-
Book Overview & Buying
-
Table Of Contents
Exam Ref AZ-104 Microsoft Azure Administrator Certification and Beyond - Second Edition
By :
Azure AD offers a directory and identity management solution within the cloud. It offers traditional username and password identity management, alongside roles and permissions management. On top of that, it offers more enterprise-grade solutions, such as Multi-Factor Authentication (MFA) and application monitoring, solution monitoring, and alerting.
Azure AD can easily be integrated with your on-premises Active Directory to create a hybrid infrastructure.
Azure AD offers the following pricing plans:
Note
For a detailed overview of the different Azure AD licenses and all the features that are offered in each plan, you can refer to https://www.microsoft.com/nl-nl/security/business/identity-access-management/azure-ad-pricing?rtc=1&market=nl.
We will begin by creating a couple of users in our Azure AD tenant from the Azure portal. To do this, perform the following steps:
Figure 1.1 – The Azure AD Users blade
PacktUser1.Packt, and in the Last name section, I have added User1. Therefore, the User name value, in my case, will be [email protected]:
Figure 1.2 – The Azure AD user creation page part 1
Azure administratorITPackt1
Figure 1.3 – The Azure AD user creation page part 2
Now that we have created users in our Azure AD tenant, we can add them to a group in Azure AD.
There are two main group types, as follows:
Security groups are used as container units to group users or devices together. There are three main membership types for security groups:
To create and manage groups from the Azure AD tenant in the Azure portal, you have to perform the following steps:
Figure 1.4 – The Azure AD group creation page part 1
Azure AdminsDynamic group for all Azure Admins
Figure 1.5 – The Azure AD group creation page part 2
For the Dynamic Query rule, the property is jobTitle, the operator is Equals, and the value is Azure administrator, as shown in the following screenshot:
Figure 1.6 – The Azure AD group dynamic query
Tip
Remember that when using dynamic groups, a Premium P1 license needs to be assigned to the user.
Now that we have created the group, replication takes around 5 minutes. Refresh the Azure web page, and the users will appear as members of the Azure admins group that we just created:
Figure 1.7 – The Azure AD group's dynamic group users added automatically based on the membership rules
In this section, we took a look at Azure AD users and groups and created a few accounts. We also created a dynamic membership group to include users via dynamic membership rules.
We encourage students to read up further by using the following links, which are based on Azure AD fundamentals such as adding users in Azure AD, assigning RBAC roles, creating Azure AD groups, and also creating dynamic groups in Azure AD:
Next, we are going to look at Azure AUs, specifically where they can be used and how to create an AU.
Change the font size
Change margin width
Change background colour