Your company has a Microsoft Entra tenant. You are designing a privileged access solution for a group of helpdesk operators. The operators must be able to reset user passwords, but they should only have these administrative privileges when actively responding to support tickets, up to a maximum of 4 hours per session. Additionally, their identity must be verified using multi-factor authentication (MFA) each time they request these privileges.
Which two configurations should you recommend to meet these requirements? (Choose two.)
- Set the assignment type for the helpdesk operators to Eligible in Microsoft Entra Privileged Identity Management (PIM).Cevap
- Configure the role activation settings in Microsoft Entra Privileged Identity Management (PIM) to require multi-factor authentication.Cevap
- CSet the assignment type for the helpdesk operators to Active in Microsoft Entra Privileged Identity Management (PIM).
- DAssign the Helpdesk Administrator role directly to each operator's individual user account in Microsoft Entra ID.
Cevap
To meet the requirements, you must set the assignment type for the operators to Eligible in Microsoft Entra Privileged Identity Management (PIM) and configure the role settings to require multi-factor authentication on activation.
Configuring the assignment as eligible in Privileged Identity Management (PIM) ensures that users do not have permanent standing administrative access and must explicitly activate the role when needed (just-in-time access). Requiring multi-factor authentication (MFA) within the PIM role activation settings ensures that the user's identity is verified at the moment of activation, fulfilling both security requirements.
Adım Adım Çözüm
Anahtar Kavram
Microsoft Entra Privileged Identity Management (PIM) enables just-in-time access governance and step-up authentication configuration for administrative roles.