Soru

Zorluk: Çok zorHybrid and Multi-Tenant Identity Solutions

Zephyr Logistics is designing a hybrid identity solution to integrate its on-premises Active Directory Domain Services (AD DS) forest, internal.zephyrlogistics.com, with a Microsoft Entra ID tenant. The solution must meet the following requirements:
- Users must be able to sign in to cloud services using their on-premises credentials.
- Authentication to cloud services must continue to function even if all on-premises Active Directory domain controllers or the corporate network connection become completely unavailable.
- Users on domain-joined corporate devices inside the corporate network must experience seamless single sign-on (SSO).
- Multi-factor authentication (MFA) must be enforced for all users when accessing cloud applications, but the design must guarantee that administrators are not locked out of the tenant in the event of an MFA service disruption.
- Users must be able to change their passwords in the cloud, and these changes must be reflected on-premises immediately.

Which two actions should you include in the hybrid identity design? (Select two.)

  1. Configure Password Hash Synchronization (PHS) and enable Seamless Single Sign-On (SSO) in Microsoft Entra Connect.Cevap
  2. Configure a Conditional Access policy requiring Multi-Factor Authentication (MFA) for all users, and exclude a dedicated emergency access account from the policy.Cevap
  3. C
    Configure Pass-through Authentication (PTA) with Microsoft Entra Connect and deploy redundant agents on on-premises servers.
  4. D
    Configure a Conditional Access policy requiring Multi-Factor Authentication (MFA) for all users, including all administrative accounts, without exceptions to ensure maximum security compliance.

Cevap

Configure Password Hash Synchronization (PHS) with Seamless SSO in Microsoft Entra Connect, and configure a Conditional Access policy requiring MFA for all users while excluding a dedicated emergency access account.
To meet the business continuity and authentication requirements, Password Hash Synchronization (PHS) is required because it syncs password hashes to the cloud, enabling users to authenticate even if on-premises servers or connectivity are down. Seamless SSO satisfies the single sign-on requirement for domain-joined corporate devices on the network. To meet the security and emergency access requirements, a Conditional Access policy enforcing MFA should be created, but it must exclude a dedicated emergency access account to prevent administrative lockout during an identity or MFA service disruption.

Adım Adım Çözüm

1
Analyze authentication and business continuity requirements.
Identify that Password Hash Synchronization (PHS) must be used because it is the only hybrid sync method that allows authentication in Microsoft Entra ID when the on-premises domain controllers or network connectivity are offline.
Pass-through Authentication (PTA) or Active Directory Federation Services (AD FS) require operational on-premises servers/agents to validate credentials, which would fail if the on-premises network or domain controllers are down.
2
Determine the required single sign-on configuration.
Choose Seamless SSO to provide single sign-on for domain-joined devices on the corporate network.
This meets the requirement of providing seamless single sign-on from corporate devices inside the corporate network without adding the complexity of AD FS.
3
Address the secure access and lockout prevention constraints.
Design a Conditional Access policy requiring MFA for all users, but explicitly exclude a dedicated emergency access account.
Excluding the emergency access account ensures that administrators can still access the tenant to resolve issues during a global MFA or federation service outage.

Anahtar Kavram

Designing a secure, resilient hybrid identity solution using Password Hash Synchronization (PHS), Seamless SSO, and Conditional Access with emergency account exclusions.
Bu soruyu puanla