Soru

Zorluk: OrtaMicrosoft Entra ID Authentication and Conditional Access

Zenith Financial Services is designing the identity security and authentication strategy for its Microsoft Entra ID tenant. The organization requires that all administrator roles use Multi-Factor Authentication (MFA). To prevent total tenant lockout during a regional authentication outage, the security team requires the creation of two emergency access accounts.

Which design decision should you recommend to meet these requirements?

  1. Configure a Conditional Access policy that requires MFA for all administrator roles, exclude the emergency access accounts from the policy, and assign the administrator roles to users as eligible in Microsoft Entra Privileged Identity Management (PIM).Cevap
  2. B
    Configure a Conditional Access policy that requires MFA for all administrator roles with no exclusions, and assign the administrator roles to users as eligible in Microsoft Entra Privileged Identity Management (PIM).
  3. C
    Configure a Conditional Access policy that requires MFA for all administrator roles, exclude the emergency access accounts from the policy, and configure the administrator roles as permanently active for all admin users.
  4. D
    Deploy an on-premises Active Directory Federation Services (AD FS) infrastructure to handle all MFA requests, federate authentication for the tenant, and exclude the emergency access accounts from Entra Connect sync.

Cevap

Configure a Conditional Access policy that requires MFA for all administrator roles, exclude the emergency access accounts from the policy, and assign the administrator roles to users as eligible in Microsoft Entra Privileged Identity Management (PIM).
The correct solution involves configuring a Microsoft Entra Conditional Access policy that mandates Multi-Factor Authentication (MFA) for administrative roles, while explicitly excluding the designated emergency access accounts. To maintain security best practices, administrative permissions should be assigned as eligible via Privileged Identity Management (PIM) rather than permanently active. This ensures just-in-time activation and minimizes the standing privilege attack surface.

Adım Adım Çözüm

1
Evaluate the requirement for enforcing administrative MFA while avoiding lockout.
Identify that a Conditional Access policy must target administrative roles to enforce MFA, but must also contain an explicit exclusion rule for emergency (break-glass) accounts.
Omitting exclusions for emergency access accounts risks permanent tenant lockout if Microsoft Entra MFA is unavailable or misconfigured.
2
Determine the optimal administrative role assignment strategy.
Recommend Microsoft Entra Privileged Identity Management (PIM) with 'eligible' role assignments rather than permanent activation.
Eligible assignments support the principle of least privilege by requiring just-in-time activation and justification.
3
Assess the hybrid authentication options.
Reject AD FS deployment as a solution for cloud-based lockout.
AD FS introduces heavy infrastructure overhead, and cloud-only emergency accounts should not depend on on-premises components anyway.

Anahtar Kavram

Conditional Access policies should enforce MFA for administrative accounts while excluding cloud-only emergency access accounts to prevent tenant lockout, complemented by PIM for just-in-time role activation.
Bu soruyu puanla