Microsoft Certified: Azure Administrator Associate flashcards
181 free flashcards. Tap a card to flip it.
Password Writeback
Flip cardAn Azure AD Connect feature that allows password changes made in Azure AD (e.g., by cloud-only users or self-service password reset) to be synchronized back to the on-premises Active Directory.
- Crucial for enabling cloud-only users to authenticate against on-premises resources.
- Supports self-service password reset (SSPR) for hybrid users.
- Requires specific permissions for the Azure AD Connect service account in on-premises AD.
Memory trick: For cloud users to unlock 'on-prem doors', their 'cloud key' must be 'written back'.
Azure Backup Disk Restore
Flip cardAzure Backup's disk restore option allows restoring individual disks (OS or data) from a VM backup to either create a new VM or replace an existing disk.
- Provides granular control over disk restoration.
- Useful for OS disk corruption while preserving data disks.
- Can be used to create a new VM from restored disks or replace a disk on an existing VM.
Memory trick: VM for whole, Disks for parts, Files for tiny starts.
Azure AD Connect Sync Rules
Flip cardConfigurable rules that control how objects and attributes flow between on-premises Active Directory and Azure AD.
- Can be used for attribute transformation, filtering, and joining objects.
- Includes inbound (AD to Metaverse) and outbound (Metaverse to Azure AD) rules.
- Custom rules can override default rules.
Memory trick: Rules Transform, Connect Flows, Make It So.
Azure Backup Geo-redundant Storage (GRS)
Flip cardA storage redundancy option in Azure Backup where your backup data is replicated synchronously three times within a primary region, and then asynchronously replicated to a single physical location in a secondary region.
- Provides protection against region-wide outages.
- Ensures data durability and availability across geographically separate locations.
- Higher cost than LRS or ZRS, but offers superior disaster recovery capabilities.
Memory trick: GRS for global reach, LRS for local peach, ZRS for zone's speech.
Log Analytics Workspace
Flip cardA Log Analytics workspace is a unique Azure environment for storing, querying, and analyzing log data collected from various Azure and on-premises resources.
- Centralized log collection point.
- Uses Kusto Query Language (KQL) for powerful data analysis.
- Foundation for Azure Monitor features like Workbooks, Alerts, and Solutions.
Memory trick: Log Analytics is the brain, where all the data is ingrained.
Azure AD Connect Synchronization Scope
Flip cardThe definition of which objects (users, groups, devices) from which parts of the on-premises Active Directory forest are synchronized to Azure AD.
- Configured during the Azure AD Connect wizard.
- Can be filtered by domains, OUs, or attributes.
- Determines the initial set of objects for synchronization.
Memory trick: Scope It All, Or Pick and Choose, Don't Miss a Bit.
Azure Monitor Alerts
Flip cardA feature in Azure Monitor that provides proactive notifications when specific conditions are met in your monitoring data, such as a metric exceeding a threshold or a log query returning a certain result.
- Triggers based on metrics, logs, or activity logs.
- Can be configured with conditions, aggregation, and frequency.
- Integrates with Action Groups for notification and automation.
Memory trick: Alerts ring, Action Groups spring, proactive monitoring takes wing.
Azure Disk Encryption (ADE) and Backup
Flip cardFor backing up and restoring Azure VMs with Azure Disk Encryption enabled, the associated encryption keys stored in Azure Key Vault must also be managed and accessible.
- ADE uses Azure Key Vault for encryption keys.
- Key Vault access is critical for encrypted VM restore.
- Backup ensures data integrity; Key Vault ensures decryption capability.
Memory trick: To unlock your restored VM data, remember where the key is kept.
Azure AD Connect Source Anchor
Flip cardA unique, immutable attribute chosen from on-premises Active Directory that Azure AD Connect uses to identify a synchronized object over its lifetime in Azure AD.
- Crucial for maintaining object identity during synchronization and across forests.
- Default attribute for users is 'objectGUID'.
- Once set, it should not be changed without careful planning.
Memory trick: The 'anchor' must be 'unique' and 'never change'.
Azure Monitor Metrics Explorer
Flip cardA feature within Azure Monitor that provides a graphical interface to plot and analyze numerical time-series data (metrics) collected from Azure resources.
- Used for visualizing performance data and trends.
