Soru

Zorluk: ZorMicrosoft Entra ID Authentication and Conditional Access

AeroSpire Aerospace is designing a hybrid identity and access management solution for a new Microsoft Entra ID tenant that integrates with an on-premises Active Directory Domain Services (AD DS) forest. The solution must meet the following requirements:

- Users on corporate-joined devices must be automatically signed in without entering credentials.
- On-premises server infrastructure dependencies and operational overhead for identity federation must be minimized.
- All directory administrators must be prompted for multi-factor authentication (MFA) when accessing the Azure portal, using a Just-In-Time (JIT) administrative access workflow.
- In the event of a tenant-wide MFA service disruption, at least one administrative account must retain emergency access to the Azure portal.

Which of the following solutions should you recommend to meet the requirements?

  1. Configure Password Hash Synchronization (PHS) with Seamless Single Sign-On (SSO). Configure Microsoft Entra Privileged Identity Management (PIM) with eligible role assignments. Implement a Conditional Access policy requiring MFA for Microsoft Azure Management, and exclude a dedicated cloud-only emergency access account from the policy.Cevap
  2. B
    Configure Active Directory Federation Services (AD FS) to establish identity federation. Configure Microsoft Entra Privileged Identity Management (PIM) with eligible role assignments. Implement a Conditional Access policy requiring MFA for Microsoft Azure Management, and exclude a dedicated cloud-only emergency access account from the policy.
  3. C
    Configure Password Hash Synchronization (PHS) with Seamless Single Sign-On (SSO). Configure Microsoft Entra Privileged Identity Management (PIM) with permanently active role assignments. Implement a Conditional Access policy requiring MFA for Microsoft Azure Management, and exclude a dedicated cloud-only emergency access account from the policy.
  4. D
    Configure Password Hash Synchronization (PHS) with Seamless Single Sign-On (SSO). Configure Microsoft Entra Privileged Identity Management (PIM) with eligible role assignments. Implement a Conditional Access policy requiring MFA for Microsoft Azure Management, and apply the policy to all administrative accounts without any exclusions.

Cevap

Configure Password Hash Synchronization (PHS) with Seamless Single Sign-On (SSO). Configure Microsoft Entra Privileged Identity Management (PIM) with eligible role assignments. Implement a Conditional Access policy requiring MFA for Microsoft Azure Management, and exclude a dedicated cloud-only emergency access account from the policy.
The correct solution uses Password Hash Synchronization (PHS) with Seamless SSO to satisfy the Single Sign-On and minimal infrastructure requirements. Microsoft Entra PIM with eligible role assignments implements the JIT administrative workflow. Finally, excluding a dedicated cloud-only emergency access account from the Conditional Access policy ensures administrative access is maintained if the MFA service is disrupted.

Adım Adım Çözüm

1
Select the appropriate hybrid authentication method.
Password Hash Synchronization (PHS) with Seamless SSO.
PHS with Seamless SSO fulfills the automatic sign-in requirement for corporate network-connected devices while keeping on-premises infrastructure minimal compared to AD FS.
2
Determine the administrative governance model.
Configure Microsoft Entra Privileged Identity Management (PIM) with eligible role assignments.
Setting assignments to eligible rather than active ensures that administrators must activate their roles when needed, implementing a JIT access model.
3
Design the Conditional Access policy and lockout protection mechanism.
Enforce MFA for the Microsoft Azure Management app while excluding a cloud-only emergency access account.
Excluding a dedicated, highly secured emergency access (break-glass) account ensures that administrators do not get locked out of the tenant in case of an MFA platform outage.

Anahtar Kavram

Designing secure, resilient identity architecture using Microsoft Entra authentication, Privileged Identity Management, and Conditional Access exclusions.
Tahmini Süre:2m 30s
Bu soruyu puanla