Microsoft Certified: Identity and Access Administrator Associate flashcards
114 free flashcards. Tap a card to flip it.
Microsoft Entra Connected Organization
Flip cardA connected organization of type 'Microsoft Entra (external directory)' allows users from a partner Microsoft Entra tenant to request access packages, enabling B2B collaboration.
- Facilitates B2B collaboration between Microsoft Entra tenants.
- Allows self-service access requests for external users.
- Requires specifying the partner tenant's domain or tenant ID.
Memory trick: For tenant-to-tenant access, it's about connecting Entra IDs like business partners.
Privileged Identity Management (PIM)
Flip cardA Microsoft Entra ID service that enables you to manage, control, and monitor access to important resources in your organization by providing just-in-time and just-enough access.
- Provides just-in-time (JIT) access for privileged roles.
- Enforces MFA for role activation.
- Audits privileged role usage and provides access reviews for privileged roles.
Memory trick: PIM is the vigilant guardian for your crown jewels of access.
PIM Eligible Assignment Duration
Flip cardA Microsoft Entra PIM setting that specifies the maximum period a user can be eligible for a privileged role before their eligibility automatically expires, enforcing time-bound access.
- Applies to 'eligible' assignments, not 'active' assignments.
- Can be configured for a fixed period (e.g., days, months) or as permanent.
- Helps enforce Just-In-Time (JIT) access principles by limiting eligibility.
Memory trick: Eligibility has a timer, activation has its own.
Azure AD Enterprise Application
Flip cardAn object in Azure AD that represents an instance of a service principal in your tenant, often used for configuring SSO and provisioning with pre-integrated SaaS applications.
- Represents an instance of an application/service principal in a specific tenant.
- Used for configuring SSO (SAML, OIDC) and user provisioning for SaaS apps.
- Found under 'Enterprise applications' in the Azure portal.
- Can be linked to a gallery app or a custom non-gallery app.
Memory trick: Enterprise App: Your tenant's gateway to external SaaS services.
Azure AD Domain Services (Azure AD DS)
Flip cardA managed domain service in Azure that provides AD-compatible services (LDAP, Kerberos, NTLM) for virtual machines and applications in Azure.
- Synchronizes with Azure AD (which can be synced from on-premises AD).
- No need to deploy, manage, or patch domain controllers.
- Supports domain-join, group policy, LDAP, and Kerberos/NTLM authentication.
Memory trick: Extend AD: Domain Services for legacy, Connect for sync, Proxy for apps.
Azure AD Security Defaults
Flip cardA set of pre-configured identity security settings in Azure AD that provide a baseline level of protection for all organizations, available for free.
- Mandatory MFA registration for all users.
- Requires MFA for risky sign-ins (admin roles).
- Blocks legacy authentication protocols.
- Protects privileged activities.
Memory trick: Default to secure, no extra cost, no fuss.
PTA Agent High Availability
Flip cardTo ensure high availability for Azure AD Pass-through Authentication, multiple authentication agents must be installed on separate servers in the on-premises environment.
- Each agent registers with Azure AD and becomes active.
- Azure AD automatically load-balances authentication requests.
- Provides resilience against agent or network failures.
Memory trick: PTA agents are like guards at multiple gates, always one open.
Azure AD Provisioning (SCIM)
Flip cardAn Azure AD service that automates the lifecycle management of user identities across various cloud and on-premises applications.
- Uses the SCIM protocol for communication with target applications.
- Automates creating, updating, and deleting user accounts.
- Synchronizes user attributes and group memberships.
Memory trick: App Integration: SSO for login, Provisioning for users, Proxy for on-prem.
Azure AD Connect Mandatory Attributes
Flip cardCertain attributes are mandatory for user objects to be successfully synchronized from on-premises Active Directory to Azure AD, including `userPrincipalName`, `sAMAccountName`, and `objectGUID`.
- Missing mandatory attributes cause synchronization failures.
- `userPrincipalName` is crucial for sign-in and uniqueness.
