A company is deploying an agent for employees. The company has the following requirements:
* Access must be restricted to the internal employees only.
* End-user authentication must be enforced.
You need to configure the agent based on the company requirements. What should you do?
Comprehensive and Detailed Explanation From Microsoft AB-620 Study Guide: Selecting Authenticate with Microsoft restricts the agent to signed-in organizational identities in the supported Microsoft channel and enables the agent to be shared with controlled users in the tenant. That meets the requirement for internal employees and enforced end-user authentication. No authentication or a public website would allow anyone with access to the link to converse with the agent and would prevent reliable organizational access control. A personal-account setting is not the enterprise identity model required here. Authentication and authorization are related but separate: after choosing Microsoft authentication, the owner must still share the agent only with the intended employees or groups and ensure connected knowledge and tools apply the user's permissions correctly. If the deployment uses a channel that requires manual Entra ID configuration, the appropriate manual authentication and sign-in requirement may be needed instead; however, among the supplied choices, Authenticate with Microsoft is the correct control. Test with authorized, unauthorized, and signed-out users before release, and review any DLP policy that mandates authentication. Study Guide alignment: Plan and configure agent solutions > Plan an agent solution > Plan identity strategy; Design agents for internal audiences.
===============
Currently there are no comments in this discussion, be the first to comment!