SC-401 · Question #85
You have a Microsoft 365 E5 subscription that contains a Windows 11 device named Device1 and three users named User1, User2, and User3. You plan to deploy Azure information Protection (AIP) and the…
The correct answer is C. Exclude User2 and User3 from multifactor authentication (MFA). Multi-factor authentication (MFA) and Azure Information Protection Rights Management connector requirements The Rights Management connector and the Microsoft Purview Information Protection scanner do not support MFA. If you deploy the connector or scanner, the following…
Question
You have a Microsoft 365 E5 subscription that contains a Windows 11 device named Device1 and three users named User1, User2, and User3. You plan to deploy Azure information Protection (AIP) and the Microsoft Purview information Protection client to Device1. You need to ensure that the users can perform the following actions on Device1 as part of the planned deployment:
- User1 will test the functionality of the client.
- User2 will install and configure the Microsoft Rights Management
connector.
- User3 will be configured as the service account for the information
protection scanner. The solution must maximize the security of the sign-in process for the users. What should you do?
Options
- AExclude User1 and User2 from multifactor authentication (MFA).
- BEnable User2 and User3 for passwordless authentication.
- CExclude User2 and User3 from multifactor authentication (MFA).
- DEnable User1, User2, and User3 for passkey (FIDO2) authentication.
How the community answered
(28 responses)- A4% (1)
- B11% (3)
- C82% (23)
- D4% (1)
Explanation
Multi-factor authentication (MFA) and Azure Information Protection Rights Management connector requirements The Rights Management connector and the Microsoft Purview Information Protection scanner do not support MFA. If you deploy the connector or scanner, the following accounts must not require MFA: The account that installs and configures the connector. [User2] The service principal account in Microsoft Entra ID, Aadrm_S-1-7-0, that the connector creates. The service account that runs the scanner. [User3] https://learn.microsoft.com/en-us/azure/information-protection/requirements-azure-ad
Topics
Community Discussion
No community discussion yet for this question.