Managing Azure AD Objects Flashcards
What are security groups used for?
Security groups are used to manage member and computer access to shared resources.
What are Microsoft 365 groups?
M365 groups facilitate collaboration opportunities.
What is the difference between manually assigning and dynamically assigning a user or device to a group?
Using the manual assignment option requires the admin to manually specify which users or devices should be members of a group. Dynamic User assignment allows you to define dynamic membership rules that will automatically add or remove group members.
Who can create and delete user accounts in the Azure portal?
Only Global Administrators or User Administrators can create and delete user accounts in the Azure portal.
What type of file is used to perform bulk operations?
CSV (Comma separated values) file
How many guest users can be invited for every Azure AD license?
5
What capabilities do guest users have access to?
Guest users have access to the capabilities that come with the license under which they were invited. If a guest was invited under a free license, they could potentially have access to the capabilities included in the free license agreement. Guests invited under a Premium P1 license could potentially have access to capabilities included in the P1 license agreement.
What is an Azure AD administrative unit?
An Azure AD resource that can be a container for other Azure AD resources. They allow you to divvy up roles and responsibilities when you have several independent divisions. They can be used to restrict administrative scopes. They can only contain users, groups, or devices.
Who can manage administrative units?
Only Global Admins and Privileged Role Administrators.
Where can you find a quick snapshot of stale devices, noncompliant devices, unmanaged devices as well as total number of devices?
Devices | Overview page
True or False:
A cloud identity can only be for user accounts defined in your Azure AD organization.
False
__________ are used to manage user and computer access to resources for groups of users or devices.
Security groups
True or False:
Administrative Units allow you to divvy up roles and responsibilities when you have several independent divisions.
True
True or False:
Being an Intune Administrator allows you to delete devices in Azure AD.
True
To delete a device, you must be a Cloud Device Administrator, Intune Administrator, Windows 365 Administrator, or Global Administrator in Azure AD.
The ______________ setting allows you to choose which users can register their devices as Azure AD joined devices.
Users may join devices to Azure AD