Microsoft Certified: Azure Administrator Associate flashcards
181 free flashcards. Tap a card to flip it.
Azure Policy 'Audit' Effect
Flip cardAn Azure Policy effect that creates a warning event in the activity log when a resource is non-compliant, without stopping the resource request.
- Identifies non-compliant resources.
- Does not block resource creation or modification.
- Useful for reporting and understanding compliance posture without enforcement.
Memory trick: Policy acts as a watchful auditor, noting non-compliance without blocking the door.
Azure AD User Lifecycle Workflows
Flip cardAzure AD user lifecycle workflows automate identity governance processes for users joining, moving, or leaving an organization, including managing user account states based on conditions.
- Automates tasks like onboarding, offboarding, and access management.
- Can be triggered by events or scheduled based on conditions (e.g., inactivity).
- Requires Azure AD Premium P2 license.
Memory trick: Workflows manage the user's journey, making sure they're active or archived.
Azure Policy for Tagging
Flip cardAzure Policy enables the enforcement of organizational standards and assessment of compliance for Azure resources, including the automatic application or modification of tags.
- Can audit for missing tags or enforce specific tag values.
- The 'Modify' effect can automatically add or replace tags.
- Policies can be assigned at various scopes, including resource groups.
Memory trick: Policy dictates the tags, ensuring everything is labeled correctly.
Azure AD Connect: Multiple Forests
Flip cardAzure AD Connect can synchronize user identities from multiple disparate on-premises Active Directory forests into a single Azure Active Directory tenant.
- Supports various topologies for mergers/acquisitions.
- Consolidates identities into one Azure AD.
- Requires careful planning for identity matching.
Memory trick: Many forests, one cloud, all connected.
Subscription Move Permissions
Flip cardMoving an Azure subscription between management groups requires specific permissions, typically the Owner role at the root scope (/) or on both the source and target management groups.
- Owner role at root scope (/) is the most common requirement.
- Alternatively, Owner on both source and target management groups.
- Subscription must be in a non-default management group after move.
Memory trick: To move the whole box, you need to be the Owner of all locks.
Azure Policy 'DeployIfNotExists' (DINE)
Flip cardAn Azure Policy effect that audits for non-compliance and then automatically deploys a specified template as a remediation within the scope of the policy assignment.
- Automates resource deployment or configuration.
- Ensures compliance with desired state after resource creation/update.
- Can be assigned at various scopes (management group, subscription, resource group).
Memory trick: Policy is the robot that makes sure every VM gets its monitoring gear.
Azure AD B2C
Flip cardAzure Active Directory B2C (Business-to-Consumer) is a customer identity access management (CIAM) solution that enables customizable, secure sign-up, sign-in, and profile management experiences for customer-facing applications.
- Manages identities for customer-facing applications.
- Supports various identity providers (social, local accounts).
- Allows customization of user journeys and branding.
Memory trick: B2C is for 'Business To Customers' – think external, self-service, social logins.
OU Filtering (Azure AD Connect)
Flip cardA feature in Azure AD Connect that enables administrators to specify which organizational units (OUs) from their on-premises Active Directory should be synchronized to Azure Active Directory.
- Limits the scope of synchronized objects.
- Configured during or after Azure AD Connect installation.
- Reduces the number of cloud identities.
Memory trick: Only synchronize the branches you need from your on-premises tree to the cloud.
Azure Policy Deny Effect
Flip cardAn Azure Policy effect that prevents the creation, update, or deletion of resources that do not meet the defined policy rules.
- Ensures strict compliance with standards.
- Blocks non-compliant operations.
- Can be used for naming conventions, allowed locations, SKU restrictions.
Memory trick: If the name's not right, Deny the light.
Azure Policy (Naming Convention Enforcement)
Flip cardAzure Policy enables the enforcement of organizational standards and assessment of compliance for Azure resources, including defining and blocking resource deployments that do not adhere to specific naming conventions.
- Uses policy definitions with rules and parameters.
- The 'Deny' effect blocks non-compliant resource creation/updates.
- Can use regular expressions for complex naming patterns.
- Can be assigned at various scopes (management group, subscription, resource group).
Memory trick: Policy is the strict editor that blocks any misnamed resource.
