Apex Autonomy is designing a secure identity and access management strategy in Microsoft Entra ID. You need to match the specific security and operational access requirements to the corresponding Microsoft Entra Conditional Access settings.
To answer, match each security requirement on the left to the correct Conditional Access setting on the right.
- Require external contractors to use phishing-resistant multi-factor authentication (MFA) when accessing sensitive source code repositories.Grant controls: Require authentication strength
- Prevent users from copying, pasting, or downloading files when they access Exchange Online from unmanaged personal devices.Session controls: Use Conditional Access App Control
- Force administrators to re-authenticate if they attempt to access the Azure portal after their session has been active for more than 4 hours.Session controls: Sign-in frequency
- Block access to the enterprise resource planning (ERP) system if a user attempts to log in from a location not defined by IP ranges or GPS coordinates.Conditions: Location
Cevap
To satisfy the security requirements:
- Requiring phishing-resistant MFA is accomplished by selecting the Grant controls: Require authentication strength setting.
- Restricting actions like downloading or copying files on unmanaged devices is achieved via the Session controls: Use Conditional Access App Control setting.
- Forcing administrative re-authentication after a set period is controlled by the Session controls: Sign-in frequency setting.
- Restricting access based on coordinates or IP ranges uses the Conditions: Location setting.
- Requiring phishing-resistant MFA is accomplished by selecting the Grant controls: Require authentication strength setting.
- Restricting actions like downloading or copying files on unmanaged devices is achieved via the Session controls: Use Conditional Access App Control setting.
- Forcing administrative re-authentication after a set period is controlled by the Session controls: Sign-in frequency setting.
- Restricting access based on coordinates or IP ranges uses the Conditions: Location setting.
Each security requirement aligns with a specific component of a Microsoft Entra Conditional Access policy. Re-authentication frequency is managed through the Sign-in frequency session control. Control over device actions such as preventing downloads requires Session controls integrated with Microsoft Defender for Cloud Apps. Phishing-resistant MFA is enforced via Authentication strength in Grant controls. Geolocation or IP limits are managed via Location conditions.
Adım Adım Çözüm
Anahtar Kavram
Microsoft Entra ID Conditional Access controls and conditions mapping
Tahmini Süre:2m 0s