SC-300 Microsoft Identity and Access Administrator Vocabulary

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/99

flashcard set

Earn XP

Description and Tags

Comprehensive flashcards covering Microsoft Entra ID, Azure security services, and identity management concepts based on the SC-300 study material.

Last updated 6:24 PM on 7/7/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

100 Terms

1
New cards

Microsoft Entra ID

A cloud-based identity and access management service that enables secure authentication and authorization for users and applications.

2
New cards

Microsoft Entra Connect

A tool that synchronizes on-premises Active Directory with Microsoft Entra ID to enable hybrid identity.

3
New cards

Microsoft Entra ID Protection

It detects, investigates, and automatically responds to identity-based risks in your environment.

4
New cards

Microsoft Entra Privileged Identity Management

Allows you to manage, monitor, and control privileged accounts in Microsoft Entra ID.

5
New cards

Microsoft Entra Verified ID

Provides a decentralized identity verification system for securely issuing and validating credentials.

6
New cards

Microsoft Entra Internet Access

A secure web gateway that protects internet traffic from threats and enforces access policies.

7
New cards

Microsoft Entra Audit Logs

Record all activities, sign-ins, and changes that occur within Microsoft Entra ID.

8
New cards

Microsoft Entra Sign

A digital signature service that integrates with Microsoft Entra ID authentication.

9
New cards

Azure Automation

Enables you to automate tasks, orchestrate workflows, and manage configurations across Azure.

10
New cards

Microsoft Defender for Cloud Apps

Provides cloud-native security posture management and threat protection across Azure, hybrid, and multi-cloud environments.

11
New cards

Zero Trust Principles

A security model that assumes no implicit trust for any user, device, or application, requiring explicit verification, least-privilege access, and continuous monitoring to protect resources.

12
New cards

Microsoft Information Protection

Helps classify, label, and protect sensitive data wherever it resides.

13
New cards

Microsoft Purview

A unified platform for data governance, risk management, and compliance.

14
New cards

Azure Policy

Enforces organizational standards and compliance requirements on Azure resources.

15
New cards

Role-Based Access Control (RBAC)

Assigns permissions to users, groups, and services based on roles.

16
New cards

Cloud Security Posture Management (CSPM)

It continuously assesses cloud configurations to ensure compliance and improve security posture.

17
New cards

Microsoft Defender for DevOps

It secures DevOps environments, pipelines, and code repositories.

18
New cards

Microsoft Defender for Identity

It detects identity-based threats in Active Directory and Microsoft Entra ID.

19
New cards

Microsoft Defender for Office 365

It protects against email, link, and collaboration threats.

20
New cards

Microsoft Graph

A unified API endpoint for accessing data across Microsoft 365 and related services.

21
New cards

Graph API

It is the RESTful interface for interacting with Microsoft Graph.

22
New cards

Graph PowerShell

A PowerShell module that allows automation of Microsoft Graph API tasks.

23
New cards

Conditional Access policy

Enforces access controls based on conditions such as device state, location, or risk.

24
New cards

Data connectors

It bring external or third-party data into Microsoft Sentinel or other security solutions.

25
New cards

Sign-in risk policy

It responds to risky sign-ins by requiring additional verification or blocking access.

26
New cards

Sign-in user policy

It controls access for specific users based on sign-in conditions.

27
New cards

Global Administrator

The highest-privilege role in Microsoft Entra ID with full control over settings and resources.

28
New cards

Data Collection Rules

It specifies what data is collected and where it is sent in Azure Monitor.

29
New cards

Just-in-Time (JIT) VM Access

It restricts inbound traffic to Azure virtual machines by allowing access only when needed and for a limited time.

30
New cards

Microsoft Entra tenant

A dedicated, isolated Microsoft Entra ID environment that represents your organization and contains its users, groups, apps, and security settings.

31
New cards

Multi-factor Authentication (MFA) settings

Security configurations that enforce the use of two or more verification methods, like a password and mobile app approval, to strengthen account protection.

32
New cards

Microsoft Entra roles

Role-based access control assignments in Entra ID that delegate specific permissions, allowing admins to manage identity, security, and apps.

33
New cards

Company branding settings

Custom options for sign-in experiences, including logos, colors, and background images, that improve user trust and reflect organizational identity.

34
New cards

Microsoft Entra admin center

The web-based management portal is used by administrators to configure authentication, apps, conditional access, and security policies.

35
New cards

PowerShell cmdlet

A command in PowerShell used to automate administrative tasks such as managing users, roles, and access policies in Microsoft Entra ID.