Azure Contributor Role
Flip cardA built-in Azure role that grants full access to manage all resources, but does not allow you to assign roles in Azure RBAC.
- Can create, update, delete resources.
- Cannot manage access permissions (RBAC).
- Often used for resource administrators.
Memory trick: Owner is King, Contributor is Craftsman, Reader is Observer.
Conditional Access Session Controls
Flip cardConditional Access session controls in Azure AD allow organizations to enforce specific requirements during a user's session, such as requiring reauthentication or controlling access to cloud apps.
- Applies to cloud apps access.
- Can enforce reauthentication during a session.
- Integrates with other Conditional Access conditions like location and device state.
Memory trick: Conditional Access is like a 'Security Gatekeeper' that checks conditions and applies session rules.
Azure AD Account Expiration
Flip cardAzure AD user accounts can have an 'accountExpires' attribute set, which automatically disables the account on the specified date, preventing further sign-ins.
- Native feature for automatic account disabling.
- Useful for temporary users like contractors.
- Can be set via PowerShell, Graph API, or Azure AD Connect (if synced).
Memory trick: AccountExpires is the 'E' for 'End date' of access.
Azure AD B2B Collaboration
Flip cardA feature in Azure AD that allows you to invite external users (guests) to your tenant, enabling them to access your applications and resources while managing their identities in their own directory.
- Invites external users as 'guest users'
- External users authenticate with their own identity provider
- Provides controlled access to specific resources
Memory trick: B2B brings external buddies to your business.
Azure AD Conditional Access Policy Application
Flip cardConditional Access policies are evaluated sequentially and independently. Each policy can target specific applications, users, locations, and device states to enforce granular access controls like MFA.
- Policies are 'if-then' statements.
- Multiple policies can apply to a single sign-in.
- Grant controls (like Require MFA) are enforced if all conditions are met.
Memory trick: Different apps, different rules: two policies are the tools.
Azure Policy 'DeployIfNotExists' and Azure Resource Locks
Flip cardDeployIfNotExists (DINE) is an Azure Policy effect that ensures a resource or configuration exists. Azure Resource Locks prevent accidental deletion or modification of resources.
- DINE automates post-creation resource configuration.
- Resource Locks provide an additional layer of protection against accidental changes.
- Both can be assigned at various scopes, including management groups, for wide enforcement.
Memory trick: Policy builds the shield, Locks secure the gate for networks.
Azure Policy
Flip cardA service in Azure that enables organizations to create, assign, and manage policies to enforce rules and effects over their Azure resources, ensuring compliance with corporate standards and service level agreements.
- Enforces rules and effects on resources.
- Can audit, deny, modify, or deploy if not compliant.
- Supports tag enforcement, resource type restrictions, etc.
Memory trick: Policies are the rules of the Azure land, enforced by the Azure Guard.
Azure Resource Locks
Flip cardAzure Resource Locks prevent accidental deletion or modification of critical Azure resources, even by users with administrative permissions, ensuring resource stability.
- Can be applied at subscription, resource group, or individual resource scope.
- Two types: CanNotDelete and ReadOnly.
- Must be explicitly removed before resource can be deleted or modified.
Memory trick: Resource Locks are like a 'do not touch' sign that even owners must respect.
Azure Policy for Naming
Flip cardAzure Policy enables the enforcement of naming conventions for resources during their creation, ensuring compliance with organizational standards.
- Uses 'deny' effect to block non-compliant creations.
- Can apply to resource groups, resources, and locations.
- Assesses compliance and provides reporting.
Memory trick: Policy is the rulebook for your Azure kingdom.
Bulk User Attribute Update (Azure AD)
Flip cardBulk updating user attributes in Azure AD involves programmatically modifying multiple user accounts simultaneously, typically using scripting tools for efficiency and accuracy.
- PowerShell with Azure AD/Microsoft Graph modules is a common method.
- Can import user data from CSV files for updates.
- Avoids manual, error-prone individual updates.
- Requires appropriate administrative permissions in Azure AD.
Memory trick: PowerShell is the command center for mass user changes.
Azure RBAC Reader Role
Flip cardThe Azure built-in 'Reader' role grants read-only access to all resources within its assigned scope, allowing users to view configurations and settings without making changes.
