Soru

Zorluk: OrtaEntra ID Governance and Privileged Access

A logistics company is designing an identity governance and privileged access solution for its Azure environment. The company needs to grant a team of cloud administrators temporary, approved Contributor rights on target subscriptions.

The solution must meet the following requirements:
- Cloud administrators must only receive Contributor access on-demand when actively performing tasks, with access automatically revoking after 4 hours.
- Every request to elevate access must enforce multi-factor authentication (MFA) and require the user to provide a business justification.
- Access rights must be managed using a scalable administrative model that avoids configuring permissions for individual user accounts.
- Emergency-access (break-glass) accounts must be protected from accidental lockout caused by strict Conditional Access policies requiring MFA.

Which two actions should you include in the design to meet these requirements? Select two.

  1. Create a Microsoft Entra security group containing the cloud administrators, and assign this group as eligible for the Contributor role using Microsoft Entra Privileged Identity Management (PIM).Cevap
  2. Configure the Microsoft Entra Privileged Identity Management (PIM) role activation settings for the Contributor role to require multi-factor authentication (MFA), require justification, and set the maximum activation duration to 4 hours.Cevap
  3. C
    Assign the Contributor role directly to each administrator's user account in Privileged Identity Management (PIM) and configure the assignment type to active.
  4. D
    Enforce a Conditional Access policy that requires MFA for all administrative directory roles, including emergency-access accounts, to ensure no accounts bypass security controls.

Cevap

To meet the governance and administrative constraints, you should create a Microsoft Entra security group containing the cloud administrators and assign the group as eligible for the Contributor role using Microsoft Entra Privileged Identity Management (PIM), and configure the PIM role activation settings for the Contributor role to require multi-factor authentication (MFA), require justification, and set the maximum activation duration to 4 hours.
To design a secure administrative model that scales, permissions should be assigned to a Microsoft Entra security group. To enforce Just-In-Time (JIT) access, this group must be designated as eligible (rather than active) for the Contributor role within Privileged Identity Management (PIM). Additionally, to enforce constraints such as MFA, justification, and a maximum activation window of 4 hours, these rules must be defined within the PIM role activation settings for the Contributor role.

Adım Adım Çözüm

1
Analyze administrative scalability and permission assignment rules.
Conclude that administrators should be managed collectively via a Microsoft Entra security group rather than applying direct assignments to individual user accounts.
Direct assignment to individual accounts increases administrative overhead and complicates access review processes.
2
Address the Just-In-Time (JIT) access and approval requirement.
Ensure the group is configured with an 'eligible' assignment type in PIM, and configure role activation settings to enforce MFA, justification, and a maximum duration of 4 hours.
Active assignments provide permanent standing access, whereas eligible assignments require explicit activation that is subject to governance constraints.
3
Address emergency access and lockout protection guidelines.
Ensure emergency-access (break-glass) accounts are explicitly excluded from MFA policies that could lock out all administrators during an Entra ID or MFA outage.
Excluding emergency accounts preserves a secure recovery path in critical situations.

Anahtar Kavram

Microsoft Entra Privileged Identity Management (PIM) configuration and best practices for role eligibility and group-based assignments.
Bu soruyu puanla