Search icon
Arrow left icon
All Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletters
Free Learning
Arrow right icon
Microsoft Identity and Access Administrator Exam Guide

You're reading from  Microsoft Identity and Access Administrator Exam Guide

Product type Book
Published in Mar 2022
Publisher Packt
ISBN-13 9781801818049
Pages 452 pages
Edition 1st Edition
Languages
Author (1):
Dwayne Natwick Dwayne Natwick
Profile icon Dwayne Natwick

Table of Contents (24) Chapters

Preface Section 1 – Exam Overview and the Evolution of Identity and Access Management
Chapter 1: Preparing for Your Microsoft Exam Chapter 2: Defining Identity and Access Management Section 2 - Implementing an Identity Management Solution
Chapter 3: Implementing and Configuring Azure Active Directory Chapter 4: Creating, Configuring, and Managing Identities Chapter 5: Implementing and Managing External Identities and Guests Chapter 6: Implementing and Managing Hybrid Identities Section 3 – Implementing an Authentication and Access Management Solution
Chapter 7: Planning and Implementing Azure Multi-Factor Authentication (MFA) and Self-Service Password Reset (SSPR) Chapter 8: Planning and Managing Password-Less Authentication Methods Chapter 9: Planning, Implementing, and Administering Conditional Access and Azure Identity Protection Section 4 – Implementing Access Management for Applications
Chapter 10: Planning and Implementing Enterprise Apps for Single Sign-On (SSO) Chapter 11: Monitoring Enterprise Apps with Microsoft Defender for Cloud Apps Section 5 – Planning and Implementing an Identity Governance Strategy
Chapter 12: Planning and Implementing Entitlement Management Chapter 13: Planning and Implementing Privileged Access and Access Reviews Section 6 – Monitoring and Maintaining Azure Active Directory
Chapter 14: Analyzing and Investigating Sign-in Logs and Elevated Risk Users Chapter 15: Enabling and Integrating Azure AD Logs with SIEM Solutions Chapter 16: Mock Test Other Books You May Enjoy

Enabling and integrating Azure AD diagnostic logs with Log Analytics and Microsoft Sentinel

In the previous chapter, we discussed how to access and use activity logs and audit logs to review user activity and filter that activity for monitoring, reporting, and managing potential vulnerabilities and threats. In this chapter, we will discuss how we can use this information within Microsoft Sentinel and third-party SIEM solutions to provide an integration of these logs to handle security operations more efficiently in one location.

This section will provide guidance on how to export logs to Microsoft Sentinel. The next section will discuss how to export logs to third-party security tools, if you are not utilizing Microsoft Sentinel. Let's start by explaining Microsoft Sentinel and what SIEM and security orchestration automated response (SOAR) solutions are.

A SIEM is a solution within a security operations center that gathers logs and events from various appliances and software...

lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $15.99/month. Cancel anytime}