Azure AD & MFA: AZ-900 Microsoft Azure Core Identity Services

Azure Core Identity Services
Azure Cloud

Share Post Now :

HOW TO GET HIGH PAYING JOBS IN AWS CLOUD

Even as a beginner with NO Experience Coding Language

Explore Free course Now

Table of Contents

Loading

This blog post is the twelfth blog  Microsoft Azure Fundamentals Certification Series (AZ-900) of Topic 3: Security Services.

Check out the previous Topic 3.1 Azure Security Network Connectivity: firewall, DDOS, NSG for better understanding.

In this blog post, we’ll cover Topic 3.2 Microsoft Azure Core Identity Services which includes Azure Active Directory(Azure AD) and Multifactor Authentication(MFA).

Identity management is the process of controlling, authenticating, and authorizing security principals i.e services, applications, users, groups, etc.

Azure provides security through additional levels of validation, monitoring suspicious activity through advanced security reporting, auditing, and alerting helps mitigate potential security issues. The security services offered by Azure are:

Azure Active Directory

  1. Azure AD is Microsoft’s cloud-based identity and access management service which is a directory of users in Azure.
  2.  It creates and manages a single identity for each user across the enterprise, keeping users, groups, and devices in sync.
  3. Provides SSO(Single sign-on) access to applications, including thousands of pre-integrated SaaS apps.
  4. Enables application access security by enforcing rules-based Multi-Factor Authentication for both on-premises & cloud applications.
  5. Provisions secure remote access to on-premises web applications through Azure AD Application Proxy.
  6. Azure AD device registration provides the device with an identity that it uses to authenticate the device when a user signs in.

Azure AD Application Proxy provides remote access and SSO for many types of on-premises web applications with thousands of SaaS applications that Azure AD supports.

Azure AD B2C is a global, identity management service for consumer-facing applications with millions of identities and is highly available. It can be integrated across mobile and web platforms. The consumers can sign in to all the applications through customizable experiences.

Also check: Microsoft Free Certification in Microsoft Ignite 2020

Note: SSO means being able to access all the applications and resources that you need to do business, by signing in only once using a single user account.

Azure Active Directory

Also read: All you need to know about Azure Resource Group

Azure Multi-Factor Authentication

  1. It is a method of authentication that requires the use of more than one verification method
  2. It adds a critical second layer of security to user sign-ins and transactions.
  3. It offers a range of verification options: phone calls, text messages, mobile app notifications, verification codes, and third-party OAuth tokens.

Multi-Factor-Authentication-Flow

Note: Azure provides Role-Based Access Control on Azure Resource Manager that allows granular control of access to the users.

Also check: Azure DeVops Certifcation Path to know more about the certifications to be a Microsoft Certified DevOps Engineer.

Sample Questions

Here are a few sample questions from the Microsoft Azure Fundamentals Certification Exam[AZ-900] that you should be able to solve after reading this blog.

Q1: Which of the following statements are true?
A. Identities stored in an on-premises Active Directory can be synchronized to Azure Active Directory (Azure AD).

B.  Identities stored in Azure Active Directory (Azure AD), third-party cloud services, and on-premises Active Directory can be used to access Azure resources.
C. Azure has built-in authentication and authorization services that provide secure access to Azure resources.

Correct Answer: A, C

Explanation: By default, on-premise AD and Azure AD are not synced but can be synced when needed.

Q2: Which of the following statements are true?
A. Azure Active Directory (Azure AD) requires the implementation of domain controllers on Azure virtual machines.
B. Azure Active Directory (Azure AD) provides authentication services for resources hosted in Azure and Microsoft 365.
C. Each user account in Azure Active Directory (Azure AD) can be assigned only one license.

Correct Answer: B

Related/References

  1. Learn how to create a Free Microsoft Azure Trial Account
  2. [AZ-900] Microsoft Azure Fundamentals: Topic 1.1 Overview & Benefits
  3. Topic 2.1 Azure Architecture: Region, Availability Zone & Geography
  4. How to Register For [AZ-900] Microsoft Azure Fundamentals Certification Exam
  5. Topic 3.1 Microsoft Azure Secure Network Connectivity: Firewall, DDOS, & NSG

Next Task For You

Begin your journey toward Mastering Azure Cloud and landing high-paying jobs. Just click on the register now button on the below image to register for a Free Class on Mastering Azure Cloud: How to Build In-Demand Skills and Land High-Paying Jobs. This class will help you understand better, so you can choose the right career path and get a higher paying job.

azure cloud job free class

Picture of mike

mike

I started my IT career in 2000 as an Oracle DBA/Apps DBA. The first few years were tough (<$100/month), with very little growth. In 2004, I moved to the UK. After working really hard, I landed a job that paid me £2700 per month. In February 2005, I saw a job that was £450 per day, which was nearly 4 times of my then salary.