- Supports various aggregations and time granularities.
- Allows comparing metrics across different resources.
Memory trick: Visualize performance, explore with Metric Explorer's graph.
Pass-through Authentication (PTA)
Flip cardAn Azure AD Connect authentication method that validates user passwords directly against on-premises Active Directory domain controllers.
- Passwords are never stored in Azure AD, even in hashed form.
- Requires lightweight agents installed on-premises.
- Provides a seamless sign-in experience for users.
Memory trick: Connect, Authenticate, Secure Your Cloud Path.
AD FS to PTA Migration
Flip cardThe process of transitioning from using Active Directory Federation Services to Pass-through Authentication for hybrid identity.
- Requires deploying PTA agents before switching authentication.
- Allows for a phased migration strategy.
- Reduces on-premises infrastructure complexity compared to AD FS.
Memory trick: Switching Authentication? Agents First, Then Flip the Switch.
Azure Site Recovery Offline Replication
Flip cardA method in Azure Site Recovery to transfer initial, large datasets to Azure using a physical appliance like Azure Data Box, avoiding internet bandwidth consumption.
- Used for initial replication of large VMs.
- Prevents high internet bandwidth usage.
- Typically involves shipping a physical device.
Memory trick: To start strong, choose the right path for your data's journey to the cloud.
ASR Replication Frequency
Flip cardThe interval at which Azure Site Recovery captures and transfers data changes (crash-consistent snapshots) from the source machine to the target region, directly impacting the Recovery Point Objective (RPO).
- Determines the maximum potential data loss.
- Configurable in the replication policy.
- Shorter frequency leads to lower RPO but higher storage/bandwidth usage.
Memory trick: RPO's clock ticks with replication frequency, consistency's the key.
Azure Monitor Diagnostic Settings
Flip cardDiagnostic settings in Azure Monitor define where to send logs and metrics from Azure resources for monitoring, archiving, or analysis.
- Configured per Azure resource.
- Allows sending logs/metrics to Log Analytics, Storage Account, Event Hubs.
- Crucial for auditing and compliance by retaining specific log types.
Memory trick: Diagnostics direct where logs go for deep dives.
Azure AD Connect Health for AD FS
Flip cardA monitoring service that provides insights into the health, performance, and authentication activities of an on-premises Active Directory Federation Services (AD FS) deployment integrated with Azure AD.
- Monitors AD FS servers, web application proxies, and authentication attempts.
- Provides alerts for critical issues and performance bottlenecks.
- Helps troubleshoot authentication failures and track usage patterns.
Memory trick: To check the 'health' of the 'federated temple', use the 'Connect Health' tool.
Azure Service Health
Flip cardAzure Service Health provides a personalized view of the health of Azure services, regions, and resources, notifying users about service incidents and planned maintenance.
- Personalized view based on your subscriptions.
- Includes service issues, planned maintenance, and health advisories.
- Integrates with Azure Monitor for alert notifications.
Memory trick: Service Health tells you if Azure itself is well.
Azure AD Connect Multi-Forest Topology
Flip cardAzure AD Connect can synchronize user identities from multiple disparate on-premises Active Directory forests into a single Azure Active Directory tenant.
- Requires network connectivity to all forests.
- Can handle different UPNs and attributes across forests.
- Supports various authentication methods (PHS, PTA, Federation).
Memory trick: Many forests can lead to one Azure AD cloud.
Azure AD Connect OU Renaming Impact
Flip cardThe effect of renaming an Organizational Unit (OU) in on-premises Active Directory on Azure AD Connect synchronization, potentially leading to de-provisioning of objects.
- Renaming an OU changes its Distinguished Name (DN).
- Synchronization scope filters often rely on OUs' DNs.
- Requires updating Azure AD Connect synchronization filters if specific OUs are selected.
Memory trick: Renaming the 'folder' means the 'sync list' needs an update.
PTA High Availability
Flip cardEnsuring continuous availability of Pass-through Authentication by deploying multiple agents.
- Requires at least two agents for redundancy.
- Agents are automatically load-balanced by Azure AD.
- Install agents on domain-joined servers, not domain controllers.
Memory trick: Two Agents, Always On, Always Ready.
