Time
8 hours 33 minutes
Difficulty
Intermediate
CEU/CPE
9

Video Transcription

00:00
Hello, Siberians. Welcome to this demonstration video titled As Your Heady Identity Management.
00:07
This lesson is part of the second model off the Is that 500 Microsoft Azure Security technologies costs
00:14
quick information on the tasks that are between you in this demonstration.
00:19
How stuck out by showing you out review. You are Joe Haiti addition on the features that your license to use.
00:26
How don't show you how to create as your Haiti users and groups is in different metals.
00:31
How created Dynamic User group with dynamic membership throat.
00:36
How Assigning user 20 Jahidi Administrative Oh,
00:41
how a sign as your resource roles to users and groups
00:45
how. Then conclude by creating an application registration,
00:49
assigning delegated permissions to heats
00:52
on, granting administrative consent for the permission.
00:56
Let's get into these.
00:57
The 1st 1 out, though, is I assure you out review You enjoyed the addition on the features that you're licensed years.
01:03
Our host show you out upgrade from a free addition to try out for me MP to addition.
01:11
Here I am in the azure Pato.
01:12
If I click on the left hand side over here, if I click on Azure Active directory,
01:19
I can see Madge or 80 addition displayed over here, so you can see I'm currently using Azure 80 Premium Peter.
01:26
However, if I want to review the information, even Father, I can click on licenses under left inside, and I can click on life since features
01:36
to review information off the features of them. License two years.
01:41
So here you can see how the different features on I can see if I'm licensed to use them.
01:47
If I wanted to sign up for your free trial off a premium pizza addition, I can click on the all products on. I can click on Try for Slash by,
01:57
and I can sign up for a free trial for it as a Haiti Premium P two or the Enterprise Mobility Sweets. If I so either off. This would give us as a Haiti premium Peter
02:07
in the nest. Ask how be showing you how to create users and groups using different methods?
02:14
Yes, official representation off. What are we, Dean Fast. Our creates three new users. She's in the azure Pato as your cli on azure. Partial.
02:24
How don't create in new assigned group called Cloud Architect on our heart to uses into the grip on back in the azure Pato
02:34
If I click on my azure A d tenants name on the left hand side over here I can go on the uses and I can click on New user Had a top here.
02:45
How fitting the information for my user
02:52
for the password. Our leave their sets toe auto generates I can click on Show the password and making not off this password
03:00
for now. How lived the groups and those
03:04
for the usage location Our type United Kingdom
03:09
How freedom the job information for this user
03:16
How? Click on create
03:19
So this creates a user called Bring the tower in the azure He d tenants,
03:23
Thanks for now show you outer creates to audit Jesus using azure cli on as your partial.
03:30
To do that out, click on cloud shell in the top right corner over here
03:37
If you're prompted to create a new storage account, if this is your first time off using cloud shower, just go ahead and click OK to that.
03:45
So right now I'm in the azure cloud shell on our pasting the commands to create a new user.
03:51
So he has the command to create a new user
03:53
that is e a d user creates, I specified, displaying him for the user. The password.
04:00
The use of principle Name on if I want to force the user to change the password on next login and also the male nickname
04:10
for Glide and first entered that
04:14
that creates two user
04:15
next one without the assure you out to create a user using as your partial. So switched this from cash to partial and I'll click on confirm
04:25
in the azure. Partial up from the 1st 1 I'll Do is I'll connects to Azure Haiti.
04:30
Now go ahead and specify the password profile that I'll be using for this user.
04:35
So here I'm creating a new object with the type of myself that opened that azure Haiti that model, that password profile
04:44
and one hour days. I'll specify the password within the profile.
04:49
The final friend out there here is how used the new Azure 80. Use a command. Let two creates the new user
04:59
so here specifying the new as your 80 user,
05:02
the display name of these er the password profile the user principal name. If the account is enabled
05:11
or not.
05:12
The mill nickname on the usage location for the user
05:15
for great and press enter to, That's
05:18
that's creates two new either. So what I'll do is I'll go ahead and closed the cloud shell.
05:24
If I refresh the screen,
05:27
I can see that M A crime has been created, and within a few seconds, I expect to see
05:32
John Lake sites account also showing here on the screen. So here we go Johnson County, Shane up. Now,
05:41
