Understand Microsoft Entra ID Flashcards

1
Q

What type of service is Entra ID?

A

Platform as a Service (PaaS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

True or false: an Azure subscription must be associated with one, and only one, Microsoft Entra tenant

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

True or false: one Entra tenant cannot be associated with multiple Azure subscriptions

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the default DNS domain name that each Entra tenant is assigned?

A

.onmicrosoft.com

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Does the Microsoft Entra schema contain more or fewer object types than that of AD-DS?

A

Fewer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

For which notable class does the Entra schema NOT include a definition?

A

Computer class

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

True or false: Entra ID includes the organisational unit class

A

False

Therefore you can’t organise its units into a hierarchy of custom containers as is common in on-prem AD-DS deployments

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How could you define an app in one tenant and use it across multiple?

A

Create a Service Principle object for the app in each tenant. Entra ID creates the object when you register the corresponding app in that Entra tenant.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What networking standard is used by AD-DS?

A

x.500

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does AD-DS use to locate resources such as domain controllers?

A

DNS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What type of calls can be used to query AD-DS?

A

LDAP (Lightweight Directory Access Protocol)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What does LDAP stand for?

A

Lightweight Directory Access Protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What protocol does AD-DS primarily use for authentication?

A

Kerberos

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

True or false: AD-DS can be deployed on an Azure VM

A

True - although it won’t make any use of Entra

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the HTTP port?

A

80

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the HTTPS port?

A

443

17
Q

True or false: Entra is a multi-tenant directory service

A

True

18
Q

True or false: Entra uses a hierarchy structure

A

False - users & groups are created in a flat structure

19
Q

What protocol does Entra use for authorisation?

A

OAuth

20
Q

Does Entra use Kerberos authentication?

A

No

21
Q

Name HTTP & HTTPS protocols used by Entra for authentication

A

SAML
WS-Federation
OpenID Connect

22
Q

Define Authentication

A

Verifying identity (e.g. username+password)

23
Q

Define Authorization

A

determining & granting the level of access

24
Q

Define Federation

A

extending SSO to apps & systems outside the corporate firewall

25
Q

What is the difference between Authorization and Authentication?

A

Authorization = determining and granting a level of access
Authentication = verifying identity (username & password)

26
Q

True or false: Entra does not support custom apps for SSO

A

False

27
Q

Where can you enable the Entra Authentication for Web Apps feature?

A

Azure portal

28
Q

What is the Enterprise SLA for Entra?

A

99.9%

29
Q

What is password reset with writeback?

A

Self-service password reset which follows the AD on-prem policy and writes password changes back to on-prem AD.

30
Q

Which Entra plan is the lowest to offer Entra Connect Health?

A

P1

31
Q

Which Entra plan is the lowest to offer Entra ID protection?

A

P2

32
Q

What is the difference between Entra Connect Health and Entra ID Protection?

A

Entra Connect Health - gives insights into usage patterns, alerts etc

Entra ID Protection - extra monitoring of user accounts. Define risk policies, sign-in policies, and review user behaviour.

33
Q

What Entra plan would you need in order to define a policy workflow that activates whenever someone wants to use admin privileges?

What feature is this part of?

A

P2

Privileged Identity Management

34
Q

True or false: Entra Domain Services requires domain controllers

A

False

35
Q

What do you need to implement to integrate Entra ID with your local AD-DS?

A

Entra Connect

36
Q

How is billing calculated for Microsoft Entra Domain Services?

A

Per hour depending on the size of the directory

37
Q

How can you organise objects in on-prem AD-DS deployments?

A

Based on attribute values or group membership