A global manufacturing company is designing an identity governance and access solution for its IT operations team. The team needs to occasionally perform security administrator tasks in Microsoft Entra ID. The solution must ensure that administrative permissions are not active by default, require multi-factor authentication (MFA) and a business justification to activate, and follow administrative best practices for scalability. Additionally, the company wants to ensure that their disaster recovery planning includes preventing tenant lockout for their break-glass accounts. Which of the following designs should you recommend to meet these requirements?
- Create a Microsoft Entra ID security group, assign the IT operations team members to the group, configure the group as eligible for the Security Administrator role in Privileged Identity Management (PIM), and exclude emergency access accounts from the administrative Conditional Access MFA policies.Cevap
- BConfigure each IT operations team member as eligible for the Security Administrator role in Privileged Identity Management (PIM) directly at the user level, and exclude emergency access accounts from the administrative Conditional Access MFA policies.
- CCreate a Microsoft Entra ID security group, assign the IT operations team members to the group, configure the group with an active assignment for the Security Administrator role in Privileged Identity Management (PIM), and exclude emergency access accounts from the administrative Conditional Access MFA policies.
- DCreate a Microsoft Entra ID security group, assign the IT operations team members to the group, configure the group as eligible for the Security Administrator role in Privileged Identity Management (PIM), and apply the administrative Conditional Access MFA policies to all administrator accounts without excluding emergency access accounts.
Cevap
Create a Microsoft Entra ID security group, assign the IT operations team members to the group, configure the group as eligible for the Security Administrator role in Privileged Identity Management (PIM), and exclude emergency access accounts from the administrative Conditional Access MFA policies.
The correct design creates a Microsoft Entra ID security group for group-based PIM assignment, configures eligibility to ensure just-in-time access, and excludes emergency access accounts from Conditional Access MFA policies to prevent lockout.
Adım Adım Çözüm
Anahtar Kavram
Privileged Identity Management group-based eligibility and emergency access exclusions
Tahmini Süre:1m 30s