Soru

Zorluk: ZorMicrosoft Entra ID Authentication and Conditional Access

An organization is designing an identity and access management architecture for its new Microsoft Entra ID tenant. The organization currently has an on-premises Active Directory Domain Services (AD DS) environment.

The design must satisfy the following technical requirements:
- Synchronize hybrid user accounts to Microsoft Entra ID while minimizing on-premises infrastructure footprint, maintenance overhead, and licensing costs.
- Secure highly privileged administrative roles by enforcing Just-In-Time (JIT) access, requiring Multi-Factor Authentication (MFA) upon role activation.
- Safeguard against accidental administrative lockout from the tenant during a widespread MFA service disruption or policy misconfiguration.

Which two of the following design recommendations should you include to meet these requirements?

  1. Recommend Password Hash Synchronization (PHS) with Seamless Single Sign-On (SSO) as the hybrid identity authentication method.Cevap
  2. Configure eligible administrative role assignments in Privileged Identity Management (PIM), and exclude emergency access accounts from the Conditional Access MFA policies.Cevap
  3. C
    Deploy Active Directory Federation Services (AD FS) on-premises to handle identity federation and authentication request routing.
  4. D
    Configure active administrative role assignments in Privileged Identity Management (PIM), and enforce Conditional Access MFA policies on all administrative accounts without exclusions.

Cevap

Recommend Password Hash Synchronization (PHS) with Seamless Single Sign-On (SSO) as the hybrid identity authentication method, and configure eligible administrative role assignments in Privileged Identity Management (PIM) while excluding emergency access accounts from the Conditional Access MFA policies.
Selecting Password Hash Synchronization (PHS) with Seamless SSO provides a high-availability identity solution with the smallest on-premises infrastructure footprint. Pairing this with eligible role assignments in Privileged Identity Management (PIM) enforces Just-In-Time access. Finally, excluding emergency access accounts from Conditional Access policies avoids administrative lockout in the event of an MFA service failure.

Adım Adım Çözüm

1
Select the hybrid authentication model that minimizes on-premises infrastructure.
Password Hash Synchronization (PHS) with Seamless Single Sign-On (SSO) is selected.
PHS does not require additional on-premises servers or inbound network access, unlike Active Directory Federation Services (AD FS) or Pass-through Authentication (PTA) with multiple agents.
2
Address the requirement for Just-In-Time (JIT) access and administrative MFA.
Configure eligible assignments in Privileged Identity Management (PIM) that require MFA verification upon activation.
Eligible assignments prevent permanent privilege accumulation and ensure admins are only granted roles temporarily after performing MFA.
3
Design lockout prevention measures for emergency tenant access.
Create emergency access (break-glass) accounts and exclude them from Conditional Access MFA policies.
If MFA is globally enforced without exclusions, a service disruption or policy misconfiguration can permanently lock all administrators out of the tenant.

Anahtar Kavram

Microsoft Entra ID hybrid identity design, Just-In-Time administrative governance, and Conditional Access lockout resilience.
Bu soruyu puanla