Microsoft Certified: Identity and Access Administrator Associate flashcards
114 free flashcards. Tap a card to flip it.
Azure AD Identity Protection
Flip cardA security module in Azure AD that automates the detection, investigation, and remediation of identity-based risks.
- Detects real-time and offline risks (e.g., suspicious sign-ins, leaked credentials).
- Calculates user and sign-in risk levels.
- Can trigger Conditional Access policies for automated remediation (e.g., MFA, password reset).
Memory trick: Identity Protection detects risks, Conditional Access enforces rules.
Federation with AD FS (Hybrid Identity)
Flip cardFederation with Active Directory Federation Services (AD FS) in a hybrid identity model means that Azure AD delegates authentication to an on-premises AD FS server. This allows users to sign in using their on-premises credentials without their passwords or hashes ever leaving the on-premises environment.
- Azure AD redirects authentication requests to AD FS.
- AD FS validates credentials against on-premises AD DS.
- Azure AD receives a security token, not credentials.
- Requires more infrastructure (AD FS servers) than PHS or PTA.
Memory trick: Hybrid authentication: Where is the password validated?
Azure Managed Identities
Flip cardAzure AD identities automatically managed by Azure, allowing Azure services to authenticate to cloud services without requiring developers to manage credentials.
- Eliminates the need for hard-coded credentials.
- Can be system-assigned (tied to a resource's lifecycle) or user-assigned (independent resource).
- Used for authenticating to any service that supports Azure AD authentication.
Memory trick: Managed identities: Your Azure resources get their own secure keys.
System-assigned managed identity
Flip cardA type of Azure AD identity automatically created and managed by Azure for a specific Azure resource, enabling that resource to authenticate to other services securely.
- Tied to the lifecycle of a single Azure resource.
- Automatically created and deleted with the resource.
- No manual credential management required.
Memory trick: Systematic Security for Single Services.
Azure AD Pass-through Authentication (PTA)
Flip cardAn Azure AD Connect authentication method that signs users in by validating their passwords directly against on-premises Active Directory.
- No password hashes stored in Azure AD.
- Requires lightweight agents on-premises.
- Provides a simple way to achieve hybrid identity.
Memory trick: PHS hashes, PTA passes, AD FS federates, Kerberos stays home.
PIM Role Settings
Flip cardConfigurations within Azure AD Privileged Identity Management that define requirements for activating and assigning a privileged role, such as approval, MFA, and maximum duration.
- Governs activation requirements (approval, MFA, justification).
- Sets maximum activation duration.
- Configured per role in PIM.
Memory trick: Settings Govern Role Activations.
Conditional Access Policy Structure
Flip cardAzure AD Conditional Access policies define 'If-Then' statements: 'If' conditions are met, 'then' enforce access controls.
- Composed of Assignments (Users, Cloud apps) and Access Controls (Grant, Session).
- Conditions (Locations, Device platforms, Client apps, Sign-in risk) refine policy applicability.
- Policies are processed after authentication and before resource access.
Memory trick: 🚦 If conditions match, 🔐 then control access.
Azure AD Optional Claims
Flip cardA feature in Azure AD that allows administrators to configure additional claims to be included in the security tokens (ID, access, SAML) issued to applications.
- Can include standard claims or directory extension attributes.
- Configured in the application's manifest or through Azure portal.
- Reduces the need for applications to make additional Graph API calls.
Memory trick: Claims make tokens rich, Optional adds the extras.
Delegated Permissions
Flip cardPermissions used by an application to act on behalf of a signed-in user, with access limited by both the granted permissions and the user's own permissions.
- Application acts 'on behalf of' a user.
- Requires user consent (or admin consent).
- Combined scope of app permissions and user's access.
Memory trick: Delegate Users, Apply Apps.
PTA + Seamless SSO + Conditional Access
Flip cardA common Azure AD authentication architecture that provides seamless sign-on for corporate users on trusted networks/devices and enforces adaptive access policies like MFA for others.
- PTA validates passwords against on-premises AD.
- Seamless SSO provides automatic sign-in on corporate networks/devices.
- Conditional Access enforces policies based on context (location, device, risk).
Memory trick: PTA Seamlessly Protects with CA.