- Errors are reported in Azure AD Connect Health.
Memory trick: Mandatory attributes are the 'must-haves' for identities to cross the bridge.
Multi-tenant Application Registration
Flip cardAn Azure AD application registration configured to accept sign-ins from users in any Azure AD tenant, allowing a single application instance to serve multiple organizations.
- Requires 'Supported account types' to be set to 'Multitenant'.
- Involves user consent from each tenant's administrators.
- Service principal is created in each tenant where consent is granted.
- Essential for SaaS applications serving multiple customers.
Memory trick: Supported Accounts Span All Tenants.
Azure AD Application Registration
Flip cardAn object in Azure AD that represents an application, allowing it to authenticate to Azure AD and be granted permissions to access other resources.
- Defines how an application interacts with Azure AD.
- Can be configured with client secrets or certificates for authentication.
- Used for both applications hosted in Azure and external applications.
- Has an associated service principal for resource access.
Memory trick: Applications Authenticate with App Registrations and Secrets.
Azure AD Connect OU Filtering
Flip cardA feature within Azure AD Connect that allows administrators to select specific Organizational Units (OUs) from on-premises Active Directory for synchronization to Azure AD.
- Configured during initial setup or post-installation.
- Prevents unwanted objects (e.g., service accounts) from syncing.
- Improves security and reduces Azure AD clutter.
Memory trick: Filter your OUs carefully, so only the 'O-K' ones go to the cloud.
Workload Identity Federation
Flip cardA feature that allows external identity providers (like GitHub Actions, AWS) to issue tokens that Azure AD trusts, enabling external workloads to authenticate to Azure AD without storing client secrets or certificates.
- Eliminates the need for client secrets or certificates for external workloads.
- Azure AD trusts tokens from specified external identity providers.
- Enhances security by reducing credential exposure.
- Commonly used with CI/CD pipelines hosted outside Azure.
Memory trick: Federation lets external friends join the Azure party without needing a secret handshake.
Identity Protection Anonymous IP Policy Actions
Flip cardActions that can be configured in Azure AD Identity Protection for sign-ins detected from anonymous IP addresses.
- Options typically include 'Block access' or 'Require multi-factor authentication'.
- MFA provides a balance between security and user experience for potentially legitimate but risky sign-ins.
- Helps mitigate risks associated with Tor browsers, anonymous VPNs, and other anonymizing technologies.
Memory trick: Risk Remediation: Block, MFA, Reset, or Ignore actions.
Azure AD Connect Group Member Limit
Flip cardAzure AD Connect has a default limit on the number of members a group can have for its membership to be synchronized to Azure AD.
- Default limit is 50,000 direct members for groups synchronized to Azure AD.
- Exceeding this limit prevents membership from syncing, but the group object itself may sync.
- This limit can be increased, but requires careful consideration of performance and Azure AD limitations.
Memory trick: Group members need enough 'headroom' to cross the sync bridge.
System-assigned Managed Identity for Function Apps
Flip cardAn identity automatically created for an Azure Function App, enabling it to authenticate to other Azure services without managing credentials, and its lifecycle is tied to the Function App.
- Eliminates credential storage in code/config.
- Automatically managed by Azure.
- Lifecycle tied to the Function App.
- Simplifies securing serverless applications.
Memory trick: System Security Simplifies Serverless Secrets.
Azure AD Conditional Access
Flip cardAzure AD Conditional Access allows organizations to enforce policies for accessing resources based on conditions like user, location, device, and application, enhancing security.
- Enforces access policies based on specific conditions.
- Can require MFA, block access, or enforce device compliance.
- Centralized control over access to cloud apps.
Memory trick: Conditioned access is like a traffic light for your apps.
Azure AD Connect Multi-Forest Sync
Flip cardAzure AD Connect supports synchronizing identities from multiple on-premises Active Directory forests to a single Azure AD tenant, enabling a unified identity experience.
- Single Azure AD Connect server can connect to multiple forests.
- Allows different topologies (e.g., full mesh, account-resource).
