QuestionQ77

Design solutions that align with security best practices and priorities

You have a Microsoft Entra tenant that synchronizes with an Active Directory Domain Services (AD DS) domain.

You have an on-premises datacenter containing 100 servers. The servers run Windows Server and are backed up by using Microsoft Azure Backup Server (MABS).

You are designing a recovery solution for ransomware attacks. The solution adheres to Microsoft Security Best Practices.

You need to ensure that a compromised local administrator account cannot be used to stop scheduled backups.

What should you do?

  • A From Azure Backup, configure multi-user authorization by using Resource Guard.
  • B From Microsoft Entra Privileged Identity Management (PIM), create a role assignment for the Backup Contributor role.
  • C From Microsoft Azure Backup Setup, register MABS with a Recovery Services vault.
  • D From a Recovery Services vault, generate a security PIN for critical operations.
Explanation

Azure Backup multi-user authorization uses a Resource Guard to require separate authorization for critical, high-impact backup operations. This additional approval boundary helps prevent a single compromised administrator account from stopping or altering protected backups, which is a key ransomware-resilience control for MABS hybrid backups.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!