membership

35
Q

What type of management is used if directory synchronization isn’t in place?

A

Cloud-based group management

36
Q

What are the two primary types of groups in Microsoft Entra ID?

A
  • Security
  • Microsoft 365
37
Q

What is the purpose of a security group in Microsoft Entra ID?

A

To manage resource access

38
Q

How does managing a security group affect access?

A

It indirectly manages access based on group membership

39
Q

Are Microsoft Entra security groups mail-enabled?

40
Q

What services do Microsoft 365 groups facilitate access management for?

A
  • Microsoft Teams
  • SharePoint
  • Outlook
41
Q

What is a characteristic of Microsoft 365 groups?

A

They are mail-enabled

42
Q

How do you create a group in Azure?

A

Navigate to Microsoft Entra ID > Groups > New group on the Azure portal

43
Q

What options can you specify when creating a group in Azure?

A
  • Group type
  • Name
  • Description
44
Q

What type of membership can be assigned to a cloud-based group?

A
  • Assigned
  • Dynamic
45
Q

What does assigned membership require?

A

Manual addition and removal of group members

46
Q

What is a characteristic of dynamic membership?

A

Members are based on a query of Microsoft Entra objects

47
Q

On what can dynamic membership be based?

A
  • Single attribute
  • Advanced membership rule with multiple attributes
48
Q

When creating a group with dynamic membership, what must you select?

A

Whether it’s for users or devices

49
Q

Which Microsoft 365 feature uses user-based groups?

A

Many features

50
Q

Which service uses device-based groups?

51
Q

What happens to groups from on-premises AD DS with dynamic membership?

A

They don’t synchronize with Microsoft Entra ID

52
Q

What is the purpose of directory synchronization between Microsoft Entra ID and on-premises AD DS?

A

To enable user, group, and contact synchronization between on-premises Active Directory and Microsoft Entra ID.

53
Q

What component is installed to perform directory synchronization?

A

A directory synchronization component on a server in your on-premises domain.

54
Q

With Microsoft Entra ID Free or Basic, what is the direction of the synchronization flow?

A

From local AD DS to Microsoft Entra ID.

55
Q

What additional capability is provided by Microsoft Entra ID P1 or P2 regarding synchronization?

A

The ability to replicate some attributes from Microsoft Entra ID to Active Directory DS.

56
Q

What is Microsoft Entra Connect used for?

A

To perform directory synchronization between Microsoft Entra ID and AD DS.

57
Q

What are the default settings for Microsoft Entra Connect?

A

Synchronizes all users and groups.

58
Q

What filtering options are available for directory synchronization?

A
  • OU
  • Domain
  • User attributes
  • Applications
59
Q

What happens when a user identity is synchronized without the password?

A

The cloud-based user account will have a separate unique password.

60
Q

What is the benefit of enabling password synchronization?

A

Allows users to authenticate using the same credentials.

61
Q

What is pass-through authentication?

A

Microsoft Entra ID verifies that the user is valid and passes the authentication request to Microsoft Entra Connect.

62
Q

What advantage does federated identities provide?

A

Claims-based authentication that multiple cloud-based apps can use.

63
Q

What permissions are required when installing Microsoft Entra Connect?

A

Local Administrator on the installation computer, enterprise administrators group for local AD DS,
global administrator for Microsoft Entra ID.

64
Q

What is necessary for the computer running Microsoft Entra Connect to communicate with Microsoft Entra ID?

A

The computer must have internet access, possibly requiring proxy server configuration.

65
Q

Where must Microsoft Entra Connect be installed?

A

On a domain member.

66
Q

Which installation option is typically used for organizations synchronizing a single AD DS forest?

A

Express settings.

67
Q

What does selecting express settings during Entra Connect installation include?

A
  • SQL Server Express installed
  • All identities in the forest synchronized
  • All attributes synchronized
  • Password synchronization enabled
  • Initial synchronization performed immediately
  • Automatic upgrade enabled
68
Q

What options can be enabled during Entra Connect custom settings installation?

A
  • Pass-through authentication
  • Federation with AD FS
  • Select an attribute for matching existing cloud-based users
  • Filtering based on OUs or attributes
  • Exchange hybrid
  • Password, group, or device writeback
69
Q

What occurs after deploying Microsoft Entra Connect with respect to new objects?

A

New user, group, and contact objects in on-premises Active Directory are added to Microsoft Entra ID.

70
Q

What happens to modified attributes of existing objects in on-premises Active Directory?

A

They are modified in Microsoft Entra ID.

71
Q

What occurs when existing user objects are disabled on-premises?

A

They are disabled in Azure, but licenses aren’t automatically unassigned.