Microsoft Certified: Azure Solutions Architect Expert flashcards
123 free flashcards. Tap a card to flip it.
Azure AD Multi-tenant Application
Flip cardAn Azure AD multi-tenant application is an application that accepts sign-ins from users in any Azure AD tenant, not just the tenant where the application is registered.
- Enables SaaS providers to offer their services to customers with their own Azure AD.
- Requires users or tenant administrators to grant consent for the application to access their tenant's data.
- Authentication is handled by Azure AD, simplifying development and security.
Memory trick: One app, many homes: multi-tenant opens the doors wide.
Azure SQL DB Automated Backups
Flip cardAzure SQL Database automatically performs full, differential, and transaction log backups, enabling point-in-time restores to meet specific RPO requirements.
- Full backups weekly, differential daily, transaction logs every 5-10 minutes.
- Enables point-in-time restore to any minute within retention.
- Meets low RPO requirements for transactional databases.
Memory trick: SQL DB: Auto-backup, point-in-time, minimal loss.
ASR Cost Optimization for DR
Flip cardAzure Site Recovery allows for cost-effective disaster recovery by replicating VMs to a secondary region without requiring active, running compute resources (VMs) in that region until a failover occurs.
- Only pays for storage and ASR replication costs in the secondary region normally.
- Compute costs are incurred only during test failovers or actual failovers.
- Enables 'cold' or 'warm' DR sites, reducing operational expenses.
- Still achieves low RTO/RPO for critical workloads.
Memory trick: ASR is the smart saver for DR, only paying for VMs when you need them.
Azure Files Zone-redundant storage (ZRS)
Flip cardA redundancy option for Azure Files that synchronously replicates data across three Azure availability zones in a single region, providing high availability and resilience against zonal failures.
- Provides 99.99% availability
- Protects against data center (Availability Zone) outages
- Synchronous replication within a single Azure region
- Suitable for frequently accessed and modified data requiring high availability
Memory trick: ZRS for Files: A trio of zones keeps your files always reachable.
Azure Service Bus Geo-disaster recovery
Flip cardA Service Bus feature that enables continuous replication of metadata between a primary and secondary namespace in different Azure regions, allowing for seamless failover in case of a regional disaster.
- Requires Service Bus Premium tier
- Automatically replicates namespace metadata (queues, topics, subscriptions)
- Requires manual or programmatic initiation of failover
- Provides a consistent alias for applications after failover
Memory trick: Geo-DR ensures messages always find their way, even if a region vanishes.
Azure App Service Zone Redundancy
Flip cardConfiguring App Service Plans to deploy across multiple Availability Zones within a single Azure region to protect applications from data center-level failures.
- Requires a Premium V3 or Isolated V2 App Service Plan.
- Distributes App Service instances across zones.
- Ensures application availability during zonal outages.
Memory trick: Zones are your regional safety nets for App Service.
Azure Front Door for Multi-Region AKS
Flip cardAzure Front Door acts as a global entry point for multi-region AKS deployments, providing intelligent traffic routing, application acceleration, and automatic failover to ensure high availability and low latency.
- Global HTTP(S) load balancing at Layer 7.
- Routes traffic to the closest healthy backend (AKS cluster).
- Provides WAF, DDoS protection, and dynamic site acceleration.
- Supports automatic failover between regional AKS clusters.
Memory trick: Front Door is the global concierge for your AKS apps, always directing users to the best experience.
Azure Application Insights
Flip cardAn Application Performance Management (APM) service that monitors live web applications, automatically detecting performance anomalies. It includes powerful analytics tools to help diagnose issues and understand what users actually do with your app.
- Monitors end-to-end application performance and availability
- Collects requests, dependencies, exceptions, and traces
- Provides code-level diagnostics and user behavior analysis
Memory trick: APP INSIGHTS for deep app dives.
Azure Site Recovery (ASR)
Flip cardA disaster recovery service that orchestrates replication, failover, and failback of virtual machines and physical servers to Azure, or between Azure regions, to ensure business continuity.
