Soru

Zorluk: OrtaHybrid and Multi-Tenant Identity Solutions

Nebula Genomics is designing a hybrid identity and governance solution to integrate their on-premises Active Directory Domain Services (AD DS) forest of 12,000 users with Microsoft Entra ID.

The solution must satisfy the following constraints:
- Users must be able to authenticate to cloud applications even if the network connection between the on-premises datacenter and Azure is temporarily offline.
- Users must be able to use self-service password reset (SSPR) in the cloud, with changes automatically updating the on-premises AD DS.
- Azure resource administrative access must support just-in-time (JIT) activation and prevent users from having persistent administrative privileges.

Which identity synchronization and governance configuration should you recommend?

  1. A
    Implement Active Directory Federation Services (AD FS) with password writeback enabled, and use Microsoft Entra Privileged Identity Management (PIM) with eligible role assignments.
  2. B
    Implement Pass-through Authentication (PTA) with password writeback enabled, and use Microsoft Entra Privileged Identity Management (PIM) with permanently active role assignments.
  3. Implement Password Hash Synchronization (PHS) with password writeback enabled, and use Microsoft Entra Privileged Identity Management (PIM) with eligible role assignments.Cevap
  4. D
    Implement Password Hash Synchronization (PHS) with password writeback enabled, and assign Azure role-based access control (RBAC) administrative roles directly to individual user accounts.

Cevap

Implement Password Hash Synchronization (PHS) with password writeback enabled, and use Microsoft Entra Privileged Identity Management (PIM) with eligible role assignments.
The correct configuration uses Password Hash Synchronization (PHS) with password writeback and Microsoft Entra Privileged Identity Management (PIM) with eligible role assignments. PHS enables authentication to function entirely in the cloud during on-premises network outages because user credentials are cached in Microsoft Entra ID. Password writeback ensures that cloud-based password resets sync back to the on-premises domain controllers. Lastly, configuring PIM with eligible role assignments enforces the principle of least privilege by requiring users to activate administrative roles on-demand (just-in-time) rather than holding permanent privileges.

Adım Adım Çözüm

1
Evaluate the authentication availability requirement.
Password Hash Synchronization (PHS) is selected.
Unlike Pass-through Authentication (PTA) or Active Directory Federation Services (AD FS), PHS allows Microsoft Entra ID to process logins entirely in the cloud, ensuring authentication remains operational if the link to the on-premises datacenter is offline.
2
Evaluate the self-service password reset (SSPR) writing back to on-premises requirement.
Password writeback must be enabled in Microsoft Entra Connect.
Password writeback is a feature of Microsoft Entra Connect that allows password changes made in the cloud to be written back to the on-premises directory in real time.
3
Evaluate the administrative governance and JIT requirement.
Configure Microsoft Entra Privileged Identity Management (PIM) with eligible role assignments.
PIM ensures that administrators do not have persistent access; they must activate their roles on-demand (JIT) using eligible assignments.

Anahtar Kavram

Designing a secure and resilient hybrid identity sync and administrative governance strategy using Password Hash Sync and Microsoft Entra Privileged Identity Management.
Tahmini Süre:1m 30s
Bu soruyu puanla