A logistics company needs to grant five IT support technicians the capability to manage Azure resources, but only when they are actively resolving support tickets. You need to design a privileged access strategy using Microsoft Entra Privileged Identity Management (PIM) that ensures administrative access is time-bound and adheres to identity governance best practices. Which of the following configurations should you include in your design? (Select TWO.)
- AAssign the target Azure roles directly to the individual user accounts of the technicians.
- BConfigure the security group's assignment in Microsoft Entra PIM as permanently Active.
- Assign the target Azure roles to a Microsoft Entra security group.Cevap
- Configure the security group's assignment in Microsoft Entra PIM as Eligible.Cevap
Cevap
The correct approach is to assign the target Azure roles to a Microsoft Entra security group and configure the security group's assignment in Microsoft Entra PIM as Eligible.
Assigning the target Azure roles to a Microsoft Entra security group adheres to the best practice of managing access at the group level rather than the individual level. Configuring the security group's assignment in Microsoft Entra PIM as Eligible ensures that the support technicians do not hold standing privileges and must explicitly activate their access when performing tasks, fulfilling the requirement for time-bound access.
Adım Adım Çözüm
Anahtar Kavram
Microsoft Entra PIM supports group-based role assignments and eligible states to enforce just-in-time access and scalable governance.
Tahmini Süre:45s