Soru

Zorluk: ZorMicrosoft Entra ID Authentication and Conditional Access

You are designing an identity security strategy for a manufacturing enterprise named Fabrikam, Inc. The enterprise has a Microsoft Entra ID tenant and wants to protect its Azure management interfaces. You must design a solution that meets the following requirements:
- All users assigned to highly privileged roles must use multi-factor authentication (MFA) to access the Azure portal.
- Privileged access must follow the principle of least privilege, ensuring roles are activated only when needed for a maximum of 4 hours.
- In the event of an unexpected Microsoft Entra MFA service outage, administrators must be able to log in to resolve the issue.
- The design must minimize administrative overhead and local infrastructure dependencies.

Which identity and access design should you recommend?

  1. A
    Configure Microsoft Entra Privileged Identity Management (PIM) with permanently active role assignments. Create a Conditional Access policy targeting administrative roles that requires MFA, and exclude a dedicated, cloud-only emergency access account from this policy.
  2. Configure Microsoft Entra Privileged Identity Management (PIM) with eligible role assignments. Create a Conditional Access policy targeting administrative roles that requires MFA, and exclude a dedicated, cloud-only emergency access account from this policy.Cevap
  3. C
    Configure Microsoft Entra Privileged Identity Management (PIM) with eligible role assignments. Create a Conditional Access policy that enforces MFA for all cloud applications for all users, ensuring no accounts are excluded to prevent security bypasses.
  4. D
    Deploy Active Directory Federation Services (AD FS) on-premises to federate authentication. Configure PIM with eligible role assignments and configure AD FS claims rules to enforce MFA for administrative logins, bypassing Microsoft Entra Conditional Access.

Cevap

Configure Microsoft Entra Privileged Identity Management (PIM) with eligible role assignments, enforce MFA for administrative roles using a Conditional Access policy, and exclude a dedicated cloud-only emergency access account from that policy.
The correct design uses Microsoft Entra Privileged Identity Management (PIM) with eligible assignments to ensure administrative roles are only active when needed, limiting standing access. Multi-factor authentication is enforced natively using a Conditional Access policy targeting administrative directory roles. By excluding a cloud-only emergency access account from this Conditional Access policy, the design ensures that administrators can regain control of the tenant if a primary authentication factor or MFA service outage occurs, minimizing local dependencies and administrative overhead.

Adım Adım Çözüm

1
Analyze role activation requirements.
Determine that Microsoft Entra Privileged Identity Management (PIM) with eligible assignments is required to achieve just-in-time (JIT) role activation and adhere to the least privilege principle.
Eligible assignments require users to perform an activation step (with timed duration), whereas active assignments grant persistent privileges.
2
Select the appropriate MFA enforcement mechanism.
Select Microsoft Entra Conditional Access targeting administrative roles to enforce MFA during portal access.
Conditional Access provides granular control to require MFA for administrative roles without needing on-premises federation servers.
3
Design lockout resilience.
Define an exclusion in the Conditional Access MFA policy for a dedicated, cloud-only emergency access account (break-glass account).
If Microsoft Entra MFA is disrupted, the excluded emergency account can still sign in to modify policies or manage the tenant.
4
Evaluate local infrastructure requirements.
Avoid configuring Active Directory Federation Services (AD FS) as it introduces on-premises infrastructure dependencies, violating the requirement to minimize overhead.
Cloud-native capabilities in Microsoft Entra ID meet all constraints without requiring local servers.

Anahtar Kavram

Microsoft Entra ID Conditional Access, PIM, and emergency access account best practices.
Tahmini Süre:2m 0s
Bu soruyu puanla