Caelum Skyworks is designing a hybrid identity solution that integrates their on-premises Active Directory Domain Services (AD DS) forest with a new Microsoft Entra ID tenant.
The design must meet the following requirements:
- Users must authenticate to cloud resources using their on-premises passwords.
- Users must be able to sign in to cloud applications even if the on-premises datacenter or its internet connection is offline.
- Users must be allowed to reset their own passwords in Microsoft Entra ID, and these changes must instantly reflect on-premises.
- A Conditional Access policy requiring Multi-Factor Authentication (MFA) for administrative roles must exclude a dedicated emergency break-glass account to prevent tenant lockout.
- Just-in-time administrative access must be used to manage Azure resources.
Which two actions should you include in the design to meet the requirements? (Select two.)
- Configure Password Hash Synchronization (PHS) and enable password writeback in Microsoft Entra Connect.Cevap
- Deploy a Conditional Access policy requiring MFA for all administrators, excluding the emergency access account.Cevap
- CDeploy Active Directory Federation Services (AD FS) and configure federation with Microsoft Entra ID.
- DDeploy a Conditional Access policy requiring MFA for all administrators, without configuring any exclusions.
- EConfigure Pass-through Authentication (PTA) in Microsoft Entra Connect and enable password writeback.
- FConfigure Microsoft Entra Privileged Identity Management (PIM) with permanently active administrative role assignments.