Aventis Pharmaceuticals is designing a secure access and identity solution for its Microsoft Entra ID tenant. The tenant will synchronize identities from an on-premises Active Directory Domain Services (AD DS) environment.
The solution must meet the following requirements:
- Enforce multi-factor authentication (MFA) for all administrative users using Conditional Access policies.
- Ensure that administrators can access the tenant even if a misconfiguration or outage affects the MFA service.
- Prevent administrators from having standing access to highly privileged roles.
- Implement the simplest possible hybrid identity authentication model that requires no on-premises server infrastructure for credential validation.
Which two of the following components should you include in the identity and authentication design? (Select TWO.)
- A dedicated, cloud-only emergency access account that is explicitly excluded from the Conditional Access policyAnswer
- Password Hash Synchronization (PHS) to provide hybrid identity authenticationAnswer
- CActive Directory Federation Services (AD FS) to handle user authentication for all synchronized identities
- DA Conditional Access policy that enforces MFA for all administrator accounts without any exclusions
- EPrivileged Identity Management (PIM) assignments configured as permanently active for the designated administrator accounts