An enterprise is designing a privileged access governance strategy for its Azure subscriptions. The strategy must meet the following requirements:
- A team of system engineers requires temporary, approved administrative access to manage virtual machines.
- Administrative permissions must be managed at a group level rather than assigned to individual user accounts to ensure scalable governance.
- To prevent tenant-wide lockout during a potential multi-factor authentication (MFA) service outage, emergency break-glass accounts must be maintained.
Which of the following designs should you recommend?
- AConfigure Microsoft Entra ID Privileged Identity Management (PIM) for Groups using a role-assignable group where engineers are permanently active members, and exclude the emergency break-glass accounts from the Conditional Access policy that requires MFA.
- BConfigure Microsoft Entra ID Privileged Identity Management (PIM) for Azure Resources to assign individual engineer user accounts directly as eligible for the Virtual Machine Contributor role, and exclude the emergency break-glass accounts from the Conditional Access policy that requires MFA.
- Configure Microsoft Entra ID Privileged Identity Management (PIM) for Groups using a role-assignable group where engineers are eligible members, and exclude the emergency break-glass accounts from the Conditional Access policy that requires MFA.Cevap
- DConfigure Microsoft Entra ID Privileged Identity Management (PIM) for Groups using a role-assignable group where engineers are eligible members, and include all accounts, including the emergency break-glass accounts, in the Conditional Access policy that requires MFA.
Cevap
Configure Microsoft Entra ID Privileged Identity Management (PIM) for Groups using a role-assignable group where engineers are eligible members, and exclude the emergency break-glass accounts from the Conditional Access policy that requires MFA.
The correct design utilizes Microsoft Entra ID PIM for Groups to grant JIT administrative privileges in a scalable, group-based manner. Additionally, it respects security best practices by excluding emergency break-glass accounts from the MFA Conditional Access policy to ensure resilience against service outages.
Adım Adım Çözüm
Anahtar Kavram
Designing secure, scalable administrative access using group-based PIM governance and resilient emergency access policies.
Tahmini Süre:1m 30s