Azure Identity Management Lab AND Quiz - WEEK3
Azure Identity Management Lab AND Quiz - WEEK3
Lab scenario
In order to allow Truevisions users to authenticate by using Azure AD, you have been tasked
with provisioning users and group accounts. Membership of the groups should be updated
automatically based on the user job titles. You also need to create a test Azure AD tenant with a
test user account and grant that account limited permissions to resources in the TrueVisions
Azure subscription.
Objectives
In this lab, you will:
Instructions
Exercise 1
Department IT
Note: Copy to clipboard the full User name. You will need it later in this ta
7. In the list of users, click the newly created user account to display its blade.
8. Review the options available in the Manage section and note that you can identify the Azure
AD roles assigned to the user account as well as the user account's permissions to Azure
resources.
10. Open an InPrivate browser window and sign in to the Azure portal using the newly created
user account. When prompted to update the password, change the password for the user. (Note:
Rather than typing the user name, you can paste the content of Clipboard.)
11. In the InPrivate browser window, in the Azure portal, search for and select Azure Active
Directory. (Note: While this user account can access the Azure Active Directory tenant, it does
not have any access to Azure resources. This is expected, since such access would need to be
granted explicitly by using Azure Role-Based Access Control.)
14. Create a new user with the following settings (leave others with their defaults):
Setting Value
Department IT
15. Sign out as the tstark user from the Azure portal and close the InPrivate browser window.
In this task, you will create Azure Active Directory groups with assigned and dynamic
membership.
1. Back in the Azure portal where you are signed in with your user account, navigate back to the
Overview blade of the Azure AD tenant and, in the Manage section, click Licenses. (Note: Azure
AD Premium P1 or P2 licenses are required in order to implement dynamic groups)
4. Refresh the browser window to verify that the activation was successful.
5. From the Licenses - All products blade, select the Azure Active Directory Premium P2
entry, and assign all license options of Azure AD Premium P2 to your user account and the two
newly created user accounts.
6. In the Azure portal, navigate back to the Azure AD tenant blade and click Groups.
7. Use the + New group button to create a new group with the following settings:
Setting Value
Note: If the Membership type drop-down list is grayed out, refresh the browser page.
Setting Value
Operator Equals
11. Back on the Groups - All groups blade of the Azure AD tenant, click the + New
group button and create a new group with the following settings:
Setting Value
Setting Value
Operator Equals
15. Back on the Groups - All groups blade of the Azure AD tenant, click the + New
group button, and create a new group with the following settings:
Setting Value
17. From the Add members blade, search and select the IT Cloud Administrators and IT
System Administrators groups and, back on the New Group blade, click Create.
18. Back on the Groups - All groups blade, click the entry representing the IT Cloud
Administrators group and, on then display its Members blade. Verify that the tstark appears in
the list of group members.
19. Navigate back to the Groups - All groups blade, click the entry representing the IT System
Administrators group and, on then display its Members blade. Verify that the dbanner appears
in the list of group members. (Note: You might experience delays with updates of the dynamic
membership groups. To expedite the update, navigate to the group blade, display its Dynamic
membership rules blade, Edit the rule listed in the Rule syntax textbox by adding a whitespace at
the end, and Save the change.)
Setting Value
Initial Domain
any valid DNS name consisting of lower case letters and digits and starting with a letter
name
Note: The green check mark in the Initial domain name text box will indicate that the dom
typed in is valid and unique.
4. Display the blade of the newly created Azure AD tenant by using the Click here to navigate
to your new directory: Truevisions Lab link or the Directory + Subscription button (directly to
the right of the Cloud Shell button) in the Azure portal toolbar.
In this task, you will create Azure AD guest users and grant them access to resources in an
Azure subscription.
1. In the Azure portal displaying the Truevisions Lab Azure AD tenant, in the Manage section,
click Users, and then click + New user.
2. Create a new user with the following settings (leave others with their defaults):
Setting Value
Department IT
Note: Copy to clipboard the full User name. You will need it later in this ta
5. Create a new guest user with the following settings (leave others with their defaults):
Setting Value
Name bmarley
Email address paste the value you copied into the Clipboard earlier in this task
Department IT
6. Click Invite.
7. Back on the Users - All users blade, click the entry representing the newly created guest
user account.
9. Click + Add membership and add the guest user account to the IT Lab
Administrators group.
Clean up resources
Note: Remember to remove any newly created Azure resources that you no longer use.
Removing unused resources ensures you will not incur unexpected costs. While, in this case,
there are no additional charges associated with Azure Active Directory tenants and their objects,
you might want to consider removing the user accounts, the group accounts, and the Azure
Active Directory tenant you created in this lab.
1. In the Azure portal, navigate to the Users - All users blade, click the entry representing
the bmarley guest user account, on the bmarley- Profile blade click Delete, and, when
prompted to confirm, click OK.
2. Repeat the same sequence of steps to delete the remaining user accounts you created in this
lab.
3. Navigate to the Groups - All groups blade, select the groups you created in this lab,
click Delete, and, when prompted to confirm, click OK.
4. Navigate to the Azure Active Directory Premium P2 - Licensed users blade, select the user
accounts to which you assigned licenses in this lab, click Remove license, and, when prompted
to confirm, click OK.
5. In the Azure portal, display the blade of the Truevisions Lab Azure AD tenant by using
the Directory + Subscription button (directly to the right of the Cloud Shell button) in the Azure
portal toolbar.
Review
In this lab, you have:
New New user. 6. Create a new user with the following settings (leave others with their defaults):
Azure AD
TOTAL POINTS 5
1.
Question 1
You have an Azure AD tenant named Truevisions and an Azure subscription named SUB1.
Truevisions contains a group named Developers. SUB1 contains a Resource Group named
DEV1.
You need to provide the Developers group with the ability to create Azure Logic Apps in the
DEV1 Resource Group.
Solution: On DEV1, you assign the Logic App Contributor role to the Developers group.
1 / 1 point
Yes
No
Correct
The Logic App Contributor role will give the Developers group the needed permissions to add
Logic Apps to their solutions.
2.
Question 2
You have an Azure subscription named SUB1. SUB1 contains the Resource Groups in the
following table:
RG1 has a Web App named WEBAPP1. WEBAPP1 is located in West Europe.
1 / 1 point
The App Service Plan for WEBAPP1 moves to North Europe, Policy 2 applies to WEBAPP1
The App Service Plan for WEBAPP1 moves to West Europe, Policy 2 applies to WEBAPP1
The App Service Plan for WEBAPP1 moves to North Europe, Policy 1 applies to WEBAPP1
The App Service Plan for WEBAPP1 moves to West Europe, Policy 1 applies to WEBAPP1
Correct
3.
Question 3
You have an Azure subscription that contains an Azure Log Analytics Workspace named
WORKSPACE1.
You need to view the Error events form a table named EVENT.
1 / 1 point
Correct
4.
Question 4
You have an Azure AD tenant named Truevisions and an Azure subscription named SUB1.
Truevisions contains a group named Developers. SUB1 contains a Resource Group named
DEV1.
You need to provide the Developers group with the ability to create Azure Logic Apps in the
DEV1 Resource Group.
Solution: On DEV1, you assign the Contributor Role to the Developers group.
1 / 1 point
Yes
No
Correct
This satisfies the requirements. You need to have the Contributor role permissions to be able to
add the Logic App to the Resource Group.
5.
Question 5
Your company has an existing Azure tenant named truevisions.onmicrosoft.com. The company
wants to start using truevisions.com. You add a custom domain to Azure. What are the other two
things you can do to verify the domain.
0 / 1 point
Add a TXT record to the DNS zone
Correct