Soru

Zorluk: OrtaMicrosoft Entra ID Authentication and Conditional Access

An organization is designing a secure access and identity infrastructure using Microsoft Entra ID. The solution must enforce different access controls and verification methods depending on the context of the authentication attempt. Match each business or technical security requirement to the most appropriate Microsoft Entra ID or Conditional Access feature.

  • Require multi-factor authentication (MFA) only when a sign-in attempt is classified as a medium or high risk based on real-time telemetry.Conditional Access sign-in risk policy
  • Block access to cloud applications when user connections originate from geographic regions outside the organization's approved operating zones.Conditional Access named locations with block controls
  • Restrict administrative access to Microsoft Azure portal to require phishing-resistant authentication methods such as FIDO2 security keys.Conditional Access authentication strengths
  • Prevent non-compliant corporate devices from accessing business-critical cloud applications.Conditional Access device compliance requirement

Cevap

Sign-in risk policy matches with requiring MFA for medium/high risk; Named locations match with blocking access from unapproved geographic regions; Authentication strengths match with restricting administrative access to phishing-resistant methods; Device compliance requirement matches with blocking non-compliant devices.
The correct mapping pairs each operational requirement to its specialized Conditional Access or Entra ID authentication capability: risk-based policies monitor real-time threat levels, named locations restrict geographic access, authentication strengths dictate the credential type (such as phishing-resistant), and device state checks verify management compliance.

Adım Adım Çözüm

1
Identify the requirement to evaluate real-time sign-in safety and apply MFA selectively.
This requires evaluating risk levels on a per-session basis, which aligns with Microsoft Entra ID Protection's sign-in risk policies.
Sign-in risk checks verify if the credentials might be compromised during the authentication flow.
2
Identify the requirement to block access based on geographic location parameters.
This maps to defining named locations (either IP ranges or countries) and targeting them within a Conditional Access policy set to block access.
Named locations are the primary mechanism for location-based Conditional Access rules.
3
Identify the requirement to enforce phishing-resistant authentication methods for administrators.
This requires using Entra ID authentication strengths within a Conditional Access policy.
Authentication strengths allow granular specification of permitted credentials (such as FIDO2 security keys) rather than a general MFA challenge.
4
Identify the requirement to verify device health status before permitting app access.
This requires using the device compliance status grant control within a Conditional Access policy.
Conditional Access can read the device compliance status from mobile device management solutions like Microsoft Intune to grant or deny access.

Anahtar Kavram

Designing granular access control policies using Microsoft Entra ID Conditional Access and authentication configurations.
Bu soruyu puanla