Soru

Zorluk: OrtaEntra ID Governance and Privileged Access

A healthcare organization is onboarding a team of four external security audit consultants to perform a two-week assessment of critical Azure subscription resources. The consultants require temporary, time-bound administrative access to the resources. To comply with security policies, the consultants must only have access when actively performing audit tasks, all role elevations must require multi-factor authentication (MFA), and administrative overhead must be minimized. The organization also needs to ensure that emergency access break-glass accounts are never locked out of the tenant by any Conditional Access policies enforced during role activation. Which of the following designs should you recommend to meet these requirements?

  1. Create a Microsoft Entra security group for the consultants. In Microsoft Entra Privileged Identity Management (PIM) for Azure resources, assign the security group as eligible for the required RBAC roles. Configure the PIM role settings to require MFA upon activation, and exclude emergency access accounts from any Conditional Access policies requiring MFA.Cevap
  2. B
    Assign the required Azure RBAC roles directly to each of the four individual consultant user accounts as eligible assignments in Microsoft Entra Privileged Identity Management (PIM). Configure the PIM role settings to require MFA upon activation, and exclude emergency access accounts from any Conditional Access policies requiring MFA.
  3. C
    Create a Microsoft Entra security group for the consultants. In Microsoft Entra Privileged Identity Management (PIM) for Azure resources, assign the security group as active for the required RBAC roles with a permanent assignment. Ensure that emergency access accounts are explicitly excluded from any Conditional Access policies requiring MFA.
  4. D
    Create a Microsoft Entra security group for the consultants. In Microsoft Entra Privileged Identity Management (PIM) for Azure resources, assign the security group as eligible for the required RBAC roles. Configure a new Conditional Access policy that enforces MFA for all users, including emergency access accounts, during role activation.

Cevap

Create a Microsoft Entra security group for the consultants, assign the group as eligible for the RBAC roles in PIM, configure PIM to require MFA upon activation, and exclude emergency access accounts from Conditional Access MFA policies.
The correct option correctly applies governance best practices by utilizing a security group to manage the external consultants, assigning the group as eligible in Privileged Identity Management (PIM) for just-in-time access, enforcing MFA at activation, and protecting tenant access by excluding emergency accounts from MFA policies.

Adım Adım Çözüm

1
Determine the optimal identity delegation structure to minimize management overhead.
Identify that assigning roles to a Microsoft Entra security group is more scalable and manageable than assigning roles to four individual accounts.
Grouping users allows for centralized administration of access membership without modifying Azure RBAC role assignments.
2
Select the appropriate assignment type in Privileged Identity Management (PIM) to meet the JIT and auditing requirements.
Configure the group with eligible assignments in PIM rather than active or permanent assignments.
Eligible assignments require users to explicitly activate the role when needed, supporting just-in-time (JIT) access and logging elevation events.
3
Establish MFA enforcement while maintaining tenant availability safeguards.
Enable MFA in the PIM role activation settings and ensure emergency access break-glass accounts are excluded from Conditional Access policies.
Excluding emergency accounts prevents tenant lockout in case of MFA outages or misconfigurations.

Anahtar Kavram

Privileged Identity Management (PIM) allows just-in-time role activation for groups, enhancing security posture while avoiding direct user assignments and mitigating lockout risks.
Tahmini Süre:1m 30s
Bu soruyu puanla