Soru

Zorluk: OrtaEntra ID Governance and Privileged Access

An enterprise is designing a privileged access governance solution for its Azure environment. The solution must satisfy the following security and administrative requirements:

- Members of the operations team must only have permissions to manage virtual machines when performing scheduled maintenance tasks.
- Permissions to manage virtual machines must be assigned at scale to groups rather than to individual user accounts.
- Emergency access accounts must be protected from lockout risks associated with tenant-wide multi-factor authentication (MFA) policies.

Which two actions should you include in the design? (Choose two.)

  1. Configure the operations team members as eligible members of a Microsoft Entra group that is assigned the Virtual Machine Contributor role by using Privileged Identity Management (PIM) for Groups.Cevap
  2. Exclude the emergency access accounts from the Conditional Access policies that require multi-factor authentication (MFA).Cevap
  3. C
    Assign the Virtual Machine Contributor role directly to each operations team user account as an eligible role assignment in Privileged Identity Management (PIM).
  4. D
    Configure the operations team members as permanently active members of the Microsoft Entra group that is assigned the Virtual Machine Contributor role.

Cevap

To meet the requirements, you should configure the operations team members as eligible members of a Microsoft Entra group that is assigned the Virtual Machine Contributor role by using Privileged Identity Management (PIM) for Groups, and exclude the emergency access accounts from the Conditional Access policies that require multi-factor authentication (MFA).
Configuring operations team members as eligible group members in PIM for Groups ensures that they only gain the Virtual Machine Contributor role on-demand, which adheres to the principle of least privilege and just-in-time access. Furthermore, excluding emergency access accounts from MFA Conditional Access policies ensures that these accounts remain accessible during a tenant-wide identity outage or MFA service disruption.

Adım Adım Çözüm

1
Analyze group governance requirements
Determine that managing individual permissions directly is inefficient at scale, necessitating group-based assignments.
Ensures that administrative actions are centralized and audit logs remain manageable.
2
Design just-in-time access controls
Use Privileged Identity Management (PIM) for Groups to configure eligibility rules for the operations team group.
Ensures users only activate their group membership when performing maintenance tasks, eliminating standing access.
3
Ensure high availability of emergency accounts
Identify policies that enforce MFA and configure exclusions for designated emergency access accounts.
Prevents administrative lockouts during MFA outages or sync issues.

Anahtar Kavram

Privileged access management using group-based PIM eligibility and emergency account lockout prevention.
Bu soruyu puanla