An organization is designing a hybrid identity and security governance strategy for its Microsoft Entra ID tenant. The organization has 10,000 users across multiple on-premises offices. The architecture must meet the following requirements:
1. On-premises Active Directory Domain Services (AD DS) user passwords must never be stored in the cloud in any form, including reversible or irreversible hashes, to comply with local financial regulations.
2. Users must be prompted for multi-factor authentication (MFA) when accessing cloud resources, except when they are working from physical corporate offices.
3. Access to privileged administrative roles in Entra ID must follow a zero-trust model requiring justification and manager approval, and administrators must be protected against tenant lockout in the event of an MFA service outage.
Which identity and access management design should the organization recommend?
- AConfigure Microsoft Entra Connect Pass-through Authentication (PTA) with seamless single sign-on. Design a Conditional Access policy that requires MFA for all users, excludes corporate network IP ranges defined as trusted locations, and excludes a dedicated emergency access account from the policy. Configure Privileged Identity Management (PIM) with permanently active role assignments.
- BConfigure Active Directory Federation Services (AD FS) to handle authentication federated with on-premises. Design a Conditional Access policy that requires MFA for all users, excludes corporate network IP ranges defined as trusted locations, and excludes a dedicated emergency access account from the policy. Configure Privileged Identity Management (PIM) with eligible role assignments.
- CConfigure Microsoft Entra Connect Pass-through Authentication (PTA) with seamless single sign-on. Design a Conditional Access policy that requires MFA for all users and excludes corporate network IP ranges defined as trusted locations, ensuring the policy applies to all administrative accounts without exception. Configure Privileged Identity Management (PIM) with eligible role assignments.
- Configure Microsoft Entra Connect Pass-through Authentication (PTA) with seamless single sign-on. Design a Conditional Access policy that requires MFA for all users, excludes corporate network IP ranges defined as trusted locations, and excludes a dedicated emergency access account from the policy. Configure Privileged Identity Management (PIM) with eligible role assignments.Cevap