- Provides low RTO and RPO for VMs
- Supports replication to Azure or between Azure regions
- Enables non-disruptive test failovers
- Orchestrates failover and failback processes
Memory trick: ASR is the DR orchestrator, handling replication and swift recovery.
Azure Traffic Manager
Flip cardA DNS-based traffic load balancer that allows you to distribute user traffic to service endpoints across global Azure regions or external endpoints.
- Uses various routing methods (Priority, Performance, Geographic, Weighted).
- Provides automatic failover to healthy endpoints.
- Improves application responsiveness and availability for globally distributed applications.
Memory trick: Traffic Manager: Your Global DNS Director.
Azure AD Conditional Access
Flip cardAzure AD Conditional Access is the tool used by Azure Active Directory to bring signals together, to make decisions, and enforce organizational policies.
- Evaluates conditions like user group, location, device platform, client application.
- Enforces controls such as MFA, compliant device, password change, or block access.
- Centralizes access management decisions for applications and resources.
Memory trick: Conditional Access: The 'Security Guard' at the gate, checking all conditions before entry.
Azure Backup for Azure VMs
Flip cardA native Azure service that provides automated, policy-based backup and recovery for Azure Virtual Machines.
- Offers application-consistent backups.
- Supports various retention policies (daily, weekly, monthly, yearly).
- Integrated with Azure Recovery Services vaults for centralized management.
Memory trick: Azure Backup: The simplest way to save your VM's day.
Azure Backup for VMs
Flip cardAzure Backup for Azure VMs provides a managed, scalable, and automated backup solution for Azure Virtual Machines, enabling point-in-time recovery of entire VMs or individual files.
- Automated, policy-driven backups.
- Supports full VM or file-level recovery.
- Integrated with Azure Recovery Services vaults.
- Offers soft delete for protection against accidental deletion.
Memory trick: Azure Backup for VMs is your 'Restore Point' for any VM trouble.
Azure Front Door
Flip cardA global, scalable entry-point that uses the Microsoft global edge network to create fast, secure, and widely scalable web applications, providing global load balancing and site acceleration.
- Offers global HTTP/HTTPS load balancing.
- Provides application acceleration and SSL offloading.
- Enables automatic failover across regions for high availability.
Memory trick: Front Door is the Global Gateway for your Apps.
Immutable Backups with Azure Backup
Flip cardConfiguring Azure Backup (specifically Recovery Services vaults) with immutable storage ensures that once backup data is written, it cannot be modified or deleted for a specified retention period, crucial for compliance and ransomware protection.
- Applies to Recovery Services vaults
- Protects backup data from accidental or malicious deletion/modification
- Supports various backup workloads (VMs, SQL, File shares)
- Critical for regulatory compliance (e.g., healthcare, finance)
Memory trick: Immutability is like a digital time capsule for backups.
Azure Monitor Suite
Flip cardAzure Monitor is a comprehensive solution for collecting, analyzing, and acting on telemetry from Azure and on-premises environments, encompassing logs, metrics, application performance, and network monitoring.
- Collects metrics and logs from various sources.
- Provides visualization, analysis, and alerting capabilities.
- Includes Log Analytics for log management and Application Insights for APM.
Memory trick: Monitor everything: logs, apps, metrics, all in one place.
Azure Files with ZRS
Flip cardAzure Files provides managed file shares in the cloud, and when configured with Zone-redundant storage (ZRS), it ensures high availability and resilience against zone-level failures.
- Provides fully managed file shares (SMB/NFS).
- ZRS replicates data synchronously across three availability zones.
- Accessible from on-premises (via VPN/ExpressRoute) and Azure VMs.
Memory trick: Azure Files ZRS: Zone safe for your shared files.
Azure IoT Hub
Flip cardAzure IoT Hub is a managed service that acts as a central message hub for bi-directional communication between your IoT application and the devices it manages. It supports millions of devices and ensures secure and reliable communication.
