Soru

Zorluk: OrtaEntra ID Governance and Privileged Access

A financial services startup is preparing for an annual regulatory audit of its Azure production environment. A third-party compliance team consisting of five auditors needs temporary access to view configuration settings across all resources in a subscription. You must design an identity governance solution that allows the auditors to self-service their access only when needed, enforces multi-factor authentication (MFA) upon activation, and minimizes administrative overhead. Which of the following solutions should you recommend?

  1. Create a Microsoft Entra ID security group for the compliance team, and configure an eligible assignment for this group to the Reader role on the subscription using Privileged Identity Management (PIM) for Azure resources, requiring MFA on activation.Cevap
  2. B
    Create a Microsoft Entra ID security group for the compliance team, and assign the group a permanent Reader role on the subscription while enforcing MFA via a Conditional Access policy.
  3. C
    Configure individual eligible assignments to the Reader role on the subscription for each auditor's user account using Privileged Identity Management (PIM) for Azure resources, requiring MFA on activation.
  4. D
    Create a Microsoft Entra ID security group for the compliance team, configure eligible assignment to the Reader role on the subscription using Privileged Identity Management (PIM), and create a Conditional Access policy that excludes this group from MFA.

Cevap

Create a Microsoft Entra ID security group for the compliance team, and configure an eligible assignment for this group to the Reader role on the subscription using Privileged Identity Management (PIM) for Azure resources, requiring MFA on activation.
The correct solution uses Microsoft Entra ID security groups combined with Privileged Identity Management (PIM) for Azure resources. Assigning role eligibility to a security group reduces administrative overhead compared to individual user assignments. Configuring the role as eligible ensures just-in-time (JIT) access, while PIM role settings enforce MFA when users activate the role.

Adım Adım Çözüm

1
Group creation
A Microsoft Entra ID security group is created for the compliance team.
Grouping users minimizes administrative overhead compared to managing assignments individually.
2
PIM assignment
An eligible assignment is configured for the security group to the Reader role at the subscription level.
This implements just-in-time (JIT) access governance, allowing the group to activate the role only during audit windows.
3
Activation settings configuration
MFA is enabled under the PIM role settings for the Reader role activation.
This guarantees that users must perform multi-factor authentication whenever they request to activate their privileged access.

Anahtar Kavram

Privileged Identity Management (PIM) eligible assignments and security group scoping
Bu soruyu puanla