Naslovnica

SC-300: Microsoft Identity and Access Administrator

Ovim treningom IT profesionalci, a osobito IT profesionalci koji se bave područjem kibernetičke sigurnosti i identitetom (engl. identity) usvojiti će vještine i znanja potrebne za implementaciju rješenja za upravljanje identitetima temeljenim na Microsoft Azure AD i povezanim tehnologijama.

Ovaj trenining obuhvaća identity sadržaj za Azure AD, registraciju aplikacija, uvjetni pristup, upravljanje identitetom (eng. identity governance) i druge identity alate.

Što ćete naučiti

  • Implementirati rješenje za upravljanje identitetom.
  • Implementirati rješenja za autentifikaciju i upravljanje pristupom.
  • Implementirati upravljanje pristupom za aplikacije.
  • Planirati i implementirati strategiju upravljanja identitetom.

Kome je namijenjeno

Identity and access administratorima koji obavljaju zadatke administracije identiteta i pristupa ili koji se tek planiraju specijalizirati za isto. Također trening se preporuča i administratorima ili inženjerima koji se žele specijalizirati u području identity rješenja i kontrole pristupa za rješenja temeljena na Azureu.

Preduvjeti

  • Najbolja sigurnosna praksa i sigurnosni zahtjevi industrije kao što su defense in depth, least privileged access, shared responsibility i zero trust model.
  • Poznavanje koncepata autetnikacije, autorizacije i Active Directoryja.
  • Iskustvo u implementaciji Azure usluga. Ovaj trening ne pokriva osnove Azure administracije, ali nadograđuje znanje osnovne Azure administracije dodajući specifične informacije iz područja sigurnosti.
  • Iskustvo s Windows i Linux operativnim sustavima i skriptnim jezicima je korisno, ali ne i nužno. Labovi koji se provode tijekom edukacije mogu koristiti PowerShell i Command-Line Interface (CLI).
Polaznicima treninga SC-300, u cilju usvajanja potrebnog predznanja, predlažemo besplatno pohađanje edukacije na našem LMS sustavu kako slijedi:
  • SC-900 part 1: Describe the concepts of security, compliance, and identity
  • SC-900 part 2: Describe the capabilities of Microsoft Identity and access management solutions
  • SC-900 part 3: Describe the capabilities of Microsoft security solutions
  • SC-900 part 4: Describe the capabilities of Microsoft compliance solutions
  • AZ-104: Manage identities and governance in Azure