if I go back to Super Clouds, the next one I'll do is I'll create a new group. On fact, click on new group.
05:46
Name of the group will be called Cloud Architect. How gave it a description Off Cloud Architect It's
05:54
and for membership type, I'll specify Assigned for now for the members, I can click on members to select two new members for type in Grender
06:05
and Emmy
06:12
on directly Consul ECT. On. If I click on Create Stock, who hits the new group with you to new members in the next task, I'll show you how to create a dynamic user group in Nigeria. Haiti. Yes, a visual representation off what I'll be showing you
06:27
how create a group called London uses
06:30
with a dynamic membership through that automatically had any user who has a stay attribute that contains London. I'm back in the azure Pato. If I go back to groups,
06:42
I can click on new group and then I can give the group and name off London users
06:46
for the membership type out changed it from a scientist Dynamic Easa.
06:51
You can see that I can either have a dynamic is our dynamic device Group by cannot have a single dynamic group that contains uses and devices.
07:00
I'll click on the hard dynamic Web It so hard a query
07:03
and I'll specify
07:05
where the city attributes off. The user
07:09
contains
07:11
the value
07:13
off London,
07:15
and you can see what the votes in tax looks like.
07:18
So one of the things to mention is that you have different operators here, where contentious means that the strength of them specifying must exist. I can also use something like match to specify wildcat way. It's gonna match a particular pattern that I'm specifying If I click, save and that
07:38
and if I click creates
07:41
one, that means peace. Any time I created new User
07:44
and I specify their city attributes to be London, other contents. London They will be automatically a hard day's to this group
07:51
on if I removed that property or that attribute from the user and user removed from this group
08:00
in the next task. How assuring you out to assign on Azure 80 administrative role to a user.
08:07
Now notice that I did know include groups because unfortunately, Onley users can be assigned to an azure 80 at Minimal.
08:16
Here's a visual representation off What are between you
08:18
when I created users earlier,
08:22
their whole just uses in azure Haiti,
08:24
if I want to grants to users administrative privileges in a joy ity itself after assigned the users toe as your 80 administrator roles
08:35
in this task of your signing Brenda to the global administrative Oh,
08:41
which means that she has full access to the tenants.
08:43
This is a road that would want to use very sparingly. Actually, Microsoft recommends not more than five global administrators in a tenant
08:54
on the identities that I global administrators should be well protected.
08:58
So back in the your Pato, if I click on the left inside and I go back to Magic Haiti Tenant,
09:05
if I click on the uses and I select Brenda.
09:09
If I click on the sign, those I can click on Add assignment
09:13
and I can specify one off the butte in votes Toe assigned to bring their
09:20
so devoted they want is Global Administrator, which gives full access if I go ahead and click on Global Administrator. And if I click on hard,
09:30
what is does is it assigns a row to bring the for the actual Haiti tenant itself in the next task. RB sharing you out to assign. As a service, Saas falls to users and groups. Yes, official representation off what are between in order to give my newly created as your Haiti users
09:50
permissions to a jury sauces.
09:52
How be assigning them toe have back rows in my job description.
09:56
Our start. By signing the owner, go to the Cloud Architect group that I created earlier.
10:03
How do L a ST John to the contributor row for the azure subscription
10:07
back in the azure Pado? If I click at the very top here and set for subscriptions,
10:13
if I click on subscriptions
10:15
and you can see that I have a single subscription called Super Cloud Prod.
10:20
If I click on that subscription,
10:22
I can click on the access control high him
10:24
and I can click on hard
10:28
and click on wall assignment.
10:30
I can specify the Azure Resource Audio Zhou Hao back row that I want to assign in this place. Owner on us pacified the azure Haiti User Group of service principle that I want to a scientist Vogtle, in this case, the Cloud Architects Crip Fig wide and click Save
10:46
that's going to apply devil assignment. If I click on the Vaal assignments,
10:50
I'll be able to verify the Cloud architect as on a permissions. I'll go back and click on Hard and I'll click on Hardball assignments this time around are be assigning a contributor. Oh, so these are called John
11:05
and I'll click on Save
11:07
and that's going to assign the vote. John on this is a separate full from the Azure 80 Administrator. Oh, this will up life. So I just descriptions and the resources within them
