An organization is designing a hybrid identity, access, and governance solution for their Microsoft Entra ID tenant. The organization currently uses an on-premises Active Directory Domain Services (AD DS) directory and plans to synchronize identities to Entra ID. The solution must satisfy the following design requirements:
- Minimize the on-premises infrastructure footprint and runtime dependencies required for user authentication.
- Enable users to authenticate directly in the cloud.
- Enforce time-bound, just-in-time access for administrative roles using Microsoft Entra Privileged Identity Management (PIM).
- Enforce Multi-Factor Authentication (MFA) via Conditional Access for administrative roles while ensuring that the organization can always access the tenant in the event of a service outage or configuration error.
Which two of the following components should you include in the identity and access design? (Select TWO.)
- Configure Microsoft Entra Connect with Password Hash Synchronization (PHS) to handle user authentication in the cloud.Answer
- Configure role assignments for administrative users as Eligible within Microsoft Entra Privileged Identity Management (PIM).Answer
- CDeploy Active Directory Federation Services (AD FS) to establish a federated trust for all user authentication.
- DConfigure role assignments for administrative users as Active and permanently assigned within Microsoft Entra Privileged Identity Management (PIM).
- ECreate a Conditional Access policy enforcing Multi-Factor Authentication that applies to all Global Administrator accounts with zero exclusions.