
This chapter looks into the entire ecosystem
This chapter looks into a description of the entire ecosystem
This chapter looks into what is Azure
This chapter looks into the Azure Free account
This chapter looks into creating an Azure Free account
This chapter looks into a tour of the Azure Portal
This chapter looks into creating an Azure resource
This chapter looks into creating a user
This chapter looks into giving access to a resource
This chapter looks into creating a group
This chapter looks into Azure AD Roles
This chapter looks into assigning an Azure AD Role
This chapter looks into custom domain names in Azure AD
This chapter looks into external identities
This chapter looks into Azure AD Premium licensing
This chapter looks into assigning a license to a user
This chapter looks into creating an external user
This chapter looks into inviting bulk users
This chapter looks into getting trial licenses
This chapter looks into assigning licenses to an Azure AD Group
This chapter looks into different types of groups
This chapter looks into Admin Center
Learn how to delete and recover users and groups in Azure Active Directory, including 30-day recovery, permanent deletion, and handling non-deletable or synced groups with PowerShell.
This chapter looks into an introduction to Azure AD Connect
This chapter looks into pre-requisites for Azure AD Connect
This chapter looks into the steps we are going to perform
This chapter looks into setting up the VM for the domain controller
This chapter looks into installing the domain controller
This chapter looks into network settings
This chapter looks into setting up the connect machine
This chapter looks into setting up Azure AD Connect
Set up a monthly budget alert in your Azure subscription and receive emails when costs hit the threshold, then delete unused resources after labs to save money.
This chapter looks into Pass-through Authentication
This chapter looks into implementing Pass-through authentication
This chapter looks into the advantages of Pass-through authentication
This chapter looks into changing user properties
This chapter looks into the organizational unit
This chapter looks into configuring single-sign on
This chapter looks into group policy for single sign-on
This chapter looks into Azure AD Connect Password reset
This chapter looks into Azure AD Connect Health
Learn high availability for Azure AD Connect by using a standby server in staging mode, with synchronization on the primary server and failover to the secondary server in full mode.
This chapter looks into Azure AD Directory extensions
This chapter looks into disabling Azure AD Connect
This chapter looks into Azure AD Connect Cloud Sync
This chapter looks into keeping the infrastructure
This chapter looks into external users pricing
Set up a user flow for external identities and enable guest self-service sign-up with a one time passcode, sending codes to external emails (such as Yahoo) with a 30-minute expiry.
This chapter looks into adding users to a mail enabled security group
This chapter looks into dynamic groups for users
This chapter looks into dynamic groups for devices
This chapter looks into administrative units
This chapter looks into a lab on administrative units
This chapter looks into important points
This chapter looks into security defaults
This chapter looks into Multi-Factor Authentication
This chapter looks into MFA on a user basis
This chapter looks into skipping MFA
This chapter looks into MFA settings
This chapter looks into Conditional Access policies
This chapter looks into a lab on conditional access policies
This chapter looks into named locations
This chapter looks into legacy apps
Demonstrate how to create a conditional access policy to block downloads for user A in SharePoint Online, enforcing Azure AD joined or compliant devices to allow downloads.
This chapter looks into Azure AD Identity Protection
This chapter looks into Azure AD Identity Protection - Important points
This chapter looks into a quick look at Azure AD Identity Protection
This chapter looks into self-service password reset
This chapter looks into enabling self-service password reset
This chapter looks into performing self-service password reset
Explore passwordless SMS-based authentication in Azure AD by creating a new user, assigning a license, and enabling SMS as a sign-in method, then test with a phone number on Office.com.
Enable per-user MFA with the Microsoft Authenticator app on Android and iOS, enabling passwordless sign-in and approvals to secure Azure Active Directory logins.
Demonstrates passwordless sign-in with the Microsoft Authenticator app as the primary authentication method, including device registration with Azure AD, screen lock, and signing in without a password.
Demonstrates configuring security key authentication in Azure Active Directory, enabling passwordless sign-in with a USB security key, setting up a key with a pin and fingerprint, and testing login.
Review the lifecycle of multi-factor authentication, from disabled to enabled to enforced, and explore per-user MFA, IP exemptions, legacy protocols, location-based controls, and passwordless options.
This chapter looks into applications in Azure AD
This chapter looks into Application Objects
This chapter looks into creating an application object
This chapter looks into using an application object
Demonstrate delegated access by showing how a logged-in user’s permissions govern resource access in Azure AD and the Graph API, contrasted with application permissions in a dotnet web app.
Set up delegated access to a storage account by creating a container, uploading a file, and assigning Azure AD roles such as reader and storage blob data reader.