Azure AD Custom Security Attributes
Flip cardA feature in Azure AD that allows organizations to define their own business-specific attributes for directory objects (users, applications, devices) and use them for authorization and policy enforcement.
- User-defined attributes in Azure AD.
- Can be assigned to users, applications, etc.
- Integrates with Conditional Access for policy enforcement.
Memory trick: Custom Attributes Control Access.
Azure AD Optional Claims for Extension Attributes
Flip cardA feature that enables the inclusion of Azure AD directory extension attributes as claims within security tokens issued to applications by Azure AD, particularly useful for custom application requirements.
- Configured via the Azure portal or application manifest.
- Supports both standard claims and directory extension attributes.
- Ensures custom user data is available in the ID or access token.
Memory trick: Optional Claims ADD attributes, Claims Mapping TRANSFORMS.
Azure AD Multi-tenant Organization (MTO)
Flip cardA feature in Azure AD that enables seamless collaboration across multiple Azure AD tenants belonging to the same enterprise, providing a unified experience for users and simplified administration.
- Facilitates cross-tenant access without individual B2B invitations.
- Users maintain their home tenant identity.
- Simplifies resource sharing and administration across organizational boundaries.
Memory trick: MTO is for my own tenants, B2B is for others.
Conditional Access Locations
Flip cardA Conditional Access policy condition that allows administrators to specify network locations (e.g., trusted IP ranges) to include or exclude from policy enforcement.
- Uses 'Named locations' defined in Azure AD.
- Can be used to enforce or bypass MFA based on network.
- Crucial for balancing security and user experience.
Memory trick: Conditions Control Access Decisions.
Directory.Read.All (Application)
Flip cardA Microsoft Graph application permission that allows an application to read all properties of all directory objects (users, groups, devices, etc.) in an Azure AD tenant.
- Application permission (no signed-in user).
- Provides read access to all directory objects.
- Requires administrator consent due to broad scope.
Memory trick: Directory Reads All for Service Needs.
OAuth 2.0 Client Authentication
Flip cardThe process by which a client application proves its identity to the authorization server when requesting tokens.
- Public clients (e.g., SPA, mobile) cannot securely store secrets.
- Confidential clients (e.g., web apps, servers) can securely store secrets.
- Methods include client secret (shared secret), client assertion (JWT signed with certificate), or managed identities.
Memory trick: Secrets need strong vaults, not open windows.
Azure AD B2B Collaboration
Flip cardA feature of Azure AD that allows organizations to securely share applications and resources with external users from other organizations.
- External users are represented as guest users in the inviting tenant.
- Supports various identity providers (Azure AD, Microsoft accounts, social identities).
- Enables self-service sign-up workflows for onboarding external partners.
Memory trick: Users are either from inside, or invited from outside.
Conditional Access with Custom Security Attributes
Flip cardLeveraging Azure AD Conditional Access policies to enforce access control based on user-defined custom security attributes, enabling highly granular authorization without modifying application code.
- Custom attributes are defined in Azure AD.
- Conditional Access policies evaluate these attributes.
- Enforcement happens at the authentication boundary.
- No changes to application code required.
Memory trick: Custom Attributes Condition Access.
Federation with AD FS
Flip cardAn Azure AD Connect authentication method where users authenticate directly against an on-premises AD FS farm, and Azure AD trusts AD FS for identity verification.
- Authentication occurs entirely on-premises.
- No password hashes or passwords stored/synchronized to Azure AD.
- Requires deployment and management of AD FS infrastructure.
Memory trick: Hash, Pass, Federate for Identities.
Azure AD Connect Staging Mode
Flip cardA feature of Azure AD Connect that allows deploying a second server that imports and synchronizes data without exporting it to Azure AD, serving as a hot standby.
- Provides high availability and disaster recovery for the synchronization service.
- Allows testing configuration changes before promoting the server to active.
- Only one server can be in active export mode at a time.
Memory trick: Connect servers: One active, one staged, always ready.
Managed Identities for Azure Resources
Flip cardManaged identities provide an automatically managed identity in Azure Active Directory for Azure services. This allows Azure services to authenticate to services that support Azure AD authentication without managing credentials.
- Eliminates the need to store credentials in code or configuration.
