CDL - Identity Flashcards
What is a directory service?
A DS maps the names of network resources to their network addresses
What is Cloud Identity?
A Identity as a Service (IDaaS) that centrally manages users and group within a SINGLE PANE OF GLASS
What features constitute Cloud Identity?
- User lifecycle management
- SSO
- Device management
- Cloud Directory
- Account security
IS Google Cloud Directory Sync a sub-service of Cloud Identity?
Yes
What is Active Directory?
A service that allows orgs to manage multiple on-prem infra components and systems using a SINGLE identity per user.
What is AD Domain Services (ADDS)?
A Microsoft server based directory service that stores and managers information about a network resources. Facilitates resource access and management
Note: AD services consist of multiple directory services.
What is Managed Service for Microsoft AD?
It is an AD hostd on the GCP platform.
If you have Managed Service for Micro Active Directory why and how would you use Cloud Identity?
1) MicroAD may have features that Cloud Identity does not
2) Via federation
What are key benefits of Managed Service for Micro AD?
1) Maintenance free
2) Seamless multi-region deployment
3) Hybrid identity support
4) Compatibility with AD-dependent apps
How does a Directory Service work?
It works as a shared information infrastructure for locating, managing, administering, and organizing resources.
Analogy - A magical map that locates all your toys and friends (resources & users)
What is a Identity Provide (IdP)?
A service that creates, maintains, and manages identity information to provide authentication to services/applications within a federation or distributed network.
Eg: FB, Amzn, Google, Twitter.
What are objects in a Directory Service?
Objects are resources.
What are examples of resources on a directory service?
Users
Goups
Devises
Folders / files
Printers
Is a directory service a critical component of a network operating system?
Yes
What is Single-sign-on (SSO)? What ia a key benefit?
Seamless
What is Lightweight Directory Access Protocol?
Hey protocol for accessing in managing directory information resources
Why use LDAP when SSO is more convenient?
What is Google Cloud Directory Sync (Exam)?
What is a Directory Server?
It is a server which provides a directory service
What are well known Directory Services ?
DNS - for the internet
MicoAD
OpenLDAP
Cloud Identity
Can Cloud Identity federate identities between different ADs?
Yes
Between GCP, AD, Azure AD, etc.
How does Cloud Identity work?
A zero trust service that Allows you to manage access and compliance across all users within your domain
AND
allows you to create a CI account for each of your users/groups.
IAM is used to manage access between GCP resources and cloud identity acounts.
What deployment principles are characteristic by ADs?
They are redundant and placed as close to end users to reduce latency