HealthFirst Solutions is implementing Microsoft Entra ID to secure their cloud resources. The security team wants to enforce multi-factor authentication (MFA) for all administrative logins. To prevent tenant-wide administrative lockout during a potential MFA service outage, the IT team must safeguard two newly created emergency access accounts.
Which policy configuration should you recommend?
- Configure the Conditional Access policy to exclude the emergency access accounts from the policy scope.Cevap
- BApply the Conditional Access policy to all administrative accounts, including the emergency access accounts, to ensure total security coverage.
- CEstablish an Active Directory Federation Services (AD FS) infrastructure to federate authentication for the emergency access accounts.
- DAssign the Global Administrator role to the emergency access accounts as permanently active assignments in Privileged Identity Management (PIM).
Cevap
Configure the Conditional Access policy to exclude the emergency access accounts from the policy scope.
Excluding the emergency access accounts from the Conditional Access policy ensures that administrators can bypass MFA and log in to the tenant using basic authentication in the event of a system-wide MFA outage.
Adım Adım Çözüm
Anahtar Kavram
Excluding emergency access (break-glass) accounts from MFA-enforcing Conditional Access policies is essential to prevent permanent administrative lockout during service outages.
Tahmini Süre:1m 0s