Soru

Zorluk: KolayEntra ID Governance and Privileged Access

You are designing a privileged access solution for a team of support staff who require temporary, time-bound access to administrative roles in Azure. You also need to configure a tenant-wide emergency access (break-glass) account. Which configuration should you recommend to ensure secure administrative access and prevent tenant lockout?

  1. Configure the administrative roles as eligible for a Microsoft Entra ID security group containing the support staff, and exclude the emergency access account from Conditional Access policies requiring Multi-Factor Authentication (MFA).Cevap
  2. B
    Configure the administrative roles as active for a Microsoft Entra ID security group containing the support staff, and exclude the emergency access account from Conditional Access policies requiring Multi-Factor Authentication (MFA).
  3. C
    Configure the administrative roles as eligible directly on the individual user accounts of the support staff, and exclude the emergency access account from Conditional Access policies requiring Multi-Factor Authentication (MFA).
  4. D
    Configure the administrative roles as eligible for a Microsoft Entra ID security group containing the support staff, and enforce Multi-Factor Authentication (MFA) on the emergency access account through Conditional Access policies.

Cevap

Configure the administrative roles as eligible for a Microsoft Entra ID security group containing the support staff, and exclude the emergency access account from Conditional Access policies requiring Multi-Factor Authentication (MFA).
The correct option combines three Microsoft Entra governance best practices. First, using eligible assignments ensures that support staff must activate their roles only when needed, minimizing the risk of compromised standing privileges. Second, assigning administrative roles to a security group rather than individuals aligns with group-based access control guidelines, reducing administrative overhead. Third, excluding the break-glass/emergency access account from MFA ensures that administrators can still access the tenant in the event of an MFA infrastructure failure.

Adım Adım Çözüm

1
Select the correct role assignment type in Microsoft Entra Privileged Identity Management (PIM).
Use 'eligible' role assignments instead of 'active' assignments to enforce just-in-time (JIT) access.
Active assignments grant standing privileges, whereas eligible assignments require users to perform activation steps only when access is needed.
2
Determine the identity structure for role assignments.
Assign the roles to a Microsoft Entra ID security group containing the users rather than to individual user accounts.
Group-based role assignment simplifies administration, aligns with RBAC best practices, and allows membership changes to govern role access automatically.
3
Apply Conditional Access policies for the emergency access account.
Exclude the emergency (break-glass) account from policies that enforce Multi-Factor Authentication (MFA).
Emergency accounts must remain accessible during MFA service outages or disaster recovery scenarios where standard administrators cannot log in.

Anahtar Kavram

Best practices for Microsoft Entra Privileged Identity Management (PIM) role assignments and emergency access governance.
Tahmini Süre:1m 0s
Bu soruyu puanla