๐Ÿ” Azure AD Study Companion

Your guided journey through Azure Active Directory mastery

0%
๐Ÿ“‹ 0/5 quests completed
โšก 0/100 XP earned
โšก
Before You Start: Get Your Azure Environment Ready
Setup Guide
๐ŸŽฏ Why This Matters

To get the FULL hands-on experience with this companion, you'll want access to Azure AD Premium P2 features. The good news? Microsoft offers a FREE 30-day trial with 100 user licenses - perfect for learning!

๐Ÿ’Ž What You'll Unlock with P2 Trial
โ€ข Self-Service Password Reset (SSPR) - Actually configure it, not just read about it
โ€ข Conditional Access - Create real policies based on location, device, risk
โ€ข Dynamic Groups - Build rule-based automatic group membership
โ€ข Privileged Identity Management (PIM) - Time-based admin access
โ€ข Identity Protection - Risk detection and automated responses

Without P2, you can only VIEW these features. With P2, you can BUILD with them! ๐Ÿš€
๐Ÿ“‹ Setup Steps (15 minutes)
  • Create Free Azure Account
    Go to azure.microsoft.com/free โ†’ Sign up with your personal email โ†’ You'll get $200 credit (30 days) PLUS 12 months of free services
  • Verify Your Account
    Microsoft will ask for a phone number and credit card (for verification only - you won't be charged during the trial)
  • Access Azure Portal
    Once verified, go to portal.azure.com and sign in
  • Navigate to Azure Active Directory
    Search for "Azure Active Directory" in the top search bar โ†’ Click to open
  • Activate P2 Trial
    In Azure AD, click "Licenses" in the left menu โ†’ Click "All products" โ†’ Click "Try/Buy" โ†’ Find "Microsoft Entra ID P2" โ†’ Click "Activate" on the Free Trial
  • Assign License to Yourself
    Go to Azure AD โ†’ "Users" โ†’ Click on your user โ†’ Click "Licenses" โ†’ Click "+ Assignments" โ†’ Select "Microsoft Entra ID P2" โ†’ Click "Save"
โš ๏ธ Important Trial Info
โ€ข Trial lasts 30 days from activation
โ€ข You get 100 licenses (way more than you need!)
โ€ข No automatic charges - premium features just stop working after 30 days
โ€ข Your free tier features and $200 credit are separate and stay active
โ€ข Plan to spend your 30 days wisely - focus on identity/security topics first!
๐Ÿ’ก Can I Skip the P2 Trial?
Yes! You can still learn from this companion without P2. The guide explains what each feature DOES and WHY it matters. However, you'll only be able to VIEW settings instead of actually configuring them.

With Free Tier Only:
โ€ข Quest 1 (Create Users/Groups): โœ… Full hands-on
โ€ข Quest 2 (Guest Access): โœ… Full hands-on
โ€ข Quest 3 (SSPR): โš ๏ธ Conceptual learning only
โ€ข Quest 4 (MFA): โš ๏ธ Security Defaults only (no Conditional Access)
โ€ข Quest 5 (Dynamic Groups): โš ๏ธ Conceptual learning only

With P2 Trial:
All quests: โœ… Full hands-on experience!

For AZ-104 exam prep, understanding the concepts is sufficient. But hands-on is always better! ๐Ÿ’ช
๐ŸŽ“ Study Timeline Suggestion
If you activate the P2 trial, here's how to maximize your 30 days:

Week 1: Identity & Access (this companion!)
โ€ข Azure AD fundamentals
โ€ข RBAC
โ€ข Conditional Access

Week 2: Governance
โ€ข Management Groups
โ€ข Azure Policy
โ€ข Cost Management

Weeks 3-4: Infrastructure
โ€ข Storage Accounts
โ€ข Virtual Machines
โ€ข Virtual Networks
โ€ข (Use your $200 credit for these!)

This way you use P2 for identity features early, then practice infrastructure topics that don't need premium licenses.
โœ… Setup Checklist
1
Create Users and Groups in Azure AD
+20 XP
๐ŸŽฏ What You'll Learn

In this quest, you'll learn how to create and manage users and groups in Azure AD. This is the foundation of identity management in Azure!