Azure AD Connect Custom UPN Mapping
Flip cardConfiguring Azure AD Connect synchronization rules to use a specific on-premises attribute (e.g., 'mail') as the source for the userPrincipalName (UPN) in Azure AD.
- Crucial when on-premises UPNs do not match desired Azure AD UPNs or primary email addresses.
- Requires creating or modifying synchronization rules in the Synchronization Rules Editor.
- Ensures consistent sign-in experience and proper identity representation in Azure AD.
Memory trick: To make the 'sign-in name' echo the 'email', 'map' it with a 'custom rule'.
Azure Backup Immutability
Flip cardA feature in Azure Backup that makes backed-up data unchangeable and undeletable for a specified retention period, even by administrators, to meet regulatory and compliance requirements.
- Prevents accidental or malicious deletion/modification of backups.
- Configured at the Recovery Services vault level.
- Essential for compliance standards requiring data retention integrity.
Memory trick: Immutable backups, like a rock, protect your data's integrity.
Routable UPN for Hybrid Identity
Flip cardEnsuring users can sign in to Azure AD with a UPN that is publicly routable, even if their on-premises UPN is non-routable.
- Requires adding the routable domain as a custom domain in Azure AD.
- Requires adding the routable domain as an alternate UPN suffix in on-premises AD.
- Users can then be assigned the routable UPN in on-premises AD.
Memory trick: Local's Not Cloud, Add the Domain, Then Sync Again.
Azure AD Connect OU Filtering
Flip cardThe ability to select which Organizational Units from on-premises Active Directory are synchronized to Azure AD.
- Configured during initial setup or by re-running the wizard.
- Prevents objects within excluded OUs from being synchronized.
- Helps manage the scope of synchronized identities.
Memory trick: Filter What Goes Up, Keep What Stays Down.
Azure AD Connect Join Rules
Flip cardSynchronization rules within Azure AD Connect that define how objects from different connected directories (e.g., multiple AD forests) are matched and combined into a single object in the metaverse.
- Essential for object consolidation in multi-forest environments.
- Uses attributes (e.g., mail, employeeID) to match objects.
- Helps create a single, unified identity in Azure AD from disparate sources.
Memory trick: To 'join' two 'forest entities' into one 'cloud person', use 'join rules'.
Azure Monitor Metric Alerts
Flip cardAzure Monitor metric alerts evaluate resource metrics at regular intervals to determine if conditions are met, triggering notifications or actions.
- Monitors numerical data (e.g., CPU, memory, network I/O).
- Can be scoped to specific resources, resource groups, or subscriptions.
- Supports various aggregation types (e.g., average, sum, min, max).
Memory trick: Metrics measure machine's might, Logs list actions day and night.
Azure Monitor SQL Insights
Flip cardA comprehensive, unified monitoring solution within Azure Monitor for Azure SQL Database, Azure SQL Managed Instance, and SQL Server on Azure Virtual Machines, offering deep performance insights.
- Provides pre-built dashboards for SQL performance.
- Monitors deadlocks, expensive queries, wait statistics, etc.
- Leverages Azure Monitor Logs for data collection and analysis.
Memory trick: SQL Insights, deep dive, deadlocks can't hide, queries come alive.
Strict Password Sovereignty
Flip cardA security policy that prohibits any form of on-premises password information, including hashes or validation requests, from leaving the on-premises network.
- Challenges standard hybrid identity authentication methods.
- PHS sends hashes.
- PTA sends validation requests through Azure AD.
- AD FS sends security tokens to Azure AD.
Memory trick: No Password Leaves, No Cloud Access for On-Premise Peace.
Azure AD Connect PHS Troubleshooting
Flip cardIdentifying and resolving issues related to Password Hash Synchronization (PHS) between on-premises Active Directory and Azure AD.
- Verify PHS feature is enabled in Azure AD Connect.
- Check Azure AD Connect synchronization service for errors related to password hash synchronization.
- Ensure network connectivity to Azure AD is functional for the sync server.
Memory trick: When the password 'key' doesn't reach the 'cloud lock', check the sync mechanism.
VSS (Volume Shadow Copy Service)
Flip cardA technology included in Microsoft Windows that allows backup applications to create consistent snapshots of computer files or volumes, even while they are in use, typically used for application-consistent backups and replication.