- Bi-directional communication (device-to-cloud, cloud-to-device)
- Device management capabilities (device twin, direct methods)
- Secure per-device authentication
- Scales to millions of devices
Memory trick: IoT Hub is the Heart of IoT.
Azure IoT Data Pipeline
Flip cardA typical Azure IoT data pipeline involves IoT Hub for device ingestion, Stream Analytics for real-time processing, and Data Lake Storage for historical data storage and analysis.
- IoT Hub handles device communication and telemetry.
- Stream Analytics processes data in motion.
- Data Lake Storage provides scalable, cost-effective storage for big data.
Memory trick: IoT Hub: The device's mailbox. Stream Analytics: The real-time sorter. Data Lake: The vast archive.
Managed Identity + CMK
Flip cardManaged Identity provides an automatically managed, Azure AD-based identity for Azure services, eliminating credential management. Customer-Managed Keys (CMK) allow customers to use their own encryption keys for data at rest in Azure services, providing greater control over encryption.
- Managed Identity: Credential-free authentication for Azure services
- Managed Identity: Azure handles identity lifecycle
- CMK: Customer controls encryption keys in Azure Key Vault
- CMK: Enhances data security and meets regulatory compliance
Memory trick: Managed Identity Guards, CMK Controls the Vault.
Azure Availability Zones
Flip cardAzure Availability Zones are physically separate locations within an Azure region, each with independent power, cooling, and networking, providing resilience against data center failures.
- Protects against data center failures within a region.
- Distributes resources across independent physical locations.
- Requires services to be zone-aware to function across zones.
Memory trick: Zones: Keep apps alive, even if one zone dies.
Azure SQL Database Failover Groups
Flip cardAzure SQL Database Failover Groups automate the replication and failover of a group of databases to a secondary region, providing business continuity for regional disasters.
- Automates failover for a group of databases.
- Supports both manual and automatic failover policies.
- Provides a read-write listener and an optional read-only listener.
- Ensures low RPO and RTO for regional disaster recovery.
Memory trick: SQL Disasters need Fast Recovery like a Failover Group.
Azure Monitor Agent (AMA)
Flip cardThe Azure Monitor Agent (AMA) is a single, unified agent for Azure Monitor that collects monitoring data from guest operating systems of Azure virtual machines, Azure Arc-enabled servers, and Azure Virtual Machine Scale Sets and delivers it to Azure Monitor Logs and Azure Monitor Metrics.
- Replaces the legacy Log Analytics agent (MMA/OMS) and Azure Diagnostics extensions.
- Uses Data Collection Rules (DCRs) for granular control over collected data.
- Supports both Windows and Linux operating systems.
Memory trick: AMA: Your 'All-in-One' agent for gathering VM intelligence.
Azure Geo-zone-redundant storage (GZRS)
Flip cardThe highest level of Azure Storage redundancy, combining zone-redundant storage (ZRS) in the primary region with geo-redundant storage (GRS) to a secondary region.
- Synchronous replication across 3 AZs in primary region.
- Asynchronous replication to secondary region.
- Offers 12 nines (99.9999999999%) durability.
- Protects against both zone and regional failures.
Memory trick: GZRS is the ultimate shield, protecting your data across zones and regions.
Managed Identities for Azure Resources
Flip cardManaged Identities for Azure Resources provide an automatically managed identity in Azure Active Directory (Azure AD) for applications to use when connecting to resources that support Azure AD authentication.
- Eliminates the need for developers to manage credentials.
- Identities are managed by Azure, enhancing security.
- Can be assigned to many Azure services, like VMs, App Services, Functions.
Memory trick: Managed Identity: Your app's invisible key to Azure's treasure chest.
Password Hash Synchronization (PHS)
Flip cardA hybrid identity method where a hash of the user's on-premises Active Directory password hash is synchronized to Azure Active Directory. This allows users to sign in to Azure AD with the same credentials they use on-premises.