11:18
and the final service off tasks. How be doing Tree tings
11:22
fast are created and agile. Haiti Application Registration in the Azure Pado,
11:28
our signed delegated permissions to the hub
11:33
Hanau Grant Administrative consent for that permission.
11:35
Yes, official representation of what I'll be Dean
11:39
first, our create an application registration called Costume Hap. How then assigned delegated permissions to allow they have to read and write on all user profiles in Azure Haiti. Finally, our grand consent for that permission as an administrator
11:56
back in the azure Pato. If I click on the left hand side and go back to Azure Active Directory,
12:03
how click on the application registrations on I'll click on new registration, in this case are specified the name of my application called Custom Hat.
12:13
I can specify whether this is going to be for my organization to victory only or if it's going to be more detainment. In this case, I would just live with us, my organization homely.
12:24
This is where I can specify David directional life or off to authentication scenarios. If I'm using Web or even mobile applications,
12:33
it makes sense to specify the redirect you of I
12:37
so that once the talking has been granted, users can be redirected to the happen. In this case, I'll leave. This is empty, are quiet and click on register have to create in the half we get on application or client Heidi. This is something that will be needing if we want to authenticate as this happened,
12:54
how just making not of it
12:56
the next one. That out, though, is are assigned delegated permissions to these application
13:01
so that this application can hacks on behalf off users that authenticates to hit.
13:07
To do that, our click on a P I permissions
13:11
and I can see that this is the fourth permission that was granted, called user dot read to the Microsoft graph AP High,
13:18
and this allows delegated permission to be able to sign in and videos of Forfar.
13:24
How does extend this a bit?
13:26
How? Click on a Microsoft graph
13:30
and how screwed right down to where we have uses on 100 that out. Click on user Vihd
13:37
on Right for Hall four Force. So if I go ahead and click on that and I'll click on object permissions
13:43
so once I've done that assigns the permission. But then I need to grant consent for the permission that I just added. To do that, I can click on grant admin consent for super Clouds
13:56
on it asked me if I want to grant consent for the requested permission,
14:00
my guide and click Yes,
14:03
he can see that it now shows the status off the permissions As granted.
14:09
Here are some quiz questions really, that the tasks that we completed in this demonstration video
14:15
the company has on a joy D tenants named Test Cloud of X y Z.
14:20
The company is developing an application named H of Hap.
14:24
They have proven as a service on a sever, and we'll hot indicates to test cloud of X Y Z toe digit directory data via mikes. Off graph
14:33
units two delegates The minimum required permissions to the h of hap,
14:37
which to reaction should you perform in sequence from the azure Pato
14:43
select in the right order.
14:46
The first step to do is to create an application registration in azure Haiti.
14:54
Then, after that, will be heading an application permission.
14:58
This will not be a delegated permission because in this case, the application is running as a service as a demon
15:05
on a sever. In other words, this is not something that can
15:11
use delegated permissions on behalf off locked in Jesus.
15:15
So that would be application permission. If you remember from the last lesson
15:18
and finally will grant consent for the permission that was assigned to the application
15:26
Quiz. Question Number two.
15:28
The company has on azure subscription named Sub one that is associated to an azure 80 tenant named Light Bob. The X y Z.
15:37
The company develops in mobile application. Named up one
15:41
Have one uses the off to implicit grand type to acquire as your Haiti access tokens.
15:48
It needs to register help one. In Azure Hedy.
15:52
What information should you obtain from the developer to register the application?
16:00
If you select that every div Actually, you would be correct if you remember when I was creating the application registration Hey earlier were given an option to specify if it the vacuum awry where users will be redirected toe after talking. Za Granted, that concludes this demonstration video.
16:18
Thanks very much for watching and I'll see you in the next lesson.

Up Next

AZ-500: Microsoft Azure Security Technologies

In the AZ-500 Microsoft Azure Security Technologies training, students will learn the skills that are needed to pass the AZ-500 certification exam. All exam topics are covered as well as exam preparation strategies and hands-on practice.

Instructed By

Instructor Profile Image
David Okeyode
Cloud Security Architect
Instructor