Zephyr Energy Solutions is designing a secure identity access strategy for its Microsoft Entra ID tenant. The design must meet the following requirements:
* All administrators must be prompted for Multi-Factor Authentication (MFA) when accessing the Azure portal.
* The risk of administrative lockout due to Conditional Access misconfiguration or MFA service failure must be minimized.
* Hybrid users must authenticate using their on-premises credentials, with authentication processed entirely in the cloud to minimize on-premises infrastructure footprint.
Which of the following configurations should you include in the design? (Select TWO.)
- Configure a Conditional Access policy that enforces MFA for administrative roles, and exclude a dedicated, cloud-only emergency access account.Cevap
- Implement Password Hash Synchronization (PHS) to enable cloud-based authentication for hybrid users.Cevap
- CConfigure a Conditional Access policy that enforces MFA for all administrative roles, ensuring no administrator accounts are excluded to maintain a strict security posture.
- DDeploy Active Directory Federation Services (AD FS) to manage federation and authentication on-premises for hybrid users.
Cevap
The configuration of a Conditional Access policy that enforces MFA while excluding a dedicated emergency access account, combined with the implementation of Password Hash Synchronization (PHS).
Excluding a dedicated emergency access account from MFA requirements ensures that administrators can access the tenant during an outage. In addition, using Password Hash Synchronization (PHS) allows authentication to occur in the cloud without requiring on-premises federation servers.
Adım Adım Çözüm
Anahtar Kavram
Microsoft Entra ID hybrid authentication methods and Conditional Access exclusion planning.
Tahmini Süre:2m 0s