- Provides comprehensive read access.
- Does not allow any write, delete, or role assignment actions.
- Ideal for monitoring, auditing, and reporting purposes.
Memory trick: Just looking? Be a Reader, not a doer.
Azure AD Connect: Multiple Forests, Single Azure AD Tenant
Flip cardAn Azure AD Connect deployment topology where user identities from multiple separate on-premises Active Directory forests are synchronized to a single Azure Active Directory tenant.
- Common in mergers and acquisitions.
- Requires careful planning for identity matching.
- Can use a single Azure AD Connect sync server.
Memory trick: Many trees, one cloud: Multiple forests, single Azure AD.
Azure Policy and Resource Locks Combination
Flip cardAzure Policy enforces configuration standards and compliance across resources, while Azure Resource Locks protect resources from accidental deletion or modification.
- Policy for 'what' configurations are allowed/required.
- Resource Locks for 'who' can delete/modify resources.
- Combined for comprehensive governance and protection.
Memory trick: Policy sets the rules, Locks keep things in place.
Conditional Access for Privileged Roles
Flip cardAzure AD Conditional Access policies are used to enforce stringent security requirements, such as mandatory MFA and blocking legacy authentication, for highly privileged administrative roles.
- Targets specific roles (e.g., Global Admin).
- Requires MFA for every sign-in.
- Blocks legacy authentication protocols.
Memory trick: Conditional Access: The bouncer for your VIP admins.
Azure AD User Administrator Role
Flip cardA built-in Azure Active Directory role that grants permissions to manage all aspects of user and group accounts, including creating, deleting, and updating user properties and group memberships.
- Can create and delete users
- Can manage user properties and passwords
- Can assign licenses
- Cannot manage administrative roles
Memory trick: User Administrator is the 'staffing manager' for Azure AD.
Azure Policy for VM Configuration
Flip cardAzure Policy can enforce specific configuration requirements for virtual machines, such as minimum RAM size or allowed deployment regions, by denying non-compliant deployments.
- Uses 'deny' effect to block non-compliant VMs.
- Can target various VM properties (SKU, image, location).
- Ensures standardization and compliance at scale.
Memory trick: Policy is the blueprint police for your VMs.
Azure RBAC Contributor Role
Flip cardA built-in Azure role that grants full management access to all resources except the ability to manage access to Azure resources (RBAC).
- Can create, manage, and delete resources.
- Does not grant permissions to manage role assignments.
- Commonly used for developers and resource managers.
Memory trick: Contributor can build and destroy the box, but can't control who holds the keys.
Bulk User Attribute Update
Flip cardTo efficiently update attributes for multiple Azure AD users, PowerShell scripts or the Microsoft Graph API are the recommended tools, enabling consistent and scalable changes.
- PowerShell cmdlets (e.g., Set-AzureADUser) for bulk updates.
- Microsoft Graph API for programmatic attribute management.
- Essential for re-organizations and large-scale changes.
Memory trick: Scripting or Graph API for bulk user data, like a data wizard.
Azure AD Group-based Licensing
Flip cardA feature that automates the assignment and removal of Azure AD licenses to users based on their membership in specific security groups.
- Assigns licenses to security groups, not individual users directly
- Automatically assigns/removes licenses when users join/leave groups
- Simplifies license management at scale
Memory trick: Groups give licenses automatically, like a membership club.
Move Azure Subscription between Management Groups
Flip cardThe process of re-parenting an Azure subscription to a different Management Group within the Azure Management Group hierarchy.
- Requires specific RBAC permissions.
- Policies and RBAC assignments from the new parent group are inherited.
- Does not impact resources within the subscription.
Memory trick: Moving a subscription requires the 'Owner' key for both the old and new floors of the building.
Azure Subscription Move Permissions
Flip cardThe specific Azure RBAC roles required for a user to successfully move an Azure subscription between management groups. It involves permissions on the subscription itself and on the target management group.
- Owner role on the subscription to be moved
- Contributor or Owner role on the destination management group
- Contributor or Owner role on the source management group (if applicable)
Memory trick: To move your subscription 'box', you need to own the box AND have permission to put it in the new house.
