dns cloud

Locking Down Identity — Conditional Access and Privileged Access

Identity is the one thing that spans a whole tenant, and most people who administer it have never configured it deliberately. This segment builds the controls, one at a time, in report-only first: a conditional access set enforced without locking anybody out, privileged roles moved from permanent to eligible, two emergency access accounts that have actually been used, and the count of permanently privileged accounts taken from eleven down to two.

  • trending_upIntermediate
  • schedule9h 36m
  • menu_book12 уроков
  • publicEnglish
  • workspace_premiumBasic

Брифинг

Everywhere you look in a cloud estate, identity is argued about and never configured. Two other segments in this catalogue own the arguments: one owns the estate you were handed and how to assess it, the other owns the governance case for every control here. This one owns the part nobody teaches hands-on, which is the building. You leave with policies built, not with an opinion. The defining risk of this subject is that a single policy applied without an exclusion locks every administrator out of the tenant, permanently, including the person who wrote it, and the only way back is a vendor support ticket and a wait measured in days. So the risk shapes the order. The lock-out warning comes before the first policy, not as a war story at the end. Every enforcement runs in report-only first, so the mistake happens where it costs nothing. Every policy carries a written line saying what it would break, because a policy nobody can explain gets switched off during the next incident by somebody who does not know what it was for. You start by counting. Five kinds of thing can hold access and most people can name two, and the count of accounts holding a directory role permanently is the number the whole segment reduces. You learn the shape of an assignment — a principal, a role, a scope — because leaving out the scope is what makes a small grant look identical to a catastrophic one. Then you trace a supplier's contractor four transitive hops to a role that administers your users, assembled entirely from four reasonable changes made by competent people. Then conditional access, as six parts and a state, so the interface can change all it likes and the knowledge does not. You read a report-only week and find the administrator with one credential and a fortnight of leave booked, hiding in the result value that reads like a shrug. You close the old protocol that cannot be challenged, where the policy was never bypassed because it was never in the path. Then privileged access, where eligible grants nothing and is merely permission to ask, and you run one elevation from request to expiry and list every record it leaves, including the two events that leave none. You design approval so that it is never the thing that is down at two in the morning. Finally the account you hope never to use, built to eleven properties because each one is a recovery that failed somewhere. You lock a throwaway tenant out on purpose and get back in against a printed page, and you mark up every line of that page that was wrong. And you write the cutover that puts all of it live in an order that works, because four correct policies in the wrong order break a tenant just as thoroughly as one wrong policy does. Every lab is completable on paper. A learner without a tenant is the normal case, and every extract you need is printed inside the pack.

План курса · 4 модулей

lockОткрывается с доступом
  1. 01 The Directory, and What a Role Assignment Grants
    3 уроков·1h 45m

    Count before you form an opinion. The counts that are always higher than anybody expects are guests, service principals, and accounts holding a directory role permanently, and that last number is…

  2. 02 Conditional Access, One Policy at a Time
    3 уроков·2h 28m

    Open on the lock-out, not on the anatomy. Then the six parts, in order, so the interface stops mattering. Report-only produces five result values and the dangerous one is the one that reads like a…

  3. 03 Privileged Access: Eligible, Not Active
    3 уроков·2h 31m

    R3 owns what a privileged access system is for and B3 owns where it sits in an engagement, and this module is the settings sheet and the migration. Four assignment combinations rather than two,…

  4. 04 Break Glass, and the Policy That Locked Everybody Out
    3 уроков·2h 52m

    Eleven properties, each one because somebody's recovery failed on it. Exclude a group rather than two accounts, so a policy written next year inherits the exclusion by habit. Custody is not a…

Часто спрашивают

Что я изучу в «Locking Down Identity — Conditional Access and Privileged Access»?
Identity is the one thing that spans a whole tenant, and most people who administer it have never configured it deliberately. This segment builds the controls, one at a time, in report-only first: a conditional access set enforced without locking anybody out, privileged roles moved from permanent to
Нужен ли мне предыдущий опыт?
Перед началом «Locking Down Identity — Conditional Access and Privileged Access» рекомендуются некоторые предыдущие знания.
Сколько времени занимает «Locking Down Identity — Conditional Access and Privileged Access»?
«Locking Down Identity — Conditional Access and Privileged Access» включает 4 модулей и 12 уроков. Вы учитесь в своём темпе.
Как мне получить доступ?
«Locking Down Identity — Conditional Access and Privileged Access» входит в любую платную подписку.

Ещё в Информатика