Contoso, Ltd. has an on-premises Active Directory Domain Services (AD DS) domain that synchronizes with a Microsoft Entra ID tenant. You are designing the identity security and hybrid authentication strategy for the organization. The design must meet the following requirements:
- Users must be able to authenticate to cloud applications even if the on-premises data center is offline.
- The security team must enforce multi-factor authentication (MFA) via Conditional Access policies for all users, but must ensure that administrators do not get locked out of the tenant in the event of a tenant-wide Entra ID MFA service outage.
Which two actions should you include in the design? (Select two.)
- Configure Password Hash Synchronization (PHS) as the primary hybrid authentication method.Cevap
- Create two dedicated emergency access accounts and exclude them from all Conditional Access policies.Cevap
- CConfigure Active Directory Federation Services (AD FS) to manage all user authentication requests.
- DEnable permanently active roles for all administrators using Microsoft Entra Privileged Identity Management (PIM).
Cevap
Configure Password Hash Synchronization (PHS) as the primary hybrid authentication method, and create two dedicated emergency access accounts and exclude them from all Conditional Access policies.
Selecting Password Hash Synchronization (PHS) ensures cloud authentication continues even if the on-premises infrastructure is unavailable, satisfying the first requirement. Creating dedicated emergency access accounts and excluding them from all Conditional Access policies ensures that administrators can still sign in and manage the tenant during an MFA outage, preventing total lockout.
Adım Adım Çözüm
Anahtar Kavram
Designing a resilient hybrid identity authentication method (PHS) and a secure Conditional Access policy that avoids lockout via emergency access exclusions.
Tahmini Süre:1m 30s