- Automatically managed by Azure.
- Can be system-assigned (tied to a resource) or user-assigned (standalone).
Memory trick: Managed identities are like having Azure itself manage your app's ID card.
Azure AD Security Group
Flip cardA collection of users, devices, or other security groups that can be used to manage access to resources and assign permissions.
- Can be used to assign licenses to users.
- Can be used to grant access to Azure resources and applications.
- Supports both assigned and dynamic membership.
Memory trick: Groups: Security for access, O365 for collaboration.
Azure AD B2B External Identities
Flip cardA capability within Azure AD B2B collaboration that allows external users to sign in using various identity providers beyond just other Azure AD tenants.
- Supports personal Microsoft accounts (MSA).
- Supports social identity providers like Google and Facebook (after configuration).
- External users are added as guest users in the inviting tenant.
Memory trick: B2B: Bring your own ID, even personal ones.
Password Hash Synchronization (PHS)
Flip cardA hybrid identity method where a hash of the on-premises AD password hash is synchronized to Azure AD, allowing users to sign in with the same credentials.
- Simplest to implement and deploy.
- Provides high availability and resilience as authentication can occur even if on-premises AD is down.
- Enables SSO to cloud applications.
- Does not store actual passwords in Azure AD, only cryptographically strong hashes of hashes.
Memory trick: PHS: 'Password Hashes Synchronized' to cloud for easy access.
UPN Suffix Management (Hybrid Identity)
Flip cardIn a hybrid identity environment, for users synchronized from on-premises AD DS, their User Principal Name (UPN) suffix must correspond to a verified custom domain in Azure AD. Mismatched UPNs can lead to sign-in failures for cloud applications.
- On-premises UPN suffix must be added as a custom domain in Azure AD.
- The custom domain must be verified in Azure AD.
- Changing the UPN on-premises will synchronize to Azure AD via Azure AD Connect.
Memory trick: UPN mismatch is like a wrong address on your ID – fix it at the source, then verify the domain.
Conditional Access with Device Compliance
Flip cardConditional Access policies can be configured to require a device to be marked as 'compliant' by a mobile device management (MDM) solution like Microsoft Intune before granting access to cloud applications. This ensures only trusted and secured devices can access sensitive resources.
- Requires integration with an MDM solution (e.g., Intune).
- The MDM solution determines device compliance.
- Conditional Access evaluates the compliance state during sign-in.
Memory trick: Conditional Access: If device is compliant, then allow.
Microsoft Graph Permission Types
Flip cardThe two main types of permissions an application can request to access Microsoft Graph: delegated (on behalf of a user) and application (app-only).
- Delegated permissions require a signed-in user.
- Application permissions allow the app to act independently.
- Both require admin or user consent, depending on the permission scope.
Memory trick: Graph: Who is acting, user or app?
Conditional Access Policy Enforcement
Flip cardWhen multiple Conditional Access policies apply to a user and resource, Azure AD enforces the most restrictive outcome among all applicable policies.
- Policies are evaluated sequentially.
- If multiple policies apply, the most restrictive control is enforced.
- 'Block access' is generally the most restrictive outcome.
- Exclusions in one policy do not override requirements in another applicable policy if the latter is more restrictive.
Memory trick: When facing multiple traffic lights, the one saying 'STOP' always wins, even if others say 'GO'.
Azure AD Seamless SSO + Conditional Access
Flip cardAzure AD Seamless Single Sign-On (SSO) provides users with an automatic sign-in experience when their corporate devices are within the corporate network. Conditional Access policies then layer on top to enforce specific access controls (like MFA, trusted locations, compliant devices) based on user, device, location, and application.
- Seamless SSO works with PHS or PTA authentication methods.
- Conditional Access allows granular control over access based on various signals.
- Combining them provides both user experience and strong security.
Memory trick: Seamless SSO for managed, Conditional Access for control.
PIM Multi-Stage Approval
Flip cardA feature in Microsoft Entra PIM that requires more than one approver to grant access to a privileged role, adding an extra layer of security and oversight.
- Can include up to two stages of approval.
- Each stage can have different approvers (e.g., manager, specific users/groups).
- Enhances security for highly sensitive roles.
