Understand Entra ID Flashcards

1
Q

A project manager is setting up a new project that includes members from different departments. The project manager wants to ensure that project team members can collaborate and have shared access to a mailbox, calendar, files, and the project’s SharePoint site.
Which Microsoft Entra feature can the project manager use to accommodate this requirement, without having to involve an administrator?

A

Microsoft 365 group

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

An organization has completed a full migration to the cloud and has purchased devices for all its employees. All employees sign in to the device through an organizational account configured in Microsoft Entra ID.
Select the option that best describes how these devices are set up in Microsoft Entra ID
- These devices are set up as Microsoft Entra registered
- These devices are set up as Microsoft Entra joined
- These devices are set up as Microsoft Entra hybrid joined

A

Microsoft Entra joined device
is a device joined to Microsoft Entra ID through an organizational account, which is then used to sign in to the device.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

A developer wants an application to connect to Azure resources that support Microsoft Entra authentication, without having to manage any credentials and without incurring any extra cost.
Which option best describes the identity type of the application?
* Service principal
* Managed identity
* Hybrid identity

A

**Managed identities **

They are a type of service principal that are automatically managed in Microsoft Entra ID and eliminate the need for developers to manage credentials.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is MS ENTRA?

A

Product family that covers all ID and access management within M365

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Name the 3 ID models for M365

A
  • Cloud ID
  • Hybrid ID
  • Federated ID
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are security groups?

A

Security groups are used for granting access to Microsoft 365 resources, such as SharePoint sites.

They can make administration easier because you need only administer the group rather than adding users to each resource individually.

Security groups can contain users or devices. Creating a security group for devices can be used with mobile device management services, such as Microsoft Intune.

Security groups can be configured for dynamic membership in Microsoft Entra ID, allowing group members or devices to be added or removed automatically based on user attributes such as department, location, or title; or device attributes such as operating system version.
Security groups can be added to a team.

Microsoft 365 Groups can’t be members of security groups.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are 365 groups ?

A

Microsoft 365 Groups are used for collaboration between users, both inside and outside your company.

With each Microsoft 365 group, members get a group email and shared workspace for conversations, files, and calendar events, Stream, and a Planner. Microsoft 365 Groups can also be connected to Teams or Viva Engage.

You can add people from outside your organization to a group as long as this has been enabled by the administrator. You can also allow external senders to send email to the group email address.

Microsoft 365 Groups can be configured for dynamic membership in Microsoft Entra ID, allowing group members to be added or removed automatically based on user attributes such as department, location, title, etc.

Microsoft 365 Groups support nesting through dynamic groups in Microsoft Entra ID.

Microsoft 365 Groups can be added to one of the three SharePoint groups (Owners, Members, or Visitors) to give people permissions to the site.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Microsoft Entra ID is a:
* IaaS
* SaaS
* PaaS

A

PaaS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is Microsoft Entra ID designed for?

A

Multi-tenant isolation between individual directory instances

Microsoft Entra ID is the world’s largest multi-tenant directory.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

From a technical standpoint, what does ‘tenant’ represent?

A

An individual Microsoft Entra instance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Why might having multiple Microsoft Entra tenants be convenient?

A

To test Microsoft Entra functionality in one tenant without affecting the others

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What allows you to grant permissions to resources in an Azure subscription?

A

Association with a Microsoft Entra tenant

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the default DNS domain name assigned to each Microsoft Entra tenant?

A

A unique prefix followed by onmicrosoft.com

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the prefix of the default DNS domain name derived from?

A

The name of the Microsoft account used to create an Azure subscription or provided explicitly during tenant creation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Is it possible to add custom domain names to a Microsoft Entra tenant?

A

Yes, adding at least one custom domain name is common

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What role does the Microsoft Entra tenant serve?

A

Security boundary and container for Microsoft Entra objects

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What types of objects can a Microsoft Entra tenant contain?

A
  • Users
  • Groups
  • Applications
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Can a single Microsoft Entra tenant support multiple Azure subscriptions?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is a notable difference between the Microsoft Entra schema and AD DS?

A

The Microsoft Entra schema contains fewer object types, notably lacking a definition for the computer class.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What class does the Microsoft Entra schema include that is absent in AD DS?

A

The device class.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What is a key feature of the Microsoft Entra schema regarding extensions?

A

The extensions of the Microsoft Entra schema are easily extensible and fully reversible.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Can Microsoft Entra ID manage computers using traditional techniques like Group Policy Objects?

A

No, the lack of support for traditional computer domain membership prevents this.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What does Microsoft Entra ID primarily provide?

