Describe access management capabilities of Microsoft Entra ID Flashcards

(28 cards)

1
Q

Conditional access

A

analyses signals including user, location, device, application, and risk to automate decisions for authorizing access to resources (apps and data).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

t or f

Conditional Access policies at their simplest are if-then statements

A

true

ex. Conditional Access policy might state that if a user belongs to a certain group, then they’re required to provide multifactor authentication to sign in to an application.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

A conditional access policy in Microsoft Entra ID consists of two components

A

assignments
access controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

t or f

When creating a conditional access policy, admins can determine which signals to use through assignments

A

true

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Assignment portion of the policy controls:

A

who
what
where
when

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

users and groups

A

assign who the policy will include or exclude

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

cloud apps or actions

A

include or exclude cloud applications, user actions, authentication contexts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

conditions

A

define where and when the policy will apply.
sign in risk
user risk
device platform
IP location info
client apps
filters for devices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

access control

A

decision to block access, grant access, grant access with extra verification, or apply a session control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

grant access

A

Administrators can grant access without any additional control, or they can choose to enforce one or more controls when granting access.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

session

A

administrator can make use of session controls to enable limited experiences within specific cloud applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

RBAC - role based access control

A

managing access using roles

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Does Microsoft Entra have built in and custom roles?

A

yes. these are consider a form of RBAC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Built in roles

A

global administrator
user administrator
billing administrator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Global administrator

A

users with this role have access to all administrative features in Microsoft Entra.

The person who signs up for the Microsoft Entra tenant automatically becomes a global administrator.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

User administrator

A

users with this role can create and manage all aspects of users and groups.

This role also includes the ability to manage support tickets and monitor service health.

17
Q

billing administrator

A

users with this role make purchases, manage subscriptions and support tickets, and monitor service health.

18
Q

Custom roles

A

a collection of permissions that you choose from a preset list

19
Q

t or f

Granting permission using custom Microsoft Entra roles is a two-step process

20
Q

what is the first step for granting permission using custom Microsoft Entra roles

A

eating a custom role definition, consisting of a collection of permissions that you add from a preset list

21
Q

what is the second step for granting permission using custom Microsoft Entra roles

A

assign that role to users or groups by creating a role assignment

22
Q

t or f

Microsoft Entra ID is an available service if you subscribe to any Microsoft Online business offer, such as Microsoft 365 and Azure.

23
Q

Microsoft Entra built in roles can be used in

A

Microsoft Entra specific roles
Service specific roles
Cross service roles

24
Q

Microsoft Entra RBAC

A

control access to Microsoft Entra resources such as users, groups, and applications.

25
Azure RBAC
control access to Azure resources such as virtual machines or storage using Azure Resource Management.
26
An organization plans to implement Conditional Access. What do admins need to do?
Create policies that enforce organizational rules.
27
Sign-in risk is a signal used by Conditional Access policies to decide whether to grant or deny access. What is sign-in risk?
The probability that the authentication request isn't authorized by the identity owner.
28
IT admins have been asked to review Microsoft Entra roles assigned to users, to improve organizational security. Which of the following should they implement?
Replace global admin roles with specific Microsoft Entra roles