Skip to content
GetHandsOn.ai

AZ-900 Study Guide


Module 5 of 1111 min read

Identity, Access & Security

Master Azure's security model with Microsoft Entra ID for identity, RBAC for permissions, and layered defense strategies like Zero Trust.

These study notes summarise Microsoft Learn material for Exam AZ-900. For the official skills measured, see the Microsoft Learn study guide for Exam AZ-900.

On this pageShow

This module is dedicated to securing your Azure environment. We will cover how Azure manages identity with Microsoft Entra ID and its key authentication features like MFA and Conditional Access. You'll learn the difference between authentication and authorization, how to apply granular permissions with Role-Based Access Control (RBAC), and how to adopt modern security philosophies like Zero Trust and Defense in Depth.

Microsoft Entra ID (formerly Azure Active Directory)

Microsoft Entra ID is Microsoft's cloud-based identity and access management (IAM) service. It is the core service that authenticates and authorizes users, services, and devices, controlling access to Azure resources, Microsoft 365, and thousands of other SaaS applications.

In Plain English

In the past, the network perimeter (the office walls) was the main security boundary. Today, with remote work and cloud apps, identity is the new security perimeter. Microsoft Entra ID is that perimeter, verifying every access request no matter where it comes from.

Authentication vs. Authorization

  • Authentication (AuthN): The process of proving you are who you say you are. This is typically done with a username and password, but can be enhanced with other factors. Are you you?
  • Authorization (AuthZ): The process of determining what an authenticated user is allowed to do. This is handled by a set of permissions. What can you do?

Core Authentication Methods

  • Single Sign-On (SSO): Allows a user to sign in once and gain access to multiple independent applications without re-entering their credentials. This improves user experience and security.
  • Multi-Factor Authentication (MFA): Adds a layer of security by requiring two or more verification methods from different categories: something you know (password), something you have (phone app), and something you are (fingerprint). Even if a password is stolen, the attacker cannot get in without the second factor.
  • Passwordless Authentication: Removes the password entirely, replacing it with more secure methods like the Microsoft Authenticator app, FIDO2 security keys (FIDO2 = Fast IDentity Online v2, a phishing-resistant hardware key standard), or Windows Hello for Business (biometrics/PIN).

Microsoft Entra Conditional Access

Conditional Access is the engine of a Zero Trust security model. It acts as an intelligent policy engine that evaluates signals from every sign-in attempt and, if necessary, enforces security controls before granting access.

IF (Signal) -> THEN (Decision)

Signal EvaluatedExample Conditions
User or GroupIs this a privileged administrator? Is it a guest user?
Location (IP)Is the user signing in from a known corporate network or an anonymous proxy?
DeviceIs the device managed by the company and compliant with security policies?
ApplicationIs the user trying to access a highly sensitive HR app or a general-purpose team site?
Sign-in RiskHas Microsoft's identity protection detected anomalous behavior for this account?

Based on these signals, Conditional Access can decide to: Allow access, Block access, or Require additional verification (like an MFA prompt).

Azure Role-Based Access Control (RBAC)

While Microsoft Entra ID handles authentication, RBAC in Azure handles authorization. It allows you to grant specific permissions to users, groups, and services at a defined scope (Management Group, Subscription, Resource Group, or individual Resource).

RBAC follows the principle of least privilege: grant only the permissions necessary to perform a job.

Built-in RoleCan Read?Can Modify/Create?Can Delete?Can Assign Roles?Typical Use Case
OwnerYesYesYesYesThe primary administrator of a subscription or resource group.
ContributorYesYesYesNoDevelopers or DevOps engineers who need to manage resources but not user access.
ReaderYesNoNoNoAuditors, finance teams, or monitoring tools that need to view resources without changing them.
User Access AdminYesNoNoYesSecurity teams that manage who has access to what, but not the resources themselves.

Zero Trust & Defense in Depth

These are two foundational security strategies for designing secure cloud environments.

Zero Trust

Zero Trust is a security model based on the principle: never trust, always verify. It assumes that the network is always hostile and every access request, whether from inside or outside the network, must be fully authenticated, authorized, and encrypted before being granted.

Zero Trust PrincipleWhat It Means in Practice
Verify ExplicitlyAlways authenticate and authorize using all available data: identity, location, device health, service, workload, and data classification.
Use Least Privilege AccessGrant users just-in-time and just-enough-access (JIT = elevate permissions only when needed; JEA = give only the minimum permissions needed for the task) to perform their tasks.
Assume BreachMinimize the blast radius of an attack. Segment networks, encrypt everything, and monitor for threats continuously.

Defense in Depth

Defense in Depth is a layered approach to security. By implementing security controls at every layer of the technology stack, you slow down attackers and ensure that a compromise at one layer does not lead to a full system breach.

LayerAzure Security Controls
PhysicalMicrosoft's secure data centers with biometric access controls.
Identity & AccessMicrosoft Entra ID, MFA, Conditional Access, RBAC.
PerimeterAzure DDoS Protection, Azure Firewall.
NetworkNetwork Security Groups (NSGs), VNet segmentation, Private Endpoints.
ComputeDefender for Servers, OS patching, endpoint protection.
ApplicationWeb Application Firewall (WAF), secure coding practices.
DataEncryption at rest and in transit, Azure Key Vault for secrets.

Microsoft Defender for Cloud

Defender for Cloud is a unified security posture management and threat protection service. It continuously assesses your Azure, on-premis.es, and multi-cloud environments for security weaknesses and provides a Secure Score-a measure of your security posture. It also provides threat detection for your workloads, raising alerts when it detects malicious activity.

Official exam information from Microsoft

Get the full AZ-900 study guide as a PDF, freeAll 11 modules in one printable file. Enter your email on the guide page and it is yours.

Keep going

Get the full AZ-900 guide as a PDFEvery module in one file. Free after you enter your email.
Practice AZ-900 questionsExam-style questions with explanations, free to start.
AZ-900 guide overviewAll modules, pick what to read next.