Manage Azure identities and governance Flashcards

1
Q

Azure AD

A

Azure Active Directory

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Azure AD: Single sign-on (SSO) access

A

Users can sign in with the same set of credentials to access all their apps

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

AAD: Ubiquitous device support

A

it supports a lot of devices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

AAD: secure remote access

A

Securing remote access for on-premises web apps. Things like MFA, conditional access policies, and group based access management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

AAD: cloud extensibility

A

act as a complete source of data for users, groups, passwords, and access to devices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

AAD: sensitive data protection

A

Admins can monitor for suspicious sign-in activity and potential vulnerabilities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

AAD: Self-service support

A

You can delegate tasks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

AAD concept: Identity

A

An identity is an object that can be authenticated. Could be a user with a username and password. Could also be applications or other servers that require authentication by using secret keys or certificates

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

AAD concept: Account

A

An account is an identity that has data associated with it. You need an identity first

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

AAD concept: AAD account

A

An AAD account is an identity that’s created through AAD or another microsoft cloud service.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

AAD concept: tenant

A

A single dedicated and trusted instance of Azure AD. Each tenant aka directory represents a single organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

AAD concept: subscription

A

an azure subscription is used to pay for azure cloud services. a tenant can have multiple subscriptions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the four AAD editions?

A

Free, Microsoft 365 apps, premium p1, and premium p2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is SSPR

A

Self Service password reset.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

user account: cloud identity

A

an account with a cloud identity is define only in Azure AD

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

User account: directory-synchornized identity

A

The identity is defined in an on-prem active directory

17
Q

User account: guest user

A

guest users are defined outside of azure

18
Q

group access rights: assigned

A

Each user is assigned rights individually

19
Q

group access rights: dynamic user

A

use dynamic membership rules to automatically add and remove group members

20
Q

group access rights: dynamic device

A

dynamic group rules to automatically add and remove devices in security groups

21
Q

regional pairs: physical isolation

A

ideally; 300 miles between regional pair datacenters so that if one is affected, the twin will unlikely to be affected as well

22
Q

regional pairs: platform-provided replication

A

some services like Geo-Redundant Storage provide automatic replication to the paired region

23
Q

regional pairs: region recover order

A

when both datacenters are out, recovery of one region is prioritized out of every pair

24
Q

regional pairs: sequential updates

A

azure system updates hit pairs one at a time

25
Q

regional pairs: data residency

A

regions reside within the same geography as their enabled set

26
Q

What are the 4 azure subscription options?

A

enterprise agreement, microsoft reseller, microsoft partner, personal free account

27
Q

azure policy: enforce rules and compliance

A

use builtin policies or make your own

28
Q

azure policy: apply policies at scale

A

apply policies to a management group with control across your entire org. define an exclusion scope

29
Q

azure policiy: perform remediation

A

conduct real-time remediation

30
Q

azure policy: exercise governance

A

support multiple engineering teams, manage multiple subscriptions, standardize and enforce how cloud resources are configured, manage regulatory compliance, cost control, security, and design consistency

31
Q

what is role-based access control?

A

RBAC is a mechanism for fine-tuning who can access your Azure resources

32
Q

rbac concept: security principal

A

an object that represents something that requests access to resources

33
Q

rbac concept: role definition

A

a set of permissions that lists the allowed operations

34
Q

rbac concept: scope

A

the boundary for the requested level of access, or “how much” access is granted

35
Q

rbac concept: assignment

A

an assignment attaches a role definition to a security principal at a particular scope

36
Q

rbac: how do security principals, role definitions, scopes, and assignments work together?

A

Security principal is the who, role definition is what they can do, scope is how high they can do it, and assignment is the whole thing written down.

37
Q

What is sspr?

A

Self service password reset