Custom Role for Security Auditor
Flip cardA custom Azure RBAC role for security auditors typically combines read-only access to security settings and logs within Azure resources with specific read permissions for Azure AD audit and sign-in logs.
- Security Reader for Azure resource security settings/logs.
- Reports Reader for Azure AD sign-in/audit logs.
- Must be read-only (deny write actions).
Memory trick: Security Reader + Reports Reader = Total Audit Vision.
Azure AD Identity Governance Access Reviews
Flip cardA feature in Azure AD Identity Governance that enables organizations to manage group memberships, access to enterprise applications, and role assignments by creating recurring access reviews.
- Automates review of user access rights.
- Supports review of guest users, groups, and applications.
- Helps enforce compliance and reduce stale access permissions.
Memory trick: Guest access needs a regular check, like a revolving door of permissions.
Azure RBAC Custom Role Definition (Resource Group Creation)
Flip cardCreating a custom Azure RBAC role to grant specific, granular permissions, such as the ability to create new resource groups without broader management rights.
- Custom roles allow fine-grained control.
- Permissions are defined using 'actions' and 'notActions'.
- The 'write' action on resource groups enables creation/update.
Memory trick: To 'write' a new chapter, you need the 'write' permission.
Azure AD Password Administrator Role
Flip cardThe Azure AD 'Password Administrator' role allows designated users to reset passwords for non-administrator users and manage their authentication methods, adhering to the principle of least privilege.
- Can reset passwords for non-administrator users.
- Can manage authentication methods for non-administrator users.
- Does NOT allow creating users, modifying other user properties, or managing administrators.
Memory trick: The Password Admin is the keymaster for standard users, nothing more.
Move Azure Subscription between Management Groups Permissions
Flip cardTo move an Azure subscription between management groups, specific RBAC permissions are required on both the subscription itself and the target management group.
- Requires 'Owner' or 'User Access Administrator' on the subscription being moved.
- Requires 'Contributor' role on the *target* management group.
- No specific role is required on the *source* management group for the move operation itself.
Memory trick: Subscription needs its own key, and the new house needs to let it in.
Azure RBAC: Security Reader Role
Flip cardThe Azure 'Security Reader' role provides read-only access to security-related information and settings across Azure resources, but it specifically excludes access to user sign-in logs and audit logs within Azure AD.
- A built-in Azure RBAC role.
- Grants read access to security center, policy, resource configurations.
- Does NOT grant access to Azure AD sign-in logs or audit logs.
- Suitable for security auditors who need to review security posture without user activity details.
Memory trick: The Security Reader sees the walls, but not the guest book.
Conditional Access Sign-in Frequency
Flip cardConditional Access 'Sign-in frequency' is a session control that determines how often users are required to re-authenticate, including re-prompting for MFA, even within an active session.
- Configured within Azure AD Conditional Access policies.
- Can be set in hours, days, or 'every time'.
- Ensures re-authentication even if MFA was previously satisfied, based on defined interval.
Memory trick: Conditional Access with Sign-in Frequency is the bouncer that re-checks everyone from suspicious areas.
Azure AD Identity Governance (User Provisioning)
Flip cardAzure AD Identity Governance, through its user provisioning capabilities, automates the creation, maintenance, and removal of user identities across various systems, often integrating with HR systems for lifecycle management.
- Automates user lifecycle from joiner to leaver.
- Can provision users to Azure AD, SaaS apps, and on-premises systems.
- Integrates with HR systems (e.g., Workday, SuccessFactors) as a source of truth.
- Manages group memberships and license assignments automatically.
Memory trick: Identity Governance is the HR manager for your digital workforce, automating joiners and leavers.
Azure AD User Account Expiration
Flip cardA setting available when creating or managing Azure AD user accounts that allows an administrator to specify a future date on which the account will automatically be disabled.
- Useful for temporary users like contractors.
- Helps enforce least privilege and reduce stale accounts.
- Can be set via Azure portal or PowerShell.
Memory trick: For temporary users, set their expiration 'date' like a library book.
Azure Policy + Azure Resource Locks
Flip cardCombining Azure Policy to enforce desired configurations (like DNS settings) and Azure Resource Locks to prevent their modification, thereby achieving immutable and compliant resource configurations.
