Design Identity and Security Solutions Flashcards
Microsoft Azure Solutions Architect Expert AZ-305 Flashcards

| Front | Back |
| Define Application Proxy in Azure AD | Application Proxy lets you securely access on-premises apps remotely. |
| Define Azure AD Authentication Methods | These are methods like passwords, biometrics, and security keys used to verify user identity. |
| Define External Identity in Azure AD | External Identity handles authentication for users from outside the organization, like customers or collaborators. |
| Define Passwordless Authentication in Azure AD | Passwordless Authentication enables secure access using biometrics or temporary codes instead of passwords. |
| Define Role-Based Access Control (RBAC) | RBAC manages access to resources based on user roles in Azure. |
| Define Single Sign-On (SSO) in Azure AD | SSO allows users to access multiple applications with one set of credentials. |
| Explain Authentication Context in Conditional Access | Authentication Context adds extra layers of identity verification based on specific conditions. |
| Explain the concept of Conditional Access | Conditional Access uses signals to determine access to apps and data. |
| Explain the concept of Identity Lifecycle Management in Azure | This manages user identity access from creation to deletion throughout their lifecycle. |
| Explain the concept of Self-Service Password Reset (SSPR) | SSPR allows users to reset their own passwords securely. |
| Explain User Risk Detection in Azure AD Identity Protection | User Risk Detection identifies suspicious activities tied to user identities. |
| How does Just-In-Time (JIT) access improve security | JIT access grants temporary access to sensitive resources. |
| How does Managed Identity work in Azure | Managed Identities allow applications to authenticate without credentials. |
| What are Azure AD Connect Health features | This tool helps monitor the health of on-premises identity sync with Azure AD. |
| What are Conditional Access Policies | These policies define controls based on user identity, location, and device state. |
| What are Security Defaults in Azure AD used for | Security Defaults help ensure basic security configurations in place for most users. |
| What does Access Reviews help achieve | Access Reviews help ensure appropriate access and compliance with policies. |
| What does Multi-Factor Authentication (MFA) add to security | MFA enhances security by requiring a second form of verification. |
| What is Azure Active Directory | Azure AD is Microsoft's cloud-based identity and access management service. |
| What is Azure AD Connect | Azure AD Connect synchronizes on-premises identity systems with Azure AD. |
| What is B2B Collaboration in Azure AD | B2B Collaboration enables external partners to securely access resources using their own credentials. |
| What is Device Risk Detection in Azure AD Identity Protection | Device Risk Detection identifies risks based on device activity and configuration. |
| What is Directory Federation Service (ADFS) | ADFS enables single sign-on using on-premises authentication. |
| What is Dynamic Membership in Azure AD Groups | Dynamic Membership automatically assigns users to groups based on conditions or attributes. |
| What is Identity and Access Review with Azure Monitor Logs | This involves analyzing access management logs for ensuring compliance and tracking anomalies. |
| What is Identity Protection in Azure AD | Identity Protection uses machine learning to manage and respond to identity risks. |
| What is Privileged Identity Management (PIM) in Azure | PIM manages and monitors access to critical roles and resources. |
| What is the Azure AD Access Package | Access Packages offer curated access to resources and groups for streamlined requests. |
| What is the Azure Identity Secure Score | This score provides recommendations to enhance identity security posture in Azure AD. |
| What is the difference between Licensed Users and Guest Users in Azure AD | Licensed Users have subscription-based access to services, Guest Users have restricted access as external affiliates. |
| What is the difference between Managed Identity and Service Principal | Managed Identity is managed by Azure and tethered to resources, Service Principal is manually created for app access. |
| What is the function of a Conditional Access Template | Templates provide predefined policies for common Conditional Access scenarios. |
| What is the purpose of Entitlement Management in Azure AD | Entitlement Management automates access to resources based on workflows and policies. |
| What is the purpose of Identity Governance in Azure AD | Identity Governance manages user access and lifecycle processes. |
| What is the purpose of Service Principals in Azure | Service Principals enable secure app authentication to access Azure resources. |
About the Flashcards
Flashcards for the Microsoft Azure Solutions Architect Expert exam help students review core Azure identity and access concepts, covering Azure Active Directory, authentication methods, and secure access controls. The deck reinforces terminology like SSO, MFA, passwordless authentication, service principals, and managed identities while explaining features such as Azure AD Connect, Application Proxy, and ADFS.
Use these cards to drill Conditional Access policies and templates, Identity Protection, Identity Governance, RBAC, PIM, Just-in-Time access, access reviews, entitlement management, and identity lifecycle management. Ideal for quick recall of definitions, typical workflows, and exam-style phrasing of key ideas tested on the exam.
Topics covered in this flashcard deck:
- Azure Active Directory
- Authentication methods
- Conditional Access policies
- Identity governance and protection
- Privileged access and RBAC
- Azure AD Connect and ADFS