139k views
0 votes
You have a Microsoft 365 E5 subscription.You need to ensure that users who are assigned the Exchange administrator role have time-limited permissions and must use multi-factor authentication (MFA) to request the permissions.What should you use to achieve the goal?

User TerryTsao
by
8.4k points

1 Answer

2 votes

Final answer:

To achieve the goal of having time-limited permissions and requiring multi-factor authentication (MFA) for users with the Exchange administrator role in a Microsoft 365 E5 subscription, you can use Conditional Access policy.

Step-by-step explanation:

To achieve the goal of having time-limited permissions and requiring multi-factor authentication (MFA) for users with the Exchange administrator role in a Microsoft 365 E5 subscription, you can use Conditional Access policy.

Conditional Access is a feature in Azure Active Directory that enables you to create policies to control access to your cloud applications based on conditions such as user location, device compliance, and other factors. By configuring a Conditional Access policy, you can enforce MFA for users with the Exchange administrator role and set time-limited permissions for them. This ensures enhanced security and reduces the risk of unauthorized access.

By leveraging the capabilities of Conditional Access, you can create a policy specific to users with the Exchange administrator role. This policy can require the use of MFA and only grant the necessary permissions for a limited time, ensuring that the access remains secure and controlled.

User Echolocation
by
8.9k points