Soru

Zorluk: OrtaEntra ID Governance and Privileged Access

A regional healthcare provider is designing an identity and access management solution for its IT operations team, which manages Azure resources. The solution must meet the following requirements:
- Manage permissions at scale without administrative overhead when members join or leave the team.
- Ensure that administrators do not have persistent access to high-privilege roles, requiring them to request access only when performing active maintenance.
- Maintain a break-glass emergency access account that is guaranteed access to the tenant even during a Microsoft Entra ID authentication outage.

Which two configurations should you include in the design? (Select two.)

  1. Create a Microsoft Entra ID security group for the administrators and make this group eligible for Azure RBAC roles within Microsoft Entra Privileged Identity Management (PIM).Cevap
  2. B
    Assign Azure RBAC roles directly to each individual administrator's user account to ensure granular auditing.
  3. Exclude the emergency access (break-glass) accounts from Microsoft Entra Conditional Access policies that enforce Multi-Factor Authentication (MFA).Cevap
  4. D
    Configure PIM role assignments as permanently active for the administrators' security group.
  5. E
    Include the emergency access (break-glass) accounts in all Microsoft Entra Conditional Access policies that enforce Multi-Factor Authentication (MFA) to ensure compliance.

Cevap

Create a Microsoft Entra ID security group for the administrators and make this group eligible for Azure RBAC roles within Microsoft Entra Privileged Identity Management (PIM), and exclude the emergency access (break-glass) accounts from Microsoft Entra Conditional Access policies that enforce Multi-Factor Authentication (MFA).
To design a secure, scalable governance structure, assigning Azure RBAC roles to Microsoft Entra security groups reduces administration because roles are automatically inherited as members join or leave the group. Configuring these groups as eligible in Microsoft Entra Privileged Identity Management (PIM) enforces just-in-time (JIT) access, which minimizes persistent privileged access. Additionally, excluding emergency access accounts from Conditional Access policies that enforce Multi-Factor Authentication (MFA) prevents administrative lockout during a system outage.

Adım Adım Çözüm

1
Evaluate the requirement for managing permissions at scale without administrative overhead when members change.
Determine that group-based role assignment is required instead of individual user assignments.
Group-based role assignments allow administrative changes to occur by updating group membership rather than updating individual role assignments.
2
Evaluate the requirement to prevent persistent high-privilege access and enforce request-based access.
Determine that Microsoft Entra Privileged Identity Management (PIM) with eligible assignments is required.
PIM eligible assignments allow administrators to activate roles only when performing maintenance, ensuring just-in-time access.
3
Evaluate the requirement to protect emergency access accounts from identity service outages.
Determine that these accounts must be excluded from Conditional Access policies that require Multi-Factor Authentication.
Excluding break-glass accounts ensures access to the Azure portal even if MFA services are unavailable.

Anahtar Kavram

Microsoft Entra ID Privileged Identity Management (PIM) eligibility and Conditional Access exclusion policies for emergency access accounts.
Bu soruyu puanla