Soru

Zorluk: Çok zorSelf-Service Password Reset and External Identities

An organization is configuring Microsoft Entra ID to support various corporate and external collaboration requirements. Match each administrative requirement on the left to its corresponding minimum configuration or licensing setting on the right.

  • Restrict guest users from searching the directory and inviting other guests, while permitting member users who do not have directory administrator roles to invite guests.Set guest invite settings to 'Member users and users assigned to specific admin roles can invite guest users' in External Collaboration settings.
  • Allow external users to self-register for a corporate web application, authenticate using their Google accounts, and automatically receive a dynamic group membership.Configure a Google Identity Provider, create a self-service sign-up user flow, and assign Microsoft Entra ID P1 licenses to support dynamic groups.
  • Ensure that when cloud-only users reset their passwords, they must provide both a mobile app notification and a security question, and this capability must only be enabled for members of a specific department.Set SSPR enablement to 'Selected' for a group, select Microsoft Entra ID P1 licenses, and choose Mobile app notification and Security questions as authentication methods.
  • Enable users synchronized from on-premises AD to perform SSPR, ensuring their passwords are changed in the on-premises directory and that custom banned passwords are blocked on-premises.Enable password writeback in Microsoft Entra Connect, deploy Microsoft Entra Password Protection agents on domain controllers, and assign Microsoft Entra ID P1 licenses.

Cevap

Match the requirements as follows: 1) Restrict guest invites to members/admins matches Guest Invite settings set to member users and specific admin roles. 2) Google self-register with dynamic groups matches Google Identity Provider, self-service user flow, and Microsoft Entra ID P1. 3) Scoped SSPR with mobile app/security questions matches SSPR enabled for Selected group, P1 licenses, and the selected auth methods. 4) Hybrid SSPR with custom banned passwords matches on-premises writeback in Entra Connect, Entra Password Protection agents, and P1 licenses.
Matching each scenario correctly requires understanding Microsoft Entra ID features and licensing tiers. Scoped SSPR, Dynamic Groups, Password Writeback, and Microsoft Entra Password Protection all require Microsoft Entra ID P1. Guest invitation restrictions are handled under External Collaboration settings, and external self-service sign-up utilizes User Flows paired with external Identity Providers like Google.

Adım Adım Çözüm

1
Analyze the guest invitation requirements.
Identified that guest users should not invite others, but members should be able to. This is configured in the External Collaboration settings of Microsoft Entra ID under Guest Invite Settings.
To restrict guest access while maintaining membership invitation privileges without requiring administrator roles.
2
Analyze the self-service sign-up and dynamic group assignment requirements.
Determined that Google federation and user flows handle external registration, and dynamic groups (which require Microsoft Entra ID P1) automate group membership.
To verify that dynamic group features for guest users require the appropriate tenant licensing tier.
3
Analyze SSPR scoping and authentication requirements for cloud-only departmental users.
Determined that scoping SSPR to 'Selected' groups rather than the entire tenant requires Microsoft Entra ID P1. The authentication methods must include mobile app notification and security questions.
To ensure correct SSPR scoping rules and authentication method selection are implemented under the correct license constraints.
4
Analyze hybrid SSPR and on-premises custom password protection requirements.
Identified that password writeback via Microsoft Entra Connect syncs password changes to on-premises AD, and Microsoft Entra Password Protection agents enforce banned passwords on-premises. Both require Microsoft Entra ID P1.
To validate hybrid SSPR writeback capability and Password Protection integration with Active Directory Domain Services.

Anahtar Kavram

Microsoft Entra ID Self-Service Password Reset (SSPR) licensing, scoping, authentication methods, hybrid writeback, and External Collaboration B2B guest invitation and user flow settings.
Bu soruyu puanla