- Simplest to implement for hybrid identity
- Provides cloud authentication if on-premises AD is unavailable
- Supports seamless SSO
Memory trick: Sync PASSWORDS, Pass-THRU, or FEDERATE.
Azure Cosmos DB Multi-Region Writes
Flip cardAzure Cosmos DB's multi-region write capability allows applications to perform writes to any configured region, ensuring high availability and low latency globally.
- Active-active distribution across multiple Azure regions.
- Automatic failover with zero RPO (Recovery Point Objective) for regional outages.
- Provides global low-latency access for both reads and writes.
Memory trick: Cosmos DB writes globally, always available.
Azure AD Multi-tenant Apps
Flip cardAn Azure AD multi-tenant application allows users from any Azure AD tenant to sign in to the application after granting consent, enabling SaaS solutions to serve multiple organizations.
- Application is registered in one Azure AD tenant.
- Users from other tenants can sign in using their own Azure AD accounts.
- Requires user or admin consent for first-time use in a new tenant.
Memory trick: Multi-tenant app: One app, many corporate doors.
Multi-Region AKS Deployment
Flip cardDeploying Azure Kubernetes Service (AKS) clusters across multiple Azure regions with a global load balancer provides disaster recovery and high availability against regional outages.
- Protects against complete Azure region failures.
- Requires a global load balancer (e.g., Azure Front Door, Traffic Manager).
- Ensures continuous API availability across regions.
Memory trick: AKS: Region-safe with global load balancing.
VNet Integration + NSG
Flip cardAzure Virtual Network (VNet) Integration for App Service allows an app to access resources in or through a VNet, effectively placing the app within a private network. Network Security Groups (NSGs) then filter network traffic to and from resources in an Azure VNet.
- VNet Integration prevents public internet access to App Service
- NSGs enable granular IP-based traffic filtering
- Used together for private and controlled access to backend services
- Can secure inbound and outbound traffic
Memory trick: VNet Integration is the House, NSG is the Door Guard.
Azure Front Door for Global AKS
Flip cardAzure Front Door is a scalable, secure, and globally distributed entry point that uses the Microsoft global edge network to create fast, secure, and highly scalable web applications, often used for routing traffic to multi-region AKS deployments.
- Global HTTP/S load balancing
- Latency-based routing to closest backend
- Integrated Web Application Firewall (WAF)
- SSL offloading and custom domains
Memory trick: Front Door is the global gatekeeper, routing and protecting.
Azure Backup Server (MABS)
Flip cardAzure Backup Server (MABS) is an enterprise-class backup solution for on-premises workloads, including SQL Server, that integrates with Azure Backup for cloud storage and recovery.
- Extends System Center Data Protection Manager (DPM) to Azure.
- Supports application-consistent backups for SQL Server.
- Enables point-in-time recovery and encryption of backups at rest.
Memory trick: MABS: Master of on-prem SQL backup to Azure.
Azure Monitor Logs (Log Analytics)
Flip cardAzure Monitor Logs, powered by a Log Analytics workspace, is a logging service that collects telemetry and other data from a variety of sources and provides a query language and analytics engine.
- Centralized log collection for Azure resources and hybrid environments.
- Uses Kusto Query Language (KQL) for powerful data analysis.
- Offers long-term data retention and integration with other Azure services.
Memory trick: Log Analytics: Your data detective for all Azure's whispers.
SQL DB Security Features
Flip cardAzure SQL Database offers multiple security features including Transparent Data Encryption (TDE) for data at rest, SSL/TLS for data in transit, and Row-Level Security (RLS) for granular access control over rows based on user identity.
- TDE: Encrypts entire database at rest
- SSL/TLS: Encrypts data communicated over network
- RLS: Filters rows returned by queries based on user context
- CLS: Restricts access to specific columns (not a direct option here but relevant)
Memory trick: TDE is Rest, SSL is Transit, RLS is Rows.
