🃏 Identity & Governance Flashcards

Review architecture decisions for identity and governance in AZ-305.

Card 1 of 5

Question

When should you use Conditional Access vs. MFA?

Click to reveal answer

Answer

Conditional Access provides context-aware policies (location, device, risk). MFA is one of the grant controls within conditional access. Always prefer conditional access for flexibility.

Click to flip back

All Identity & Governance Flashcards

1

Q: When should you use Conditional Access vs. MFA?

A: Conditional Access provides context-aware policies (location, device, risk). MFA is one of the grant controls within conditional access. Always prefer conditional access for flexibility.

2

Q: What is the difference between Azure Policy and RBAC?

A: Azure Policy enforces what properties resources can have (compliance). RBAC controls who can perform actions on resources (access).

3

Q: When should you use PIM?

A: Privileged Identity Management provides just-in-time access for admin roles, reducing standing privileges. Use when you need approval workflows, time-limited access, or audit trails for elevated permissions.

4

Q: How do management groups help governance?

A: They create a hierarchy above subscriptions for applying policies and RBAC at scale. Up to 6 levels deep. Policies inherit downward.

5

Q: What is a landing zone?

A: A pre-configured, compliant subscription environment with networking, identity, governance, and security already set up. Part of Cloud Adoption Framework.

More AZ-305 Flashcard Decks