Soru

Zorluk: OrtaMicrosoft Entra ID Authentication and Conditional Access

AeroSpace Tech Partners is designing a hybrid identity solution that integrates their on-premises Active Directory Domain Services (AD DS) with Microsoft Entra ID. The design must satisfy the following requirements:
- On-premises users must authenticate to cloud resources using their existing credentials.
- Cloud authentication must remain functional even if the on-premises datacenter experiences a complete network and power outage.
- The deployment of additional on-premises servers or agents for authentication must be avoided.
- All users must be prompted for multi-factor authentication (MFA) when accessing cloud applications.
- The organization must prevent administrative lockout in the event of an MFA service outage or misconfiguration.

Which identity authentication and Conditional Access design should you recommend?

  1. A
    Implement Pass-through Authentication (PTA) as the authentication method, and configure a Conditional Access policy that requires MFA for all users except for a dedicated emergency access account that is excluded from the policy.
  2. B
    Implement Password Hash Synchronization (PHS) as the authentication method, and configure a Conditional Access policy that requires MFA for all users, ensuring that no accounts are excluded to maintain maximum security and zero-trust alignment.
  3. Implement Password Hash Synchronization (PHS) as the authentication method, and configure a Conditional Access policy that requires MFA for all users except for a dedicated emergency access account that is excluded from the policy.Cevap
  4. D
    Implement Password Hash Synchronization (PHS) as the authentication method. Configure a Conditional Access policy requiring MFA, and assign the emergency access account to a permanently active Global Administrator role using Privileged Identity Management (PIM).

Cevap

Implement Password Hash Synchronization (PHS) as the authentication method, and configure a Conditional Access policy that requires MFA for all users except for a dedicated emergency access account that is excluded from the policy.
The correct answer proposes Password Hash Synchronization (PHS) which satisfies the requirement to authenticate users in the cloud even if the on-premises network or datacenter experiences an outage, without deploying additional servers. It also correctly recommends excluding a dedicated emergency access account from the multi-factor authentication (MFA) Conditional Access policy, which is the standard Microsoft architecture guidance to prevent tenant lockout during MFA service failures.

Adım Adım Çözüm

1
Determine the appropriate hybrid authentication method based on availability and infrastructure constraints.
Select Password Hash Synchronization (PHS) as the authentication method.
Unlike Pass-through Authentication (PTA) or federation, PHS processes authentication requests entirely in the cloud using synchronization, meaning cloud authentication remains fully functional if the on-premises datacenter experiences an outage. It also requires no additional on-premises agents or servers for authentication flow.
2
Identify the resilience best practices for administrator accounts in Microsoft Entra ID.
Determine that a dedicated emergency access ('break-glass') account must be created and excluded from Conditional Access MFA policies.
If a service failure affects multi-factor authentication (MFA), having an active, excluded administrator account prevents complete administrative lockout.
3
Combine the authentication mechanism and policy configuration into a unified architecture design.
Design the system to use PHS, and enforce MFA via Conditional Access with an exclusion for the emergency access account.
This configuration satisfies all availability, management overhead, and tenant safety requirements.

Anahtar Kavram

Designing hybrid identity authentication and resilient Conditional Access policies including emergency access exclusions.
Bu soruyu puanla