Azure Kubernetes Service (AKS) Availability Zones
Flip cardAzure Kubernetes Service (AKS) can be deployed with Availability Zones to distribute cluster nodes across multiple isolated physical locations within a single Azure region, enhancing resilience against zone-wide failures.
- Distributes nodes across 3 Availability Zones.
- Protects against datacenter-level failures within a region.
- Ensures high availability for AKS workloads.
- Requires specifying zones during cluster creation.
Memory trick: AKS in AZs keeps your Kube pods safe from Zonal outages.
Azure Backup for SQL Server in Azure VMs
Flip cardA native Azure Backup solution designed to protect SQL Server databases running inside Azure Virtual Machines, offering application-consistent backups and point-in-time recovery.
- Supports long-term retention policies for SQL Server backups.
- Provides granular recovery options (database, file, log mark).
- Integrated with Azure Recovery Services vaults for centralized management.
Memory trick: SQL on VM? Azure Backup is the best for your data's journey.
Azure Blob Storage Archive Tier & Immutability
Flip cardAzure Blob Storage Archive tier offers the lowest cost for rarely accessed, long-term data. Object immutability policies ensure data retention and protection from alteration for compliance.
- Archive tier: lowest storage cost, highest retrieval cost/latency.
- Ideal for long-term data retention (e.g., 7 years).
- Object immutability (WORM) ensures compliance by preventing deletion/modification.
Memory trick: Archive + Immutability: Store long, secure strong.
Azure Service Bus Geo-DR
Flip cardAzure Service Bus Geo-disaster recovery (Geo-DR) provides continuous replication of metadata between primary and secondary namespaces across regions, enabling seamless failover.
- Pairs primary and secondary Service Bus namespaces.
- Asynchronously replicates metadata, not message data (message data is in transit/at rest).
- Enables failover to a secondary region for messaging continuity.
Memory trick: Service Bus Geo-DR: Messages flow, even if regions go.
Azure Blob Storage Immutability Policies
Flip cardAllows you to store business-critical data in a WORM (Write Once, Read Many) state, preventing modification or deletion for a specified period or until a legal hold is removed.
- Supports time-based retention and legal holds.
- Can be applied to Hot, Cool, and Archive tiers.
- Ensures data integrity for compliance and regulatory needs.
Memory trick: Always Secure Data: Immutability is the Key.
Azure Front Door + SQL DB Active Geo-replication
Flip cardA powerful combination for global, highly available web applications: Front Door for global traffic management and application-level failover, and Active Geo-replication for cross-region, readable database replicas.
- Front Door provides global load balancing, WAF, and application acceleration.
- Active Geo-replication enables up to 4 readable secondaries for SQL DB.
- Together, they offer a robust multi-region HA/DR solution for web apps with SQL backends.
Memory trick: Front Door opens the way globally, while SQL Geo-replication mirrors your data everywhere.
Azure AD Privileged Identity Management (PIM)
Flip cardAzure AD PIM is a service that enables you to manage, control, and monitor access to important resources in Azure AD, Azure, and other Microsoft Online Services.
- Provides just-in-time privileged access to minimize exposure time.
- Enforces time-bound access, requiring re-activation after a set period.
- Supports approval workflows for role activation and provides audit trails.
Memory trick: PIM: Your royal guard for temporary, approved access to the kingdom's treasures.
Azure PIM
Flip cardAzure Privileged Identity Management (PIM) is an Azure AD service that enables you to manage, control, and monitor access to important resources in Azure AD, Azure, and other Microsoft online services.
- Provides just-in-time (JIT) privileged access
- Enforces time-bound access for roles
- Supports approval workflows for role activation
- Can require MFA for role activation
Memory trick: PIM Protects Important Members with Time and MFA.
Azure SQL Database Point-in-Time Restore (PITR)
Flip cardA recovery feature that allows you to restore an Azure SQL Database to any point in time within its configured retention period, using automated backups.
- Leverages full, differential, and transaction log backups.
