Soru

Zorluk: OrtaMicrosoft Entra ID Authentication and Conditional Access

An organization is designing the identity security and authentication strategy for its Microsoft Entra ID tenant. You need to match the business and security requirements to the correct Microsoft Entra ID or Conditional Access feature. Match each requirement on the left to its corresponding feature on the right.

  • Require users accessing sensitive applications from untrusted network locations to complete a multi-factor authentication (MFA) prompt.Conditional Access policy utilizing Location conditions and Grant controls
  • Block access or require MFA for sign-in attempts that exhibit atypical travel patterns or malware-linked IP addresses.Conditional Access policy utilizing Sign-in risk conditions
  • Enforce read-only web-only access and prevent file downloads when users access SharePoint Online from unmanaged personal devices.Conditional Access policy utilizing App Enforced Restrictions session controls
  • Allow users to authenticate in the cloud using their on-premises passwords, with authentication requests validated directly against local Active Directory domain controllers without storing hashes in the cloud.Pass-through Authentication (PTA) with Microsoft Entra Connect

Cevap

The business requirements are matched as follows: location-based MFA requirements match with Location conditions and Grant controls; risk-based sign-in blocking/MFA requirements match with Sign-in risk conditions; read-only access for unmanaged devices on SharePoint Online matches with App Enforced Restrictions session controls; and password validation against on-premises Active Directory without cloud hashes matches with Pass-through Authentication.
The correct matches align the scenarios with their proper Azure security and authentication mechanisms. Requiring MFA for untrusted locations matches Location conditions and Grant controls. Sign-in risks like atypical travel match Sign-in risk conditions. Restricting downloads on unmanaged devices matches App Enforced Restrictions. Validating passwords on-premises without cloud hashes matches Pass-through Authentication.

Adım Adım Çözüm

1
Analyze the requirement for location-based MFA to determine which Conditional Access condition and control applies.
Identify that Location conditions define the network source, and Grant controls enforce the MFA requirement.
This matches the requirement of requiring MFA when users access applications from untrusted networks.
2
Analyze the requirement to detect atypical travel or malware-linked IP addresses during sign-in.
Identify that these behaviors are flagged as sign-in risks, which are handled using Sign-in risk conditions under Conditional Access.
This matches the requirement to enforce security controls based on real-time sign-in risk.
3
Analyze the requirement to restrict SharePoint Online downloads from unmanaged personal devices.
Identify that App Enforced Restrictions session controls allow SharePoint Online to limit session capabilities based on device compliance/management state.
This matches the requirement to prevent downloads and enforce a limited web-only session.
4
Analyze the authentication requirement that validates passwords on-premises without cloud hash storage.
Identify that Pass-through Authentication (PTA) routes password validation directly to on-premises domain controllers using agents, keeping password verification local.
This satisfies the hybrid identity authentication requirement without storing password hashes in Microsoft Entra ID.

Anahtar Kavram

Microsoft Entra ID Authentication methods and Conditional Access policies (including locations, risks, session controls, and hybrid authentication modes like Pass-through Authentication).
Tahmini Süre:1m 30s
Bu soruyu puanla