Identity Design
- Conditional access: device compliance + location + risk level = grant/block decisions.
- PIM provides just-in-time privileged access with approval workflows and time limits.
- B2B for partner access (invited guests); B2C for customer-facing identity (branded sign-up).
- Managed identities for service-to-service auth; no credentials in code.
Governance Design
- Management group hierarchy: root → business unit → environment → subscription.
- Azure Policy enforces standards; initiatives group related policies.
- Landing zones provide repeatable, compliant subscription provisioning.
- Cost Management budgets + alerts prevent unexpected spending.
Practice Entra ID & Azure Policy Questions
Put your knowledge to the test with practice questions.