- Azure Policy defines and enforces rules (e.g., 'DeployIfNotExists' for DNS)
- Resource Locks prevent deletion or read-only modification
- Ensures configuration compliance and immutability
Memory trick: Policy sets the rules, Locks bolt them down.
Azure Monitor Metrics
Flip cardA feature of Azure Monitor that collects numerical data from Azure resources into a time-series database. It is used to track the performance and health of resources.
- Collects numerical data (e.g., CPU %, disk IOPS)
- Provides near real-time insights
- Supports charting, alerting, and auto-scaling based on metrics
- Data retained for 93 days by default
Memory trick: Metrics Measure Machine's Might.
Azure Application Gateway
Flip cardA web traffic load balancer that enables you to manage traffic to your web applications.
- Operates at Layer 7 (HTTP/S).
- Supports URL-based routing and session affinity.
- Includes Web Application Firewall (WAF) capabilities.
Memory trick: Application Gateway is the smart bouncer for your web traffic, checking the invite (URL) at the door.
Azure Container Instances (ACI)
Flip cardA serverless service that allows you to run Docker containers directly in Azure without managing underlying virtual machines or orchestrators.
- Fastest way to run a container in Azure.
- Per-second billing.
- Ideal for simple, stateless, or burstable workloads.
- No VM or orchestrator management overhead.
Memory trick: ACI for Quick Container Runs.
Azure VMSS Rolling Upgrades
Flip cardA method for updating instances within a Virtual Machine Scale Set in batches, allowing for controlled, gradual rollout of changes (OS, application, configuration) with minimal downtime and integrated health monitoring.
- Updates instances in a specified batch size.
- Monitors instance health between batches.
- Minimizes downtime during updates.
- Supports Automatic, Rolling, and Manual upgrade modes.
Memory trick: Rolling Upgrades Roll Out Smoothly.
Azure App Service Configuration
Flip cardA feature within Azure App Service that allows you to manage application settings, connection strings, and environment variables, which are injected into the application at runtime.
- Provides secure storage for application settings.
- Connection strings are encrypted at rest.
- Can reference secrets stored in Azure Key Vault for enhanced security.
- Environment variables are automatically exposed to the application process.
Memory trick: Config for Env, Key Vault for Secrets.
Azure Ephemeral OS Disk
Flip cardAn Azure VM disk type that is created on the local VM host storage, offering ultra-low latency and high throughput, but is non-persistent and tied to the VM's lifecycle.
- Stored on the VM's local host, not in Azure Storage.
- Offers significantly lower latency and higher throughput compared to managed disks.
- Non-persistent: data is lost if the VM is deallocated, moved, or redeployed.
- Ideal for stateless applications, temporary data, or caching where high I/O is critical.
Memory trick: Ephemeral: Extremely Fast, but Easily Gone.
Azure Load Balancer Health Probes
Flip cardMechanisms used by Azure Load Balancer to determine the health of backend instances. If a probe fails, the instance is taken out of rotation until it passes the probe again.
- Supports TCP, HTTP, and HTTPS protocols.
- HTTP/HTTPS probes are best for application health checks.
- TCP probes check if a port is listening.
- Configured with interval and unhealthy threshold.
Memory trick: Probes Check App's Life.
Azure Shared Disks
Flip cardA feature of Azure Managed Disks that allows multiple Azure VMs to concurrently attach a single disk.
- Enables building highly available clustered applications (e.g., WSFC).
- Provides shared storage for stateful workloads.
- Requires a cluster manager (e.g., Windows Server Failover Clustering) to manage disk access.
Memory trick: To share state and fail over fast, make sure your disks are shared and clustered.
Azure VMSS Auto-scale
Flip cardA feature of Azure Virtual Machine Scale Sets that automatically adjusts the number of VM instances based on defined rules, such as CPU utilization, queue length, or schedules.
- Optimizes performance and cost by matching capacity to demand.
- Supports metric-based, schedule-based, and manual scaling.
- Can define both scale-out (increase instances) and scale-in (decrease instances) rules.
- Commonly uses CPU usage as a scaling metric.
Memory trick: Scale Sets Sense CPU Swings.
