Soru

Zorluk: KolayMicrosoft Entra ID Authentication and Conditional Access

HealthFirst Solutions is implementing Microsoft Entra ID to secure their cloud resources. The security team wants to enforce multi-factor authentication (MFA) for all administrative logins. To prevent tenant-wide administrative lockout during a potential MFA service outage, the IT team must safeguard two newly created emergency access accounts.

Which policy configuration should you recommend?

  1. Configure the Conditional Access policy to exclude the emergency access accounts from the policy scope.Cevap
  2. B
    Apply the Conditional Access policy to all administrative accounts, including the emergency access accounts, to ensure total security coverage.
  3. C
    Establish an Active Directory Federation Services (AD FS) infrastructure to federate authentication for the emergency access accounts.
  4. D
    Assign the Global Administrator role to the emergency access accounts as permanently active assignments in Privileged Identity Management (PIM).

Cevap

Configure the Conditional Access policy to exclude the emergency access accounts from the policy scope.
Excluding the emergency access accounts from the Conditional Access policy ensures that administrators can bypass MFA and log in to the tenant using basic authentication in the event of a system-wide MFA outage.

Adım Adım Çözüm

1
Identify the primary risk being addressed, which is a tenant-wide lockout in the event of an MFA service disruption.
Emergency access accounts must be able to bypass the MFA requirement during an outage.
If emergency accounts require MFA and the MFA service is down, administrators cannot log in to resolve the issue.
2
Evaluate the configuration options for Microsoft Entra Conditional Access policies.
Exclusions are the standard mechanism to exempt specific accounts from policy requirements.
Adding the emergency accounts to the exclusion list of the MFA Conditional Access policy allows them to authenticate with password-only credentials.

Anahtar Kavram

Excluding emergency access (break-glass) accounts from MFA-enforcing Conditional Access policies is essential to prevent permanent administrative lockout during service outages.
Tahmini Süre:1m 0s
Bu soruyu puanla