- Ensures data integrity for applications by coordinating with them.
- Used by Azure Site Recovery and Azure Backup for Windows VMs.
- Creates a 'point-in-time' copy of data, including open files and in-memory data.
Memory trick: VSS on Windows, a consistent snapshot it sends, applications' data defends.
Azure Monitor Action Group
Flip cardA collection of notification preferences and automated actions that Azure Monitor alerts can trigger, allowing for a centralized response to incidents.
- Triggered by Azure alerts.
- Combines multiple actions (email, SMS, webhook, function).
- Centralizes alert response.
Memory trick: When an alert goes off, a 'group' of actions springs into motion.
Password Hash Synchronization (PHS)
Flip cardA method of hybrid identity that synchronizes a cryptographic hash of a user's password from on-premises Active Directory to Azure AD, enabling cloud authentication.
- Simplest method for hybrid identity password synchronization.
- Provides a form of cloud authentication.
- Enables immediate reflection of on-premises password changes in Azure AD.
Memory trick: To reflect changes, you must sync the password's 'essence'.
Azure Backup Vault Isolation
Flip cardAzure Backup stores recovery points in a Recovery Services vault, isolating them from the source data, thus protecting against accidental deletion of the source resource.
- Recovery Services vaults are independent resources.
- Backup data persists even if the original resource is deleted.
- Crucial for protecting against catastrophic data loss due to source deletion.
Memory trick: Vaults guard backups, even if the source gets zapped.
Azure VM Backup Granular Disk Restore
Flip cardA capability of Azure Backup for virtual machines that allows users to restore individual disks or even specific files and folders from a VM backup, without needing to recover the entire virtual machine.
- Reduces recovery time and resource consumption compared to full VM restore.
- Provides flexibility for targeted data recovery.
- Supported for both Windows and Linux Azure VMs.
Memory trick: VM backup's disk restore, just a piece, not the whole floor.
PTA Agent Inactive Status
Flip cardWhen an Azure AD Pass-through Authentication agent is unable to communicate with Azure AD, resulting in it being marked as 'Inactive' in Azure AD Connect Health.
- Commonly caused by network connectivity issues (firewall, proxy, DNS).
- Can also be due to the agent service being stopped or unhealthy.
- Requires investigation of the server hosting the agent.
Memory trick: Inactive agent? First, check its 'lifeline' to the cloud.
Azure Monitor Workbook
Flip cardA flexible canvas in Azure Monitor for creating interactive and customizable visual reports that combine various data sources like metrics, logs, and text.
- Combines multiple data sources.
- Allows for rich visual reports.
- Interactive and customizable.
Memory trick: To see all your data in one book, you need a workbook.
Azure AD Pass-through Authentication
Flip cardAn Azure AD Connect feature that validates users' passwords directly against their on-premises Active Directory without storing passwords in Azure AD, using lightweight agents.
- Provides a simple password validation for users against on-premises AD.
- Requires no inbound firewall ports to the on-premises network.
- Uses lightweight agents installed on-premises to process authentication requests.
Memory trick: Choose the path that respects the 'no inbound' rule.
Azure AD Connect Health
Flip cardA monitoring service that provides insights into the health and performance of your on-premises identity infrastructure synchronized with Azure AD.
- Monitors Azure AD Connect sync, AD FS, and AD DS.
- Provides alerts for issues like sync errors or agent downtime.
- Accessible via the Azure portal.
Memory trick: Health Checks Connect, Keep Identity Strong.
PHS and Password Policy
Flip cardPassword Hash Synchronization (PHS) transfers password hashes to Azure AD but does not inherently synchronize on-premises password policies or expiration dates.
- Azure AD applies its own password policy to synced users.
- On-premises password expiration is not directly enforced by PHS in Azure AD.
- Password writeback is for writing Azure AD password changes back to on-premises AD.
Memory trick: Hash is Sent, Policy Stays, Expiration's Own Way.
Azure Site Recovery Recovery Plan
Flip cardAn Azure Site Recovery feature that orchestrates and automates the failover of multiple virtual machines, allowing for controlled and testable disaster recovery.
- Orchestrates multi-VM failover.
- Automates failover steps.
- Enables non-disruptive failover testing.
