Soru

Zorluk: ZorHybrid and Multi-Tenant Identity Solutions

Vanguard Retail Group has an on-premises Active Directory Domain Services (AD DS) forest named corp.vanguardretail.com that contains 14,200 users. You are designing a hybrid identity and governance solution to integrate the on-premises environment with a new Microsoft Entra ID tenant.

The solution must meet the following requirements:
- Users must be able to sign in to cloud services using their on-premises passwords, even if the connection between the on-premises network and Azure is temporarily lost.
- Users must have the ability to reset their passwords in the cloud, with the new passwords synchronizing back to the on-premises AD DS.
- All user accounts must be subject to Conditional Access policies that require Multi-Factor Authentication (MFA), but the design must prevent administrative lockout during an MFA service disruption.
- Privileged administrative roles must not be permanently assigned to users, and access permissions for Azure subscriptions must be managed to minimize administrative overhead.

Which design solution should you recommend?

  1. A
    Deploy Microsoft Entra Connect with Password Hash Synchronization (PHS) and password writeback enabled. Create two emergency access accounts that are included in all Conditional Access MFA policies. Configure Microsoft Entra Privileged Identity Management (PIM) with active role assignments. Assign Azure RBAC roles directly to individual user accounts.
  2. B
    Deploy Microsoft Entra Connect with Pass-through Authentication (PTA) and password writeback enabled. Create two emergency access accounts that are excluded from all Conditional Access MFA policies. Configure Microsoft Entra Privileged Identity Management (PIM) with eligible role assignments. Assign Azure RBAC roles directly to individual user accounts.
  3. Deploy Microsoft Entra Connect with Password Hash Synchronization (PHS) and password writeback enabled. Create two emergency access accounts that are excluded from all Conditional Access MFA policies. Configure Microsoft Entra Privileged Identity Management (PIM) with eligible role assignments. Assign Azure RBAC roles to Microsoft Entra ID security groups.Cevap
  4. D
    Deploy Active Directory Federation Services (AD FS) and password writeback. Create two emergency access accounts that are included in all Conditional Access MFA policies. Configure Microsoft Entra Privileged Identity Management (PIM) with active role assignments. Assign Azure RBAC roles to Microsoft Entra ID security groups.

Cevap

Deploy Microsoft Entra Connect with Password Hash Synchronization (PHS) and password writeback enabled. Create two emergency access accounts that are excluded from all Conditional Access MFA policies. Configure Microsoft Entra Privileged Identity Management (PIM) with eligible role assignments. Assign Azure RBAC roles to Microsoft Entra ID security groups.
The correct solution involves deploying Password Hash Synchronization (PHS) because it enables users to sign in to cloud services using their on-premises passwords even if the on-premises network or connection is lost. It also enables leaked credential detection. Password writeback on Microsoft Entra Connect enables self-service password reset (SSPR) changes to sync back to the on-premises Active Directory. Excluding emergency access accounts from Conditional Access MFA policies prevents lockout during MFA provider outages. Using Privileged Identity Management (PIM) with eligible assignments prevents standing administrative privileges, and assigning RBAC roles to security groups rather than individual users reduces management overhead.

Adım Adım Çözüm

1
Determine the hybrid sync method.
Choose Password Hash Synchronization (PHS) with password writeback enabled.
This satisfies the requirement to authenticate using on-premises passwords even during a network disconnect, and enables password writeback for self-service password reset (SSPR).
2
Configure administrative lockout prevention.
Create two emergency access accounts and exclude them from Conditional Access MFA policies.
This ensures that administrators can access the tenant to troubleshoot if the MFA service experiences an outage.
3
Address privileged access governance.
Configure Microsoft Entra Privileged Identity Management (PIM) with eligible assignments for administrative roles.
This enforces just-in-time (JIT) access and prevents permanent standing privileges.
4
Design resource access management.
Assign Azure RBAC roles to Microsoft Entra ID security groups.
This minimizes administrative overhead compared to assigning roles to individual user accounts.

Anahtar Kavram

Designing hybrid identity and access governance solutions using Microsoft Entra ID, Microsoft Entra Connect, and PIM.
Tahmini Süre:3m 0s
Bu soruyu puanla