๐Ÿ’ก Where to Start
Navigate to the Azure Portal (portal.azure.com) โ†’ Search for "Azure Active Directory" in the top search bar โ†’ Click on it to open the Azure AD blade.
๐Ÿ“‹ Step-by-Step Guide
  • In Azure AD, click on "Users" in the left menu
  • Click "+ New user" โ†’ Choose "Create new user"
  • Fill in User Principal Name and Display Name (e.g., john.doe@yourdomain.onmicrosoft.com)
  • Set a temporary password (or use auto-generate)
  • Click "Create" - congrats, you created your first user! ๐ŸŽ‰
โš ๏ธ Free Tier Note
Your free Azure account gives you Azure AD Free tier. This is perfect for learning the basics! Some advanced features (like dynamic groups) require Azure AD P1, but don't worry - you'll learn about those in the "Understand & Explain" section.
๐Ÿ’ก Now Try Groups
Creating a Security Group:

1. Go back to Azure AD โ†’ Click "Groups"
2. Click "+ New group"
3. Choose Group type: "Security"
4. Enter a name like "IT-Admins"
5. Membership type: "Assigned" (Dynamic requires P1)
6. Click "Create"

Add your user to the group:

1. Click on your new group
2. Click "Members" โ†’ "+ Add members"
3. Select the user you created
4. Click "Select"
๐Ÿ’ช Pro Tip
Try creating 2-3 users and organizing them into different groups (like "Marketing", "Engineering", "Finance"). This mimics real-world scenarios and helps you understand group-based management!
โœ… Completion Checklist
2
Configure Guest User Access
+20 XP
๐ŸŽฏ What You'll Learn

Guest users let you collaborate with external partners while keeping your tenant secure. This is called B2B (Business-to-Business) collaboration!

๐Ÿ’ก Understanding Guest vs Member Users
Member Users: Internal employees with full access to your Azure AD

Guest Users: External collaborators with limited access by default

Think of it like: Members have keys to all the rooms, Guests only get keys to the meeting rooms!
๐Ÿ“‹ Step-by-Step Guide
  • Go to Azure AD โ†’ "Users"
  • Click "+ New user" โ†’ Choose "Invite external user"
  • Enter an email address (can be any personal email like Gmail)
  • Add a personal message (optional but nice!)
  • Click "Invite" - the guest will receive an email invitation
๐Ÿงช Testing Tip
Use your personal email address as the guest! This lets you see both sides of the experience - as the admin and as the guest user. Check your personal email for the invitation!
๐Ÿ’ก Guest Settings Configuration
Explore External Collaboration Settings:

1. Azure AD โ†’ "External Identities"
2. Click "External collaboration settings"
3. Notice the different permission levels for guests
4. See who can invite guests (important for security!)

Don't change anything yet - just observe what options are available!
๐Ÿง  Knowledge Check: What user type designation does an invited external collaborator get?
A) External
B) Guest
C) Partner
D) Visitor
โœ… Completion Checklist
3
Set Up Self-Service Password Reset (SSPR)
+20 XP
๐ŸŽฏ What You'll Learn

SSPR lets users reset their own passwords without calling IT. This saves time and empowers users!

โš ๏ธ Free Tier Limitation
SSPR is a Premium P1 feature. With the free tier, you can EXPLORE the settings but can't fully enable it. That's okay - understanding the configuration is what matters for the exam!
๐Ÿ“‹ Exploration Guide
  • Azure AD โ†’ Search for "Password reset" in left menu
  • Click "Properties" - see that it's disabled (needs Premium)
  • Explore "Authentication methods" - notice multiple verification options
  • Check "Registration" settings - see how users would enroll
  • Review "Notifications" - understand alert options
๐Ÿ’ก Understanding SSPR Concepts
Key Concepts to Know:

โ€ข Gates: Number of authentication methods required (usually 1 or 2)
โ€ข Methods: Mobile app, phone, email, security questions
โ€ข Registration: Users must register before they can use SSPR
โ€ข Writeback: Syncs password changes back to on-premises AD (hybrid scenarios)

Even if you can't enable it now, understanding these concepts is crucial!
๐Ÿ“š Exam Focus
For AZ-104, know: SSPR requires Azure AD Premium P1 or P2, supports multiple authentication methods, and can integrate with on-premises Active Directory through password writeback.
๐Ÿง  Knowledge Check: What Azure AD license tier is required for SSPR?
A) Azure AD Free
B) Azure AD Premium P1
C) Azure AD Premium P2
D) Microsoft 365 E3
โœ… Completion Checklist
4
Configure Multi-Factor Authentication (MFA)
+20 XP
๐ŸŽฏ What You'll Learn

MFA adds an extra layer of security by requiring two forms of verification. This is CRITICAL for protecting accounts!

