1/99
Comprehensive flashcards covering Microsoft Entra ID, Azure security services, and identity management concepts based on the SC-300 study material.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Microsoft Entra ID
A cloud-based identity and access management service that enables secure authentication and authorization for users and applications.
Microsoft Entra Connect
A tool that synchronizes on-premises Active Directory with Microsoft Entra ID to enable hybrid identity.
Microsoft Entra ID Protection
It detects, investigates, and automatically responds to identity-based risks in your environment.
Microsoft Entra Privileged Identity Management
Allows you to manage, monitor, and control privileged accounts in Microsoft Entra ID.
Microsoft Entra Verified ID
Provides a decentralized identity verification system for securely issuing and validating credentials.
Microsoft Entra Internet Access
A secure web gateway that protects internet traffic from threats and enforces access policies.
Microsoft Entra Audit Logs
Record all activities, sign-ins, and changes that occur within Microsoft Entra ID.
Microsoft Entra Sign
A digital signature service that integrates with Microsoft Entra ID authentication.
Azure Automation
Enables you to automate tasks, orchestrate workflows, and manage configurations across Azure.
Microsoft Defender for Cloud Apps
Provides cloud-native security posture management and threat protection across Azure, hybrid, and multi-cloud environments.
Zero Trust Principles
A security model that assumes no implicit trust for any user, device, or application, requiring explicit verification, least-privilege access, and continuous monitoring to protect resources.
Microsoft Information Protection
Helps classify, label, and protect sensitive data wherever it resides.
Microsoft Purview
A unified platform for data governance, risk management, and compliance.
Azure Policy
Enforces organizational standards and compliance requirements on Azure resources.
Role-Based Access Control (RBAC)
Assigns permissions to users, groups, and services based on roles.
Cloud Security Posture Management (CSPM)
It continuously assesses cloud configurations to ensure compliance and improve security posture.
Microsoft Defender for DevOps
It secures DevOps environments, pipelines, and code repositories.
Microsoft Defender for Identity
It detects identity-based threats in Active Directory and Microsoft Entra ID.
Microsoft Defender for Office 365
It protects against email, link, and collaboration threats.
Microsoft Graph
A unified API endpoint for accessing data across Microsoft 365 and related services.
Graph API
It is the RESTful interface for interacting with Microsoft Graph.
Graph PowerShell
A PowerShell module that allows automation of Microsoft Graph API tasks.
Conditional Access policy
Enforces access controls based on conditions such as device state, location, or risk.
Data connectors
It bring external or third-party data into Microsoft Sentinel or other security solutions.
Sign-in risk policy
It responds to risky sign-ins by requiring additional verification or blocking access.
Sign-in user policy
It controls access for specific users based on sign-in conditions.
Global Administrator
The highest-privilege role in Microsoft Entra ID with full control over settings and resources.
Data Collection Rules
It specifies what data is collected and where it is sent in Azure Monitor.
Just-in-Time (JIT) VM Access
It restricts inbound traffic to Azure virtual machines by allowing access only when needed and for a limited time.
Microsoft Entra tenant
A dedicated, isolated Microsoft Entra ID environment that represents your organization and contains its users, groups, apps, and security settings.
Multi-factor Authentication (MFA) settings
Security configurations that enforce the use of two or more verification methods, like a password and mobile app approval, to strengthen account protection.
Microsoft Entra roles
Role-based access control assignments in Entra ID that delegate specific permissions, allowing admins to manage identity, security, and apps.
Company branding settings
Custom options for sign-in experiences, including logos, colors, and background images, that improve user trust and reflect organizational identity.
Microsoft Entra admin center
The web-based management portal is used by administrators to configure authentication, apps, conditional access, and security policies.
PowerShell cmdlet
A command in PowerShell used to automate administrative tasks such as managing users, roles, and access policies in Microsoft Entra ID.
External collaboration settings
Controls that define how external guest users are invited, authenticated, and granted access to an organization's resources.