Memory trick: Two approvals mean double the check, double the security.
PIM Active Assignment (Permanent)
Flip cardAn assignment type in PIM where a user is permanently assigned to a role and does not need to activate it through the PIM service. This is typically used for break-glass accounts.
- Role is always active for the assigned user.
- Bypasses PIM activation workflow (just-in-time).
- Recommended for a very limited number of emergency/break-glass accounts.
Memory trick: PIM assignments: a key for every door, some always open.
Entitlement Management Approval
Flip cardA feature within Microsoft Entra entitlement management that allows administrators to define approval workflows for access package requests, ensuring appropriate oversight before access is granted.
- Can include single or multi-stage approvals.
- Supports manager approval, specific users/groups, or sponsored guests.
- Requests can expire if not approved within a set timeframe.
Memory trick: Approve access, managers give the green light.
PIM Assignment Duration for Eligible Assignments
Flip cardA PIM setting that defines the maximum period a user can maintain an 'eligible' assignment for a privileged role before their eligibility automatically expires.
- Controls the maximum duration of *eligibility*.
- Ensures Just-In-Time (JIT) principles for *potential* access.
- Requires re-request for eligibility after expiration.
Memory trick: Eligibility has a clock, after 90 days, it's off the block.
Microsoft Entra Connected Organization
Flip cardA connected organization of type 'Microsoft Entra (external directory)' allows users from a partner Microsoft Entra tenant to request access packages, enabling B2B collaboration.
- Facilitates B2B collaboration between Microsoft Entra tenants.
- Allows self-service access requests for external users.
- Requires specifying the partner tenant's domain or tenant ID.
Memory trick: For tenant-to-tenant access, it's about connecting Entra IDs like business partners.
Privileged Identity Management (PIM)
Flip cardA Microsoft Entra ID service that enables you to manage, control, and monitor access to important resources in your organization by providing just-in-time and just-enough access.
- Provides just-in-time (JIT) access for privileged roles.
- Enforces MFA for role activation.
- Audits privileged role usage and provides access reviews for privileged roles.
Memory trick: PIM is the vigilant guardian for your crown jewels of access.
PIM Eligible Assignment Duration
Flip cardA Microsoft Entra PIM setting that specifies the maximum period a user can be eligible for a privileged role before their eligibility automatically expires, enforcing time-bound access.
- Applies to 'eligible' assignments, not 'active' assignments.
- Can be configured for a fixed period (e.g., days, months) or as permanent.
- Helps enforce Just-In-Time (JIT) access principles by limiting eligibility.
Memory trick: Eligibility has a timer, activation has its own.
PIM Maximum Activation Duration
Flip cardA PIM setting that specifies the longest period a privileged role can remain active after a user has activated it, promoting Just-In-Time (JIT) access.
- Limits time-bound access to privileged roles.
- Automatically deactivates the role after the set duration.
- Enhances security by minimizing exposure time of privileged accounts.
Memory trick: Activation has a timer, don't let it run any higher.
PIM Access Review for Eligible Assignments
Flip cardA PIM setting that mandates periodic access reviews for users who are eligible for a privileged role, ensuring that their eligibility remains appropriate.
- Helps maintain least privilege by removing unnecessary eligible assignments.
- Can be configured with specific reviewers and review frequency.
- Applies to users who 'can' activate the role, not just those who have activated it.
Memory trick: PIM governance: review assignments, keep roles lean.
Access Review Delegation & Automation
Flip cardConfiguring Microsoft Entra access reviews to delegate review responsibilities (e.g., to group owners) and to automatically enforce review outcomes, including actions for non-responsive reviewers.
- Delegating reviews to group owners empowers resource governance.
- 'Auto apply results' enforces decisions (approve/deny) and default action for unreviewed.
- Default for unreviewed when auto-apply is on for group memberships is often 'Remove access'.
Memory trick: Owners review, system cuts if silent.
Connected Organizations
Flip cardA feature in Microsoft Entra entitlement management that allows you to specify external Microsoft Entra organizations or other identity providers (like Microsoft accounts) whose users can request access packages.
- Defines external identity providers for access package requests.
- Supports Microsoft Entra organizations (B2B) and Microsoft accounts (MSA).
