SC-100 · Question #198
You have a Microsoft Entra tenant that contains 10 Windows 11 devices and two groups named Group1 and Group2. The Windows 11 devices are joined to the Microsoft Entra tenant and are managed by using…
The correct answer is C. Add Group2 to the local Administrators group. Add the user that is assigned the Security. Separate and manage privileged accounts Emergency access accounts What: Ensure that you are not accidentally locked out of your Microsoft Entra organization in an emergency situation. Why: Emergency access accounts rarely used and highly damaging to the organization if…
Question
You have a Microsoft Entra tenant that contains 10 Windows 11 devices and two groups named Group1 and Group2. The Windows 11 devices are joined to the Microsoft Entra tenant and are managed by using Microsoft Intune. You are designing a privileged access strategy based on the rapid modernization plan (RaMP). The strategy will include the following configurations:
- Each user in Group1 will be assigned a Windows 11 device that will be
configured as a privileged access device.
- The Security Administrator role will be mapped to the privileged
access security level.
- The users in Group1 will be assigned the Security Administrator role.
- The users in Group2 will manage the privileged access devices.
You need to configure the local Administrators group for each privileged access device. The solution must follow the principle of least privilege. What should you include in the solution?
Options
- AOnly add Group2 to the local Administrators group.
- BConfigure Windows Local Administrator Password Solution (Windows LAPS) in legacy Microsoft
- CAdd Group2 to the local Administrators group. Add the user that is assigned the Security
How the community answered
(23 responses)- A9% (2)
- B17% (4)
- C74% (17)
Explanation
Separate and manage privileged accounts Emergency access accounts What: Ensure that you are not accidentally locked out of your Microsoft Entra organization in an emergency situation. Why: Emergency access accounts rarely used and highly damaging to the organization if compromised, but their availability to the organization is also critically important for the few scenarios when they are required. Ensure you have a plan for continuity of access that accommodates both expected and unexpected events. https://learn.microsoft.com/en-us/security/privileged-access-workstations/security-rapid- modernization-plan
Topics
Community Discussion
No community discussion yet for this question.