Soru

Zorluk: OrtaMicrosoft Entra ID Authentication and Conditional Access

Meridian Retail is designing an identity security strategy for its Microsoft Entra ID tenant. You are configuring a Conditional Access policy that enforces multi-factor authentication (MFA) for all directory administrators. The design must prevent administrative lockout in the event of an Azure MFA service outage or policy misconfiguration. Which strategy should you include in the design?

  1. Exclude a dedicated, cloud-only emergency access account from the Conditional Access policy.Cevap
  2. B
    Apply the Conditional Access policy to all administrative accounts without any exclusions to guarantee uniform policy enforcement.
  3. C
    Assign administrative roles in Privileged Identity Management (PIM) as permanently active rather than eligible to bypass policy verification checks.
  4. D
    Implement on-premises Active Directory Federation Services (AD FS) to serve as the sole identity provider and MFA enforcement point for the cloud administrators.

Cevap

Exclude a dedicated, cloud-only emergency access account from the Conditional Access policy.
Excluding a dedicated, cloud-only emergency access account from the Conditional Access policy is a Microsoft best practice. In the event of an MFA service outage or policy misconfiguration, this excluded account can be used to log in and modify or disable the problematic policy.

Adım Adım Çözüm

1
Analyze the lockout risk requirement.
Identify that a tenant-wide Conditional Access policy enforcing MFA could lock out all administrators if a misconfiguration occurs or the MFA service experiences an outage.
To design a resilient authentication system, you must plan for contingency access.
2
Select the correct mitigation strategy.
Exclude a dedicated, highly secure, cloud-only administrative account (emergency or break-glass account) from the policy.
Excluding an account allows it to bypass the policy and serve as a recovery mechanism in emergencies.
3
Evaluate and discard incorrect alternatives.
Confirm that omitting exclusions, using permanently active PIM assignments, or introducing complex AD FS federation do not safely resolve the lockout concern and violate best practices.
This ensures the final solution adheres to Microsoft's identity design guidelines.

Anahtar Kavram

Microsoft Entra ID emergency access accounts and Conditional Access policy exclusions
Bu soruyu puanla