Understand Entra ID Flashcards
A project manager is setting up a new project that includes members from different departments. The project manager wants to ensure that project team members can collaborate and have shared access to a mailbox, calendar, files, and the project’s SharePoint site.
Which Microsoft Entra feature can the project manager use to accommodate this requirement, without having to involve an administrator?
Microsoft 365 group
An organization has completed a full migration to the cloud and has purchased devices for all its employees. All employees sign in to the device through an organizational account configured in Microsoft Entra ID.
Select the option that best describes how these devices are set up in Microsoft Entra ID
- These devices are set up as Microsoft Entra registered
- These devices are set up as Microsoft Entra joined
- These devices are set up as Microsoft Entra hybrid joined
Microsoft Entra joined device
is a device joined to Microsoft Entra ID through an organizational account, which is then used to sign in to the device.
A developer wants an application to connect to Azure resources that support Microsoft Entra authentication, without having to manage any credentials and without incurring any extra cost.
Which option best describes the identity type of the application?
* Service principal
* Managed identity
* Hybrid identity
**Managed identities **
They are a type of service principal that are automatically managed in Microsoft Entra ID and eliminate the need for developers to manage credentials.
What is MS ENTRA?
Product family that covers all ID and access management within M365
Name the 3 ID models for M365
- Cloud ID
- Hybrid ID
- Federated ID
What are security groups?
Security groups are used for granting access to Microsoft 365 resources, such as SharePoint sites.
They can make administration easier because you need only administer the group rather than adding users to each resource individually.
Security groups can contain users or devices. Creating a security group for devices can be used with mobile device management services, such as Microsoft Intune.
Security groups can be configured for dynamic membership in Microsoft Entra ID, allowing group members or devices to be added or removed automatically based on user attributes such as department, location, or title; or device attributes such as operating system version.
Security groups can be added to a team.
Microsoft 365 Groups can’t be members of security groups.
What are 365 groups ?
Microsoft 365 Groups are used for collaboration between users, both inside and outside your company.
With each Microsoft 365 group, members get a group email and shared workspace for conversations, files, and calendar events, Stream, and a Planner. Microsoft 365 Groups can also be connected to Teams or Viva Engage.
You can add people from outside your organization to a group as long as this has been enabled by the administrator. You can also allow external senders to send email to the group email address.
Microsoft 365 Groups can be configured for dynamic membership in Microsoft Entra ID, allowing group members to be added or removed automatically based on user attributes such as department, location, title, etc.
Microsoft 365 Groups support nesting through dynamic groups in Microsoft Entra ID.
Microsoft 365 Groups can be added to one of the three SharePoint groups (Owners, Members, or Visitors) to give people permissions to the site.
Microsoft Entra ID is a:
* IaaS
* SaaS
* PaaS
PaaS
What is Microsoft Entra ID designed for?
Multi-tenant isolation between individual directory instances
Microsoft Entra ID is the world’s largest multi-tenant directory.
From a technical standpoint, what does ‘tenant’ represent?
An individual Microsoft Entra instance
Why might having multiple Microsoft Entra tenants be convenient?
To test Microsoft Entra functionality in one tenant without affecting the others
What allows you to grant permissions to resources in an Azure subscription?
Association with a Microsoft Entra tenant
What is the default DNS domain name assigned to each Microsoft Entra tenant?
A unique prefix followed by onmicrosoft.com
What is the prefix of the default DNS domain name derived from?
The name of the Microsoft account used to create an Azure subscription or provided explicitly during tenant creation
Is it possible to add custom domain names to a Microsoft Entra tenant?
Yes, adding at least one custom domain name is common
What role does the Microsoft Entra tenant serve?
Security boundary and container for Microsoft Entra objects
What types of objects can a Microsoft Entra tenant contain?
- Users
- Groups
- Applications
Can a single Microsoft Entra tenant support multiple Azure subscriptions?
Yes
What is a notable difference between the Microsoft Entra schema and AD DS?
The Microsoft Entra schema contains fewer object types, notably lacking a definition for the computer class.
What class does the Microsoft Entra schema include that is absent in AD DS?
The device class.
What is a key feature of the Microsoft Entra schema regarding extensions?
The extensions of the Microsoft Entra schema are easily extensible and fully reversible.
Can Microsoft Entra ID manage computers using traditional techniques like Group Policy Objects?
No, the lack of support for traditional computer domain membership prevents this.
What does Microsoft Entra ID primarily provide?
Directory services, storing and publishing user, device, and application data, and handling authentication and authorization.
What cloud service relies on Microsoft Entra ID as its identity provider?
Microsoft 365.