
Learn Azure Active Directory and identity concepts, including users, groups, service principals, app management, and on-premise connections, then explore zero trust, conditional access, MFA, and role-based access control.
Azure active directory is a cloud-based identity as a service that manages users, groups, devices, and applications, with licensing from free to premium and B2C, dynamic groups, and conditional access.
Explore Azure AD key capabilities, including user management, device management with Intune, conditional access with MFA, and B2B/B2C collaboration, plus on-premises connectivity and monitoring user activity and apps.
Learn how to create and manage Azure AD users and groups across cloud and on-premises identities, including B2B guest access and multi-factor authentication, with Azure portal, PowerShell, and CLI.
Create and manage Azure AD users and guests, assign roles and groups, and configure security settings, password options, MFA, and audit logs to control access and monitor activity.
Explore groups in Azure AD, including security and Office 365 groups, and learn how assigned and dynamic user and device memberships govern access.
Learn to create groups in Azure AD, choose security or Office 365 group types, assign owners and members, and manage group properties, licenses, and audit logs for governance.
Explore user settings for external collaboration in Azure Active Directory, including guest permissions, invite rules, and domain restrictions to secure and control access.
Register apps and provide secure, seamless access to cloud and on-premise apps with Azure AD, enabling single sign-on, governance, conditional access, and risk reduction.
Register your application in Azure Active Directory and create a service principal to access subscriptions and resources, using app registrations, permissions, and secrets or certificates.
Learn how single sign-on lets a user log in once through an identity provider to securely access multiple applications, reducing administration and boosting productivity.
Explore single sign-on options with Azure Active Directory, including OpenID Connect, SAML, password-based authentication, and linked identities, plus header-based authentication and the disabled option.
Azure AD Connect is a hybrid identity tool that links on-premises and cloud identities, enabling synchronized sign-in, common identity, and seamless access to both on-premises and cloud applications.
Explore Azure AD Connect authentication types—password hash synchronization, pass-through authentication, and federation integration—and a decision tree to choose the right method for cloud and on-premises apps.
Learn how Azure identity types, including system-assigned and user-assigned managed identities, enable secure authentication for apps and virtual machines without embedded credentials, and their lifecycle differences.
Learn how to configure system-assigned and user-assigned identities for azure virtual machines, attach identities during creation or afterward, and grant vm access to resources without hardcoding credentials.
Explore how to enable and assign system and user managed identities to virtual machines in Azure Active Directory, including the identity tab workflow and granting access to resources.
Discover enterprise data roaming in Azure AD, delivering a unified, secure experience by syncing Windows settings across devices and protecting corporate data with encryption and Microsoft Information Protection.
Zero trust treats every access request as untrusted and verifies every user and device, internal or external, in a cloud era with micro segmentation and verification over traditional perimeters.
Explore zero trust guiding principles: authenticate and authorize users based on data points, implement least privileged access with just-in-time controls, and assume breach to improve security and visibility.
Explore the six foundational pillars of zero trust: infrastructure, network, devices, applications, data, and identities, and learn to apply monitoring, just-in-time access, strong authentication, and encryption across layers.
Explore zero trust with conditional access in Azure Active Directory, learning how never trust, always verify, and identity as the control plane secure access across apps and devices.
Explore Azure conditional access, showing how conditions and access controls enforce organization policy under zero trust using signals like location, devices, and MFA prompts.
Discover the three pillars of Azure conditional access—common signals, decisions, and applied policies—and how signals from users, devices, and IP ranges drive secure, productive access.
Learn how Azure conditional access evaluates multiple policies in two phases, blocking access when any policy requires it, and prioritizes controls like MFA and compliant devices to enable day-to-day tasks.
Learn to configure a MFA-based conditional access policy in Azure, create a user, apply access controls, and test what-if scenarios to secure portal login.
Explore role-based access control by defining security principles, role definitions, and scope to grant fine-grained access to resources like virtual machines and databases.
Explore the security principal concept in Azure RBAC, defining users, groups, and service principals, and how authentication and authorization govern access to resources.
Explore Azure RBAC role definitions, built-in and custom, with owner, contributor, and reader permissions. Understand management versus data operations and how they control access to storage accounts and blob data.
Discover how scope in Azure RBAC defines where access applies across management groups, subscriptions, and resource groups using roles such as reader, contributor, and lead.
Explore how Azure RBAC uses security principals, role definitions, and scope to assign permissions via rule assignments, enabling contributors to access resources such as resource groups and storage accounts.
Demonstrates configuring role based access control in Azure by creating a security principal group, assigning the reader role, and applying scope to a resource group or subscription for access control.
Celebrate completing the Azure Active Directory identity concepts course and invite feedback and five-star ratings to help others discover this content.
In this course, you will gain an understanding of Azure directory service options and the benefits that it offers.
The course has been divided into several sections and details about the topics covered in each section are mentioned below:
Section 1: Covering Basics around Azure Active Directory
What is Azure Active Directory and its payment models
Key capabilites of Azure AD
Users in Azure AD
Demo : Create Users in Azure AD and Configure user related settings
Groups in Azure AD
Demo : Create Groups in Azure AD and Understand Group settings
Demo : User Security / B2B external collaboration settings
Application Management Via Azure AD
Demo: Create Service Principal/Application Registration in Azure AD
Section 2 : Single Sign-on and Azure AD Connect Concept
Single SignOn and its working
Single SignOn option with Azure AD
What is Azure AD Connect ?
Azure AD Connect : Authentication Types
Section 3: Identity management in Azure AD
Azure Identity and its types
Demo : System-Assigned and User-assigned identity in Azure
Azure Active Directory Identity Protection
Enterprise State Roaming in Azure AD
Section 4 : Understand the concept of Zero Trust
What is Zero Trust
Zero Trust Guiding Principles
Zero Trust - Six foundational pillars
Achieve Zero Trust With Conditional Access
Section 5 : Implement Conditional Access Policies via Azure AD
Overview - Azure Conditional Access
3 Pillars of Azure Conditional Access
How Azure Conditional Access Work ?
Demo: Configure MFA Based Conditional Access Policy
Section 6: Roles based access control (RBAC) in Azure AD
Roles based access control (RBAC)
Pillar 1- Security Principal in Azure RBAC
Pillar 2 - Role Definition in Azure RBAC
Pillar 3 - Scope in Azure RBAC
How RBAC Work in Azure ?
Demo : Configure RBAC in Azure
We will go though all the topics mentioned below. For actual details, Please have a look at the course agenda and preview videos in this course .
In case you are planning to prepare for Az 500, SC- 900 SC-200 or SC-300 , the course material would be helpful in clearing your concepts in the Azure and Identity space. In case clearing certification is not in your agenda even then this course would help you to prepare for the real discussion with your cloud team.
I hope the course would be helpful to you. I welcome you to the course .Let's get started .