Soru

Zorluk: OrtaEntra ID Governance and Privileged Access

An enterprise is onboarding an external vendor to perform temporary maintenance on Azure Virtual Machines located in a production resource group. The maintenance window is 30 days. The design must enforce the principle of least privilege, require multi-factor authentication (MFA) and manager approval before accessing the resources, and automatically clean up access after the maintenance period. Which two configurations should you include in the identity governance and privileged access design?

  1. Create a Microsoft Entra ID security group for the vendor accounts, and configure the group as eligible for the Virtual Machine Contributor role at the resource group level in Privileged Identity Management (PIM).Cevap
  2. Configure PIM role settings for the Virtual Machine Contributor role to require MFA and approval upon activation, and set the assignment duration to expire after 30 days.Cevap
  3. C
    Assign the Virtual Machine Contributor role directly to each vendor user account at the resource group level.
  4. D
    Configure a permanently active role assignment in PIM for the vendor group to ensure access is always available without delay.

Cevap

Configure group eligibility for the Virtual Machine Contributor role using PIM, and configure PIM settings to require MFA, manager approval, and an eligibility duration of 30 days.
The correct architecture uses group-based role assignments in Entra ID to simplify management. By configuring the group as eligible in Privileged Identity Management (PIM), the vendor accounts do not hold permanent administrative privileges. Activating the role requires MFA and approval as configured in the role settings, and setting an eligibility lifetime of 30 days ensures access is automatically revoked.

Adım Adım Çözüm

1
Consolidate the vendor users into a dedicated Entra ID security group.
Simplifies governance by avoiding direct user role assignments.
Aligns with Microsoft's recommended practice of group-based identity administration.
2
Assign the security group as eligible for the Virtual Machine Contributor role at the resource group scope in PIM.
Ensures the role is not constantly active and can be requested on-demand.
Implements Just-In-Time (JIT) access to enforce the principle of least privilege.
3
Modify the Virtual Machine Contributor role activation settings in PIM to require MFA and approval, and limit the eligibility duration to 30 days.
Enforces strong authentication, administrative oversight, and automatic decommissioning of access.
Meets the specific business requirements of MFA enforcement, approval, and auto-revocation.

Anahtar Kavram

Applying Entra ID Privileged Identity Management (PIM) with group-based RBAC to enforce temporary, approved, and authenticated just-in-time administrative access.
Bu soruyu puanla