- Typically offers an RPO of 5 minutes or less.
- Enables rapid recovery for operational data loss scenarios.
Memory trick: PITR: Your time machine for SQL Database recovery.
Azure Blob Immutable Storage
Flip cardA feature of Azure Blob Storage that stores data in a WORM (Write Once, Read Many) state, preventing modification or deletion for a specified retention period or until a legal hold is removed.
- Supports time-based retention policies and legal holds.
- Prevents data modification or deletion, even by administrators.
- Essential for regulatory compliance (e.g., FINRA, SEC, HIPAA).
Memory trick: Immutable storage locks your data like a vault for a set time.
Azure Site Recovery (ASR) Test Failover
Flip cardA critical feature of Azure Site Recovery that allows for non-disruptive disaster recovery drills by creating isolated copies of replicated VMs in a test network.
- Enables validation of recovery plans without impacting production.
- Creates a copy of replicated VMs in an isolated network.
- Essential for meeting compliance and RTO objectives.
- Helps identify and resolve potential issues in the DR plan.
Memory trick: ASR is your DR rehearsal stage, testing recovery without breaking the show.
Azure AD PIM
Flip cardAzure Active Directory Privileged Identity Management (PIM) is a service that enables you to manage, control, and monitor access to important resources in Azure AD, Azure, and other Microsoft services.
- Provides just-in-time (JIT) and time-bound access to roles.
- Requires activation (e.g., MFA, approval) for privileged roles.
- Offers auditing and review capabilities for privileged access.
Memory trick: PIM: The temporary key that locks itself after use.
Azure AD Connect Pass-through Authentication (PTA)
Flip cardAzure AD Connect Pass-through Authentication (PTA) allows users to sign in to both on-premises and cloud-based applications using the same passwords. It achieves this by validating passwords directly against your on-premises Active Directory.
- Provides a simple way to achieve single sign-on with on-premises AD.
- Does not store user passwords in Azure AD; only the hash of the password is sent for comparison.
- Requires lightweight agents on-premises to forward authentication requests.
Memory trick: PTA: Your password 'passes through' to its home for verification.
Azure Management Groups
Flip cardAzure Management Groups are containers that help you manage access, policy, and compliance across multiple Azure subscriptions. They provide a level of organization above subscriptions.
- Hierarchical structure for organizing subscriptions
- Policies and RBAC roles inherit down the hierarchy
- Enables consistent governance across the enterprise
- Supports up to six levels of depth
Memory trick: Management Groups Manage Many Subscriptions.
Azure AD Domain Services (AAD DS)
Flip cardA managed domain service provided by Azure that offers domain join, group policy, lightweight directory access protocol (LDAP), and Kerberos/NTLM authentication compatible with Windows Server Active Directory.
- Provides AD-compatible services in Azure without managing DCs
- Supports legacy applications requiring LDAP, Kerberos, NTLM
- Synchronizes with Azure AD for user identities
Memory trick: AAD DS is the 'Legacy Bridge' for AD services.
Azure Storage Geo-zone-redundant storage (GZRS)
Flip cardCombines high availability within a primary region (using Availability Zones) with disaster recovery to a secondary region, offering maximum durability and availability.
- Data is replicated synchronously across three Azure Availability Zones in the primary region.
- Data is then asynchronously replicated to a single physical location in a secondary region.
- Offers 99.99999999999999% (16 nines) annual durability.
Memory trick: Redundancy Levels: L-Z-G-GZ, each step increases protection.
Azure SQL Database Active Geo-replication
Flip cardA feature that allows you to create up to four readable secondary databases in different Azure regions for disaster recovery and global distribution.
- Provides continuous asynchronous replication of transactions.
- Supports manual or automatic failover via failover groups.
- Secondaries are readable, enabling offloading read workloads.
Memory trick: Globally Syncing Data Keeps SQL Always Alive.
