Manage Identities and Governance in Azure Flashcards
Azure AD; User & Group Accounts (43 cards)
Multi-tenant cloud-based directory and identity management service
Azure AD
A dedicated and trusted instance of Azure AD
Azure tenant/directory
Differences between Azure AD and AD DS
- Identity Solution; -REST API Querying; Communication Protocols; Federation Services; Flat Structure
Azure AD uses the __ __ over __ and ___.
REST API; HTTP & HTTPS
Communication protocols that can be used by Azure AD:
SAML, WS-Federation, OpenID Connect (OAuth)
Azure AD Four Editions:
Free, Microsoft 365 Apps, Premium P1, Premium P2
Azure AD Edition included with an Azure Subscription
Free
Azure AD edition available through a Microsoft Enterprise Agreement, the Open Volume License Program, and the Cloud Solution Providers program
Premium editions
Azure AD edition that adds in Identity Protection & Governance
Premium P2
Designed to provide access to organizational apps and resources and to simplify Windows deployments of work-owned devices
Azure AD Join
AD Join benefits:
SSO, Enterprise state roaming, Access to Microsoft Store for Business, Windows Hello, Restriction of Access, Seamless access to on-premise resources
Azure AD two options:
Registering & Joining
AD defines users in 3 ways:
Cloud, Directory-synchronized, Guest users
Examples include accounts from other cloud providers and Microsoft accounts such as Xbox LIVE accounts
Guest users
Deleted users can be restored for ___ days.
30
In addition to the Portal, Users can also be added to Azure AD through ___, ___, and the ___.
Microsoft 365 Admin Center, Microsoft Intune admin console, and the CLI
Azure AD allows you to define two different types of groups:
Security & Microsoft 365 groups
Provide collaboration opportunities by giving members access to a shared mailbox, calendar, files, SharePoint site, and more
Microsoft 365 Groups
Three ways to assign access rights (add members to groups):
Assigned, Dynamic User, Dynamic Device (Security groups only)
Can manage administrative units by using the __, ___ __ & ___, or ___.
Azure Portal, PowerShell Cmdlets & Scripts, or Microsoft Graph
Regional pairs key knowledge:
Physical isolation, Platform-provided replication, Region recovery order, Sequential updates, Data residency
Azure prefers at least ___ miles of separation between datacenters in a regional pair.
300
Logical unit of Azure services that is linked to an Azure account
Azure subscription
Four ways to get an Azure subscription:
Enterprise, Resellers, Partners, Personal