Cross-tenant access settings
Policies that manage authentication, trust, and collaboration between multiple Microsoft Entra tenants.
Cross-tenant synchronization
A feature that synchronizes users and groups across different Entra tenants to support secure cross-organization collaboration.
Security Assertion Markup Language (SAML)
An XML-based Single Sign-On (SSO) protocol that enables identity providers to pass authentication assertions to applications.
Web Services Federation (WS-Fed)
A federation protocol that provides Single Sign-On (SSO) by exchanging authentication tokens between services and identity providers.
Microsoft Entra Connect Sync
A synchronization service that integrates on-premises Active Directory with Microsoft Entra ID to unify identities across environments.
Microsoft Entra Cloud Sync
An agent-based synchronization solution that provides lightweight, scalable user and group syncing to Entra ID.
Password hash synchronization
A method that copies password hashes from on-prem AD to Entra ID, enabling cloud-based sign-ins without storing plain credentials.
Pass-through authentication
A method where Entra ID forwards sign-in requests to on-prem AD for real-time validation without storing passwords in the cloud.
Single sign-on (SSO)
A capability that lets users authenticate once and then access multiple apps and services without re-entering credentials.
Active Directory Federation Service (AD FS)
An on-premises identity service that provides federation and Single Sign-On (SSO) using security tokens for cloud and apps.
Microsoft Entra Connect Health
A monitoring service that provides insights, alerts, and reports on the health of hybrid identity components like Connect and AD FS.
Microsoft Entra user authentication
The identity verification process in Entra ID that validates user credentials through configured authentication methods.
Temporary access pass
A time-bound authentication method that allows secure sign-in or recovery when users cannot access their usual credentials.
OAUTH tokens
Digital tokens used in the OAuth 2.0 protocol that grant temporary access to apps and APIs without exposing user credential
Microsoft Authenticator
A mobile application that provides push approvals, verification codes, and passwordless authentication for stronger user security.
Passkey (FIDO2)
A passwordless authentication method using FIDO2 standards where users sign in with biometrics, PINs, or hardware keys tied to their device.
Self-service password reset (SSPR)
A feature that allows users to reset or unlock their accounts securely by verifying their identity with alternate methods like MFA.
Windows Hello for Business
A passwordless authentication solution that uses biometrics or a device-bound PIN to securely sign in to Windows and cloud resources.
Microsoft Entra password protection
A feature that prevents users from creating weak or banned passwords by enforcing a global and custom banned password list.
Microsoft Entra Kerberos authentication
Support for Kerberos authentication in Microsoft cloud services that enables hybrid environments to use modern authentication with legacy protocols.
Risky users
Accounts flagged as compromised or at high risk due to suspicious signals like leaked credentials or abnormal behavior.
Risky sign-ins
Sign-in attempts detected as unusual or malicious based on risk signals such as impossible travel or unfamiliar devices.
Global Secure Access clients
Endpoint clients that connect users securely to corporate resources using Microsoft's Zero Trust global secure access solutions.
Managed identity
An automatically created identity in Entra ID that applications or Azure resources can use to securely access services without credentials.
Microsoft Entra Application Proxy
A secure remote access service that allows external users to connect to on-premises web applications through Microsoft Entra ID.
Admin consent
Approval granted by an administrator to allow an application to access organizational data or resources on behalf of users.
User consent
Permission that an end user gives an application to access their personal or organizational data within Microsoft Entra ID.
App authentication
The process through which applications securely authenticate with Microsoft Entra ID to access APIs or organizational resources.
App registrations
The process of registering an application in Entra ID involves establishing identity, configuring permissions, and enabling secure access.
Application-enforced restrictions
Access restrictions are applied within applications themselves to control user activities, such as download prevention or read-only mode.
Conditional Access app control
A feature that extends Conditional Access by applying real-time monitoring and session controls through Defender for Cloud Apps.