- Requires network connectivity between Connect server and all forests.
Memory trick: One Connect server can wrangle all your forest identities into the cloud.
Azure AD Access Reviews
Flip cardAn Azure AD Identity Governance feature that enables organizations to manage group memberships, access to enterprise applications, and role assignments by automating the process of reviewing and certifying user access.
- Automates recurring access reviews.
- Reviewers can be group owners, managers, or self-review.
- Helps enforce least privilege and compliance.
Memory trick: Review access, renew trust.
Application Permissions (Microsoft Graph)
Flip cardPermissions granted directly to an application, allowing it to act as its own identity and access resources without a signed-in user.
- Used by daemon applications or services (e.g., background services, Azure Functions).
- Application acts on its own behalf.
- Requires administrator consent.
- Often provides broad access (e.g., .Read.All, .Write.All).
Memory trick: Daemon's direct access: Application permissions, no user needed.
Azure AD Application Provisioning (SCIM)
Flip cardAutomates the creation, maintenance, and removal of user identities across various cloud applications and HR systems.
- Uses the SCIM protocol for interoperability.
- Supports inbound (HR to AD) and outbound (AD to SaaS) provisioning.
- Ensures attribute consistency and reduces manual overhead.
Memory trick: Provisioning is the 'HR hand-off' to Azure AD, keeping everyone in sync.
Identity Protection Policy Exclusions
Flip cardAllows specific users or groups to be excluded from the enforcement of an Azure AD Identity Protection policy.
- Provides granular control for managing exceptions to security policies.
- Useful for service accounts, break-glass accounts, or users with specific accessibility needs.
- Should be used sparingly and with careful consideration of security implications.
Memory trick: Policy Management: Create, Exclude, Report, and Monitor carefully.
Azure AD User Risk Policy
Flip cardA Conditional Access policy that defines automated responses based on a user's accumulated risk score, which indicates the likelihood of a compromised identity.
- Applies to the user's identity, not individual sign-ins.
- Risk is aggregated over time from various detections.
- Common actions: Block access, Require password change, Require MFA.
Memory trick: Risk policies are like a 'security guard' at the door: high risk, no entry!
Identity Protection Policy Evaluation
Flip cardAzure AD Identity Protection evaluates user risk and sign-in risk policies independently. If any policy configured to block access has its conditions met, access is blocked.
- Two main policy types: User risk and Sign-in risk.
- Policies are evaluated concurrently.
- Blocking takes precedence if any applicable policy's conditions are met.
Memory trick: Risk policies are like two separate gates; if either one is closed, you don't get through.
Managed Identity Credential Rotation
Flip cardThe automatic process by which Azure AD securely rotates the underlying credentials (certificates) used by managed identities to authenticate to Azure AD.
- Fully automated by Azure AD.
- Eliminates the need for manual credential management.
- Enhances security by ensuring credentials are short-lived and frequently renewed.
- Applies to both system-assigned and user-assigned managed identities.
Memory trick: Managed Identity: Azure handles the keys, no worries, just automation!
Azure AD Connect Multi-Forest Synchronization
Flip cardThe capability of Azure AD Connect to synchronize user and group identities from multiple on-premises Active Directory forests into a single Azure Active Directory tenant.
- Supports forests with and without trust relationships.
- Can handle different UPN suffixes.
- Typically uses a single Azure AD Connect server (with optional staging server for HA/DR).
Memory trick: Connect all your forests to one cloud.
System-Assigned MI for Function Apps
Flip cardEnabling a system-assigned managed identity for an Azure Function App, allowing the functions within it to securely authenticate to other Azure services without managing credentials.
- Identity is created and deleted with the Function App.
- Automatic credential management by Azure.
- Ideal for single-resource identity needs.
- Simplifies secure access to services like Key Vault, Storage, Cosmos DB.
Memory trick: Function App's built-in identity: simple, secure, no secrets to hold.
Pass-through Authentication (PTA)
Flip cardAn Azure AD Connect authentication method that validates user passwords directly against on-premises Active Directory without storing them in Azure AD.
