Ovim treningom IT profesionalci, a osobito IT profesionalci koji se bave područjem kibernetičke sigurnosti i identitetom (engl. identity) usvojiti će vještine i znanja potrebne za implementaciju rješenja za upravljanje identitetima temeljenim na Microsoft Azure AD i povezanim tehnologijama.
Ovaj trenining obuhvaća identity sadržaj za Azure AD, registraciju aplikacija, uvjetni pristup, upravljanje identitetom (eng. identity governance) i druge identity alate.
Što ćete naučiti
- Implementirati rješenje za upravljanje identitetom.
- Implementirati rješenja za autentifikaciju i upravljanje pristupom.
- Implementirati upravljanje pristupom za aplikacije.
- Planirati i implementirati strategiju upravljanja identitetom.
Kome je namijenjeno
Identity and access administratorima koji obavljaju zadatke administracije identiteta i pristupa ili koji se tek planiraju specijalizirati za isto. Također trening se preporuča i administratorima ili inženjerima koji se žele specijalizirati u području identity rješenja i kontrole pristupa za rješenja temeljena na Azureu.
Preduvjeti
- Najbolja sigurnosna praksa i sigurnosni zahtjevi industrije kao što su defense in depth, least privileged access, shared responsibility i zero trust model.
- Poznavanje koncepata autetnikacije, autorizacije i Active Directoryja.
- Iskustvo u implementaciji Azure usluga. Ovaj trening ne pokriva osnove Azure administracije, ali nadograđuje znanje osnovne Azure administracije dodajući specifične informacije iz područja sigurnosti.
- Iskustvo s Windows i Linux operativnim sustavima i skriptnim jezicima je korisno, ali ne i nužno. Labovi koji se provode tijekom edukacije mogu koristiti PowerShell i Command-Line Interface (CLI).
- SC-900 part 1: Describe the concepts of security, compliance, and identity
- SC-900 part 2: Describe the capabilities of Microsoft Identity and access management solutions
- SC-900 part 3: Describe the capabilities of Microsoft security solutions
- SC-900 part 4: Describe the capabilities of Microsoft compliance solutions
- AZ-104: Manage identities and governance in Azure
Nastavni plan
Pregledaj
- Module 1: Explore identity in Microsoft Entra ID This module covers definitions and available services for identity provided in Microsoft Entra ID and to Microsoft 365. You will start with authentication, authorization, and access tokens then build into full identity solutions. After completing this module, students will be able to:
- Define common identity terms and explain how they're used in the Microsoft Cloud
- Explore the common management tools and needs of an identity solution
- Review the goal of Zero Trust and how it's applied in the Microsoft Cloud
- Explore the available identity services in the Microsoft Cloud
- Implement initial configuration of Azure Active Directory
- Create, configure, and manage identities
- Implement and manage external identities (excluding B2C scenarios)
- Implement and manage hybrid identity
- Create, configure, and manage users
- Create, configure, and manage groups
- Manage licenses
- Explain custom security attributes and automatic user provisioning
- Manage external collaboration settings in Microsoft Entra ID
- Invite external users (individually or in bulk)
- Manage external user accounts in Microsoft Entra ID
- Configure identity providers (social and SAML/WS-fed)
- Plan, design, and implement Microsoft Entra Connect
- Manage Microsoft Entra Connect
- Manage password hash synchronization (PHS)
- Manage pass-through authentication (PTA)
- Manage seamless single sign-on (seamless SSO)
- Manage federation excluding manual ADFS deployments
- Troubleshoot synchronization errors
- Implement and manage Microsoft Entra Connect Health
- Learn about Microsoft Entra multifactor authentication (Microsoft Entra multifactor authentication)
- Create a plan to deploy Microsoft Entra multifactor authentication
- Turn on Microsoft Entra multifactor authentication for users and specific apps
- Administer authentication methods (FIDO2 / Passwordless)
- Implement an authentication solution based on Windows Hello for Business
- Configure and deploy self-service password reset
- Deploy and manage password protection
- Implement and manage tenant restrictions
- Plan and implement security defaults
- Plan conditional access policies
- Implement conditional access policy controls and assignments (targeting, applications, and conditions)
- Test and troubleshoot conditional access policies
- Implement application controls
- Implement session management
- Configure smart lockout thresholds
- Implement and manage a user risk policy
- Implement and manage sign-in risk policies
- Implement and manage MFA registration policy
- Monitor, investigate, and remediate elevated risky users
- Configure and use Azure roles within Microsoft Entra ID
- Configure and managed identity and assign it to Azure resources
- Analyze the role permissions granted to or inherited by a user
- Configure access to data in Azure Key Vault using RBAC-policy
- Discover apps by using Defender for Cloud Apps or ADFS app report
- Design and implement access management for apps
- Design and implement app management roles
- Configure preintegrated (gallery) SaaS apps
- Implement token customizations
- Implement and configure consent settings
- Integrate on-premises apps by using Microsoft Entra application proxy
- Integrate custom SaaS apps for SSO
- Implement application user provisioning
- Monitor and audit access/Sign-On to Microsoft Entra ID integrated enterprise applications
- Plan your line of business application registration strategy
- Implement application registrations
- Configure application permissions
- Plan and configure multi-tier application permissions
- Define catalogs
- Define access packages
- Plan, implement and manage entitlements
- Implement and manage terms of use
- Manage the lifecycle of external users in Microsoft Entra Identity Governance settings
- Plan for access reviews
- Create access reviews for groups and apps
- Monitor the access review findings
- Manage licenses for access reviews
- Automate management tasks for access review
- Configure recurring access reviews
- Define a privileged access strategy for administrative users (resources, roles, approvals, and thresholds)
- Configure Privileged Identity Management for Microsoft Entra roles
- Configure Privileged Identity Management for Azure resources
- Assign roles
- Manage PIM requests
- Analyze PIM audit history and reports
- Create and manage emergency access accounts
- Analyze and investigate sign in logs to troubleshoot access issues
- Review and monitor Microsoft Entra audit logs
- Enable and integrate Microsoft Entra diagnostic logs with Log Analytics / Azure Sentinel
- Export sign in and audit logs to a third-party SIEM (security information and event management)
- Review Microsoft Entra activity by using Log Analytics / Azure Sentinel, excluding KQL (Kusto Query Language) use
- Analyze Microsoft Entra workbooks / reporting
- Configure notifications
Povezani certifikati
- Certifikacijski ispit: Exam SC-300: Microsoft Identity and Access Administrator
- Certifikat: Microsoft Certified: Identity and Access Administrator Associate