Soru

Zorluk: OrtaEntra ID Governance and Privileged Access

An enterprise is designing a privileged access governance strategy for its Azure subscriptions. The strategy must meet the following requirements:
- A team of system engineers requires temporary, approved administrative access to manage virtual machines.
- Administrative permissions must be managed at a group level rather than assigned to individual user accounts to ensure scalable governance.
- To prevent tenant-wide lockout during a potential multi-factor authentication (MFA) service outage, emergency break-glass accounts must be maintained.

Which of the following designs should you recommend?

  1. A
    Configure Microsoft Entra ID Privileged Identity Management (PIM) for Groups using a role-assignable group where engineers are permanently active members, and exclude the emergency break-glass accounts from the Conditional Access policy that requires MFA.
  2. B
    Configure Microsoft Entra ID Privileged Identity Management (PIM) for Azure Resources to assign individual engineer user accounts directly as eligible for the Virtual Machine Contributor role, and exclude the emergency break-glass accounts from the Conditional Access policy that requires MFA.
  3. Configure Microsoft Entra ID Privileged Identity Management (PIM) for Groups using a role-assignable group where engineers are eligible members, and exclude the emergency break-glass accounts from the Conditional Access policy that requires MFA.Cevap
  4. D
    Configure Microsoft Entra ID Privileged Identity Management (PIM) for Groups using a role-assignable group where engineers are eligible members, and include all accounts, including the emergency break-glass accounts, in the Conditional Access policy that requires MFA.

Cevap

Configure Microsoft Entra ID Privileged Identity Management (PIM) for Groups using a role-assignable group where engineers are eligible members, and exclude the emergency break-glass accounts from the Conditional Access policy that requires MFA.
The correct design utilizes Microsoft Entra ID PIM for Groups to grant JIT administrative privileges in a scalable, group-based manner. Additionally, it respects security best practices by excluding emergency break-glass accounts from the MFA Conditional Access policy to ensure resilience against service outages.

Adım Adım Çözüm

1
Address the group-based governance requirement.
Identify that administrative privileges must be granted to an Entra ID group rather than assigning individual roles directly to user accounts.
Direct assignments to user accounts violate scalability best practices and complicate management.
2
Ensure privileged access is temporary and just-in-time (JIT).
Configure the group assignments using Microsoft Entra ID PIM for Groups, defining the engineers as eligible members rather than active members.
Active assignments grant standing access, whereas eligible assignments require JIT activation, which enforces approval and tracking.
3
Mitigate the risk of tenant lockout during MFA failure.
Exclude emergency break-glass accounts from the Conditional Access policy that enforces MFA for administrative access.
Excluding these accounts guarantees access to the tenant in emergency situations where the MFA provider is unavailable.

Anahtar Kavram

Designing secure, scalable administrative access using group-based PIM governance and resilient emergency access policies.
Tahmini Süre:1m 30s
Bu soruyu puanla