Session policies
Rules that monitor and control user sessions in real time to restrict risky activities such as data exfiltration.
Access policies
Configured rules that determine how and under what conditions users or apps can access specific resources.
OAuth apps
Applications that use the OAuth 2.0 protocol to request delegated permissions and access resources securely without exposing credentials.
Cloud app catalog
A collection of recognized cloud applications in Microsoft Defender for Cloud Apps that helps organizations assess risk and apply policies.
Entitlement management
A governance feature that automates how users request, approve, and manage access to resources through workflows and policies.
Access packages
Bundles of resources, roles, and policies in entitlement management that can be requested and assigned to users for controlled access.
Access requests
User-initiated requests to gain access to specific resources, which are then reviewed and approved or denied based on policy.
Terms of Use (ToU)
Agreements that users must accept before accessing organizational resources, helping ensure compliance with company policies.
Access review activity
The process of periodically reviewing and validating that users still need access to specific applications or resources.
PIM audit history
Logs and records of Privileged Identity Management activity, including role activations and just-in-time access events.
Break-glass accounts
Emergency administrator accounts with permanent access that bypass restrictions are used only during critical outages or lockouts.
Diagnostic settings
Configuration options that determine where monitoring and diagnostic data, such as logs, are sent for storage and analysis.
Log Analytics workspaces
Centralized storage locations in Azure Monitor where logs and metrics from multiple services can be collected and queried.
Storage accounts
Azure resources used to securely store log and monitoring data, often as part of compliance or long-term archiving.
Event hubs
A big data streaming platform in Azure that ingests and processes large volumes of telemetry and log data in real time.
KQL queries
Used in Azure Monitor and Sentinel to analyze, visualize, and extract insights from large datasets.
Workbooks
Interactive dashboards in Azure Monitor that allow administrators to visualize and analyze log data with customizable reports.
Azure Firewall
A managed cloud-based firewall service that protects Azure networks with traffic filtering, rules, and logging capabilities.
Azure Key Vault
A secure cloud service that stores secrets, encryption keys, and certificates to protect sensitive data and manage cryptographic operations.
Cloud App Security Administrator
A role with permissions to manage Microsoft Defender for Cloud Apps features, policies, and monitoring capabilities.
Cloud Discovery
A feature in Defender for Cloud Apps that identifies and analyzes shadow IT usage by detecting unapproved cloud applications.
Cloud Apps
Applications delivered over the cloud that can be discovered, managed, and secured through Microsoft Entra ID and Defender for Cloud Apps.
Microsoft Endpoint Manager
A unified management platform that combines Intune and Configuration Manager to secure and manage devices, applications, and policies.
Microsoft Entra Private Access
A Zero Trust Network Access (ZTNA) solution that provides secure, seamless access to private apps and resources without a VPN.
Microsoft Exchange Online
A cloud-based email and calendaring service that delivers enterprise-grade communication and integrates with Microsoft 365 security features.
Microsoft Office 365 Enterprise E5
A premium Microsoft 365 subscription plan that includes advanced security, compliance, analytics, and telephony features.
Microsoft SharePoint Online
A cloud-based collaboration platform that enables organizations to manage, share, and secure content across teams and departments.
App Protection Policy
Policies applied to mobile applications that protect organizational data by enforcing rules like encryption, access controls, and data sharing restrictions.
Basic Authentication
A legacy authentication method using usernames and passwords in plain text, now deprecated due to weak security and lack of modern controls.
Compliance Policy
A set of rules in Microsoft Endpoint Manager that ensures devices and users meet security requirements before accessing organizational resources.
Administrative Units
A way to delegate administrative tasks by dividing a Microsoft Entra tenant into logical units for scopes of management, limiting role assignments to subsets of users/devices.
Identity Secure Score
A metric feature that gives a score and recommendations for improving your identity security posture in Microsoft Entra.
Smart lockout
Prevents brute-force attacks by automatically locking out malicious sign-in attempts while distinguishing genuine user behavior.