Meridian Retail is designing an identity security strategy for its Microsoft Entra ID tenant. You are configuring a Conditional Access policy that enforces multi-factor authentication (MFA) for all directory administrators. The design must prevent administrative lockout in the event of an Azure MFA service outage or policy misconfiguration. Which strategy should you include in the design?
- Exclude a dedicated, cloud-only emergency access account from the Conditional Access policy.Cevap
- BApply the Conditional Access policy to all administrative accounts without any exclusions to guarantee uniform policy enforcement.
- CAssign administrative roles in Privileged Identity Management (PIM) as permanently active rather than eligible to bypass policy verification checks.
- DImplement on-premises Active Directory Federation Services (AD FS) to serve as the sole identity provider and MFA enforcement point for the cloud administrators.
Cevap
Exclude a dedicated, cloud-only emergency access account from the Conditional Access policy.
Excluding a dedicated, cloud-only emergency access account from the Conditional Access policy is a Microsoft best practice. In the event of an MFA service outage or policy misconfiguration, this excluded account can be used to log in and modify or disable the problematic policy.
Adım Adım Çözüm
Anahtar Kavram
Microsoft Entra ID emergency access accounts and Conditional Access policy exclusions