๐ŸŽ‰ Good News!
Security defaults include MFA and are available in the free tier! Let's explore them.
๐Ÿ“‹ Step-by-Step Guide
  • Azure AD โ†’ "Properties" โ†’ Scroll to bottom
  • Click "Manage security defaults"
  • Notice it can be Enabled or Disabled
  • If disabled, consider enabling it (protects your account!)
  • Security defaults automatically enable MFA for all users
๐Ÿ’ก Understanding Security Defaults vs Conditional Access
Security Defaults (Free):
โ€ข Basic MFA for all users
โ€ข All-or-nothing approach
โ€ข Great for small organizations
โ€ข Can't customize when MFA is required

Conditional Access (Premium P1):
โ€ข Granular control over MFA policies
โ€ข Can require MFA based on location, device, risk level
โ€ข Can exclude specific users or groups
โ€ข Way more flexible!

Think: Security Defaults = light switch (on/off), Conditional Access = smart home (total control)
โš ๏ธ Important
If you enable security defaults, you'll need to set up MFA on your own account next time you sign in. Have your phone ready with the Microsoft Authenticator app!
๐Ÿ’ก Advanced: Exploring Conditional Access (View Only)
Even though you can't create Conditional Access policies with the free tier, you can still explore the interface:

1. Azure AD โ†’ Search for "Conditional Access"
2. Click "Policies" - see the interface
3. Notice the structure: Assignments (who/what) โ†’ Conditions (when) โ†’ Access controls (what happens)
4. This is the "pro version" of MFA control you'll use in enterprise environments!
๐Ÿง  Knowledge Check: What's the main difference between Security Defaults and Conditional Access?
A) Security Defaults is more secure
B) Conditional Access offers granular policy control
C) They're the same thing
D) Security Defaults requires Premium P2
โœ… Completion Checklist
5
Understand Dynamic Group Membership
+20 XP
๐ŸŽฏ What You'll Learn

Dynamic groups automatically add/remove members based on user attributes. Super powerful for automation!

โš ๏ธ Premium Feature Alert
Dynamic groups require Azure AD Premium P1. You can't create them with the free tier, BUT you can still learn how they work - which is the key exam knowledge!
๐Ÿ“‹ Conceptual Learning
  • Go to Azure AD โ†’ "Groups" โ†’ Try "+ New group"
  • Notice the "Membership type" dropdown
  • See "Dynamic User" and "Dynamic Device" (greyed out)
  • Click the "Learn more" link to read Microsoft docs
  • Understand: these use rules like "department equals Marketing"
๐Ÿ’ก How Dynamic Groups Work
Example Scenarios:

All Marketing users:
Rule: (user.department -eq "Marketing")

All users in Chicago:
Rule: (user.city -eq "Chicago")

Contractors expiring soon:
Rule: (user.employeeType -eq "Contractor") -and (user.accountEnabled -eq true)

The group membership updates automatically as user attributes change!
๐Ÿ’ช Exam Tip
Key things to remember: Dynamic groups require Azure AD P1, they use rule-based expressions, membership updates automatically, and there's a processing time (not instant!). Also know: you can have dynamic USER groups and dynamic DEVICE groups.
๐Ÿ’ก Comparison: Assigned vs Dynamic
Assigned Groups (Free tier):
โ€ข Manual membership management
โ€ข You add/remove members one by one
โ€ข Full control, but time-consuming
โ€ข Best for small, static groups

Dynamic Groups (Premium P1):
โ€ข Automatic membership based on rules
โ€ข Updates as user attributes change
โ€ข Requires P1 license
โ€ข Perfect for large, changing organizations

Real-world example: A company has 500 employees. When someone joins the Marketing dept, they're automatically added to "Marketing-Team" group, get access to marketing resources, and receive marketing emails. When they transfer to Sales, they're automatically moved! No admin work needed.
๐Ÿง  Knowledge Check: What Azure AD license is required for dynamic group membership?
A) Azure AD Free
B) Azure AD Premium P1
C) Office 365 E3
D) It's available in all tiers
โœ… Completion Checklist

๐ŸŽ‰ Congratulations! ๐ŸŽ‰

You've mastered Azure AD fundamentals!
You earned 100 XP and unlocked the next skill in your tree!

Ready to level up? Check out RBAC (Role-Based Access Control) next! ๐ŸŽญ

๐Ÿ“š Additional Resources for Azure AD Mastery
โ†’ MS Learn: Azure Identity & Security โ†’ Microsoft Entra ID Documentation โ†’ John Savill's Azure AD Deep Dive (Video) โ†’ Identity Management Best Practices