Azure Identity, Access and Security
Identity and security questions test Microsoft Entra ID, Entra Domain Services, SSO, MFA, passwordless, external identities, Conditional Access, RBAC, Zero Trust, defense in depth, and Defender for Cloud.
How to study for AZ-900
Treat each AZ-900 item as a cloud fit decision: identify the cloud model, Azure service category, responsibility boundary, governance need, or management tool.
Core concepts
Concept 1
Azure Identity, Access and Security questions reward Azure service selection and responsibility reasoning rather than memorizing portal labels.
Exam cue: Identify whether the item is about cloud concepts, Azure services, or management and governance.
Concept 2
The best answer identifies the cloud model, Azure resource, management boundary, security control, or governance tool that matches the scenario.
Exam cue: Separate Microsoft responsibility from customer configuration and data responsibility.
Concept 3
Eliminate answers that confuse IaaS, PaaS, and SaaS responsibilities or use a monitoring, cost, or governance tool for the wrong job.
Exam cue: Match the Azure tool to the requested outcome: deploy, secure, govern, monitor, or optimize cost.
Risk pitfalls and guardrails
Assuming cloud always removes customer responsibility.
Guardrail: Avoid answers that remove all customer responsibility, use monitoring for pricing estimates, use tags for network security, or confuse Azure Policy with RBAC.
Choosing a named Azure service without checking whether the scenario asks for compute, networking, storage, identity, governance, or monitoring.
Guardrail: Avoid answers that remove all customer responsibility, use monitoring for pricing estimates, use tags for network security, or confuse Azure Policy with RBAC.
Confusing reactive monitoring dashboards with proactive cost alerts or policy enforcement.
Guardrail: Avoid answers that remove all customer responsibility, use monitoring for pricing estimates, use tags for network security, or confuse Azure Policy with RBAC.
Memory anchors
Microsoft Entra ID
Microsoft Entra ID is Azure's cloud identity and access management service.
Entra Domain Services
Microsoft Entra Domain Services provides managed domain services such as domain join and LDAP-compatible access.
SSO
Single sign-on lets users access multiple applications after one authentication event.
MFA
Multifactor authentication requires additional proof beyond a password.
Passwordless
Passwordless authentication reduces reliance on memorized secrets.
External Identity
External identities allow collaboration with users outside the organization.
Conditional Access
Conditional Access applies access decisions based on signals such as user, device, location, risk, and app.
Azure RBAC
Azure role-based access control assigns permissions to Azure resources using roles and scopes.
Zero Trust
Zero Trust assumes no implicit trust and verifies identity, device, and context.
Defender for Cloud
Microsoft Defender for Cloud helps assess and improve cloud security posture.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
What is Microsoft Entra ID?
Which object can authenticate as a person in Microsoft Entra ID?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