Memory trick: To direct your disaster recovery, you need a carefully planned script.
Azure Monitor Action Groups
Flip cardAzure Monitor Action Groups are reusable sets of notification preferences and actions that can be triggered by any Azure Monitor alert, enabling automated responses.
- Can include email, SMS, push notifications, webhooks, ITSM, runbooks, Azure Functions.
- Used across various alert types (metric, log, activity log).
- Centralizes alert response configurations.
Memory trick: Alerts trigger actions, grouped for reaction.
Azure Front Door Priority Routing
Flip cardAn Azure Front Door routing method that directs all traffic to the primary (highest priority) healthy backend pool. If the primary becomes unhealthy, traffic automatically fails over to the next highest priority healthy backend pool.
- Ideal for active/passive or active/standby disaster recovery scenarios.
- Provides automatic failover based on backend health probes.
- Priorities are assigned to backend pools.
Memory trick: Front Door routes, priorities decide, latency's quick, weights divide.
Azure Backup Enhanced Policy
Flip cardAn Azure Backup policy type for Azure VMs offering granular control over backup frequency and retention, including distinct daily, weekly, and monthly retention settings.
- Offers advanced retention settings.
- Supports daily, weekly, monthly, and yearly retention points.
- Provides more flexibility than the Standard policy.
Memory trick: For VM protection, choose the policy that enhances your retention options.
Azure Activity Log Diagnostic Settings to Storage Account
Flip cardConfiguring Azure Activity Log data to be exported to an Azure Storage account for long-term, cost-effective archival and compliance retention.
- Cost-effective for long retention periods.
- Data is stored as JSON blobs.
- Good for compliance and infrequent auditing access.
Memory trick: Archive logs to storage, cheap and long, for audits strong.
ASR Offline Initial Replication
Flip cardA method in Azure Site Recovery to transfer the initial, large dataset of protected items to Azure using a physical appliance like Azure Data Box, instead of over the network.
- Reduces WAN bandwidth consumption for large initial replications.
- Uses Azure Data Box or Data Box Heavy.
- Ideal for environments with low bandwidth or very large datasets.
Memory trick: When WAN is slow, ship the data box, then let ASR flow.
ASR Compute Settings
Flip cardAzure Site Recovery's compute settings allow customization of the target virtual machine's properties in the disaster recovery region, including VM size, availability set, and power state.
- Configurable per replicated VM.
- Helps manage costs by allowing VMs to remain off until failover.
- Ensures compatibility with target region resources.
Memory trick: Compute settings control the replicated VM's 'powers'.
Azure Site Recovery Plan
Flip cardAn Azure Site Recovery Plan orchestrates the failover, failback, and test failover of multiple virtual machines, allowing for grouping, sequencing, and custom scripting.
- Groups VMs for consistent failover order.
- Allows pre- and post-failover scripts for automation.
- Crucial for defining network mappings and IP configurations for failed-over VMs.
Memory trick: Plans orchestrate the failover dance, ensuring networks get a second chance.
Azure Backup Policy
Flip cardAn Azure Backup policy defines the schedule for when backups are taken and the retention duration for those backup recovery points.
- Configured within a Recovery Services vault.
- Specifies backup frequency (daily, weekly).
- Defines retention ranges for daily, weekly, monthly, and yearly recovery points.
Memory trick: Schedule for 'when', retention for 'how long'.
Azure Policy and Resource Locks Combination
Flip cardAzure Policy enforces configuration standards and compliance across resources, while Azure Resource Locks protect resources from accidental deletion or modification.
- Policy for 'what' configurations are allowed/required.
- Resource Locks for 'who' can delete/modify resources.
- Combined for comprehensive governance and protection.
Memory trick: Policy sets the rules, Locks keep things in place.
Azure Policy 'Modify' Effect
Flip cardThe 'Modify' effect in Azure Policy is used to add, update, or remove tags, properties, or resource configurations on existing resources or during resource creation, ensuring compliance with organizational standards.
- Automates remediation of non-compliant resources.
- Can add or update tags and other resource properties.
- Runs after resource creation or through a remediation task.
Memory trick: Azure Policy with 'Modify' is like an 'Auto-Stamper' for your resources, ensuring tags are always there.
