The five-day course is intended for all Active Directory Domain Services (AD DS) administrators who want to delve into the secrets of how EntraID/AzureAD accounts, groups, roles and access control work compared to their on-prem AD experience. [...]
  • GOC218
  • Duration 5 days
  • 50 ITK points
  • 3 terms
  • ČR (33 600 Kč)

    SR (1 300 €)

The five-day course is intended for all Active Directory Domain Services (AD DS) administrators who want to delve into the secrets of how EntraID/AzureAD accounts, groups, roles and access control work compared to their on-prem AD experience. Web SSO authentication (OpenID Connect, SAML 2.0 and WS-Fed) of users using MFA is examined in detail both in browsers, GUI applications and on Windows stations connected both directly to EntraID/AzureAD and hybridly connected to AD and EntraID. The course also examines in detail the possibilities of synchronizing accounts between AD and EntraID in both directions (Connect Sync and Cloud Sync), password policies and their integration with the on-prem environment, troubleshooting problems with logging synchronized and purely cloud users and logging their access. The intricacies of Windows Hello for Business (WHB) and its integration with on-prem Kerberos in key trust and cloud trust modes are essential. We will also conduct detailed investigation and troubleshooting in the case of Conditional Access and accordingly set up reliable break-glass accounts with full phishing-resistant MFA using FIDO2 keychains.

»

Knowledge in extent of the courses which are listed in the bellow sections Previous Courses and Related Courses
All attendees should have experience with Active Directory Domain Services (AD DS) administration

Administration of users and groups
EntraID/AzureAD security settings
Multi-factor authentication
Passwordless authentication, FIDO2, Windows Hello
Management of PCs and mobile devices
Hybrid identity
Account synchronization using Entra Connect Sync and Entra Cloud Connect (Azure AD Connect)
Password hash synchronization
Pass-through authentication
Seamless SSO
Federation with Active Directory Federation Services
Self-service password reset (SSPR)
Entra/AAD Identity Protection
Entra/AAD Privileged Identity Management (PIM)
Entra/AAD Password Protection
3rd party identity consumers, SAML, OpenID Connect
Azure PowerShell
Integration with Azure, Office 365, and Intune

Most Microsoft certification exams do not require students to attend an official MOC course in order to pass the exam. This applies to all certifications except for MCM
Official Microsoft MOC courses as well as our own GOC courses are good ways of preparation for Microsoft certifications such as MCP, MTA, MCSA, MCSE or MCM
This does not mean that official MOC courses would serve as the only necessary praparation. The primary goal of an MOC course is to provide for sufficient theoretical knowledge and practical experience to effectively work with the related product
MOC courses usually cover most of the topics required by their respective certification exams, but often do not give every topic the same amount of time and emphassis as may be required to completelly pass the exam

Current offer
Training location
Course language

The prices are without VAT.

Custom Training

Didn’t find a suitable date or need training tailored to your team’s specific needs? We’ll be happy to prepare custom training for you.