Soru

Zorluk: OrtaMicrosoft Entra ID Authentication and Conditional Access

Zephyr Energy Solutions is designing a secure identity access strategy for its Microsoft Entra ID tenant. The design must meet the following requirements:

* All administrators must be prompted for Multi-Factor Authentication (MFA) when accessing the Azure portal.
* The risk of administrative lockout due to Conditional Access misconfiguration or MFA service failure must be minimized.
* Hybrid users must authenticate using their on-premises credentials, with authentication processed entirely in the cloud to minimize on-premises infrastructure footprint.

Which of the following configurations should you include in the design? (Select TWO.)

  1. Configure a Conditional Access policy that enforces MFA for administrative roles, and exclude a dedicated, cloud-only emergency access account.Cevap
  2. Implement Password Hash Synchronization (PHS) to enable cloud-based authentication for hybrid users.Cevap
  3. C
    Configure a Conditional Access policy that enforces MFA for all administrative roles, ensuring no administrator accounts are excluded to maintain a strict security posture.
  4. D
    Deploy Active Directory Federation Services (AD FS) to manage federation and authentication on-premises for hybrid users.

Cevap

The configuration of a Conditional Access policy that enforces MFA while excluding a dedicated emergency access account, combined with the implementation of Password Hash Synchronization (PHS).
Excluding a dedicated emergency access account from MFA requirements ensures that administrators can access the tenant during an outage. In addition, using Password Hash Synchronization (PHS) allows authentication to occur in the cloud without requiring on-premises federation servers.

Adım Adım Çözüm

1
Evaluate hybrid authentication options.
Password Hash Synchronization (PHS) is selected as it processes authentication entirely in the cloud and requires minimal on-premises infrastructure, unlike Active Directory Federation Services (AD FS).
To satisfy the requirement of minimal on-premises footprint while allowing users to use their on-premises passwords.
2
Evaluate security controls and lockout prevention for administrators.
A Conditional Access policy is designed to enforce MFA for administrators, while excluding a dedicated, cloud-only emergency access account.
To satisfy the requirement of requiring MFA for Azure portal access while mitigating the risk of total tenant lockout in the event of an MFA service disruption.

Anahtar Kavram

Microsoft Entra ID hybrid authentication methods and Conditional Access exclusion planning.
Tahmini Süre:2m 0s
Bu soruyu puanla