Azure AD Bulk User Attribute Update (PowerShell)
Flip cardUsing PowerShell cmdlets from the Azure AD module to programmatically modify attributes for multiple user accounts in Azure Active Directory.
- Efficient for large numbers of users.
- Reduces manual effort and potential for errors.
- Requires Azure AD PowerShell module and appropriate permissions.
Memory trick: For many users, PowerShell is the bulk update wizard.
Azure AD Connect Multiple Forests, Single Azure AD Tenant
Flip cardAn Azure AD Connect deployment topology where identities from two or more on-premises Active Directory forests are synchronized into one Azure Active Directory tenant.
- Supports various forest topologies (resource forest, account-resource forest).
- Requires careful planning for identity matching.
- Consolidates identities into a single cloud directory.
Memory trick: Many on-prem trees feeding one cloud.
Azure AD Bulk User Attribute Update
Flip cardBulk updating user attributes in Azure AD for many users simultaneously is most efficiently done using scripting tools like PowerShell with CSV input, or through Azure AD Connect if changes originate on-premises.
- PowerShell with CSV is common for direct Azure AD bulk updates.
- Azure AD Connect handles bulk updates from on-premises AD.
- Azure portal is for individual user management.
Memory trick: Many users, many changes? PowerShell saves the day!
Managed Identities for Azure Resources
Flip cardManaged Identities provide an automatically managed identity in Azure Active Directory (Azure AD) for Azure services, eliminating the need for developers to manage credentials.
- Eliminates credential management in code.
- Azure automatically manages the identity lifecycle.
- Supports system-assigned and user-assigned identities.
- Used for authenticating Azure services to other Azure AD-protected services.
Memory trick: Managed Identity is your 'Secret Keeper' for Azure services, no more manual keys!
Azure RBAC Reader + Azure AD Directory Readers
Flip cardThis combination of roles provides comprehensive read-only access: the Azure RBAC Reader role for Azure resources and the Azure AD Directory Readers role for Azure Active Directory objects.
- Reader (Azure RBAC) allows viewing all Azure resources.
- Directory Readers (Azure AD) allows viewing user and group properties in Azure AD.
- Adheres to the principle of least privilege for auditing.
Memory trick: To 'Read Everything', you need both 'Resource Reader' and 'Directory Reader'.
Azure AD Conditional Access
Flip cardA feature of Azure Active Directory that allows organizations to enforce policies for accessing resources based on conditions such as user, device, location, and application.
- Enables fine-grained access control.
- Supports conditions like trusted IP ranges.
- Can enforce MFA conditionally.
Memory trick: MFA is like a bouncer: sometimes needed, sometimes not, depending on where you enter.
Azure Policy DeployIfNotExists (DINE)
Flip cardAn Azure Policy effect that automatically deploys a specified resource or template when a condition is met and the target resource does not exist.
- Used to ensure foundational resources are always present.
- Requires a deployment template within the policy definition.
- Evaluates after a resource (e.g., Resource Group) is created or updated.
Memory trick: If it's not there, DINE will make it appear.
Azure AD Domain Services (Azure AD DS)
Flip cardA managed domain service provided by Azure that offers domain join, group policy, LDAP, Kerberos/NTLM authentication, and DNS, compatible with traditional Active Directory.
- Provides domain services without IaaS domain controllers.
- Integrates with existing on-premises AD DS via Azure AD Connect.
- Supports legacy applications requiring traditional authentication protocols.
Memory trick: Legacy apps in the cloud need a familiar identity door: AD DS.
Azure Blueprints
Flip cardA service that enables you to define a repeatable set of Azure resources, policies, and RBAC assignments that can be consistently applied across subscriptions to ensure compliance and standardization.
- Packages policies, RBAC, ARM templates, and resource groups.
- Provides versioning for blueprints.
- Ensures consistent environment setups.
Memory trick: Blueprints are the master plans for building consistent Azure environments.
Azure Policy Modify Effect
Flip cardAn Azure Policy effect used to add, update, or remove properties or tags on a resource during creation or update, ensuring compliance without blocking resource deployment.
- Ideal for enforcing naming conventions, tagging standards, and property settings.
- Can apply default values or enforce specific values.
- Evaluates before a resource is created or updated.
Memory trick: To fix or add a tag, Modify is the flag.