Soru

Zorluk: ZorHybrid and Multi-Tenant Identity Solutions

Caelum Skyworks is designing a hybrid identity solution that integrates their on-premises Active Directory Domain Services (AD DS) forest with a new Microsoft Entra ID tenant.

The design must meet the following requirements:
- Users must authenticate to cloud resources using their on-premises passwords.
- Users must be able to sign in to cloud applications even if the on-premises datacenter or its internet connection is offline.
- Users must be allowed to reset their own passwords in Microsoft Entra ID, and these changes must instantly reflect on-premises.
- A Conditional Access policy requiring Multi-Factor Authentication (MFA) for administrative roles must exclude a dedicated emergency break-glass account to prevent tenant lockout.
- Just-in-time administrative access must be used to manage Azure resources.

Which two actions should you include in the design to meet the requirements? (Select two.)

  1. Configure Password Hash Synchronization (PHS) and enable password writeback in Microsoft Entra Connect.Cevap
  2. Deploy a Conditional Access policy requiring MFA for all administrators, excluding the emergency access account.Cevap
  3. C
    Deploy Active Directory Federation Services (AD FS) and configure federation with Microsoft Entra ID.
  4. D
    Deploy a Conditional Access policy requiring MFA for all administrators, without configuring any exclusions.
  5. E
    Configure Pass-through Authentication (PTA) in Microsoft Entra Connect and enable password writeback.
  6. F
    Configure Microsoft Entra Privileged Identity Management (PIM) with permanently active administrative role assignments.

Cevap

The correct configuration requires configuring Password Hash Synchronization (PHS) with password writeback in Microsoft Entra Connect, and deploying a Conditional Access policy requiring MFA for all administrators while excluding the emergency access account.
To satisfy both authentication and business continuity during an on-premises outage, Password Hash Synchronization (PHS) must be utilized because Entra ID acts as the authority without needing to contact on-premises domain controllers. Password writeback must be enabled in Microsoft Entra Connect to support bidirectional SSPR. Additionally, to enforce MFA for administrators while protecting the tenant against lockout, a Conditional Access policy should require MFA for administrative roles but explicitly exclude the emergency access account.

Adım Adım Çözüm

1
Analyze the authentication and resilience requirements.
Password Hash Synchronization (PHS) must be chosen. Pass-through Authentication (PTA) and Active Directory Federation Services (AD FS) rely on real-time on-premises connectivity, which fails when the datacenter is offline.
Ensures authentication business continuity during on-premises outages.
2
Determine the configuration needed for self-service password reset (SSPR) to sync back on-premises.
Enable password writeback in Microsoft Entra Connect.
Allows cloud-initiated password changes to be written back to the on-premises directory instantly.
3
Evaluate the administrative access policy and lockout prevention requirements.
A Conditional Access policy requiring MFA for administrators must be deployed, with the emergency access account added to the exclusions list.
Protects administrative roles while avoiding lockout scenarios by maintaining an unmanaged, highly secure emergency account.

Anahtar Kavram

Designing a secure, resilient hybrid identity solution with Microsoft Entra ID and Microsoft Entra Connect
Bu soruyu puanla