Soru

Zorluk: KolayMicrosoft Entra ID Authentication and Conditional Access

A financial services firm is designing a secure identity infrastructure. The lead architect must map specific security compliance requirements to the correct Microsoft Entra ID and Conditional Access features. Match each requirement to the appropriate Microsoft Entra ID or Conditional Access feature.

  • Validate user login credentials directly against on-premises Active Directory in real-time without storing password hashes in the cloud.Pass-through Authentication (PTA)
  • Block users from downloading attachments when accessing Exchange Online from unmanaged personal devices.Conditional Access session controls
  • Enforce Multi-Factor Authentication (MFA) only when a user's sign-in attempt is flagged as anomalous or high risk.Microsoft Entra ID Protection sign-in risk policies

Cevap

Validate credentials directly on-premises matches Pass-through Authentication (PTA); block downloads from unmanaged devices matches Conditional Access session controls; enforce MFA for anomalous attempts matches Microsoft Entra ID Protection sign-in risk policies.
Pass-through Authentication validates credentials on-premises using a local agent; session controls restrict specific actions like downloads on unmanaged devices; Microsoft Entra ID Protection risk policies evaluate anomalous behavior to prompt for MFA dynamically.

Adım Adım Çözüm

1
Analyze the first requirement: validating credentials against on-premises Active Directory in real-time without storing password hashes in the cloud.
This requirement is satisfied by Pass-through Authentication (PTA), which uses a local agent to pass credentials back to on-premises AD for validation.
Password Hash Synchronization stores password hashes in the cloud, which does not meet the design constraint of not storing hashes in the cloud.
2
Analyze the second requirement: blocking downloads when accessing Exchange Online from unmanaged personal devices.
This is satisfied by Conditional Access session controls, specifically using App Control or session restrictions.
Session controls are designed to apply restrictions within the context of an active web application session.
3
Analyze the third requirement: enforcing MFA only when a user's sign-in is flagged as anomalous or high risk.
This is satisfied by Microsoft Entra ID Protection sign-in risk policies.
ID Protection dynamically evaluates sign-in signals to assess risk level, allowing policies to trigger MFA conditionally on threat indicators.

Anahtar Kavram

Microsoft Entra ID Authentication and Conditional Access
Tahmini Süre:1m 30s
Bu soruyu puanla