A

Directory services, storing and publishing user, device, and application data, and handling authentication and authorization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What cloud service relies on Microsoft Entra ID as its identity provider?

A

Microsoft 365.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

What class is not included in Microsoft Entra ID that is often used in on-premises AD DS deployments?

A

The organizational unit (OU) class.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Why is the lack of organizational units (OUs) in Microsoft Entra ID not considered a significant shortcoming?

A

OUs in AD DS are primarily used for Group Policy scoping and delegation, they can be accomplished in Entra by organizing objects based on group membership.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

What do objects of the Application and servicePrincipal classes represent in Microsoft Entra ID?

A

Applications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

What does an object in the Application class contain?

A

An application definition.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

What constitutes an instance of an application in the current Microsoft Entra tenant?

A

An object in the servicePrincipal class.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

What is the benefit of separating application definitions and service principal objects?

A

It allows defining an application in one tenant and using it across multiple tenants.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

What action does Microsoft Entra ID perform when you register an application in a tenant?

A

It creates the service principal object for the application in that Microsoft Entra tenant.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

What is Active Directory Domain Services (ADDS)?

A

AD DS is the traditional deployment of Windows Server-based Active Directory on a physical or virtual server.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

What components are included in the Windows Active Directory suite of technologies?

A
  • Active Directory Certificate Services (AD CS)
  • Active Directory Lightweight Directory Services (AD LDS)
  • Active Directory Federation Services (AD FS)
  • Active Directory Rights Management Services (AD RMS)
34
Q

What type of structure does AD DS have?

A

AD DS has a hierarchical X.500-based structure.

35
Q

What protocol does AD DS use for locating resources?

A

AD DS uses Domain Name System (DNS) for locating resources such as domain controllers.

36
Q

How can you query and manage AD DS?

A

You can query and manage AD DS by using Lightweight Directory Access Protocol (LDAP) calls.

37
Q

What protocol does AD DS primarily use for authentication?

A

AD DS primarily uses the Kerberos protocol for authentication.

38
Q

What management structures does AD DS utilize?

A

AD DS uses OUs and GPOs for management.

39
Q

What do computer objects in AD DS represent?

A

Computer objects represent computers that join an Active Directory domain.

40
Q

How does AD DS facilitate delegated management between domains?

A

AD DS uses trusts between domains for delegated management.

41
Q

Can you deploy AD DS on an Azure virtual machine?

A

Yes, you can deploy AD DS on an Azure virtual machine to enable scalability and availability for an on-premises AD DS.

42
Q

Does deploying AD DS on an Azure virtual machine utilize Microsoft Entra ID?

A

No, deploying AD DS on an Azure virtual machine doesn’t make any use of Microsoft Entra ID.

43
Q

What is the primary function of Microsoft Entra ID?

A

Identity solution designed for internet-based applications

44
Q

What communication protocols does Microsoft Entra ID use?

A

HTTP (port 80) and HTTPS (port 443)

45
Q

What type of directory service is Microsoft Entra ID?

A

Multi-tenant directory service

46
Q

How are users and groups structured in Microsoft Entra ID?

A

Flat structure without OUs or GPOs

47
Q

Can Microsoft Entra ID be queried using LDAP?

A

No, it uses REST API over HTTP and HTTPS

48
Q

What authentication methods does Microsoft Entra ID employ?

A

SAML, WS-Federation, and OpenID Connect

49
Q

What authorization protocol is used by Microsoft Entra ID?

50
Q

Does Microsoft Entra ID use Kerberos authentication?

51
Q

Which third-party service is mentioned as being federated with Microsoft Entra ID?

52
Q

True or False: Microsoft Entra ID is the same as deploying an Active Directory domain controller on Azure.

53
Q

What is required for cloud services like Microsoft 365 or Intune?

A

Directory services in the cloud for authentication and authorization

54
Q

What identity service covers all Microsoft cloud-based services?

A

Microsoft Entra ID

55
Q

What does Microsoft Entra ID provide for applications in Azure?

A

Centralized authentication and authorization

56
Q

What user experience does Microsoft Entra ID provide when using certain applications?

A

SSO experience

57
Q

Which applications can provide SSO experience with Microsoft Entra ID?

A
  • Facebook
  • Google services
  • Yahoo
  • Microsoft cloud services
58
Q

Where can you enable Microsoft Entra authentication in Azure App Service?

A

Authentication/Authorization blade in the Azure portal

59
Q

What can you ensure by designating the Microsoft Entra tenant?