Demonstrates implementing delegated access in a .NET app to read Azure storage using user impersonation. Configure an Azure AD application object, grant storage delegated permissions, and complete the consent flow.
This chapter looks into Azure AD Roles
This chapter looks into Azure AD Application Proxy
This chapter looks into setting the environment
This chapter looks into Azure AD Proxy Implementation
This chapter looks into Enterprise Applications
This chapter looks into registering for an enterprise application
This chapter looks into Azure AD Enterprise Applications - Single Sign On
This chapter looks into Enterprise Applications - Self-service
This chapter looks into Identity Governance
This chapter looks into Access Reviews
This chapter looks into License requirement for Access Reviews
This chapter looks into setting up an Access Review
This chapter looks into a self-review
This chapter looks into a manager review
This chapter looks into other important points
This chapter looks into entitlement management
This chapter looks into creating an access package
This chapter looks into requesting an access package
This chapter looks into Privileged Identity Management
This chapter looks into an introduction to Privileged Identity Management
This chapter looks into Privileged Identity Management - Assign Eligibility
This chapter looks into Privileged Identity Management - Role settings
This chapter looks into Privileged Identity Management - Assigning identities
This chapter looks into Privileged Identity Management - Approval
This chapter looks into Privileged Identity Management - Access Review
This chapter looks into Azure AD Sign-in Logs
This chapter looks into Azure AD - Audit Logs
This chapter looks into Azure AD logs retention
Explore the Azure Monitor service, including the activity log for control plane activities, and create alerts from queries in a log analytics workspace based on resource metrics like CPU utilization.
Create an alert from sign-in logs in a log analytics workspace by filtering result types not zero, then configure a threshold-based alert rule and an action group for email.
Discover Azure AD workbooks to visualize sign-in data, including successful, pending, and failed events, by location and device. See built-in workbooks and learn to create your own for directory insights.
Export sign in logs to json or csv to determine if conditional access was applied. Use json-based logs to view the applied policy name and details in a structured format.
Explore the Azure sentinel service, a SIEM and SOAR platform that collects sign-in data from Azure Active Directory, detects threats with rules, and automates responses within the log analytics workspace.
Understand break-glass and emergency accounts in Azure, including a plain, permanently assigned account not tied to any user, with multi-factor authentication and an authentication method from the primary global administrator.
Explore how to synchronize on-premises identities to Azure Active Directory with Azure AD Connect, configure password hash synchronization or pass-through authentication, and publish on-prem apps via Application Proxy.
Assign licenses to users or groups on Azure AD, choosing Azure AD premium licenses for conditional access and identity protection, or Microsoft 365 licenses for Exchange Online and SharePoint Online.
Explore the types of groups in Azure Active Directory, including security and Microsoft 365 groups, and how cloud and on-premises users join, with dynamic groups for automatic licensing.
Enforce global and custom banned password lists with azure ad password protection, blocking obfuscated passwords. Extend protection on-prem with the password protection proxy and dc agent on a domain controller.
Examine conditional access policies, including filtering users and groups, and creating rules by name and location. Configure multi-factor authentication enforcement, block older authentication protocols, and manage access from high-risk locations.
Retain Azure Active Directory sign-in and audit logs with diagnostic settings. Leverage Log Analytics and Azure Sentinel data connectors to detect threats and monitor apps, including Defender for cloud apps.
Review user access across groups, applications, Azure AD roles, and RBAC roles with access reviews. Automate access with entitlement management packages, enabling cross-tenant restrictions and streamlined provisioning.
Right here! Avail special discount coupon links for all of my Al Azure and AWS Courses
This course is designed for students to prepare for the SC-300: Microsoft Identity and Access Administrator exam.
The various objectives and chapters that will be covered include
Implement an identity management solution
In this section we will cover the below important aspects
How to work with users and groups in Azure Active Directory
How do you assign licenses to users and groups
The different type of groups in Azure Active Directory
Working with Azure AD Roles
Working with Azure AD Connect
Implement an authentication and access management solution
In this section we will cover the below important aspects
What is Multi-Factor Authentication and how does it work on a user by user basis
How can be use Conditional Access Policies to enable Multi-Factor Authentication
How can we protect identities in Azure Active Directory with the use of Azure AD Identities Protection
How to implement self-service password reset
Implement access management for apps
In this section we will cover the below important aspects
How to we manage applications in Azure AD
How to perform self-service for enterprise applications
Working with Azure AD Application Proxy
Plan and implement an identity governance strategy
In this section we will cover the below important aspects
What are Access Reviews
How can you conduct Access Reviews
What is Entitlement management
Working with Privileged Identity Management
Audit and Sign-in logs in Azure AD