📝 Section Review: Identity & Authentication
اہم نکاتKey TakeawaysKey Takeaways
- Identity Awareness صارفین کو IPs سے جوڑتا ہے تاکہ رولز پتے کے بجائے 'Finance team' کہہ سکیں — Zero Trust سوچ۔Identity Awareness users ko IPs se map karta hai taake rules address ke bajaye 'Finance team' keh sakein — Zero Trust سوچ۔Identity Awareness maps users to IPs so rules can say 'the Finance team' instead of an address — Zero Trust thinking.
- شناخت کے ذرائع: AD Query، Identity Agent، browser-based auth، captive portal — ماحول کے مطابق چنیں۔Identity sources: AD Query, Identity Agent, browser-based auth, captive portal — environment ke mutabiq chunein.Identity sources: AD Query, Identity Agent, browser-based auth, captive portal — pick what fits the environment.
- رول کے ذرائع کے طور پر Access Roles (AD گروپس سے منسلک) استعمال کریں؛ یہ نفاذ کے وقت صارفین میں حل ہوتے ہیں۔Rule sources ke tor par Access Roles (AD groups se linked) use karein; yeh enforcement ke waqt users mein resolve hote hain.Use Access Roles (tied to AD groups) as rule sources; they resolve to users at enforcement time.
- Captive portal مہمانوں/BYOD کو cover کرتا ہے جہاں agent یا AD لاگ اِن موجود نہ ہو۔Captive portal guests/BYOD ko cover karta hai jahan agent ya AD logon maujood na ho.Captive portal covers guests/BYOD where no agent or AD logon exists.
خود جانچ (مشق)Self-Check (Practice)Self-Check (Practice)
یہ مشقی سوالات ہیں، امتحانی سوالات نہیں۔These are practice questions, not exam questions.These are practice questions, not exam questions.
❓ چار شناخت کے ذرائع کے نام بتائیں۔Chaar identity sources ke naam batayein.Name the four identity sources.
AD Query (ڈومین لاگ اِن events)، کمپیوٹر پر Identity Agent، browser-based authentication، اور captive portal۔AD Query (domain logon events), PC par Identity Agent, browser-based authentication, aur captive portal۔AD Query (domain logon events), Identity Agent on the PC, browser-based authentication, and captive portal.
❓ صارف پر مبنی رول کبھی میچ نہیں کرتا۔ کیا رول ٹوٹا ہے؟User-based rule kabhi match nahi karta. Kya rule toota hai?A user-based rule never matches. Is the rule broken?
نہیں — گیٹ وے نے صارف کی شناخت کبھی سیکھی ہی نہیں۔ شناخت کا ذریعہ چیک کریں (AD connectivity، agent، captive portal trigger) اور لاگز میں صارف دیکھیں۔Nahi — gateway ne user ki identity kabhi seekhi hi nahi. Identity source check karein (AD connectivity, agent, captive portal trigger) aur logs mein user dekhein.No — the gateway never learned the user's identity. Check the identity source (AD connectivity, agent, captive portal trigger) and look for the user in the logs.
❓ بغیر AD اکاؤنٹ والے مہمانوں کو کیسے authenticate کریں؟Baghair AD account wale guests ko kaise authenticate karein?How do you authenticate guests with no AD account?
Captive portal: نامعلوم صارفین کو شناخت پر مبنی رولز لگنے سے پہلے گیٹ وے لاگ اِن صفحہ ملتا ہے — مہمانوں اور BYOD کے لیے بہترین۔Captive portal: unknown users ko identity-based rules lagne se pehle gateway login page milta hai — guests aur BYOD ke liye behtareen.Captive portal: unknown users get a gateway login page before identity-based rules apply — ideal for guests and BYOD.