Soru

Zorluk: OrtaMicrosoft Entra ID Authentication and Conditional Access

Veloce Logistics is designing a hybrid identity and security strategy to integrate its on-premises Active Directory Domain Services (AD DS) environment with Microsoft Entra ID. The IT security team has the following requirements:

- Users must be able to sign in to cloud resources using their on-premises credentials.
- If a security incident occurs in the on-premises environment or network connectivity to on-premises is lost, users must still be able to sign in to cloud services without relying on on-premises infrastructure.
- To prevent tenant lockout during a cloud-based multi-factor authentication (MFA) service outage, the security administrator must ensure at least one highly privileged emergency access account can bypass MFA.
- Administrative roles must be managed using Privileged Identity Management (PIM) to prevent persistent administrative privileges.

Which of the following represents the most appropriate combination of hybrid authentication and policy design for Veloce Logistics?

  1. A
    Deploy Active Directory Federation Services (AD FS) to handle all authentication requests directly against on-premises domain controllers. Create a Conditional Access policy requiring MFA for all users, but exclude a dedicated emergency access account from this policy. Configure Privileged Identity Management (PIM) role assignments as eligible rather than active.
  2. Configure Microsoft Entra Connect with Password Hash Synchronization (PHS). Create a Conditional Access policy requiring MFA for all users, but exclude a dedicated emergency access account from this policy. Configure Privileged Identity Management (PIM) role assignments as eligible rather than active.Cevap
  3. C
    Configure Microsoft Entra Connect with Password Hash Synchronization (PHS). Create a Conditional Access policy requiring MFA for all users and administrative accounts, with no exclusions, to maximize security. Configure Privileged Identity Management (PIM) role assignments as eligible rather than active.
  4. D
    Configure Microsoft Entra Connect with Password Hash Synchronization (PHS). Create a Conditional Access policy requiring MFA for all users, but exclude a dedicated emergency access account from this policy. Configure Privileged Identity Management (PIM) role assignments as active rather than eligible.

Cevap

Configure Microsoft Entra Connect with Password Hash Synchronization (PHS), exclude a dedicated emergency access account from the MFA Conditional Access policy, and assign Privileged Identity Management (PIM) roles as eligible.
The correct option correctly identifies Password Hash Synchronization (PHS) as the hybrid identity solution that satisfies the dependency requirement, since authentication occurs directly in Microsoft Entra ID without calling back to on-premises. It also ensures that the emergency access account is excluded from the MFA requirement to prevent tenant lockout during a service outage, and specifies that PIM roles must be eligible rather than active to prevent persistent administrative privileges.

Adım Adım Çözüm

1
Evaluate the hybrid authentication options against the resiliency requirement.
Password Hash Synchronization (PHS) is selected because it replicates credential hashes to Microsoft Entra ID. This allows users to authenticate in the cloud even if on-premises domain controllers or connection links are offline. Active Directory Federation Services (AD FS) and Pass-through Authentication (PTA) require active on-premises communication.
To ensure authentication capability is not dependent on on-premises infrastructure or connectivity.
2
Address the risk of lockout during a cloud MFA service outage.
Exclude a dedicated emergency access (break-glass) account from the Conditional Access policy requiring MFA.
This guarantees that administrators can still access the tenant if the cloud MFA service is experiencing an outage.
3
Configure the administrative access governance model.
Configure Privileged Identity Management (PIM) role assignments as 'Eligible' rather than 'Active'.
This ensures administrators must explicitly activate their roles on-demand (just-in-time) rather than maintaining permanent, persistent privileges.

Anahtar Kavram

Designing a resilient hybrid identity, authentication, and access control strategy using Microsoft Entra ID, including Password Hash Synchronization, Conditional Access policy exclusions, and Privileged Identity Management (PIM) eligibility.
Tahmini Süre:1m 30s
Bu soruyu puanla