Soru

Zorluk: Çok zorMicrosoft Entra ID Authentication and Conditional Access

An organization is designing a hybrid identity, access, and governance solution for their Microsoft Entra ID tenant. The organization currently uses an on-premises Active Directory Domain Services (AD DS) directory and plans to synchronize identities to Entra ID. The solution must satisfy the following design requirements:
- Minimize the on-premises infrastructure footprint and runtime dependencies required for user authentication.
- Enable users to authenticate directly in the cloud.
- Enforce time-bound, just-in-time access for administrative roles using Microsoft Entra Privileged Identity Management (PIM).
- Enforce Multi-Factor Authentication (MFA) via Conditional Access for administrative roles while ensuring that the organization can always access the tenant in the event of a service outage or configuration error.

Which two of the following components should you include in the identity and access design? (Select TWO.)

  1. Configure Microsoft Entra Connect with Password Hash Synchronization (PHS) to handle user authentication in the cloud.Cevap
  2. Configure role assignments for administrative users as Eligible within Microsoft Entra Privileged Identity Management (PIM).Cevap
  3. C
    Deploy Active Directory Federation Services (AD FS) to establish a federated trust for all user authentication.
  4. D
    Configure role assignments for administrative users as Active and permanently assigned within Microsoft Entra Privileged Identity Management (PIM).
  5. E
    Create a Conditional Access policy enforcing Multi-Factor Authentication that applies to all Global Administrator accounts with zero exclusions.

Cevap

The correct components to include are configuring Microsoft Entra Connect with Password Hash Synchronization (PHS) for hybrid authentication and setting administrative role assignments as Eligible in Privileged Identity Management (PIM).
The design correctly selects Password Hash Synchronization (PHS) because it authenticates users directly in the cloud and has the lowest on-premises infrastructure footprint. Additionally, configuring PIM role assignments as Eligible ensures that administrators only obtain privileges when required and justified (just-in-time), rather than holding them permanently.

Adım Adım Çözüm

1
Analyze the hybrid identity requirements to choose the correct authentication method.
Password Hash Synchronization (PHS) is selected because it enables direct cloud authentication and requires minimal on-premises infrastructure, unlike AD FS which requires a large federation server footprint.
This satisfies the requirement to minimize on-premises infrastructure and authenticate directly in the cloud.
2
Evaluate administrative access requirements to select the appropriate Privileged Identity Management (PIM) configuration.
Administrative role assignments must be configured as 'Eligible' rather than permanently 'Active'.
This ensures users only receive privileged access just-in-time and for a limited duration, fulfilling the least-privileged access requirement.
3
Design the Conditional Access policy to enforce multi-factor authentication (MFA) safely.
Exclude emergency access (glass-breaker) accounts from the Conditional Access MFA policy.
This prevents administrative lockout in case of tenant-wide MFA issues or policy misconfigurations, ensuring emergency access is always available.
4
Synthesize the architecture choices to identify the correct design components.
Select the options recommending PHS and Eligible PIM assignments, while avoiding options proposing AD FS, permanently active PIM roles, or zero-exclusion MFA policies.
This integrates the selected authentication, privilege governance, and recovery components into a compliant design.

Anahtar Kavram

Microsoft Entra ID hybrid authentication methods, Privileged Identity Management (PIM) role configurations, and Conditional Access exclusion planning.
Tahmini Süre:3m 0s
Bu soruyu puanla