- Passwords never leave the on-premises network.
- Requires lightweight agents to be installed on-premises.
- Provides a seamless sign-in experience (SSO).
Memory trick: PHS is 'hash it and stash it', PTA is 'pass it through, no view', AD FS is 'federate and delegate'.
Azure AD B2B Federation
Flip cardAzure AD B2B federation allows external users from other organizations (e.g., Azure AD, Google, Facebook) to sign in to your Azure AD tenant using their existing credentials.
- Supports various identity providers (Azure AD, Google, Facebook, SAML/WS-Fed).
- Streamlines guest user sign-in experience.
- Reduces administrative overhead for guest account management.
Memory trick: B2B federation is the 'easy pass' for guests with their own keys.
Azure AD SCIM Provisioning
Flip cardAzure AD supports System for Cross-domain Identity Management (SCIM) for automated user provisioning and deprovisioning between Azure AD and various cloud applications or HR systems.
- Automates identity lifecycle management.
- Uses the SCIM protocol for integration.
- Supports HR-driven provisioning to Azure AD and then to SaaS apps.
Memory trick: SCIM is the 'seamless' way to manage identities across systems.
Azure AD CredentialLifetimePolicy
Flip cardA policy type in Azure AD that allows administrators to set custom lifetimes for application and service principal credentials (secrets and certificates).
- Applies to application registrations and their associated service principals.
- Can define maximum secret/certificate lifetimes.
- Helps enforce security best practices for credential rotation.
- Configured using Azure AD PowerShell or Microsoft Graph API.
Memory trick: Credential Lifetime Policy: Time's up for old secrets!
Identity Protection MFA Registration Policy
Flip cardAn Azure AD Identity Protection policy that enforces multi-factor authentication registration for users.
- Can require users to register for MFA within a specified number of days.
- Can block users from signing in until MFA registration is complete.
- Helps improve overall security posture by ensuring MFA adoption.
Memory trick: Protection policies: MFA register, risky sign-ins, and risky users.
Conditional Access Policy Exclusions
Flip cardConditional Access policies can include exclusions for users, groups, cloud apps, or conditions (like locations or device states) to refine policy application.
- Exclusions always 'win' over inclusions.
- Can be specified for users/groups, cloud apps, and conditions.
- Allows fine-tuning access controls for specific scenarios.
Memory trick: Conditions come first, then controls, but exclusions always win the race.
User-Assigned Managed Identity
Flip cardA standalone Azure resource that can be created, configured, and then assigned to multiple Azure services, enabling them to authenticate to Azure AD.
- Independent lifecycle from the Azure resources it's assigned to.
- Can be assigned to multiple Azure resources.
- Allows for centralized management of permissions for a group of resources.
- Eliminates the need for developers to manage credentials.
Memory trick: User-assigned identity, like a universal key for many locks.
Identity Protection Report Only Mode
Flip cardA configuration option for Azure AD Identity Protection policies that allows administrators to evaluate the impact of a policy without enforcing any actions, by simply logging detected risks.
- Enables monitoring of policy effectiveness.
- Helps identify potential false positives.
- Crucial step before full policy enforcement.
Memory trick: Report Only: Review before you React.
Conditional Access Policy Precedence
Flip cardIn Conditional Access, 'Block access' policies take precedence over 'Grant access' policies (like 'Require MFA') when multiple policies apply and conflict.
- All policies are evaluated simultaneously.
- If any policy blocks access, the sign-in is blocked.
- If multiple 'Grant' policies apply, all 'Grant' controls must be satisfied.
Memory trick: Block always wins, it's the 'ultimate veto' in the policy parliament.
Cross-Subscription Managed Identity
Flip cardUsing a user-assigned managed identity to grant an Azure resource (e.g., a service) access to resources located in different Azure subscriptions within the same Azure AD tenant.
- Requires a user-assigned managed identity, as it's a standalone resource.
- The managed identity is created in one subscription and assigned RBAC roles in others.