Azure Private Subnet
Flip cardA segment of an Azure Virtual Network (VNet) where resources are not directly accessible from the internet by default, providing an isolated network environment for internal applications.
- Resources within can communicate with each other and other VNet resources.
- Requires Network Security Groups (NSGs) for granular traffic control.
- Enhances security by limiting internet exposure.
- Can be connected to on-premises networks via VPN/ExpressRoute.
Memory trick: Private Subnets Protect Internal Paths.
Azure Kubernetes Service (AKS)
Flip cardA managed container orchestration service that simplifies deploying, managing, and scaling containerized applications using Kubernetes.
- Provides full control over Kubernetes clusters.
- Offers advanced networking features (e.g., custom DNS, network policies).
- Deep integration with Azure Virtual Networks.
- Suitable for complex, microservices-based applications.
Memory trick: When you need 'K'ontrol over 'K'ontainers and 'K'omplex networking, think AKS.
Azure Managed Image
Flip cardA resource in Azure that allows you to capture a snapshot of a generalized (sysprepped) virtual machine's operating system and data disks, enabling you to create identical VMs from that image.
- Used for creating 'golden images' or templates.
- VM must be generalized (sysprepped for Windows) before capture.
- Simplifies consistent deployment of multiple VMs.
- Can be shared across subscriptions or tenants.
Memory trick: Sysprep a Source, Save as Image.
Azure App Service
Flip cardA fully managed platform-as-a-service (PaaS) for building, deploying, and scaling web apps, mobile backends, and RESTful APIs, supporting multiple languages and frameworks.
- Supports auto-scaling and deployment slots.
- Integrated monitoring and diagnostics.
- Can scale to zero with specific plans (e.g., Consumption for Functions).
- Reduces infrastructure management overhead.
Memory trick: App Service Shines for Scalable Sites.
Azure Compute Gallery
Flip cardA service that helps you manage and share custom VM images across subscriptions and tenants.
- Stores custom VM images (including OS, data disks, software).
- Enables consistent deployment of pre-configured VMs.
- Provides versioning and regional replication for images.
Memory trick: To share your perfect VM 'blueprint', use the Compute Gallery.
Azure Ultra Disk
Flip cardA high-performance, low-latency disk storage option for Azure VMs, offering configurable IOPS and throughput.
- Offers sub-millisecond latency.
- Provides highest IOPS and throughput among Azure disk types.
- Ideal for I/O-intensive applications like databases.
Memory trick: For ultimate speed, go Ultra; everything else is just a warm-up.
PowerShell Desired State Configuration (DSC) Extension
Flip cardAn Azure VM extension that allows you to apply PowerShell Desired State Configuration (DSC) configurations to Windows VMs, enabling consistent and automated software installation and system configuration.
- Uses configuration scripts to define desired state.
- Ensures idempotency (running multiple times yields same result).
- Can be used for software installation, service configuration, and more.
- Delivered via the Azure VM extension mechanism.
Memory trick: DSC Designs Consistent Configs.
Azure Availability Sets
Flip cardA logical grouping capability for isolating VM resources from each other when they're deployed. It ensures that VMs are distributed across different physical hardware in a datacenter.
- Protects against unplanned hardware failures
- Protects against planned maintenance
- Distributes VMs across Fault Domains (up to 3)
- Distributes VMs across Update Domains (up to 20)
Memory trick: Availability Sets Keep VMs Safe in the Same House.
Azure Static Public IP
Flip cardA public IP address assigned to an Azure resource (like a VM) that does not change over time, even after the resource is deallocated or restarted.
- Ensures consistent IP address for external access
- Required for DNS records, firewall rules, client configurations
- Incurs a small cost even when not actively used
- Can be assigned to VMs, load balancers, application gateways
Memory trick: Static IP: Stay Put, Don't Move.
Azure Container Apps
Flip cardA serverless platform for building and deploying modern apps and microservices using containers. It offers auto-scaling, integrated ingress, and support for event-driven architectures.
- Serverless container execution
- Ideal for microservices and event-driven apps
- Automatic scaling and integrated ingress
- Supports HTTP/HTTPS, TCP, and Event-Driven Scale (KEDA)
Memory trick: Containers Can Be Awesome, Just Keep Scaling