Soru

Zorluk: ZorMicrosoft Entra ID Authentication and Conditional Access

An organization named Meridian Global Solutions plans to design a hybrid identity solution using Microsoft Entra ID. The organization has an on-premises Active Directory Domain Services (AD DS) forest. You need to recommend an identity architecture that meets the following requirements:
- Users must sign in to cloud resources using their on-premises credentials.
- Users' compromised credentials must be automatically detected and flagged on Microsoft Entra ID without depending on on-premises authentication infrastructure.
- All users assigned to highly privileged roles must be forced to use multi-factor authentication (MFA) to access the Azure portal.
- The risk of complete administrative lockout due to MFA service disruptions or misconfigured Conditional Access policies must be mitigated.
- The exposure of privileged roles must be minimized by requiring approval and just-in-time activation.

Which combination of hybrid authentication, Conditional Access configuration, and role assignment strategy should you recommend?

  1. A
    Implement Active Directory Federation Services (AD FS), configure a Conditional Access policy requiring MFA for all administrative roles with an exclusion for an emergency access account, and assign users as eligible for privileged roles in Privileged Identity Management (PIM).
  2. B
    Implement Password Hash Synchronization (PHS), configure a Conditional Access policy requiring MFA for all administrative roles with no exclusions, and assign users as eligible for privileged roles in Privileged Identity Management (PIM).
  3. Implement Password Hash Synchronization (PHS), configure a Conditional Access policy requiring MFA for all administrative roles with an exclusion for an emergency access account, and assign users as eligible for privileged roles in Privileged Identity Management (PIM).Cevap
  4. D
    Implement Password Hash Synchronization (PHS), configure a Conditional Access policy requiring MFA for all administrative roles with an exclusion for an emergency access account, and assign users as permanently active for privileged roles in Privileged Identity Management (PIM).

Cevap

Implement Password Hash Synchronization (PHS), configure a Conditional Access policy requiring MFA for all administrative roles with an exclusion for an emergency access account, and assign users as eligible for privileged roles in Privileged Identity Management (PIM).
The correct option outlines the optimal architecture. Password Hash Synchronization (PHS) natively enables Microsoft Entra ID Protection to perform leaked credential detection in the cloud, fulfilling the requirement without requiring on-premises server evaluation. Setting up a Conditional Access policy that enforces MFA for administrative roles but excludes a designated emergency access account prevents admin lockout in the event of a tenant-wide MFA disruption. Using eligible assignments in Microsoft Entra Privileged Identity Management (PIM) enforces just-in-time activation and requires approvals, keeping highly privileged roles inactive until needed.

Adım Adım Çözüm

1
Select the appropriate hybrid authentication method based on requirements.
Password Hash Synchronization (PHS) is selected.
PHS allows Microsoft Entra ID to perform leaked credential detection directly in the cloud without relying on on-premises agents or redirecting authentication requests to local servers, minimizing infrastructure overhead.
2
Design the Conditional Access policy and lockout mitigation strategy.
A Conditional Access policy is designed to enforce MFA for all administrative roles, with a specific exclusion group containing a dedicated emergency access (glass-breaker) account.
Excluding an emergency access account from MFA enforcement ensures that administrators can still sign in and remediate issues in the event of an MFA service failure or policy misconfiguration.
3
Design the privileged access lifecycle and role assignment strategy.
Privileged Identity Management (PIM) is utilized, configuring administrative roles as eligible rather than permanently active.
Eligible assignments mandate that administrators perform just-in-time (JIT) activation with optional approval, minimizing the attack surface and mitigating risks associated with compromised privileged credentials.

Anahtar Kavram

Microsoft Entra ID hybrid identity design, Conditional Access policy exclusions, and Privileged Identity Management (PIM) role assignments.
Tahmini Süre:2m 30s
Bu soruyu puanla