AZ-900 Study Guide
Module 5 of 1111 min read
Identity, Access & Security
Master Azure's security model with Microsoft Entra ID for identity, RBAC for permissions, and layered defense strategies like Zero Trust.
These study notes summarise Microsoft Learn material for Exam AZ-900. For the official skills measured, see the Microsoft Learn study guide for Exam AZ-900.
On this pageShow
This module is dedicated to securing your Azure environment. We will cover how Azure manages identity with Microsoft Entra ID and its key authentication features like MFA and Conditional Access. You'll learn the difference between authentication and authorization, how to apply granular permissions with Role-Based Access Control (RBAC), and how to adopt modern security philosophies like Zero Trust and Defense in Depth.
Microsoft Entra ID (formerly Azure Active Directory)
Microsoft Entra ID is Microsoft's cloud-based identity and access management (IAM) service. It is the core service that authenticates and authorizes users, services, and devices, controlling access to Azure resources, Microsoft 365, and thousands of other SaaS applications.
In Plain English
In the past, the network perimeter (the office walls) was the main security boundary. Today, with remote work and cloud apps, identity is the new security perimeter. Microsoft Entra ID is that perimeter, verifying every access request no matter where it comes from.
Authentication vs. Authorization
- Authentication (AuthN): The process of proving you are who you say you are. This is typically done with a username and password, but can be enhanced with other factors. Are you you?
- Authorization (AuthZ): The process of determining what an authenticated user is allowed to do. This is handled by a set of permissions. What can you do?
Core Authentication Methods
- Single Sign-On (SSO): Allows a user to sign in once and gain access to multiple independent applications without re-entering their credentials. This improves user experience and security.
- Multi-Factor Authentication (MFA): Adds a layer of security by requiring two or more verification methods from different categories: something you know (password), something you have (phone app), and something you are (fingerprint). Even if a password is stolen, the attacker cannot get in without the second factor.
- Passwordless Authentication: Removes the password entirely, replacing it with more secure methods like the Microsoft Authenticator app, FIDO2 security keys (FIDO2 = Fast IDentity Online v2, a phishing-resistant hardware key standard), or Windows Hello for Business (biometrics/PIN).
Microsoft Entra Conditional Access
Conditional Access is the engine of a Zero Trust security model. It acts as an intelligent policy engine that evaluates signals from every sign-in attempt and, if necessary, enforces security controls before granting access.
IF (Signal) -> THEN (Decision)
| Signal Evaluated | Example Conditions |
|---|---|
| User or Group | Is this a privileged administrator? Is it a guest user? |
| Location (IP) | Is the user signing in from a known corporate network or an anonymous proxy? |
| Device | Is the device managed by the company and compliant with security policies? |
| Application | Is the user trying to access a highly sensitive HR app or a general-purpose team site? |
| Sign-in Risk | Has Microsoft's identity protection detected anomalous behavior for this account? |
Based on these signals, Conditional Access can decide to: Allow access, Block access, or Require additional verification (like an MFA prompt).
Azure Role-Based Access Control (RBAC)
While Microsoft Entra ID handles authentication, RBAC in Azure handles authorization. It allows you to grant specific permissions to users, groups, and services at a defined scope (Management Group, Subscription, Resource Group, or individual Resource).
RBAC follows the principle of least privilege: grant only the permissions necessary to perform a job.
| Built-in Role | Can Read? | Can Modify/Create? | Can Delete? | Can Assign Roles? | Typical Use Case |
|---|---|---|---|---|---|
| Owner | Yes | Yes | Yes | Yes | The primary administrator of a subscription or resource group. |
| Contributor | Yes | Yes | Yes | No | Developers or DevOps engineers who need to manage resources but not user access. |
| Reader | Yes | No | No | No | Auditors, finance teams, or monitoring tools that need to view resources without changing them. |
| User Access Admin | Yes | No | No | Yes | Security teams that manage who has access to what, but not the resources themselves. |
Zero Trust & Defense in Depth
These are two foundational security strategies for designing secure cloud environments.
Zero Trust
Zero Trust is a security model based on the principle: never trust, always verify. It assumes that the network is always hostile and every access request, whether from inside or outside the network, must be fully authenticated, authorized, and encrypted before being granted.
| Zero Trust Principle | What It Means in Practice |
|---|---|
| Verify Explicitly | Always authenticate and authorize using all available data: identity, location, device health, service, workload, and data classification. |
| Use Least Privilege Access | Grant users just-in-time and just-enough-access (JIT = elevate permissions only when needed; JEA = give only the minimum permissions needed for the task) to perform their tasks. |
| Assume Breach | Minimize the blast radius of an attack. Segment networks, encrypt everything, and monitor for threats continuously. |
Defense in Depth
Defense in Depth is a layered approach to security. By implementing security controls at every layer of the technology stack, you slow down attackers and ensure that a compromise at one layer does not lead to a full system breach.
| Layer | Azure Security Controls |
|---|---|
| Physical | Microsoft's secure data centers with biometric access controls. |
| Identity & Access | Microsoft Entra ID, MFA, Conditional Access, RBAC. |
| Perimeter | Azure DDoS Protection, Azure Firewall. |
| Network | Network Security Groups (NSGs), VNet segmentation, Private Endpoints. |
| Compute | Defender for Servers, OS patching, endpoint protection. |
| Application | Web Application Firewall (WAF), secure coding practices. |
| Data | Encryption at rest and in transit, Azure Key Vault for secrets. |
Microsoft Defender for Cloud
Defender for Cloud is a unified security posture management and threat protection service. It continuously assesses your Azure, on-premis.es, and multi-cloud environments for security weaknesses and provides a Secure Score-a measure of your security posture. It also provides threat detection for your workloads, raising alerts when it detects malicious activity.
Official exam information from Microsoft
- Study guide for Exam AZ-900: Microsoft Azure Fundamentals (skills measured, weights and passing score), and the Microsoft Certified: Azure Fundamentals certification page.