Continue your lesson
Trace the identity, credential, token, assignment, policy decision, resource, and audit record for each access request.
Block 1 of 6Compare Enterprise application gallery · Application consent policy
Current · 12 min
Compare Enterprise application gallery · Application consent policy
Optional concept notes
Enterprise application gallery
Provides templates for integrating supported software-as-a-service applications.
Application consent policy
Controls which delegated permissions users may approve for applications.
Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.
Your lesson stays open here while the provider opens in another tab. Choose one source; the notes above are optional.
Block 2 of 6Compare Enterprise application · User and group assignment · Enterprise application administrator role · Application collection
18 min
Compare Enterprise application · User and group assignment · Enterprise application administrator role · Application collection
Optional concept notes
Enterprise application
Exposes a tenant's service-principal configuration assignments permissions and sign-on controls.
User and group assignment
Limits an enterprise application to selected identities when assignment is required.
Enterprise application administrator role
Grants supported permissions for managing enterprise application configuration.
Application collection
Groups enterprise applications so access and visibility can be organized for users.
Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.
Your lesson stays open here while the provider opens in another tab. Choose one source; the notes above are optional.
Block 3 of 6Compare Tenant consent setting · Enterprise application sign-in monitoring
15 min
Compare Tenant consent setting · Enterprise application sign-in monitoring
Optional concept notes
Tenant consent setting
Defines whether users may consent and which permissions remain administrator-only.
Enterprise application sign-in monitoring
Uses application sign-in evidence to troubleshoot access and integration behavior.
Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.
Your lesson stays open here while the provider opens in another tab. Choose one source; the notes above are optional.
Block 4 of 6Understand Automatic application provisioning
12 min
Understand Automatic application provisioning
Optional concept notes
Automatic application provisioning
Creates updates and removes accounts in a target application through a provisioning connector.
Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.
Your lesson stays open here while the provider opens in another tab. Choose one source; the notes above are optional.
Block 5 of 6Understand Microsoft Entra application proxy
12 min
Understand Microsoft Entra application proxy
Optional concept notes
Microsoft Entra application proxy
Publishes an on-premises web application through outbound connectors and Entra preauthentication.
Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.
Your lesson stays open here while the provider opens in another tab. Choose one source; the notes above are optional.
Block 6 of 6Compare SAML-based single sign-on · Claims mapping policy
15 min
Compare SAML-based single sign-on · Claims mapping policy
Optional concept notes
SAML-based single sign-on
Uses signed SAML assertions to authenticate users to an integrated application.
Claims mapping policy
Changes selected claims issued to a supported service principal.
Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.
Your lesson stays open here while the provider opens in another tab. Choose one source; the notes above are optional.
Practice the reasoning here
Use a fictional tenant. Draw one access path, apply least privilege, test an exception, and name the logs that would confirm the result.
- State the expected result before changing or testing anything.
- Name the observation, command, log, or report that would confirm it.
- Explain why the closest alternative does not fit the same requirement.
Check the whole objective
This unlocks objective 3.2 for recall. The latest checkpoint needs 70% or higher; a lower result puts the lesson back near the front of your timeline.