dns cloud

Locking Down Identity — Conditional Access and Privileged Access

Identity is the one thing that spans a whole tenant, and most people who administer it have never configured it deliberately. This segment builds the controls, one at a time, in report-only first: a conditional access set enforced without locking anybody out, privileged roles moved from permanent to eligible, two emergency access accounts that have actually been used, and the count of permanently privileged accounts taken from eleven down to two.

  • trending_upIntermediate
  • schedule9h 36m
  • menu_book12개 강의
  • publicEnglish
  • workspace_premiumBasic
Locking Down Identity — Conditional Access and Privileged Access

개요

Everywhere you look in a cloud estate, identity is argued about and never configured. Two other segments in this catalogue own the arguments: one owns the estate you were handed and how to assess it, the other owns the governance case for every control here. This one owns the part nobody teaches hands-on, which is the building. You leave with policies built, not with an opinion. The defining risk of this subject is that a single policy applied without an exclusion locks every administrator out of the tenant, permanently, including the person who wrote it, and the only way back is a vendor support ticket and a wait measured in days. So the risk shapes the order. The lock-out warning comes before the first policy, not as a war story at the end. Every enforcement runs in report-only first, so the mistake happens where it costs nothing. Every policy carries a written line saying what it would break, because a policy nobody can explain gets switched off during the next incident by somebody who does not know what it was for. You start by counting. Five kinds of thing can hold access and most people can name two, and the count of accounts holding a directory role permanently is the number the whole segment reduces. You learn the shape of an assignment — a principal, a role, a scope — because leaving out the scope is what makes a small grant look identical to a catastrophic one. Then you trace a supplier's contractor four transitive hops to a role that administers your users, assembled entirely from four reasonable changes made by competent people. Then conditional access, as six parts and a state, so the interface can change all it likes and the knowledge does not. You read a report-only week and find the administrator with one credential and a fortnight of leave booked, hiding in the result value that reads like a shrug. You close the old protocol that cannot be challenged, where the policy was never bypassed because it was never in the path. Then privileged access, where eligible grants nothing and is merely permission to ask, and you run one elevation from request to expiry and list every record it leaves, including the two events that leave none. You design approval so that it is never the thing that is down at two in the morning. Finally the account you hope never to use, built to eleven properties because each one is a recovery that failed somewhere. You lock a throwaway tenant out on purpose and get back in against a printed page, and you mark up every line of that page that was wrong. And you write the cutover that puts all of it live in an order that works, because four correct policies in the wrong order break a tenant just as thoroughly as one wrong policy does. Every lab is completable on paper. A learner without a tenant is the normal case, and every extract you need is printed inside the pack.

강의 커리큘럼 · 4개 모듈

lock접근 시 이용 가능
  1. 01 디렉토리와 역할 할당이 부여하는 것
    3개 강의·1h 45m

    의견을 형성하기 전에 세어봅시다. 항상 누구도 예상하는 것보다 높은 수는 게스트, 서비스 주체, 그리고 디렉토리 역할을 영구적으로 보유하는 계정이며, 마지막 숫자가 Module 3이 줄이는 것입니다. 세 부분 형태인 주체, 역할, 범위는 전체 세그먼트의 척추입니다. 범위를 빼면 작은 할당이 재앙적인 할당과 동일해 보입니다. 랩은 게스트 계정을 네 단계의…

  2. 02 조건부 액세스, 정책 하나씩
    3개 강의·2h 28m

    잠금에서 열되, 구조에서는 열지 마라. 그다음 6개 부분을 순서대로, 인터페이스가 상관없어질 때까지. 보고서 전용은 5개의 결과값을 생성하고 위험한 것은 어깨를 으쓱하는 것처럼 읽히는 것이다. 전역 관리자를 단일 자격증명과 2주간의 휴가로 숨기기 때문이다. 모듈은 경로에 절대 없는 경로에서 닫힌다. 2차 인증을 제시할 수 없는 레거시 프로토콜, 정책이…

  3. 03 권한 액세스: 승인됨, 활성화 안 됨
    3개 강의·2h 31m

    R3은 권한 액세스 시스템이 무엇인지를 소유하고 B3은 그것이 업무 전개에서 어디에 위치하는지를 소유하며, 이 모듈은 설정 시트와 마이그레이션이다. 두 가지 대신 네 가지 할당 조합, 보안 결정이 아닌 사용성 결정으로서의 활성화 지속 시간, 그리고 여섯 개 옵션의 드롭다운은 아무것도 증명하지 못하므로 자유 텍스트 정당성이다. 그 다음 실제 활성화, 세…

  4. 04 긴급 접근과 모두를 막아낸 정책
    3개 강의·2h 52m

    열 가지 속성, 각각은 누군가의 복구가 실패했기 때문. 두 계정이 아닌 그룹을 제외하면, 내년에 작성된 정책이 습관적으로 그 제외를 상속한다. 보관은 기술적 문제가 아니며, 복구되는 시스템 내에 보유된 복구 자격증명인 순환은 조용한 공통 실패다. 그 다음 실제로 수행된 잠금, 인쇄된 절차를 다른 사람이 들고 강사가 침묵 속에서 지켜보는 것인데, 이것이…

자주 묻는 질문

Locking Down Identity — Conditional Access and Privileged Access에서 무엇을 배우나요?
Identity is the one thing that spans a whole tenant, and most people who administer it have never configured it deliberately. This segment builds the controls, one at a time, in report-only first: a conditional access set enforced without locking anybody out, privileged roles moved from permanent to
사전 경험이 필요한가요?
Locking Down Identity — Conditional Access and Privileged Access을 시작하기 전에 기초 지식이 있으면 좋아요.
Locking Down Identity — Conditional Access and Privileged Access은 얼마나 걸리나요?
Locking Down Identity — Conditional Access and Privileged Access은 4개 모듈과 12개 강의로 구성되어 있고, 자신의 속도로 학습할 수 있어요.
어떻게 접근하나요?
Locking Down Identity — Conditional Access and Privileged Access은 모든 유료 구독에 포함되어 있어요.

컴퓨터 과학의 다른 강의