Topic module

Azure Identity, Access and Security

Identity and security questions test Microsoft Entra ID, Entra Domain Services, SSO, MFA, passwordless, external identities, Conditional Access, RBAC, Zero Trust, defense in depth, and Defender for Cloud.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for AZ-900

Treat each AZ-900 item as a cloud fit decision: identify the cloud model, Azure service category, responsibility boundary, governance need, or management tool.

Core concepts

Concept 1

Azure Identity, Access and Security questions reward Azure service selection and responsibility reasoning rather than memorizing portal labels.

Exam cue: Identify whether the item is about cloud concepts, Azure services, or management and governance.

Concept 2

The best answer identifies the cloud model, Azure resource, management boundary, security control, or governance tool that matches the scenario.

Exam cue: Separate Microsoft responsibility from customer configuration and data responsibility.

Concept 3

Eliminate answers that confuse IaaS, PaaS, and SaaS responsibilities or use a monitoring, cost, or governance tool for the wrong job.

Exam cue: Match the Azure tool to the requested outcome: deploy, secure, govern, monitor, or optimize cost.

Risk pitfalls and guardrails

Assuming cloud always removes customer responsibility.

Guardrail: Avoid answers that remove all customer responsibility, use monitoring for pricing estimates, use tags for network security, or confuse Azure Policy with RBAC.

Choosing a named Azure service without checking whether the scenario asks for compute, networking, storage, identity, governance, or monitoring.

Guardrail: Avoid answers that remove all customer responsibility, use monitoring for pricing estimates, use tags for network security, or confuse Azure Policy with RBAC.

Confusing reactive monitoring dashboards with proactive cost alerts or policy enforcement.

Guardrail: Avoid answers that remove all customer responsibility, use monitoring for pricing estimates, use tags for network security, or confuse Azure Policy with RBAC.

Memory anchors

Microsoft Entra ID

Microsoft Entra ID is Azure's cloud identity and access management service.

Entra Domain Services

Microsoft Entra Domain Services provides managed domain services such as domain join and LDAP-compatible access.

SSO

Single sign-on lets users access multiple applications after one authentication event.

MFA

Multifactor authentication requires additional proof beyond a password.

Passwordless

Passwordless authentication reduces reliance on memorized secrets.

External Identity

External identities allow collaboration with users outside the organization.

Conditional Access

Conditional Access applies access decisions based on signals such as user, device, location, risk, and app.

Azure RBAC

Azure role-based access control assigns permissions to Azure resources using roles and scopes.

Zero Trust

Zero Trust assumes no implicit trust and verifies identity, device, and context.

Defender for Cloud

Microsoft Defender for Cloud helps assess and improve cloud security posture.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

What is Microsoft Entra ID?

Which object can authenticate as a person in Microsoft Entra ID?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.