36
New cards

External collaboration settings

Controls that define how external guest users are invited, authenticated, and granted access to an organization's resources.

37
New cards

Cross-tenant access settings

Policies that manage authentication, trust, and collaboration between multiple Microsoft Entra tenants.

38
New cards

Cross-tenant synchronization

A feature that synchronizes users and groups across different Entra tenants to support secure cross-organization collaboration.

39
New cards

Security Assertion Markup Language (SAML)

An XML-based Single Sign-On (SSO) protocol that enables identity providers to pass authentication assertions to applications.

40
New cards

Web Services Federation (WS-Fed)

A federation protocol that provides Single Sign-On (SSO) by exchanging authentication tokens between services and identity providers.

41
New cards

Microsoft Entra Connect Sync

A synchronization service that integrates on-premises Active Directory with Microsoft Entra ID to unify identities across environments.

42
New cards

Microsoft Entra Cloud Sync

An agent-based synchronization solution that provides lightweight, scalable user and group syncing to Entra ID.

43
New cards

Password hash synchronization

A method that copies password hashes from on-prem AD to Entra ID, enabling cloud-based sign-ins without storing plain credentials.

44
New cards

Pass-through authentication

A method where Entra ID forwards sign-in requests to on-prem AD for real-time validation without storing passwords in the cloud.

45
New cards

Single sign-on (SSO)

A capability that lets users authenticate once and then access multiple apps and services without re-entering credentials.

46
New cards

Active Directory Federation Service (AD FS)

An on-premises identity service that provides federation and Single Sign-On (SSO) using security tokens for cloud and apps.

47
New cards

Microsoft Entra Connect Health

A monitoring service that provides insights, alerts, and reports on the health of hybrid identity components like Connect and AD FS.

48
New cards

Microsoft Entra user authentication

The identity verification process in Entra ID that validates user credentials through configured authentication methods.

49
New cards

Temporary access pass

A time-bound authentication method that allows secure sign-in or recovery when users cannot access their usual credentials.

50
New cards

OAUTH tokens

Digital tokens used in the OAuth 2.0 protocol that grant temporary access to apps and APIs without exposing user credential

51
New cards

Microsoft Authenticator

A mobile application that provides push approvals, verification codes, and passwordless authentication for stronger user security.

52
New cards

Passkey (FIDO2)

A passwordless authentication method using FIDO2 standards where users sign in with biometrics, PINs, or hardware keys tied to their device.

53
New cards

Self-service password reset (SSPR)

A feature that allows users to reset or unlock their accounts securely by verifying their identity with alternate methods like MFA.

54
New cards

Windows Hello for Business

A passwordless authentication solution that uses biometrics or a device-bound PIN to securely sign in to Windows and cloud resources.

55
New cards

Microsoft Entra password protection

A feature that prevents users from creating weak or banned passwords by enforcing a global and custom banned password list.

56
New cards

Microsoft Entra Kerberos authentication

Support for Kerberos authentication in Microsoft cloud services that enables hybrid environments to use modern authentication with legacy protocols.

57
New cards

Risky users

Accounts flagged as compromised or at high risk due to suspicious signals like leaked credentials or abnormal behavior.

58
New cards

Risky sign-ins

Sign-in attempts detected as unusual or malicious based on risk signals such as impossible travel or unfamiliar devices.

59
New cards

Global Secure Access clients

Endpoint clients that connect users securely to corporate resources using Microsoft's Zero Trust global secure access solutions.

60
New cards

Managed identity

An automatically created identity in Entra ID that applications or Azure resources can use to securely access services without credentials.

61
New cards

Microsoft Entra Application Proxy

A secure remote access service that allows external users to connect to on-premises web applications through Microsoft Entra ID.

62
New cards

Admin consent

Approval granted by an administrator to allow an application to access organizational data or resources on behalf of users.

63
New cards

User consent

Permission that an end user gives an application to access their personal or organizational data within Microsoft Entra ID.

64
New cards

App authentication

The process through which applications securely authenticate with Microsoft Entra ID to access APIs or organizational resources.

65
New cards

App registrations

The process of registering an application in Entra ID involves establishing identity, configuring permissions, and enabling secure access.

66
New cards

Application-enforced restrictions

Access restrictions are applied within applications themselves to control user activities, such as download prevention or read-only mode.

67
New cards

Conditional Access app control

A feature that extends Conditional Access by applying real-time monitoring and session controls through Defender for Cloud Apps.

