Reader small image

You're reading from  Microsoft Azure Fundamentals Certification and Beyond - Second Edition

Product typeBook
Published inJan 2024
PublisherPackt
ISBN-139781837630592
Edition2nd Edition
Right arrow
Author (1)
Steve Miles
Steve Miles
author image
Steve Miles

Steve Miles works in a technology leadership role for the cloud practice of a multi-billion turnover IT distributor based in the UK and Ireland. He is a Microsoft Azure MVP (Most Valuable Professional), MCT (Microsoft Certified Trainer) and Microsoft technologies author. Steve has more than 25 years of experience in hosted datacenter services, hybrid, and multi-cloud platforms. In his free time, Steve also can be found tinkering on cars.
Read more about Steve Miles

Right arrow

Azure Identity and Access

In Chapter 4, Azure Core Resources, you looked at the core building block resources available in Azure of “compute”, “storage”, and “networking.”

This chapter will outline the core building block service of “Identity and Access” available in Azure; you will look at directory services in Azure, authentication methods, external identities, conditional access, and role-based access control.

This chapter primarily focuses on the Describe Azure identity and access module from the Skills Measured section of the AZ-900 Azure Fundamentals exam.

Note

You can find a detailed AZ-900 Azure Fundamentals exam skills area in the Appendix, Assessing AZ-900 Exam Skills of this book.

By the end of this chapter, you will be able to answer questions on the following confidently:

  • Authentication and authorization
  • Microsoft Entra ID
  • Identity and access management

In addition, this chapter...

Authentication and Authorization

Accessing resources is based on a two-stage concept of first authenticating and then authorizing; identifying “who you are” and determining “what you can do.”

Authentication, also referred to as AuthN, is the process of establishing and proving the identity of a person (or service). This can be done by validating provided access credentials information against stored or known identifying information.

Authorization, also referred to as AuthZ, is the process of establishing what level of access the authenticated person (or service) has to the resources, that is, what they can access and what actions they may perform.

Figure 5.1 visualizes the concepts of authentication and authorization.

Figure 5.1 – The concepts of authentication and authorization

In this section, you looked at the concepts of authentication and authorization. The following section looks at Microsoft Entra ID.

Microsoft Entra ID

Microsoft Entra ID, previously named (Azure Active Directory), is a multi-tenant cloud-based identity and access management solution that is part of Microsoft’s Microsoft Entra “identity platform” product family.

Microsoft Entra ID is primarily a “cloud-based” centralized Identity Provider (IDP) and “directory service” for objects, which are stored in Microsoft Entra ID with attributes.

For “user identities,” the core attributes would be their sign-in name, their User Principal Name (UPN), “password,” “location,” “assigned roles,” “group membership,” “devices,” “licenses,” and “authentication methods.”

The directory service is the foundation of granting access to resources through Identity and Access Management (IAM) for cloud and hybrid environments. It provides authentication and authorization...

Identity and Access Management (IAM)

This section will look at aspects of implementing, managing, and controlling IAM; you will cover role-based access control, Azure subscription access control, Azure roles, and external identity access.

Role-Based Access Control (RBAC)

RBAC is a concept that refers to authorized user access based on defined roles that have been assigned. It allows you to create “granular access control” to Azure resources through “defined roles” and “custom roles.” You can segregate duties by granting only the access required to perform the required tasks.

It is an effective practice for governance “only to allow the minimum access” required to complete a task. This is the basis for the principle of least privilege and should always be adopted. So, users are only given access through a role(s) that is the most appropriate for the tasks they need to carry out.

This least privilege approach enhances...

Summary

This chapter included identity and access content for coverage of the following AZ-900 Azure Fundamentals exam skills area: Describe Azure identity, access, and security.

In this chapter, you learned how to describe directory services in Azure including Microsoft Entra ID (previously named Azure AD) and Microsoft Entra Domain Services (previously named Azure AD Domain Services), describe authentication methods in Azure (including SSO, multi-factor authentication, and passwordless), external identities and guest access in Azure, conditional access, and Azure RBAC.

The next chapter looks at Azure Security. You will learn the concept of Zero Trust, the purpose of the defense-in-depth model, and Microsoft Defender for Cloud.

Exam Readiness Drill – Chapter Review Questions

Apart from a solid understanding of key concepts, being able to think quickly under time pressure is a skill that will help you ace your certification exam. That is why working on these skills early on in your learning journey is key.

Chapter review questions are designed to improve your test-taking skills progressively with each chapter you learn and review your understanding of key concepts in the chapter at the same time. You’ll find these at the end of each chapter.

How To Access These Resources

To learn how to access these resources, head over to the chapter titled Chapter 11, Accessing the Online Practice Resources.

To open the Chapter Review Questions for this chapter, perform the following steps:

  1. Click the link – https://packt.link/AZ900E2_CH05.

Alternatively, you can scan the following QR code (Figure 5.9):

Figure 5.9 – QR code that opens Chapter Review...

Working On Timing

Target: Your aim is to keep the score the same while trying to answer these questions as quickly as possible. Here’s an example of how your next attempts should look like:

Attempt

Score

Time Taken

Attempt 5

77%

21 mins 30 seconds

Attempt 6

78%

18 mins 34 seconds

Attempt 7

76%

14 mins 44 seconds

Table 5.1 – Sample timing practice drills on the online platform

Note

The time limits shown in the above table are just examples. Set your own time limits with each attempt based on the time limit of the quiz on the website.

With each new attempt, your score should stay above 75% while your “time taken...

Online Hands-On Activities

Once you complete this book, complete the hands-on activities that align with this chapter. These are available on the accompanying online platform. Perform the following steps to open hands-on activities:

  1. Navigate to the Dashboard.
  2. Click the Hands-On Activities menu.
  3. Select the activity you want to attempt.
  4. The following activities align with this chapter:
    1. Set 1 – Microsoft Entra ID Users and Groups (Accessible at https://packt.link/activity2)
    2. Set 1 – Tenant Global Administrators (Accessible at https://packt.link/activity3)

Each activity will have a set of tasks. Complete all the tasks to shore up your practical knowledge. For example, Figure 5.11 shows the tasks aligned with the activity Microsoft Entra ID Users and Groups:

Figure 5.11 – Tasks in Microsoft Entra ID Users and Groups activity

Additional Information and Study References

This section provides links to additional exam information and study references.

lock icon
The rest of the chapter is locked
You have been reading a chapter from
Microsoft Azure Fundamentals Certification and Beyond - Second Edition
Published in: Jan 2024Publisher: PacktISBN-13: 9781837630592
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
undefined
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at €14.99/month. Cancel anytime

Author (1)

author image
Steve Miles

Steve Miles works in a technology leadership role for the cloud practice of a multi-billion turnover IT distributor based in the UK and Ireland. He is a Microsoft Azure MVP (Most Valuable Professional), MCT (Microsoft Certified Trainer) and Microsoft technologies author. Steve has more than 25 years of experience in hosted datacenter services, hybrid, and multi-cloud platforms. In his free time, Steve also can be found tinkering on cars.
Read more about Steve Miles