Nastavni plan

Pregledaj
Module 1: Explore identity in Microsoft Entra ID This module covers definitions and available services for identity provided in Microsoft Entra ID and to Microsoft 365. You will start with authentication, authorization, and access tokens then build into full identity solutions. After completing this module, students will be able to:
  • Define common identity terms and explain how they're used in the Microsoft Cloud
  • Explore the common management tools and needs of an identity solution
  • Review the goal of Zero Trust and how it's applied in the Microsoft Cloud
  • Explore the available identity services in the Microsoft Cloud
Module 2: Implement initial configuration of Microsoft Entra ID Learn to create an initial Azure Active Directory configuration to ensure all the identity solutions available in Azure are ready to use. This module explores how to build and configure an Azure AD system. After completing this module, students will be able to:
  • Implement initial configuration of Azure Active Directory
  • Create, configure, and manage identities
  • Implement and manage external identities (excluding B2C scenarios)
  • Implement and manage hybrid identity
Module 3: Create, configure, and manage identities Access to cloud-based workloads needs to be controlled centrally by providing a definitive identity for each user and resource. You can ensure employees and vendors have just-enough access to do their job. After completing this module, students will be able to:
  • Create, configure, and manage users
  • Create, configure, and manage groups
  • Manage licenses
  • Explain custom security attributes and automatic user provisioning
Module 4: Implement and manage external identities Inviting external users to use company Azure resources is a great benefit, but you want to do it in a secure way. Explore how to enable secure external collaboration. After completing this module, students will be able to:
  • Manage external collaboration settings in Microsoft Entra ID
  • Invite external users (individually or in bulk)
  • Manage external user accounts in Microsoft Entra ID
  • Configure identity providers (social and SAML/WS-fed)
Module 5: Implement and manage hybrid identity Creating a hybrid-identity solution to use your on-premises active directory can be challenging. Explore how to implement a secure hybrid-identity solution. After completing this module, students will be able to:
  • Plan, design, and implement Microsoft Entra Connect
  • Manage Microsoft Entra Connect
  • Manage password hash synchronization (PHS)
  • Manage pass-through authentication (PTA)
  • Manage seamless single sign-on (seamless SSO)
  • Manage federation excluding manual ADFS deployments
  • Troubleshoot synchronization errors
  • Implement and manage Microsoft Entra Connect Health
Module 6: Secure Microsoft Entra users with multifactor authentication Learn how to use multifactor authentication with Microsoft Entra ID to harden your user accounts. After completing this module, students will be able to:
  • Learn about Microsoft Entra multifactor authentication (Microsoft Entra multifactor authentication)
  • Create a plan to deploy Microsoft Entra multifactor authentication
  • Turn on Microsoft Entra multifactor authentication for users and specific apps
Module 7: Manage user authentication There are multiple options for authentication in Microsoft Entra ID. Learn how to implement and manage the right authentications for users based on business needs. After completing this module, students will be able to:
  • Administer authentication methods (FIDO2 / Passwordless)
  • Implement an authentication solution based on Windows Hello for Business
  • Configure and deploy self-service password reset
  • Deploy and manage password protection
  • Implement and manage tenant restrictions
Module 8: Plan, implement, and administer Conditional Access Conditional Access gives a fine granularity of control over which users can do specific activities, access which resources, and how to ensure data and systems are safe. After completing this module, students will be able to:
  • Plan and implement security defaults
  • Plan conditional access policies
  • Implement conditional access policy controls and assignments (targeting, applications, and conditions)
  • Test and troubleshoot conditional access policies
  • Implement application controls
  • Implement session management
  • Configure smart lockout thresholds
Module 9: Manage Microsoft Entra Identity Protection Protecting a user's identity by monitoring their usage and sign-in patterns ensure a secure cloud solution. Explore how to design and implement Microsoft Entra Identity protection. After completing this module, students will be able to:
  • Implement and manage a user risk policy
  • Implement and manage sign-in risk policies
  • Implement and manage MFA registration policy
  • Monitor, investigate, and remediate elevated risky users
Module 10: Implement access management for Azure resources Explore how to use built-in Azure roles, managed identities, and RBAC-policy to control access to Azure resources. Identity is the key to secure solutions. After completing this module, students will be able to:
  • Configure and use Azure roles within Microsoft Entra ID
  • Configure and managed identity and assign it to Azure resources
  • Analyze the role permissions granted to or inherited by a user
  • Configure access to data in Azure Key Vault using RBAC-policy
Module 11: Plan and design the integration of enterprise apps for SSO Enterprise app deployment enables control over which users can access the apps, easily log into apps with single-sign-on, and provide integrated usage reports. After completing this module, students will be able to:
  • Discover apps by using Defender for Cloud Apps or ADFS app report
  • Design and implement access management for apps
  • Design and implement app management roles
  • Configure preintegrated (gallery) SaaS apps
Module 12: Implement and monitor the integration of enterprise apps for SSO Deploying and monitoring enterprise applications to Azure solutions can ensure security. Explore how to deploy on-premises and cloud based apps to users. After completing this module, students will be able to:
  • Implement token customizations
  • Implement and configure consent settings
  • Integrate on-premises apps by using Microsoft Entra application proxy
  • Integrate custom SaaS apps for SSO
  • Implement application user provisioning
  • Monitor and audit access/Sign-On to Microsoft Entra ID integrated enterprise applications
Module 13: Implement app registration Line of business developed in-house need registration in Microsoft Entra ID and assigned to users for a secure Azure solution. Explore how to implement app registration. After completing this module, students will be able to:
  • Plan your line of business application registration strategy
  • Implement application registrations
  • Configure application permissions
  • Plan and configure multi-tier application permissions
Module 14: Plan and implement entitlement management When new users or external users join your site, quickly assigning them access to Azure solutions is a must. Explore how to entitle users to access your site and resources. After completing this module, students will be able to:
  • Define catalogs
  • Define access packages
  • Plan, implement and manage entitlements
  • Implement and manage terms of use
  • Manage the lifecycle of external users in Microsoft Entra Identity Governance settings
Module 15: Plan, implement, and manage access review Once identity is deployed, proper governance using access reviews is necessary for a secure solution. Explore how to plan for and implement access reviews. After completing this module, students will be able to:
  • Plan for access reviews
  • Create access reviews for groups and apps
  • Monitor the access review findings
  • Manage licenses for access reviews
  • Automate management tasks for access review
  • Configure recurring access reviews
Module 16: Plan and implement privileged access Ensuring that administrative roles are protected and managed to increase your Azure solution security is a must. Explore how to use PIM to protect your data and resources. After completing this module, students will be able to:
  • Define a privileged access strategy for administrative users (resources, roles, approvals, and thresholds)
  • Configure Privileged Identity Management for Microsoft Entra roles
  • Configure Privileged Identity Management for Azure resources
  • Assign roles
  • Manage PIM requests
  • Analyze PIM audit history and reports
  • Create and manage emergency access accounts
Module 17: Monitor and maintain Microsoft Entra ID Audit and diagnostic logs within Microsoft Entra ID provide a rich view into how users are accessing your Azure solution. Learn to monitor, troubleshoot, and analyze sign-in data. After completing this module, students will be able to:
  • Analyze and investigate sign in logs to troubleshoot access issues
  • Review and monitor Microsoft Entra audit logs
  • Enable and integrate Microsoft Entra diagnostic logs with Log Analytics / Azure Sentinel
  • Export sign in and audit logs to a third-party SIEM (security information and event management)
  • Review Microsoft Entra activity by using Log Analytics / Azure Sentinel, excluding KQL (Kusto Query Language) use
  • Analyze Microsoft Entra workbooks / reporting
  • Configure notifications

Povezani certifikati

  • Certifikacijski ispit: Exam SC-300: Microsoft Identity and Access Administrator  
  • Certifikat: Microsoft Certified: Identity and Access Administrator Associate