An organization is designing a security and access control strategy for its Microsoft Entra ID tenant to protect cloud resources. You need to align the specific security requirements to the corresponding Microsoft Entra ID or Conditional Access features. Match each security requirement to the correct Microsoft Entra ID condition or session control.
- Enforce a maximum session lifetime of 1 hour for high-privilege web access to the Azure portal.Conditional Access session control: Sign-in frequency
- Restrict downloading, printing, or syncing files from SharePoint Online when users connect from unmanaged personal devices.Conditional Access session control: App-enforced restrictions
- Prompt for multi-factor authentication (MFA) only when Entra ID Protection flags a sign-in attempt as having anomalous telemetry.Conditional Access condition: Sign-in risk
- Force a password change and require MFA when there is high confidence that a user's credentials have been leaked on the dark web.Conditional Access condition: User risk
Cevap
Enforce session lifetime matches Sign-in frequency; restrict SharePoint downloads matches App-enforced restrictions; anomalous sign-in prompt matches Sign-in risk; password change for leaked credentials matches User risk.
The correct pairings map each technical requirement to the correct Entra ID capability. Enforcing a maximum session lifetime is configured via Sign-in frequency. Restricting file actions in SharePoint Online is handled by App-enforced restrictions. anomalous sign-in sessions are assessed using Sign-in risk, and leaked credentials represent identity compromise assessed via User risk.
Adım Adım Çözüm
Anahtar Kavram
Microsoft Entra ID Authentication and Conditional Access
Tahmini Süre:2m 0s