68
New cards

Session policies

Rules that monitor and control user sessions in real time to restrict risky activities such as data exfiltration.

69
New cards

Access policies

Configured rules that determine how and under what conditions users or apps can access specific resources.

70
New cards

OAuth apps

Applications that use the OAuth 2.0 protocol to request delegated permissions and access resources securely without exposing credentials.

71
New cards

Cloud app catalog

A collection of recognized cloud applications in Microsoft Defender for Cloud Apps that helps organizations assess risk and apply policies.

72
New cards

Entitlement management

A governance feature that automates how users request, approve, and manage access to resources through workflows and policies.

73
New cards

Access packages

Bundles of resources, roles, and policies in entitlement management that can be requested and assigned to users for controlled access.

74
New cards

Access requests

User-initiated requests to gain access to specific resources, which are then reviewed and approved or denied based on policy.

75
New cards

Terms of Use (ToU)

Agreements that users must accept before accessing organizational resources, helping ensure compliance with company policies.

76
New cards

Access review activity

The process of periodically reviewing and validating that users still need access to specific applications or resources.

77
New cards

PIM audit history

Logs and records of Privileged Identity Management activity, including role activations and just-in-time access events.

78
New cards

Break-glass accounts

Emergency administrator accounts with permanent access that bypass restrictions are used only during critical outages or lockouts.

79
New cards

Diagnostic settings

Configuration options that determine where monitoring and diagnostic data, such as logs, are sent for storage and analysis.

80
New cards

Log Analytics workspaces

Centralized storage locations in Azure Monitor where logs and metrics from multiple services can be collected and queried.

81
New cards

Storage accounts

Azure resources used to securely store log and monitoring data, often as part of compliance or long-term archiving.

82
New cards

Event hubs

A big data streaming platform in Azure that ingests and processes large volumes of telemetry and log data in real time.

83
New cards

KQL queries

Used in Azure Monitor and Sentinel to analyze, visualize, and extract insights from large datasets.

84
New cards

Workbooks

Interactive dashboards in Azure Monitor that allow administrators to visualize and analyze log data with customizable reports.

85
New cards

Azure Firewall

A managed cloud-based firewall service that protects Azure networks with traffic filtering, rules, and logging capabilities.

86
New cards

Azure Key Vault

A secure cloud service that stores secrets, encryption keys, and certificates to protect sensitive data and manage cryptographic operations.

87
New cards

Cloud App Security Administrator

A role with permissions to manage Microsoft Defender for Cloud Apps features, policies, and monitoring capabilities.

88
New cards

Cloud Discovery

A feature in Defender for Cloud Apps that identifies and analyzes shadow IT usage by detecting unapproved cloud applications.

89
New cards

Cloud Apps

Applications delivered over the cloud that can be discovered, managed, and secured through Microsoft Entra ID and Defender for Cloud Apps.

90
New cards

Microsoft Endpoint Manager

A unified management platform that combines Intune and Configuration Manager to secure and manage devices, applications, and policies.

91
New cards

Microsoft Entra Private Access

A Zero Trust Network Access (ZTNA) solution that provides secure, seamless access to private apps and resources without a VPN.

92
New cards

Microsoft Exchange Online

A cloud-based email and calendaring service that delivers enterprise-grade communication and integrates with Microsoft 365 security features.

93
New cards

Microsoft Office 365 Enterprise E5

A premium Microsoft 365 subscription plan that includes advanced security, compliance, analytics, and telephony features.

94
New cards

Microsoft SharePoint Online

A cloud-based collaboration platform that enables organizations to manage, share, and secure content across teams and departments.

95
New cards

App Protection Policy

Policies applied to mobile applications that protect organizational data by enforcing rules like encryption, access controls, and data sharing restrictions.

96
New cards

Basic Authentication

A legacy authentication method using usernames and passwords in plain text, now deprecated due to weak security and lack of modern controls.

97
New cards

Compliance Policy

A set of rules in Microsoft Endpoint Manager that ensures devices and users meet security requirements before accessing organizational resources.

98
New cards

Administrative Units

A way to delegate administrative tasks by dividing a Microsoft Entra tenant into logical units for scopes of management, limiting role assignments to subsets of users/devices.

99
New cards

Identity Secure Score

A metric feature that gives a score and recommendations for improving your identity security posture in Microsoft Entra.

100
New cards

Smart lockout

Prevents brute-force attacks by automatically locking out malicious sign-in attempts while distinguishing genuine user behavior.