- Simplifies centralized service access to distributed resources.
- Allows decentralized control over permissions by subscription owners.
Memory trick: User-assigned identity: One key to unlock many subscription doors.
Delegated Permissions (Microsoft Graph)
Flip cardPermissions that allow an application to act on behalf of a signed-in user, accessing resources that the user has permission to access, subject to user or administrator consent.
- Application acts as the signed-in user.
- Access is limited by the user's permissions.
- Requires user or administrator consent.
Memory trick: Delegated: 'On behalf of me', the user's access is the key.
Admin Consent Flow
Flip cardA process where an Azure AD administrator explicitly grants permissions to an application on behalf of all users in the tenant, typically for high-privilege permissions or when a tenant-wide setting requires it.
- Required for application permissions.
- Required for certain high-privilege delegated permissions.
- Can be mandatory for all permissions based on tenant settings.
Memory trick: Admin Consent: If not the king, you can't open the door, only the admin has the power to explore.
Managed Identity with RBAC
Flip cardCombining Azure Managed Identities for secure, credential-less authentication with Azure Role-Based Access Control (RBAC) to grant granular, least-privilege access to Azure resources.
- Managed Identity handles authentication to Azure AD.
- RBAC defines specific permissions and scope.
- Eliminates credential management and enforces least privilege.
Memory trick: Managed Identity + RBAC: Identity gets the key, RBAC tells it where to play.
System-assigned Managed Identity (Scenario based)
Flip cardAn Azure AD identity automatically created and managed by Azure, tied to the lifecycle of a specific Azure resource, providing unique, non-sharable authentication capabilities to other Azure services.
- Unique to a single Azure resource.
- Lifecycle is bound to the parent resource.
- No manual credential management required.
Memory trick: System-assigned: VM's own shadow, bound to its life, no sharing allowed.
CredentialLifetimePolicy
Flip cardAn Azure AD policy that allows administrators to specify the lifetime of secrets and certificates for application registrations and service principals, enforcing rotation schedules.
- Applies to secrets and certificates.
- Can be set at the tenant or service principal level.
- Enforces rotation and reduces risk from compromised credentials.
Memory trick: CredentialLifetimePolicy: Time's up for secrets, policy sets the clock.
PIM for Workload Identities
Flip cardExtending Azure AD Privileged Identity Management (PIM) to manage just-in-time (JIT) access for service principals (workload identities) to Azure AD roles or Azure resource roles, enabling time-bound and approved elevated permissions.
- Provides just-in-time (JIT) access.
- Can be configured for service principals (application registrations).
- Enhances security by limiting exposure of high-privilege roles.
Memory trick: PIM for Workloads: Just-in-time, like a temporary key, security's prime.
User-assigned MI for Shared Access
Flip cardAn Azure AD identity created as a standalone resource, ideal for scenarios where multiple Azure resources need to share the same identity to access a common resource, simplifying permission management.
- Independent lifecycle from assigned resources.
- Can be assigned to multiple Azure services.
- Centralizes permissions management for shared resources.
Memory trick: User-assigned MI: One identity for many friends, shared key vault, security transcends.
Managed Identity for Azure VM
Flip cardAn Azure AD identity assigned to an Azure Virtual Machine, allowing the VM and applications running on it to authenticate to other Azure services securely without managing credentials.
- Eliminates hardcoded credentials.
- Supports both system-assigned and user-assigned types.
- Seamless integration with Azure AD-protected services.
Memory trick: VM's MI: The machine gets its own ID, no secrets for apps to hide.
Workload Identity Federation with PIM
Flip cardA solution combining Workload Identity Federation (secret-less authentication for workloads) with Azure AD Privileged Identity Management (PIM) to enable just-in-time, time-bound access for service principals. This allows CI/CD pipelines or other workloads to authenticate without managing secrets and gain elevated privileges only when needed.
- Eliminates the need for client secrets/certificates for workload authentication.
- PIM provides just-in-time (JIT) and time-bound access to Azure AD roles.
