Soru

Zorluk: ZorEntra ID Governance and Privileged Access

You are designing an identity governance and privileged access solution for a large Azure enterprise environment. The environment has the following requirements:

* A team of tier-2 cloud engineers must be able to manage role assignments on a critical subscription, but only when actively performing scheduled maintenance.
* To maintain a clear audit trail and ease of administration, individual user accounts must not be assigned roles directly.
* All administrative activations must require multi-factor authentication (MFA) and administrative approval.
* The organization's emergency access (glass-breaker) account must be protected from accidental lockout during a Microsoft Entra ID authentication outage.

Which design recommendation should you include in the identity governance strategy to meet these requirements?

  1. Configure a Microsoft Entra ID security group, make the cloud engineers eligible members of the group using Privileged Identity Management (PIM) for Groups, and assign the group the User Access Administrator role on the subscription. Exclude the emergency access account from the Conditional Access policy that enforces MFA for administrative roles.Cevap
  2. B
    Assign the User Access Administrator role directly to each cloud engineer's account, configuring the assignments as eligible in Privileged Identity Management (PIM) for Azure resources. Exclude the emergency access account from the Conditional Access policy that enforces MFA for administrative roles.
  3. C
    Assign the User Access Administrator role permanently to a Microsoft Entra ID security group containing the cloud engineers. Use a Conditional Access policy to restrict group member sign-ins to scheduled maintenance windows, and exclude the emergency access account from the Conditional Access policy.
  4. D
    Configure a Microsoft Entra ID security group, make the cloud engineers eligible members of the group using Privileged Identity Management (PIM) for Groups, and assign the group the User Access Administrator role on the subscription. Enforce a Conditional Access policy requiring MFA for all administrator roles, ensuring no accounts are excluded.

Cevap

Configure a Microsoft Entra ID security group, make the cloud engineers eligible members of the group using Privileged Identity Management (PIM) for Groups, and assign the group the User Access Administrator role on the subscription. Exclude the emergency access account from the Conditional Access policy that enforces MFA for administrative roles.
The correct recommendation implements group-based access control using PIM for Groups to make engineers eligible, ensuring that they must activate their membership using MFA and approval only when needed. It also ensures the emergency access account is excluded from CA MFA policies to mitigate lockout risks during an identity provider outage.

Adım Adım Çözüm

1
Select the target identity container for the engineering team.
A Microsoft Entra ID security group is chosen instead of individual assignments.
This satisfies the requirement that individual user accounts must not be assigned roles directly, aligning with enterprise governance best practices.
2
Configure the privileged access method for the security group.
Use Privileged Identity Management (PIM) for Groups to make the engineers eligible members.
Eligible membership allows engineers to request elevation dynamically, supporting MFA and manager approval workflows prior to activation.
3
Define the emergency access policy exemptions.
Exclude the emergency access (glass-breaker) account from the Conditional Access MFA policy.
This protects the organization from administrative lockout if the Entra ID authentication or MFA services experience an outage.

Anahtar Kavram

Designing secure administrative access using Privileged Identity Management (PIM) for Groups alongside appropriate Conditional Access exclusions for emergency accounts.
Tahmini Süre:2m 0s
Bu soruyu puanla