NSG + VPN Gateway
Flip cardNetwork Security Groups (NSGs) control network traffic to Azure resources, while Azure VPN Gateway establishes secure, encrypted connections between on-premises networks and Azure virtual networks.
- NSGs filter traffic based on IP, port, protocol.
- VPN Gateway enables secure private connectivity.
- NSG Flow Logs can be enabled for auditing network traffic.
Memory trick: NSG + VPN: The bouncer and the secret tunnel.
Managed Identities
Flip cardManaged Identities for Azure Resources provide an automatically managed identity in Azure Active Directory for applications to use when connecting to resources that support Azure AD authentication.
- Eliminates credential management for developers
- Azure automatically manages identity lifecycle
- Can be assigned to Azure services (VMs, App Services, Functions, etc.)
- Supports System-assigned and User-assigned types
Memory trick: Managed Identities Make Secrets Invisible.
VNet + VPN Gateway + Azure AD
Flip cardAzure Virtual Network (VNet) provides private network isolation. A VPN Gateway creates a secure, encrypted connection to a VNet from on-premises networks. Azure Active Directory (Azure AD) provides centralized user authentication for applications.
- VNet isolates resources from public internet
- VPN Gateway enables secure, encrypted on-premises connectivity
- Azure AD provides robust user authentication
- Combined, they ensure private, authenticated, encrypted access
Memory trick: VNet is the House, VPN is the Private Road, AD is the Key.
Azure Role-Based Access Control (RBAC)
Flip cardAn authorization system built on Azure Resource Manager that provides fine-grained access management of Azure resources. It allows you to control who has access to which resources, what they can do with those resources, and at what scope.
- Uses 'who', 'what', 'where' model (Security principal, Role definition, Scope)
- Supports built-in and custom roles
- Integrates with Azure AD users, groups, and service principals
Memory trick: RBAC: ROLES grant access, like job titles.
Azure SQL DB Point-in-Time Restore (PITR)
Flip cardA built-in feature of Azure SQL Database that allows restoring a database to an earlier point in time, typically within its automated backup retention period.
- Uses automated full, differential, and transaction log backups.
- Default retention is 7 days (can be extended up to 35 days).
- Ideal for recovering from accidental data deletion or corruption.
Memory trick: PITR is like a time machine for your database, going back to a specific moment.
Azure Policy
Flip cardAzure Policy is a service in Azure that you use to create, assign, and manage policies that enforce rules and effects over your resources to stay compliant with your corporate standards and service level agreements.
- Enforces rules and effects on Azure resources
- Can audit, deny, or modify resource deployments
- Supports built-in and custom policy definitions
- Applied at various scopes (management group, subscription, resource group)
Memory trick: Azure Policy Polices Your Resources.
Azure AD Connect with PTA
Flip cardAzure AD Connect with Pass-through Authentication (PTA) is a sign-in method that validates user passwords directly against the on-premises Active Directory when they try to access Azure AD-connected applications.
- Provides single sign-on (SSO) for hybrid environments.
- Does not store user passwords in Azure AD.
- Requires agents to be installed on-premises.
Memory trick: Connect on-premises to cloud, pass-through securely.
Azure AD Pass-through Authentication (PTA)
Flip cardAzure AD Pass-through Authentication allows users to sign in to both on-premises and cloud-based applications using the same passwords. It achieves this by validating users' passwords directly against their on-premises Active Directory.
- No password hashes stored in Azure AD
- Lightweight agents on-premises
- Seamless single sign-on experience
- Supports legacy authentication protocols
Memory trick: PTA Passes Through to AD.
Cosmos DB Multi-Region Writes
Flip cardAn Azure Cosmos DB capability that allows all regions configured for an account to be active for both reads and writes, enabling global ultra-low latency and high availability.
- All regions are writable and readable.
- Provides global low latency for both reads and writes.
- Offers automatic failover and high availability.
- Often paired with session consistency for optimal global performance.
Memory trick: Cosmos DB Multi-Region Writes: Write anywhere, read anywhere, instantly, globally.