Soru

Zorluk: OrtaEntra ID Governance and Privileged Access

A digital publishing company is implementing a governance policy for external compliance reviewers who need temporary read-only access to all resources in a production subscription. The access must be time-limited, require multi-factor authentication (MFA) and business justification, and minimize administrative overhead by avoiding individual assignment configurations.

Which two configurations should you recommend as part of the solution? (Select two.)

  1. Create a Microsoft Entra security group, assign the Reader role to this group at the subscription scope, and configure the compliance reviewers as eligible members of this group in Privileged Identity Management (PIM).Cevap
  2. In the PIM activation settings for the group, require multi-factor authentication (MFA), justification, and set the maximum activation duration to 8 hours.Cevap
  3. C
    Assign the Reader role directly to each compliance reviewer's user account and configure them as eligible for the role in PIM for Azure resources.
  4. D
    Configure the compliance reviewers as active, permanent members of the security group and configure a Conditional Access policy to restrict their access during non-working hours.

Cevap

Create a Microsoft Entra security group, assign the Reader role to this group at the subscription scope, and configure the compliance reviewers as eligible members of this group in Privileged Identity Management (PIM), and in the PIM activation settings for the group, require multi-factor authentication (MFA), justification, and set the maximum activation duration to 8 hours.
To design a secure, low-overhead solution, you should assign the subscription Reader role to a Microsoft Entra security group and configure the reviewers as eligible members of the group in PIM. This leverages group-based RBAC to keep administrative overhead low. Additionally, you should configure the PIM activation settings for the group to enforce the requirements of multi-factor authentication (MFA), justification, and a maximum activation duration of 8 hours, ensuring time-bound and justified just-in-time access.

Adım Adım Çözüm

1
Evaluate the administrative overhead requirement.
Determine that assigning roles directly to individual user accounts scales poorly and increases administrative overhead. Group-based assignment must be used.
Best practice dictates using group-based assignments for RBAC rather than individual assignments to keep governance manageable and scalable.
2
Determine the PIM approach for group-based resources.
Create a Microsoft Entra ID group, assign the subscription Reader role to it, and use PIM for Groups to manage group membership eligibility.
This allows the external reviewers to be added as eligible members who can activate their membership in the group on-demand, which automatically grants them the Reader role at the subscription level.
3
Enforce just-in-time constraints, MFA, and justification.
Configure the PIM group activation settings to require MFA, business justification, and a maximum activation duration of 8 hours.
This ensures that users can only activate their access when needed, must justify it, must perform MFA, and the access automatically expires after 8 hours.

Anahtar Kavram

Using Privileged Identity Management (PIM) for Groups to manage membership eligibility with JIT activation settings, combined with group-based Azure RBAC assignment, to enforce least privilege and minimize administrative overhead.
Bu soruyu puanla