Soru

Zorluk: OrtaMicrosoft Entra ID Authentication and Conditional Access

Solas Renewable Energy is designing an identity and access management solution for its Microsoft Entra ID tenant. The solution must meet the following requirements:

- Enforce multi-factor authentication (MFA) for all users assigned to privileged administrator roles when they access the Azure portal.
- Prevent administrative users from being permanently assigned to privileged roles, requiring them to activate roles on demand.
- Ensure that the tenant remains accessible to administrators even during a widespread Microsoft Entra MFA service outage.

Which of the following configurations should you include in the design? (Select TWO.)

  1. Create a Conditional Access policy requiring multi-factor authentication for administrative roles, and exclude a dedicated, cloud-only emergency access account.Cevap
  2. Configure eligible role assignments in Microsoft Entra Privileged Identity Management (PIM) for the administrative roles.Cevap
  3. C
    Configure active role assignments in Microsoft Entra Privileged Identity Management (PIM) for the administrative roles.
  4. D
    Deploy Active Directory Federation Services (AD FS) to manage multi-factor authentication and role assignment exclusion rules.

Cevap

Create a Conditional Access policy requiring multi-factor authentication for administrative roles, and exclude a dedicated, cloud-only emergency access account; and configure eligible role assignments in Microsoft Entra Privileged Identity Management (PIM) for the administrative roles.
To meet the security and reliability goals, you must enforce MFA using Conditional Access while excluding an emergency access account to prevent lockout during service outages. Additionally, to avoid permanent privileges, you must configure eligible assignments in Microsoft Entra Privileged Identity Management (PIM), which allows administrators to elevate their access on demand.

Adım Adım Çözüm

1
Identify the requirement to prevent permanent administrative assignment.
Determine that Microsoft Entra Privileged Identity Management (PIM) must be used with eligible assignments, not active assignments, to enforce just-in-time role activation.
Active assignments leave the privilege permanently assigned to the user.
2
Identify the requirement to enforce MFA for administrators while preventing tenant lockout during outages.
Determine that a Conditional Access policy must target administrative roles with MFA required, and exclude a dedicated, cloud-only emergency access account.
Excluding the emergency access account ensures admins can log in if Entra MFA is offline, avoiding a tenant lockout scenario.

Anahtar Kavram

Designing Microsoft Entra ID Conditional Access policies with emergency exclusions and integrating Privileged Identity Management (PIM) for just-in-time access.
Bu soruyu puanla