Soru

Zorluk: ZorMicrosoft Entra ID Authentication and Conditional Access

Tailwind Traders is designing an identity and access management solution for their Microsoft Entra ID tenant. The tenant is synchronized with an on-premises Active Directory Domain Services (AD DS) environment.

The solution must meet the following requirements:
- Enforce Multi-Factor Authentication (MFA) for all administrative roles.
- Ensure that administrators can access privileged roles only when required, using a Just-In-Time (JIT) access model that enforces justification and MFA.
- Mitigate the risk of tenant lockout in the event of a Microsoft Entra ID MFA service outage.
- Minimize infrastructure complexity and administrative overhead.

Which identity and access design should you recommend?

  1. A
    Deploy Active Directory Federation Services (AD FS) to manage authentication and MFA. Configure Microsoft Entra Privileged Identity Management (PIM) with eligible assignments for administrative roles. Create a Conditional Access policy requiring MFA for administrators, and exclude two cloud-only emergency access accounts.
  2. B
    Deploy Password Hash Synchronization (PHS). Configure Microsoft Entra Privileged Identity Management (PIM) with permanently active assignments for administrative roles to prevent delays. Create a Conditional Access policy requiring MFA for administrators, and exclude two cloud-only emergency access accounts.
  3. Deploy Password Hash Synchronization (PHS). Configure Microsoft Entra Privileged Identity Management (PIM) with eligible assignments for administrative roles. Create a Conditional Access policy requiring MFA for administrators, and exclude two cloud-only emergency access accounts that are assigned the Global Administrator role permanently and use non-phone-based authentication.Cevap
  4. D
    Deploy Password Hash Synchronization (PHS). Configure Microsoft Entra Privileged Identity Management (PIM) with eligible assignments for administrative roles. Create a Conditional Access policy requiring MFA for all administrators, ensuring that no accounts are excluded from the policy to maintain a strict security posture.

Cevap

Deploy Password Hash Synchronization (PHS), configure eligible administrative role assignments in Privileged Identity Management (PIM), and create a Conditional Access policy enforcing MFA while excluding two cloud-only emergency access accounts.
The correct design uses Password Hash Synchronization (PHS) to keep hybrid identity infrastructure simple. It leverages Privileged Identity Management (PIM) with eligible assignments to ensure that administrators do not hold standing privileges and must request activation (enforcing Just-In-Time access with MFA and justification). Finally, it secures the tenant against outages by excluding dedicated, cloud-only emergency access accounts from the Conditional Access MFA policy, in alignment with Microsoft architectural guidelines.

Adım Adım Çözüm

1
Select the hybrid authentication method that minimizes infrastructure complexity.
Password Hash Synchronization (PHS) is selected instead of Active Directory Federation Services (AD FS) because it requires no complex on-premises federation infrastructure.
The scenario requires minimizing infrastructure complexity and administrative overhead.
2
Configure role governance for Just-In-Time (JIT) access.
Microsoft Entra Privileged Identity Management (PIM) is configured with eligible assignments for administrative roles, requiring justification and MFA upon activation.
Eligible assignments prevent permanent privilege accumulation and enforce JIT governance.
3
Configure Conditional Access policies to prevent lockout during MFA service outages.
Excluding dedicated, cloud-only emergency access (glass-breaker) accounts from the Conditional Access policy ensures access is maintained if the MFA service fails.
Microsoft best practices dictate that at least one or two emergency access accounts must be excluded from MFA policies to mitigate the risk of tenant lockout.

Anahtar Kavram

Designing resilient identity, hybrid authentication, and conditional access policies in Microsoft Entra ID.
Tahmini Süre:2m 0s
Bu soruyu puanla