An organization is designing a privileged access solution for a team of external database administrators who need temporary access to the DocumentDB Database Account Contributor role on a production Cosmos DB account. The solution must minimize administrative overhead, enforce multi-factor authentication (MFA) and justification prior to access activation, and ensure that emergency access accounts are protected from lockout during MFA service outages. Which configuration should you recommend?
- AAssign the role eligibility directly to each administrator's user account in Privileged Identity Management (PIM) requiring justification and MFA for activation, and exclude emergency access accounts from the Conditional Access policy requiring MFA.
- Create a Microsoft Entra ID security group for the administrators, make the group eligible for the role in Privileged Identity Management (PIM) requiring justification and MFA for activation, and exclude emergency access accounts from the Conditional Access policy requiring MFA.Answer
- CCreate a Microsoft Entra ID security group for the administrators, assign the group permanently active status for the role in Privileged Identity Management (PIM) to avoid activation delays, and exclude emergency access accounts from the Conditional Access policy requiring MFA.
- DCreate a Microsoft Entra ID security group for the administrators, make the group eligible for the role in Privileged Identity Management (PIM) requiring justification and MFA for activation, and require MFA for all accounts including emergency access accounts in the Conditional Access policy.
Answer
Create a Microsoft Entra ID security group for the administrators, make the group eligible for the role in Privileged Identity Management (PIM) requiring justification and MFA for activation, and exclude emergency access accounts from the Conditional Access policy requiring MFA.
The correct option addresses all governance requirements by using group-based assignment to minimize management overhead, configuring eligible status in PIM to require JIT activation with justification and MFA, and excluding emergency access accounts from MFA requirements to prevent administrative lockout.
Step-by-Step Solution
Key Concept
Entra ID Privileged Access and Governance
Estimated Time:1m 30s