Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

7.1. Glossary A-Z

  • Access Package — A bundled, requestable set of resources under entitlement management (3.4.1).
  • Access Review — A recurring process verifying existing access is still needed (3.4.2).
  • Active Directory Domain Services (AD DS) — Microsoft's on-premises directory service (2.2.4).
  • Adaptive Application Controls — Learns normal application behavior on a VM and alerts on unexpected software (4.2.4).
  • Agent ID — An identity type for AI agents acting autonomously (3.1.2).
  • Assume Breach — A Zero Trust principle: design as though an attacker is already inside (2.1.3).
  • Asymmetric Encryption — Encryption using a linked public/private key pair (2.1.4).
  • Audit (Purview) — Logs and searches user/admin activity across Microsoft 365 (5.4.3).
  • Authentication — Verifying who a user or identity is (2.2.2).
  • Authorization — Determining what an authenticated identity is allowed to do (2.2.2).
  • Azure Bastion — Managed, secure RDP/SSH access without exposing public IPs (4.1.6).
  • Azure Firewall — Centralized, managed L3-L7 firewall with FQDN filtering and threat intel (4.1.2).
  • Azure Key Vault — Centralized store for secrets, keys, and certificates (4.1.7).
  • CIA Triad — Confidentiality, integrity, availability — the three properties security protects (1.1).
  • Cloud Security Posture Management (CSPM) — Continuous scanning for misconfigurations against best practices (4.2.2).
  • Cloud Workload Protection (CWP) — Active threat detection/prevention for running workloads (4.2.4).
  • Compliance Manager — Purview's workflow tool for assessments and improvement actions (5.2.2).
  • Compliance Score — A risk-weighted numeric summary generated from Compliance Manager (5.2.3).
  • Conditional Access — A policy engine granting access based on real-time signals (3.3.1).
  • Content Explorer — Shows where classified sensitive content currently exists (5.3.2).
  • Data Loss Prevention (DLP) — Real-time policies blocking or flagging risky sharing of sensitive content (5.3.4).
  • Defender for Cloud — Unified multicloud CSPM + workload protection platform (4.2.1).
  • Defender for Cloud Apps — CASB discovering and governing SaaS application usage (4.4.4).
  • Defender for Endpoint — EDR platform detecting and responding to device-level threats (4.4.3).
  • Defender for Identity — Monitors on-premises AD signals for identity-based attacks (4.4.5).
  • Defender for Office 365 — Protects email/collaboration content from phishing and malicious attachments (4.4.2).
  • Defender Portal — Unified console for incidents across all Defender products (4.4.8).
  • Defender Threat Intelligence (Defender TI) — External attacker infrastructure and IOC data (4.4.7).
  • Defender Vulnerability Management — Discovers, assesses, and prioritizes software/device vulnerabilities (4.4.6).
  • Defender XDR — Correlation layer unifying signals across Defender products into single incidents (4.4.1).
  • Defense-in-Depth — Layered security controls across multiple independent layers (2.1.2).
  • Directory Service — A structured store of identity objects like users and groups (2.2.4).
  • Disposition Review — Human review before disposal of a record at end of retention (5.3.5).
  • DDoS Protection — Mitigates volumetric denial-of-service attacks (4.1.1).
  • eDiscovery — Identifies, preserves, and exports content relevant to legal matters (5.4.2).
  • Entitlement Management — Governed, requestable access packages under Entra ID Governance (3.4.1).
  • Federation — A trust relationship letting one identity provider's authentication be accepted by another system (2.2.5).
  • FIDO2 — A phishing-resistant, passwordless hardware authentication key standard (3.2.1).
  • GRC (Governance, Risk, and Compliance) — Three interdependent disciplines: setting policy, prioritizing risk, verifying adherence (2.1.5).
  • Hashing — A one-way transformation used for integrity verification or secret storage (2.1.4).
  • Hybrid Identity — Synchronizing on-premises AD identities with Microsoft Entra ID (3.1.3).
  • Identity Protection (Entra ID Protection) — Detects and scores sign-in/user risk (3.4.4).
  • Identity Provider (IdP) — A service that authenticates identities and issues tokens (2.2.3).
  • Insider Risk Management — Detects risky behavior signals from within the organization (5.4.1).
  • Just-in-Time (JIT) Access — Access granted only when needed, for a limited window (3.4.3, 4.2.4).
  • Least Privilege — Granting only the access needed, for only as long as needed (2.1.3).
  • Legal Hold — Preserves content from deletion during an active eDiscovery case (5.4.2).
  • Managed Identity — A credential-free, Azure-managed service principal (3.1.2).
  • Microsoft Entra Connect — The synchronization engine for hybrid identity (3.1.3).
  • Microsoft Entra ID — Microsoft's cloud-native identity provider and directory platform (3.1.1).
  • Microsoft Purview — Microsoft's unified compliance and data governance platform (5.2.1).
  • Multifactor Authentication (MFA) — Requiring two or more independent verification factors (3.2.2).
  • Network Security Group (NSG) — A stateful, lightweight L3/4 packet filter (4.1.5).
  • Password Protection — Blocks known weak/breached passwords at set/change time (3.2.3).
  • Pass-Through Authentication — A hybrid identity method forwarding auth checks to on-prem AD (3.1.3).
  • Password Hash Sync — A hybrid identity method syncing a hash of the password hash to the cloud (3.1.3).
  • Playbook (Sentinel) — An automated, orchestrated response to a detected incident (4.3.1).
  • Privileged Identity Management (PIM) — Just-in-time, time-bound activation of eligible privileged roles (3.4.3).
  • RBAC (Role-Based Access Control) — Granting permissions via role assignment rather than individual grants (3.3.2).
  • Records Management — Formal lifecycle management of official regulated business records (5.3.5).
  • Retention Label — Granular, item-level control over how long content is kept (5.3.6).
  • Retention Policy — Broad, location-level control over how long content is kept (5.3.6).
  • Risk (security) — The likelihood and impact of a threat exploiting a vulnerability (1.1).
  • Secure Score — Defender for Cloud's summary metric of security best-practice adherence (4.2.1).
  • Self-Service Password Reset (SSPR) — Lets users reset a forgotten password without help-desk involvement (3.2.3).
  • Sensitive Information Type — A pattern-based classifier for structured sensitive data (5.3.1).
  • Sensitivity Label — A persistent tag enforcing content protection like encryption (5.3.3).
  • Service Principal — An identity representing an application or service (3.1.2).
  • Service Trust Portal — Microsoft's repository of audit reports and compliance documentation (5.1.1).
  • Shared Responsibility Model — How security obligations split between provider and customer by service type (2.1.1).
  • SIEM (Security Information and Event Management) — Collecting and analyzing security data to detect patterns (4.3.1).
  • SOAR (Security Orchestration, Automated Response) — Automating response actions to detected threats (4.3.1).
  • Symmetric Encryption — Encryption using one shared key for both encrypting and decrypting (2.1.4).
  • Threat — Anything that could exploit a vulnerability (1.1).
  • Trainable Classifier — A machine-learning model identifying less-structured sensitive content categories (5.3.1).
  • Vulnerability — A weakness that a threat could exploit (1.1).
  • Web Application Firewall (WAF) — Layer 7 protection against application-layer attacks like SQL injection (4.1.3).
  • Windows Hello for Business — Biometric or PIN-based, device-bound passwordless authentication (3.2.1).
  • Zero Trust — A security model of verify explicitly, least privilege, and assume breach (2.1.3).
Alvin Varughese
Written byAlvin Varughese
Founder18 professional certifications