User1 という名前のユーザーを含む Microsoft 365 サブスクリプションがあります。 User1 には、次のタスクを実行するための管理者アクセスが必要です。 Microsoft Exchange Online の設定を管理します。 Microsoft 365 グループを作成します。 User1 には 8 時間のみ管理者アクセス権があり、ロールの割り当てが行われる前に承認が必要であることを確認する必要があります。 何を使えばいいのでしょうか?
正解:D
Explanation Privileged Identity Management provides time-based and approval-based role activation to mitigate the risks of excessive, unnecessary, or misused access permissions on resources that you care about. Here are some of the key features of Privileged Identity Management: Provide just-in-time privileged access to Azure AD and Azure resources Assign time-bound access to resources using start and end dates Require approval to activate privileged roles Enforce multi-factor authentication to activate any role Use justification to understand why users activate Get notifications when privileged roles are activated Conduct access reviews to ensure users still need roles Download audit history for internal or external audit Prevents removal of the last active Global Administrator and Privileged Role Administrator role assignments. Reference: https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-configure