Microsoft Identity & Access Management Flashcards
7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Microsoft Identity & Access Management flashcards as text
What is a 'managed identity' in Azure and how does it differ from a service principal?
Answer: A managed identity has its credentials automatically managed by Azure, eliminating the need to store secrets
Managed identities have credentials automatically maintained by Azure, so developers never need to handle or rotate secrets.
In Azure AD Conditional Access, what is a 'named location'?
Answer: A trusted IP range or country used as a condition in access policies
Named locations define trusted IP ranges or countries/regions that can be referenced as conditions in Conditional Access policies.
Which Azure AD license tier is required to use Conditional Access policies?
Answer: Azure AD Premium P1 or P2
Conditional Access is a premium feature requiring Azure AD Premium P1 (or P2 for risk-based policies).
What is 'federation' in the context of Azure AD identity management?
Answer: Establishing trust between Azure AD and another identity provider so users authenticate at their home directory
Federation creates a trust relationship so users can authenticate with their own identity provider and access federated resources.
Azure AD Access Reviews are primarily used to:
Answer: Periodically verify that users still need their current group memberships or role assignments
Access Reviews enable periodic recertification of user access to ensure only appropriate users retain group/role memberships.
What is the Zero Trust principle of 'assume breach'?
Answer: Designing systems as if attackers are already inside, minimizing blast radius and segmenting access
Assume breach means designing security so that even if an attacker gains entry, lateral movement and damage are contained.
Which feature of Azure AD allows you to group users dynamically based on attributes like department or job title?
Answer: Dynamic groups
Dynamic groups in Azure AD automatically add or remove members based on user attribute rules, eliminating manual membership management.