Master identity and access management with Azure Active Directory, Role-Based Access Control, authentication methods, and security features essential for cloud governance.
After completing this session, you'll be ready for Quiz 17 and able to:
Azure Active Directory is Microsoft's cloud-based identity and access management service. Think of it as the central security guard for your organization - it controls who can access what resources and under what conditions.
Employee badges control access to different floors and rooms
Digital identities control access to cloud resources and applications
Right person, right access, right time - whether physical or digital!
Up to 500,000 objects, basic reports, SSO
99.9% SLA, group-based access, branding
Conditional access, MFA, advanced security
Identity Protection, PIM, risk-based policies
Free: 500,000 objects, Premium: Unlimited
Conditional Access needs Premium P1+
Risk-based access requires Premium P2
Know which features need which edition!
One organization can have many Azure subscriptions
A user can be member of up to 500 tenants
Subscriptions trust the Azure AD tenant for authentication
RBAC is like assigning job roles in a company - each role has specific permissions. A security guard can't access the CEO's office, just like a Reader role can't modify Azure resources.
User, Group, Service Principal, or Managed Identity
Collection of permissions (Owner, Contributor, Reader)
Where the permissions apply (Resource, RG, Subscription)
Linking Principal + Role + Scope together
Built-in roles are too broad or narrow
Need precise control for audit purposes
Permissions for specific Azure services
5,000 per Azure AD tenant
4,000 per subscription maximum
Quiz Tip: Know the difference between Azure AD roles (manage Azure AD) and Azure RBAC roles (manage Azure resources)!
Password, PIN, Security Questions
Phone, Hardware Token, Authenticator App
Fingerprint, Face Recognition, Voice
MFA Security: Using at least 2 of these 3 factors significantly improves security!
Less secure, vulnerable to SIM swapping
Microsoft Authenticator recommended for TOTP
High security for device-based authentication
Biometric or PIN-based, device-bound
Hardware-based, phishing-resistant
Microsoft Authenticator push notifications
IF user is from untrusted location AND accessing sensitive app THEN require MFA + compliant device
Let's create users, groups, and configure RBAC assignments to understand Azure AD identity management practically. This lab prepares you for Quiz 17's real-world scenarios.
Understand your tenant structure and current configuration
Set up test users and groups for RBAC practice
Practice role assignments at different scopes
Verify that roles work as expected
Remove test users to avoid confusion
Here are example questions similar to what you'll see in Quiz 17. Master these Azure AD and RBAC concepts!
"Which RBAC role allows full access to all resources and can manage access?"
"What is the maximum number of objects in Azure AD Free?"
📝 Quiz 17 Topics: Azure AD editions, RBAC roles, authentication methods, MFA, conditional access, PIM, B2B, groups, tenants
Take Quiz 17 NowYou now understand how to manage identities, control access with RBAC roles, configure authentication methods, and implement advanced security features in Azure Active Directory. You're ready to secure any Azure environment!
Excellent! You've mastered Azure Active Directory and Role-Based Access Control concepts. Now test your knowledge with Quiz 17, which covers all the identity and access management topics from this session.