Soru

Zorluk: KolayAzure RBAC and Subscription Governance

An enterprise is designing a security and subscription governance strategy for its Azure environment. Which two of the following configurations align with Microsoft best practices for scalable access control and the principle of least privilege?

  1. Create Microsoft Entra ID groups for administrative functions and assign the required Azure RBAC roles to these groups.Cevap
  2. B
    Assign Azure RBAC roles directly to individual user accounts to guarantee precise user-level audit tracking.
  3. Configure Microsoft Entra Privileged Identity Management (PIM) role assignments as eligible rather than permanently active.Cevap
  4. D
    Configure Microsoft Entra Privileged Identity Management (PIM) assignments as permanently active to reduce access activation overhead.

Cevap

The correct configurations are to assign Azure RBAC roles to Microsoft Entra ID groups instead of individual users, and to configure Microsoft Entra Privileged Identity Management (PIM) role assignments as eligible instead of permanently active.
Assigning roles to Microsoft Entra ID groups instead of individual users simplifies administration and ensures scalability. Using Privileged Identity Management (PIM) with eligible assignments enforces the principle of least privilege through just-in-time access control, requiring activation rather than granting standing privileges.

Adım Adım Çözüm

1
Evaluate the scalability of assigning RBAC roles to users versus groups.
Assigning roles to Microsoft Entra ID groups reduces administrative overhead and ensures scalability as team members change.
Direct user assignments violate identity governance best practices and make access management difficult to audit and maintain.
2
Analyze the access duration and eligibility configuration for highly privileged roles.
Configuring PIM assignments as eligible ensures users must request activation to obtain permissions, adhering to just-in-time access.
Permanently active assignments violate the principle of least privilege by leaving privileged access continuously enabled.

Anahtar Kavram

Azure RBAC Group Assignment and PIM Just-In-Time Access
Bu soruyu puanla