Skip to content

Commit b68068d

Browse files
committed
update module
1 parent caba4a4 commit b68068d

8 files changed

Lines changed: 183 additions & 203 deletions

learn-pr/wwl-sci/design-solutions-identity-access-management/1-introduction.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,6 @@ metadata:
88
author: ceperezb
99
ms.author: ceperezb
1010
ms.topic: unit
11-
durationInMinutes: 2
11+
durationInMinutes: 3
1212
content: |
1313
[!include[](includes/1-introduction.md)]

learn-pr/wwl-sci/design-solutions-identity-access-management/2-design-cloud-hybrid-multi-cloud-access-strategies.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,6 @@ metadata:
88
author: ceperezb
99
ms.author: ceperezb
1010
ms.topic: unit
11-
durationInMinutes: 7
11+
durationInMinutes: 8
1212
content: |
1313
[!include[](includes/2-design-cloud-hybrid-multi-cloud-access-strategies.md)]

learn-pr/wwl-sci/design-solutions-identity-access-management/3-design-solution-external-identities.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,6 @@ metadata:
88
author: ceperezb
99
ms.author: ceperezb
1010
ms.topic: unit
11-
durationInMinutes: 12
11+
durationInMinutes: 13
1212
content: |
1313
[!include[](includes/3-design-solution-external-identities.md)]

learn-pr/wwl-sci/design-solutions-identity-access-management/6-specify-requirements-secure-active-directory-domain-services.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,6 @@ metadata:
88
author: ceperezb
99
ms.author: ceperezb
1010
ms.topic: unit
11-
durationInMinutes: 7
11+
durationInMinutes: 12
1212
content: |
1313
[!include[](includes/6-specify-requirements-secure-active-directory-domain-services.md)]

learn-pr/wwl-sci/design-solutions-identity-access-management/7-design-solution-manage-secrets-keys-certificates.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,6 @@ metadata:
88
author: ceperezb
99
ms.author: ceperezb
1010
ms.topic: unit
11-
durationInMinutes: 7
11+
durationInMinutes: 11
1212
content: |
1313
[!include[](includes/7-design-solution-manage-secrets-keys-certificates.md)]

learn-pr/wwl-sci/design-solutions-identity-access-management/includes/6-specify-requirements-secure-active-directory-domain-services.md

Lines changed: 67 additions & 88 deletions
Large diffs are not rendered by default.

learn-pr/wwl-sci/design-solutions-identity-access-management/includes/7-design-solution-manage-secrets-keys-certificates.md

Lines changed: 70 additions & 81 deletions
Large diffs are not rendered by default.

learn-pr/wwl-sci/design-solutions-identity-access-management/includes/9-summary.md

Lines changed: 41 additions & 29 deletions
Original file line numberDiff line numberDiff line change
@@ -14,55 +14,67 @@ You learned how to:
1414

1515
- **Consolidate identity on Microsoft Entra ID** as the central identity provider across all environments, including AWS and GCP, to simplify governance and enable consistent access policies.
1616
- **Choose Cloud Sync for new hybrid deployments** and password hash synchronization as the default authentication method for the strongest security features and resiliency.
17-
- **Apply Zero Trust across all identity decisions**verify explicitly with Conditional Access, enforce least privilege with PIM and access reviews, and assume breach with continuous monitoring.
17+
- **Apply Zero Trust across all identity decisionsverify explicitly with Conditional Access, enforce least privilege with PIM and access reviews, and assume breach with continuous monitoring.
1818
- **Protect secrets with Azure Key Vault** using RBAC, managed identities, and automated rotation to eliminate hardcoded credentials.
1919
- **Harden AD DS with tiered administration** and integrate sign-in signals with Microsoft Sentinel for centralized threat detection across hybrid and multicloud environments.
2020