- Essential for enabling self-service access for external users.
Memory trick: Connected Orgs are like the 'guest list' for external access.
Entitlement Policy Requestor Conditions
Flip cardSettings within an Entitlement Management access package policy that define who is eligible to request access and what attributes they must possess to even see or submit a request.
- Controls both the visibility and eligibility of an access package.
- 'For users in your directory' specifies which internal users/groups can request.
- 'Requestor must have attributes' enforces specific user attribute conditions for requesting.
Memory trick: Request control: who sees, who qualifies, only the best get in.
Entitlement Management Roles
Flip cardSpecific roles within Microsoft Entra ID that delegate administrative responsibilities for managing access packages, catalogs, and related resources.
- Catalog Creator: Can create and manage catalogs.
- Catalog Owner: Can manage existing catalogs and add/remove resources.
- Access package manager: Can manage access packages within a catalog.
Memory trick: Delegation in entitlement management is like assigning specific 'department chiefs' to manage their own resource 'sections'.
PIM MFA for Activation
Flip cardA security setting in Privileged Identity Management that mandates multi-factor authentication (MFA) for users before they can activate an eligible privileged role.
- Adds an extra layer of security to privileged role activation.
- Protects against credential compromise.
- Applicable to both Microsoft Entra roles and Azure resource roles.
Memory trick: MFA for PIM is like a second lock on the vault door.
PIM 'Require approval to activate'
Flip cardA PIM setting that mandates an explicit approval from a designated approver(s) for a user's role activation request to proceed.
- Enhances security for privileged role activations.
- Requires a specified approver or group.
- Justification is typically part of the approval review.
Memory trick: Activation needs a 'go', not just a 'why' or a 'how long' to flow.
Access Review Notifications
Flip cardSettings within Microsoft Entra access reviews that control email communications to reviewers and administrators regarding the review lifecycle, including start notifications, reminders, and completion summaries.
- Automates communication to reviewers.
- Includes start notifications and periodic reminders.
- Can send summaries of review completion to administrators.
Memory trick: Access Review notifications are the 'digital secretary' for timely reviews.
Attribute-Based Access in Entitlement Management
Flip cardUsing user attributes defined in Microsoft Entra ID as conditions for granting and maintaining access to an access package, allowing for dynamic policy enforcement.
- Conditions can be set for requests (e.g., user must have attribute X).
- Access can be automatically revoked if attributes change or are removed.
- Enhances compliance and 'least privilege' by tying access to current user state.
Memory trick: Attributes are the access gatekeepers, changing them locks the door.
Entitlement Management Catalog Owner
Flip cardA role in Microsoft Entra entitlement management that grants full administrative control over a specific access catalog, enabling decentralized management of access packages and policies.
- Can create, update, and delete access packages within their catalog.
- Can manage policies and resources for access packages in their catalog.
- Provides a scope for delegated administration, avoiding Global Administrator permissions.
Memory trick: Catalog owner holds the keys to their domain.
Entitlement Management Requestor Conditions Policy
Flip cardA policy within Entitlement Management that uses attribute-based conditions (e.g., department, job title) to determine if an access request should be automatically approved or sent for manual approval.
- Enables granular, attribute-driven access decisions.
- Can trigger automatic approval or specific approval stages.
- Enhances security and automation for access requests.
Memory trick: If the 'Requestor's Conditions' are right, access can be granted with no more fight.
Entitlement Management
Flip cardA Microsoft Entra ID feature that enables organizations to manage identity and access lifecycle at scale by automating access requests, approvals, provisioning, and de-provisioning.
- Automates access lifecycle for internal and external users.
- Uses access packages to bundle resources.
- Supports approval workflows and time-limited access.
Memory trick: Entitlement Management grants and revokes access like a meticulous librarian.
Microsoft Entra Connected Organizations
Flip cardA feature in Microsoft Entra entitlement management that allows you to establish trust with external Microsoft Entra tenants or social identities, enabling users from those organizations to request access to your resources.
- Facilitates B2B collaboration without individual invitations.
- Users from connected organizations can request access to access packages.
- Can be configured for specific Entra ID tenants or social identity providers.
Memory trick: Connect with others to share access securely.
