Microsoft Entra Groups Flashcards
To study how Microsoft Entra Groups work
Group Type: Used to manage user and computer access to shared resources. For example, you can create a ______ group so that all group members have the same set of security permissions. Members of a ______ group can include users, devices, service principals, and other groups (also known as nested groups), which define access policy and permissions. Owners of a security group can include users and service principals.
Security
Group Type: provides collaboration opportunities by giving group members access to a shared mailbox, calendar, files, SharePoint sites, and more. This option also lets you give people outside of your organization access to the group. Members of a ______ group can only include users. Owners of a ________ group can include users and service principals.
Microsoft 365
Membership type: Lets you add specific users as members of a group and have unique permissions.
Assigned
Membership type: Lets you use dynamic membership rules to automatically add and remove members. If a member’s attributes change, the system looks at your dynamic group rules for the directory to see if the member meets the rule requirements (is added), or no longer meets the rules requirements (is removed).
Dynamic user
Membership type: Lets you use dynamic group rules to automatically add and remove devices. If a device’s attributes change, the system looks at your dynamic group rules for the directory to see if the device meets the rule requirements (is added), or no longer meets the rules requirements (is removed).
Dynamic device
The resource owner directly assigns the user to the resource
Direct assignment
The resource owner assigns a Microsoft Entra group to the resource, which automatically gives all of the group members access to the resource. Group membership is managed by both the group owner and the resource owner, letting either owner add or remove members from the group.
Group assignment
The resource owner creates a group and uses a rule to define which users are assigned to a specific resource. The rule is based on attributes that are assigned to individual users. The resource owner manages the rule, determining which attributes and values are required to allow access the resource.
Rule-based assignment
Access comes from an external source, such as an on-premises directory or a SaaS app. In this situation, the resource owner assigns a group to provide access to the resource and then the external source manages the group members.
External authority assignment