Soru

Zorluk: OrtaMicrosoft Entra ID Authentication and Conditional Access

You are designing an identity and access management solution for a company. Match each security requirement to the most appropriate Microsoft Entra ID or Conditional Access feature.

  • Require administrative users to request temporary elevation to active roles and verify their identity via MFA prior to managing Azure resources.Entra ID Privileged Identity Management (PIM) role activation settings
  • Bypass MFA requirements for users who are accessing cloud resources from the corporate office's public IP range.Conditional Access policy using Named Locations (IP ranges) configured as trusted locations
  • Block access to cloud applications for users connecting from specific geographical locations outside of the corporate footprint.Conditional Access policy using geography-based Named Locations with block controls
  • Enforce multifactor authentication (MFA) only when a user's sign-in attempt shows a medium or high risk level.Entra ID Protection User risk or Sign-in risk policy

Cevap

The security requirements are mapped as follows: Role activation settings in Entra ID Privileged Identity Management (PIM) are used to enforce MFA and approval for temporary admin elevation. Trusted IP Named Locations in Conditional Access are used to bypass MFA for corporate networks. Geography-based Named Locations with block controls in Conditional Access are used to block access from unauthorized countries. Entra ID Protection Sign-in risk policies are used to enforce MFA dynamically based on sign-in risk levels.
The correct pairings align specific identity and security controls with Entra ID features. Enabling PIM role activation settings manages temporary admin privilege elevation. Marking corporate IP ranges as trusted Named Locations enables location-based MFA bypass in Conditional Access. Creating geographic Named Locations with block controls restricts unauthorized international sign-ins. Applying Entra ID Protection policies secures sign-ins based on calculated risk thresholds.

Adım Adım Çözüm

1
Analyze administrative elevation and MFA requirements.
Identify that temporary elevation and MFA before administrative actions map to Entra ID Privileged Identity Management (PIM).
PIM is designed to manage, control, and monitor access to important resources, including requiring approval and MFA for active role assignment.
2
Analyze trusted network bypass requirements.
Identify that bypassing MFA using corporate office IP ranges maps to Conditional Access with IP-based trusted Named Locations.
Conditional Access policies can exclude trusted locations (defined by IP ranges) from MFA requirements.
3
Analyze geographical restriction requirements.
Identify that blocking access from unauthorized countries maps to Conditional Access with geography-based Named Locations.
Geography-based Named Locations define country borders, which can be referenced in Conditional Access policies to deny or block access.
4
Analyze risk-based authentication requirements.
Identify that medium or high sign-in risk triggers map to Entra ID Protection policies.
Entra ID Protection evaluates sign-in telemetry and enforces controls like MFA or password changes based on user or sign-in risk levels.

Anahtar Kavram

Microsoft Entra ID Authentication and Conditional Access
Tahmini Süre:1m 30s
Bu soruyu puanla