A

Only users with accounts in that directory can access the website

60
Q

6

Which services are included in MS Entra free version?

A
  • User and group management
  • On-premises directory synchronization
  • Basic reports
  • Self-service password change for cloud users
  • Single sign-on across Azure, Microsoft 365, and many popular SaaS apps
  • MFA
61
Q

9

Which features are available in MS ENTRA P1 version ?

A
  • All features in MS Entra free version
  • Self-service group management.
  • Advanced security reports and alerts.
  • Full Multi-factor authentication.
  • Microsoft Identity Manager (MIM) licensing.
  • Enterprise SLA of 99.9%.
  • Password reset with writeback.
  • Cloud App Discovery feature of Microsoft Entra ID.
  • Microsoft Entra Connect Health.
62
Q

What is Self-service group management feature?

A
  • simplifies the administration of groups
  • users are given the rights to create and manage the M365 groups.
  • End users can create requests to join other M365 groups, and group owners can approve requests and maintain their groups’ memberships.
63
Q

What are the benefits of the feature Advanced security reports and alerts

A

You can monitor and protect access to your cloud applications by viewing detailed logs that show advanced anomalies and inconsistent access pattern reports.
Advanced reports are machine learning based and can help you gain new insights to improve access security and respond to potential threats.

64
Q

What is Microsoft Identity Manager feature?

A
  • provides hybrid identity solutions.
  • can bridge multiple on-premises authentication stores such as AD DS, LDAP, Oracle, and other applications with Microsoft Entra ID.
  • This provides consistent experiences to on-premises line-of-business (LOB) applications and SaaS solutions.
65
Q

What is Password reset with writeback feature?

A

Self-service password reset follows the Active Directory on-premises password policy.

66
Q

3

Which features are available in MS ENTRA P2 version ?

A
  • All features in free and P1
  • Microsoft Entra ID Protection
  • Microsoft Entra Privileged Identity Management.
67
Q

What is Microsoft Entra ID Protection feature?

A

provides enhanced functionalities for monitoring and protecting user accounts.
You can define user risk policies and sign-in policies.
In addition, you can review users’ behavior and flag users for risk.

68
Q

What is Microsoft Entra Privileged Identity Management functionality?

A

lets you configure additional security levels for privileged users such as administrators.
you define permanent and temporary administrators.
You also define a policy workflow that activates whenever someone wants to use administrative privileges to perform some task.

69
Q

What is one key issue when moving LOB applications to Azure?

A

Providing authentication services to these apps

70
Q

What service does Microsoft provide as an alternative to traditional authentication methods?

A

Microsoft Entra Domain Services

71
Q

What does Microsoft Entra Domain Services provide?

A

Domain services such as Group Policy management, domain joining, and Kerberos authentication

72
Q

What tiers of Microsoft Entra ID include Microsoft Entra Domain Services?

A

P1 or P2 tier

73
Q

How does Microsoft Entra ID integrate with local AD DS?

A

Through Microsoft Entra Connect

74
Q

What are the 3 benefits of using Microsoft Entra Domain Services?

A
  • Administrators don’t need to manage, update, and monitor domain controllers.
  • Administrators don’t need to deploy and manage Active Directory replication.
  • There’s no need to have Domain Admins or Enterprise Admins groups for domains that Microsoft Entra ID manages.
75
Q

What limitations exist in Microsoft Entra Domain Services?

A
  • Only the base computer Active Directory object is supported.
  • not possible to extend the schema for the Microsoft Entra Domain Services domain.
  • The organizational unit (OU) structure is flat and nested OUs aren’t currently supported.
  • There’s a built-in Group Policy Object (GPO), and it exists for computer and user accounts.
  • It’s not possible to target OUs with built-in GPOs. Additionally, you can’t use Windows Management Instrumentation filters or security-group filtering.
76
Q

What is the structure of the organizational unit (OU) in Microsoft Entra Domain Services?

A

Flat; nested OUs aren’t currently supported

77
Q

What type of Group Policy Object (GPO) exists in Microsoft Entra Domain Services?

A

A built-in GPO for computer and user accounts

78
Q

What protocols can applications that use Microsoft Entra Domain Services migrate to the cloud utilize?

A

LDAP, NTLM, or Kerberos

79
Q

What applications can be deployed in Azure IaaS without needing domain controllers in the cloud?

A

Microsoft SQL Server or Microsoft SharePoint Server

80
Q

How can you enable Microsoft Entra Domain Services?

A

Using the Azure portal

81
Q

How is the cost for Microsoft Entra Domain Services calculated?

A

Per hour based on the size of your directory