Soru

Zorluk: Çok zorMicrosoft Entra ID Authentication and Conditional Access

An organization is designing a security and access control strategy for its Microsoft Entra ID tenant to protect sensitive cloud resources and workloads. The security team has defined several key access requirements for their environment. Match each security requirement to the corresponding Microsoft Entra ID or Conditional Access feature that best satisfies it.

  • Secure access to a critical financial application by requiring users to authenticate using phishing-resistant methods like FIDO2 security keys, ignoring weaker multi-factor authentication methods.Conditional Access Authentication Strength
  • Revoke active OAuth 2.0 access tokens in near real-time when a user's password is reset or their account is disabled, bypassing standard token lifetimes.Continuous Access Evaluation (CAE)
  • Trigger a step-up authentication challenge dynamically within a custom line-of-business application when a user attempts to view highly confidential files.Conditional Access Authentication Context
  • Configure Microsoft 365 services to automatically block file downloads and enforce read-only web access when connected from unmanaged devices.Conditional Access App Enforced Restrictions

Cevap

The requirement for phishing-resistant methods matches Conditional Access Authentication Strength; near real-time token revocation matches Continuous Access Evaluation (CAE); dynamically triggering step-up authentication matches Conditional Access Authentication Context; and blocking file downloads from unmanaged devices matches Conditional Access App Enforced Restrictions.
The correct mapping pairs the security requirements with their respective Entra ID features: FIDO2 requirement pairs with Conditional Access Authentication Strength, near real-time token revocation pairs with Continuous Access Evaluation (CAE), dynamic step-up authentication pairs with Conditional Access Authentication Context, and restricting unmanaged devices to read-only access pairs with Conditional Access App Enforced Restrictions.

Adım Adım Çözüm

1
Analyze the requirement for enforcing specific phishing-resistant MFA methods.
Identify that Conditional Access Authentication Strength allows administrators to specify exactly which MFA methods (e.g., FIDO2 keys) are acceptable for a policy.
Standard MFA policies only require multi-factor authentication generally, whereas authentication strength defines the specific combination of allowed methods.
2
Analyze the requirement for near real-time revocation of active sessions upon account events.
Identify Continuous Access Evaluation (CAE) as the mechanism that enables active token revocation within minutes when events like password resets occur.
Without CAE, tokens remain valid until their standard expiration lifetime (typically 1 hour) even if the user account is disabled.
3
Analyze the requirement for triggering MFA step-up dynamically within an application session.
Identify Conditional Access Authentication Context as the bridge between application-level actions and Conditional Access policies.
Authentication context allows custom apps or SharePoint to prompt for additional verification only when accessing specific high-sensitivity data.
4
Analyze the requirement for restricting downloads and enforcing read-only web access on unmanaged devices.
Identify Conditional Access App Enforced Restrictions as the session control that communicates device state to Microsoft 365 workloads.
This session control allows workloads like SharePoint to control the browser behavior based on compliance signals passed by Entra ID.

Anahtar Kavram

Designing granular and secure Microsoft Entra ID Authentication and Conditional Access policies using authentication strengths, session controls, real-time evaluation, and application-level integration.
Tahmini Süre:3m 0s
Bu soruyu puanla