Soru

Zorluk: OrtaMicrosoft Entra ID Authentication and Conditional Access

Aetherius Manufacturing plans to integrate its on-premises Active Directory Domain Services (AD DS) directory with a Microsoft Entra ID tenant.

You need to design the identity and access management architecture. The solution must satisfy the following requirements:
- Ensure that users can authenticate to cloud services using their on-premises passwords, even if the on-premises domain controllers are offline.
- Enforce multi-factor authentication (MFA) for all administrative sessions to the Azure portal, while ensuring that dedicated emergency-access accounts remain accessible in the event of an MFA service disruption.
- Minimize the administrative overhead and the physical server footprint required for the identity sync solution.

Which two configurations should you include in the design to meet the requirements? (Select two.)

  1. Configure Microsoft Entra Connect with Password Hash Synchronization (PHS).Cevap
  2. Create a Conditional Access policy that requires multi-factor authentication (MFA) for the Microsoft Azure Management app, and configure a group exclusion for the emergency-access accounts.Cevap
  3. C
    Deploy Active Directory Federation Services (AD FS) and establish a federated trust with the Microsoft Entra ID tenant.
  4. D
    Create a Conditional Access policy that requires multi-factor authentication (MFA) for the Microsoft Azure Management app, with no policy exclusions configured.
  5. E
    Use Microsoft Entra Privileged Identity Management (PIM) to assign administrative roles as permanently active to privileged users.

Cevap

To satisfy the requirements, you should configure Microsoft Entra Connect with Password Hash Synchronization (PHS) and create a Conditional Access policy that requires multi-factor authentication (MFA) for the Microsoft Azure Management app with an exclusion group configured for emergency-access accounts.
Password Hash Synchronization (PHS) meets the resiliency and minimal overhead requirements because it authenticates users directly in Microsoft Entra ID using stored password hashes, eliminating reliance on on-premises domain controller availability during login and requiring no extra on-premises infrastructure. Additionally, configuring a Conditional Access policy for the Microsoft Azure Management app that enforces MFA ensures administrative sessions are secure, while excluding emergency-access accounts from the policy prevents administrative lockout in the event of an MFA service disruption.

Adım Adım Çözüm

1
Evaluate the hybrid authentication options against the offline authentication and minimal infrastructure requirements.
Password Hash Synchronization (PHS) is selected.
PHS copies password hashes to Microsoft Entra ID, allowing authentication to occur in the cloud when local domain controllers are offline, and requires only the basic sync agent footprint without AD FS servers.
2
Evaluate the Conditional Access policy design for protecting the Azure portal while preventing tenant lockout.
A Conditional Access policy targeting the Microsoft Azure Management app with MFA required and a group exclusion for emergency-access accounts is selected.
This configuration enforces MFA for administrative operations while avoiding lockout risks for break-glass accounts during an MFA outage.

Anahtar Kavram

Microsoft Entra ID hybrid authentication architecture and resilient Conditional Access design
Bu soruyu puanla