Soru

Zorluk: Çok zorMicrosoft Entra ID Authentication and Conditional Access

An international shipping company, Pacific Cargo Enterprises, is designing an identity and access management solution for its Microsoft Entra ID tenant. The tenant contains several custom administrative roles and standard built-in roles. The security architecture must meet the following requirements:
1. All users assigned to administrative roles must be prompted for multi-factor authentication (MFA) and must connect from a compliant device when accessing Azure management portals.
2. The risk of administrative lockout due to an emergency or a misconfigured Conditional Access policy must be mitigated.
3. Access to high-privilege roles, such as Global Administrator, must be limited to just-in-time (JIT) activation and subject to approval.

Which two configurations should you include in the design to satisfy these requirements? (Select two.)

  1. A Conditional Access policy that targets all administrative directory roles, requires multi-factor authentication and device compliance, and excludes a group containing two dedicated emergency access accounts.Cevap
  2. Microsoft Entra Privileged Identity Management (PIM) role settings for the Global Administrator role configured with eligible assignments that require justification, multi-factor authentication, and approval upon activation.Cevap
  3. C
    A single Conditional Access policy that targets all directory roles and enforces multi-factor authentication with zero exclusions to guarantee that administrative bypass is impossible.
  4. D
    Microsoft Entra Privileged Identity Management (PIM) role settings for the Global Administrator role configured as active assignments with a permanent duration to allow immediate recovery during a tenant outage.

Cevap

A Conditional Access policy that targets administrative directory roles, requires multi-factor authentication and device compliance, and excludes emergency access accounts; along with Microsoft Entra Privileged Identity Management (PIM) configured with eligible assignments requiring approval.
To secure administrative access while preventing accidental lockout, a best-practice design uses Microsoft Entra Conditional Access policies combined with emergency access (break-glass) accounts. These emergency accounts must be excluded from policies that enforce multi-factor authentication (MFA) and device compliance, ensuring they can still log in if MFA or device registration services fail. Additionally, using Microsoft Entra Privileged Identity Management (PIM) with eligible assignments ensures that high-privilege roles like Global Administrator are only active when needed (just-in-time) and require approval, rather than being permanently assigned.

Adım Adım Çözüm

1
Analyze the access and resiliency requirements for administrative accounts in Microsoft Entra ID.
Identify that emergency access (break-glass) accounts are required to mitigate tenant lockout.
Excluding emergency accounts from strict Conditional Access policies is critical to maintain tenant access during a failure.
2
Determine the optimal configuration for Microsoft Entra Privileged Identity Management (PIM).
Select eligible assignments for the Global Administrator role instead of active assignments.
Eligible assignments enforce just-in-time access, reducing the exposure of highly privileged accounts.
3
Synthesize the results to select the correct architectural recommendations.
Combine the exclusion of emergency accounts in Conditional Access with eligible assignments in PIM.
This dual approach fulfills the security requirement for MFA and device compliance while maintaining tenant recoverability and least privilege.

Anahtar Kavram

Designing secure administrative access using Microsoft Entra ID Conditional Access exclusions and Privileged Identity Management (PIM).
Tahmini Süre:3m 0s
Bu soruyu puanla