PIM Approval Workflow
Flip cardA security control in Microsoft Entra Privileged Identity Management (PIM) that mandates an approval process before users can activate eligible privileged roles, often requiring justification and/or a support ticket.
- Enhances security by adding human oversight to sensitive role activations.
- Can be configured with single or multiple approvers.
- Includes options to require justification and/or a support ticket number.
Memory trick: PIM activates securely with approval's key.
Entitlement Management Requestor Conditions
Flip cardA policy setting in Microsoft Entra entitlement management that defines which users are allowed to request access to an access package, enabling fine-grained control over access initiation.
- Can specify individual users, security groups, or connected organizations.
- Essential for controlling who can even see and apply for an access package.
- Part of creating an access package policy.
Memory trick: Only authorized requestors can ask for the package.
Entitlement Management Lifecycle Settings
Flip cardMicrosoft Entra entitlement management's lifecycle settings define how long assigned access remains valid and when it should be revoked, including options for attribute-based expiration.
- Manages when access assignments expire.
- Can be set to expire after a certain number of days, on a specific date, or 'Never'.
- Can leverage attribute-based conditions to automatically revoke access when user attributes change.
Memory trick: Lifecycle dictates when access dies; attributes trigger the end.
Access Review Automation Settings
Flip cardSettings within Microsoft Entra ID access reviews that control how review decisions are enforced and what action is taken for users whose access is not explicitly reviewed.
- 'Auto apply results to resource' automatically enforces approved/denied decisions.
- 'If reviewers don't respond' defines default action for unreviewed users.
- Options for unreviewed users include 'Remove access', 'Take no action', or 'Recommend approval'.
Memory trick: Access reviews: automate cuts, silence means removal.
PIM MFA with Certificate-Based Authentication
Flip cardThe PIM setting 'Require multi-factor authentication on activation' can enforce strong authentication methods like Certificate-Based Authentication (CBA) configured in Microsoft Entra ID, enabling digital signing for privileged role activations.
- MFA can be satisfied by various credential types, including CBA.
- CBA provides a strong, cryptographically backed identity proof.
- PIM leverages Entra ID's authentication policies for activation.
Memory trick: MFA is the key, and a certificate makes it extra secure, you see.
PIM for Privileged Roles
Flip cardMicrosoft Entra Privileged Identity Management (PIM) provides time-based and approval-based role activation to mitigate the risks of excessive, unnecessary, or misused access permissions.
- Enforces just-in-time (JIT) and just-enough access.
- Provides an audit trail of role activations and usage.
- Can convert permanent assignments to eligible or remove them after a grace period.
Memory trick: PIM is the 'privileged access gatekeeper' with a detailed logbook.
Multi-stage Approval
Flip cardA feature in Microsoft Entra entitlement management policies that requires multiple distinct approvals for an access request to be granted.
- Enhances security for sensitive resources.
- Allows different approvers or groups at each stage.
- Configurable within access package policies.
Memory trick: Many managers make sure it's right, two locks for sensitive light.
Entitlement Management Connected Organizations
Flip cardConnected organizations in Microsoft Entra entitlement management represent external Microsoft Entra tenants or social identities that an organization collaborates with, allowing their users to request access to resources.
- Establishes trust with external partners.
- Enables external users to request access packages.
- Streamlines guest user lifecycle management.
Memory trick: Bridging your tenant to partners' tenants.
PIM Permanent Eligible Assignment
Flip cardA PIM setting that configures a user's eligibility for a privileged role to be indefinite, meaning it does not have an automatic expiration date and remains active until manually removed or revoked by an access review.
- No automatic expiration for eligibility.
- Requires manual removal or access review revocation.
- Typically recommended for highly critical roles with strict governance.
Memory trick: For permanent eligibility, no date should be set, so the access won't be met with regret.
Automatic Request Approval (Entitlement Management)
Flip cardA feature in Entitlement Management that allows access requests to be automatically approved if the requesting user meets predefined conditions within the access package policy.
- Eliminates manual approval steps for compliant requests.
- Conditions can include department, user attributes, or group membership.
- Streamlines access provisioning for well-defined scenarios.
Memory trick: Entitlement policies: conditions grant keys automatically.