2121
## Learn more
2222

23+
### Design a solution for access to SaaS, PaaS, IaaS, hybrid, and multicloud resources
24+
25+
- [Microsoft Entra identity management and access management for AWS](/azure/architecture/reference-architectures/aws/aws-azure-ad-security)
26+
- [Microsoft security solutions for AWS](/azure/architecture/guide/aws/aws-azure-security-solutions)
27+
28+
### Design a solution for Microsoft Entra ID, including hybrid and multicloud environments
29+
2330
- [Microsoft Entra ID documentation](/entra/identity/)
24-
- [Microsoft Entra Conditional Access](/entra/identity/conditional-access/)
25-
- [Microsoft Entra External ID](/entra/external-id/)
26-
- [Best practices for securing Active Directory](/windows-server/identity/ad-ds/plan/security-best-practices/best-practices-for-securing-active-directory)
27-
- [Azure Key Vault documentation](/azure/key-vault/)
2831
- [What is Microsoft Entra Cloud Sync?](/entra/identity/hybrid/cloud-sync/what-is-cloud-sync)
29-
- [What is Microsoft Entra Connect?](/entra/identity/hybrid/connect/whatis-azure-ad-connect)
3032
- [Choose the right authentication method for your Microsoft Entra hybrid identity solution](/entra/identity/hybrid/connect/choose-ad-authn)
3133
- [Microsoft Entra seamless single sign-on](/entra/identity/hybrid/connect/how-to-connect-sso-how-it-works)
32-
- [What is workload identity federation?](/entra/workload-id/workload-identity-federation)
33-
- [What is Microsoft Entra Domain Services?](/entra/identity/domain-services/overview)
34-
- [Microsoft Entra identity management and access management for AWS](/azure/architecture/reference-architectures/aws/aws-azure-ad-security)
35-
- [Microsoft security solutions for AWS](/azure/architecture/guide/aws/aws-azure-security-solutions)
3634
- [Hybrid identity scenarios](/entra/identity/hybrid/common-scenarios)
35+
- [What is Microsoft Entra Domain Services?](/entra/identity/domain-services/overview)
36+
- [What is workload identity federation?](/entra/workload-id/workload-identity-federation)
37+
38+
### Design a solution for external identities
39+
40+
- [Microsoft Entra External ID](/entra/external-id/)
41+
42+
### Design modern authentication and authorization strategies
43+
3744
- [Authentication vs. authorization in the Microsoft identity platform](/entra/identity-platform/authentication-vs-authorization)
3845
- [Hybrid modern authentication overview](/microsoft-365/enterprise/hybrid-modern-auth-overview)
3946
- [Microsoft Entra authentication methods](/entra/identity/authentication/overview-authentication)
4047
- [Authentication strengths in Conditional Access](/entra/identity/authentication/concept-authentication-strengths)
41-
- [Conditional Access policies](/entra/identity/conditional-access/concept-conditional-access-policies)
42-
- [Conditional Access session controls](/entra/identity/conditional-access/concept-conditional-access-session)
43-
- [Plan a Conditional Access deployment](/entra/identity/conditional-access/plan-conditional-access)
44-
- [Common Conditional Access policy templates](/entra/identity/conditional-access/concept-conditional-access-policy-common)
45-
- [Microsoft-managed Conditional Access policies](/entra/identity/conditional-access/managed-policies)
46-
- [Block legacy authentication with Conditional Access](/entra/identity/conditional-access/policy-block-legacy-authentication)
47-
- [Conditional Access What If tool](/entra/identity/conditional-access/what-if-tool)
48-
- [Report-only mode for Conditional Access](/entra/identity/conditional-access/concept-conditional-access-report-only)
49-
- [Conditional Access insights and reporting](/entra/identity/conditional-access/howto-conditional-access-insights-reporting)
50-
- [Conditional Access gap analyzer workbook](/entra/identity/monitoring-health/workbook-conditional-access-gap-analyzer)
51-
- [Conditional Access optimization agent](/entra/security-copilot/conditional-access-agent-optimization)
52-
- [Filter for applications in Conditional Access](/entra/identity/conditional-access/concept-filter-for-applications)
48+
- [Microsoft Entra Conditional Access](/entra/identity/conditional-access/)
5349
- [Continuous access evaluation](/entra/identity/conditional-access/concept-continuous-access-evaluation)
54-
- [Conditional Access for Agent ID](/entra/identity/conditional-access/agent-id)
55-
- [Security for AI agents](/entra/agent-id/identity-professional/security-for-ai)
56-
- [Microsoft Entra agent identities for AI agents](/entra/agent-id/identity-professional/microsoft-entra-agent-identities-for-ai-agents)
57-
- [Risky agents in ID Protection](/entra/id-protection/concept-risky-agents)
5850
- [Microsoft Entra ID Protection](/entra/id-protection/overview-identity-protection)
59-
- [Identity Protection policies](/entra/id-protection/concept-identity-protection-policies)
60-
- [Risk detection types](/entra/id-protection/concept-risk-detection-types)
6151
- [Protected actions overview](/entra/identity/role-based-access-control/protected-actions-overview)
62-
- [Add protected actions](/entra/identity/role-based-access-control/protected-actions-add)
6352
- [Emergency access accounts](/entra/identity/role-based-access-control/security-emergency-access)
6453
- [Securing privileged access overview](/entra/identity/role-based-access-control/security-planning)
54+
55+
### Design Conditional Access policies for AI agents
56+
57+
- [Conditional Access for Agent ID](/entra/identity/conditional-access/agent-id)
58+
- [Security for AI agents](/entra/agent-id/identity-professional/security-for-ai)
59+
- [Microsoft Entra agent identities for AI agents](/entra/agent-id/identity-professional/microsoft-entra-agent-identities-for-ai-agents)
60+
- [Risky agents in ID Protection](/entra/id-protection/concept-risky-agents)
61+
62+
### Validate alignment of Conditional Access policies with a Zero Trust strategy
63+
6564
- [Securing identity with Zero Trust](/security/zero-trust/deploy/identity)
6665
- [Zero Trust identity and device access policies](/security/zero-trust/zero-trust-identity-device-access-policies-overview)
6766
- [Common identity and device access policies](/security/zero-trust/zero-trust-identity-device-access-policies-common)
6867
- [Zero Trust security in Azure](/azure/security/fundamentals/zero-trust)
68+
69+
### Specify requirements for securing Active Directory Domain Services
70+
71+
- [Credential Guard overview](/windows/security/identity-protection/credential-guard/)
72+
- [Best practices for securing Active Directory](/windows-server/identity/ad-ds/plan/security-best-practices/best-practices-for-securing-active-directory)
73+
- [Privileged access: Enterprise access model](/security/privileged-access-workstations/privileged-access-access-model)
74+
- [Pilot and deploy Microsoft Defender for Identity](/defender-xdr/pilot-deploy-defender-identity)
75+
- [Windows LAPS overview](/windows-server/identity/laps/laps-overview)
76+
- [Microsoft Entra Password Protection for on-premises AD DS](/entra/identity/authentication/concept-password-ban-bad-on-premises)
77+
78+
### Design a solution to manage secrets, keys, and certificates
79+
80+
- [Azure Key Vault documentation](/azure/key-vault/)

0 commit comments

Comments
 (0)