IAM Concepts Covered
- Explore identity in Microsoft Entra ID
- Microsoft Entra ID controls secure access for users, devices, apps, and external users using Zero Trust principles
-
Identity acts as the control plane for authentication, authorization, auditing, and licensing
Customize the sign-in experience and configure tenant settings, including branding and custom domains
-
Manage Microsoft Entra roles and permissions using least-privilege and administrative units for secure delegation
- Manage users, groups, and devices in Microsoft Entra ID
- Assign and control licenses for users and groups
- Use automation and security attributes to simplify identity management
- Enable secure guest access (B2B) for external users in Microsoft Entra ID
- Invite, manage, and control external users across Entra ID and Microsoft 365
- Use identity providers, cross-tenant access, and Verified ID for secure collaboration
- Integrate on-premises Active Directory with Microsoft Entra ID using Entra Connect and authentication methods like PHS, PTA, SSO, and federation
- Monitor, manage, and troubleshoot synchronization and identity health using Entra Connect Health / Entra Health
- Multifactor Authentication (MFA) adds an extra verification step to secure Microsoft Entra user sign-ins
- Plan, enable, and configure MFA methods to protect accounts and reduce unauthorized access
- Implement and manage multiple authentication methods in Microsoft Entra ID, including passwordless (FIDO2, Windows Hello), MFA, and certificates
- Secure user sign-ins with password protection, self-service password reset, and smart lockout
8.Plan, implement, and administer Conditional Access
- Plan and implement Conditional Access policies to control user access based on identity, device, location, and risk
- Use policy controls, session management, and testing to enforce security and continuously evaluate access
- Detect and manage user and sign-in risks using risk policies and enforced MFA
- Monitor, investigate, and remediate risky users and workload identities to protect the environment
- Manage Azure resource access using Azure RBAC, including built-in and custom role assignments
- Secure applications with managed identities and Azure Key Vault RBAC
- Use Microsoft Entra Global Secure Access to apply Zero Trust, making identity the gatekeeper for internet and private app access
- Configure Internet Access, Private Access, Conditional Access, and monitoring to securely connect users to resources
- Integrate and manage enterprise and custom applications in Microsoft Entra ID using SSO, app registration, and app roles
- Secure app access with policies, OAuth permissions, monitoring, and role-based management
Cloud Identity Structure
-
Users (employees, admins)
-
Groups (HR, IT, Finance)
-
Roles (Global Admin, User Admin)
-
-
Identity Architecture Diagram
-
On-prem AD → Entra ID (Hybrid model)
-
-
User & Group Management System
-
Create users automatically
-
Assign groups dynamically
-
-
Role-Based Access Control (RBAC)
-
Admin vs normal user access
-
-
Hybrid Identity Setup
-
Sync on-prem Active Directory with cloud
-
-
Secure Login System
-
Password + MFA
-
OTP / Authenticator app
-
-
Conditional Access Policies
-
Allow login only from India
-
Block risky sign-ins
Implement Access Management for Applications
-
Single Sign-On (SSO) System
-
One login → many apps
-
-
Enterprise App Access Control
-
Who can access:
-
HR app
-
Finance app
-
-
Comments
Post a Comment