An organization is designing a Microsoft Entra Conditional Access policy to require multi-factor authentication (MFA) for all administrative users. To prevent administrative lockout in the event of an authentication outage or misconfiguration, which policy configuration should you recommend?
- Exclude a dedicated emergency access account from the Conditional Access policyCevap
- BApply the Conditional Access policy to all administrative accounts with no exclusions
- CConfigure the emergency access accounts with permanently active administrator roles in Microsoft Entra Privileged Identity Management (PIM)
- DDeploy Active Directory Federation Services (AD FS) to manage authentication for the emergency access accounts
Cevap
Exclude a dedicated emergency access account from the Conditional Access policy
Excluding a dedicated emergency access account from the Conditional Access policy ensures that there is always at least one highly privileged account that can bypass standard authentication checks in the event of an outage or configuration error.
Adım Adım Çözüm
Anahtar Kavram
Microsoft Entra ID emergency access accounts bypass standard Conditional Access policies to prevent tenant lockout.