Soru

Zorluk: OrtaMicrosoft Entra ID Authentication and Conditional Access

Contoso, Ltd. has an on-premises Active Directory Domain Services (AD DS) domain that synchronizes with a Microsoft Entra ID tenant. You are designing the identity security and hybrid authentication strategy for the organization. The design must meet the following requirements:
- Users must be able to authenticate to cloud applications even if the on-premises data center is offline.
- The security team must enforce multi-factor authentication (MFA) via Conditional Access policies for all users, but must ensure that administrators do not get locked out of the tenant in the event of a tenant-wide Entra ID MFA service outage.

Which two actions should you include in the design? (Select two.)

  1. Configure Password Hash Synchronization (PHS) as the primary hybrid authentication method.Cevap
  2. Create two dedicated emergency access accounts and exclude them from all Conditional Access policies.Cevap
  3. C
    Configure Active Directory Federation Services (AD FS) to manage all user authentication requests.
  4. D
    Enable permanently active roles for all administrators using Microsoft Entra Privileged Identity Management (PIM).

Cevap

Configure Password Hash Synchronization (PHS) as the primary hybrid authentication method, and create two dedicated emergency access accounts and exclude them from all Conditional Access policies.
Selecting Password Hash Synchronization (PHS) ensures cloud authentication continues even if the on-premises infrastructure is unavailable, satisfying the first requirement. Creating dedicated emergency access accounts and excluding them from all Conditional Access policies ensures that administrators can still sign in and manage the tenant during an MFA outage, preventing total lockout.

Adım Adım Çözüm

1
Analyze the resiliency requirement for authentication when the on-premises data center is offline.
Identify that Password Hash Synchronization (PHS) allows Microsoft Entra ID to perform authentication directly in the cloud, removing any runtime dependency on on-premises AD DS.
This directly fulfills the requirement of enabling user authentication during on-premises outages.
2
Analyze the requirement to prevent administrator lockout during an Entra ID MFA service outage.
Identify that Microsoft Entra ID best practices dictate the creation of dedicated emergency access (break-glass) accounts that are excluded from all Conditional Access policies, including MFA.
This ensures that at least one administrative account can bypass Conditional Access blocks to access the tenant if the MFA service experiences an outage.

Anahtar Kavram

Designing a resilient hybrid identity authentication method (PHS) and a secure Conditional Access policy that avoids lockout via emergency access exclusions.
Tahmini Süre:1m 30s
Bu soruyu puanla