- Ideal for CI/CD pipelines requiring temporary elevated access to Azure resources.
Memory trick: FEDERATE for NO secrets, PIM for JIT powers.
Cross-Subscription Managed Identity Access
Flip cardEnabling an Azure resource in one subscription to authenticate and access another Azure resource in a different subscription using a managed identity. This is typically achieved by creating a user-assigned managed identity in the source subscription and granting it RBAC permissions on the target resource in the destination subscription.
- User-assigned managed identities are preferred for cross-subscription scenarios.
- Managed identity is created in the same subscription as the accessing resource.
- RBAC permissions are granted on the target resource (in the other subscription) to this managed identity.
Memory trick: IDENTITY lives LOCAL, ACCESS is GLOBAL.
Microsoft Graph Permissions (Application vs. Delegated)
Flip cardMicrosoft Graph uses two main types of permissions: Delegated permissions (on behalf of a user) and Application permissions (as the application itself). Consent can be user consent or admin consent.
- Delegated: Requires a signed-in user, permissions are the intersection of user's and app's.
- Application: No signed-in user, app acts as itself, often requires admin consent.
- Admin consent: Required for application permissions and high-privilege delegated permissions in multi-tenant apps.
Memory trick: Application works alone, Delegated acts with a person.
Microsoft Graph Consent Models
Flip cardMicrosoft Graph permissions utilize different consent models (user or admin) depending on the permission type (delegated or application) and the sensitivity/scope of the requested access.
- User consent: Granted by individual users for delegated permissions that don't require admin privileges.
- Admin consent: Granted by a tenant administrator for application permissions or high-privilege delegated permissions (tenant-wide).
- Delegated permissions: Act on behalf of a signed-in user.
- Application permissions: Act as the application itself, no signed-in user.
Memory trick: User acts FOR, App acts ALONE.
PIM MFA for Activation (with CBA)
Flip cardA PIM setting that requires users to complete a multi-factor authentication challenge, potentially using methods like certificate-based authentication (CBA), during the activation of an eligible role.
- Enhances security during role activation.
- Can leverage strong MFA methods like CBA.
- Protects against compromised credentials.
Memory trick: PIM Secures Activation with Strong ID.
MFA Registration Policy
Flip cardAn Azure AD Identity Protection policy designed to ensure users register for multi-factor authentication, often with a grace period.
- Enforces MFA registration for non-registered users.
- Can set a grace period (e.g., days after first sign-in).
- Part of Azure AD Identity Protection.
Memory trick: MFA Register: The Policy that MAKES you register.
Azure AD Seamless SSO
Flip cardAzure AD Seamless Single Sign-On (Seamless SSO) automatically signs users in when they are on their corporate network and their devices are joined to Azure AD, without requiring them to type their passwords.
- Provides a true single sign-on experience for Azure AD-joined devices.
- Works with both Password Hash Synchronization and Pass-through Authentication.
- Requires client-side configuration (e.g., Internet Explorer zone settings via GPO) for full functionality.
Memory trick: Simple Sign-On, Smooth Experience, Securely.
Conditional Access Conditions
Flip cardConditional Access policies in Azure AD define 'when' a policy applies by evaluating conditions related to users, devices, locations, applications, and risks.
- Conditions determine the scope of a policy.
- Multiple conditions can be combined using AND logic.
- Common conditions include Users, Cloud apps, Conditions (Sign-in risk, User risk, Device platforms, Locations, Client apps, Device state, Filter for devices).
Memory trick: If THIS happens, THEN do THAT.
Conditional Access Session Controls
Flip cardConditional Access session controls provide granular control over user sessions after sign-in, allowing administrators to enforce specific requirements like re-authentication frequency or persistent browser sessions.
- Applied after initial access is granted.
- Includes 'Sign-in frequency' (how often to re-authenticate).
- Includes 'Persistent browser session' (allow users to stay signed in).
- Can integrate with Microsoft Defender for Cloud Apps for advanced session controls.
Memory trick: Session Controls: Set the Schedule, Stay in Charge.