Enabling multi-user authorization with Resource Guard to protect backups from a compromised admin
You have a Microsoft Entra tenant that syncs with an Active Directory Domain Services (AD DS) domain. You have an on-premises datacenter that contains 100 servers. The servers run Windows Server and are backed up by using Microsoft Azure Backup Server (MABS). You are designing a recovery solution for ransomware attacks. The solution follows Microsoft Security Best Practices. You need to ensure that a compromised local administrator account cannot be used to stop scheduled backups. What should you do?
Community Votes
50% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Resource Guard MUA requires a second authorized identity (often in a separate tenant) to approve critical operations, so a single compromised admin cannot stop backups alone; a security PIN is weaker because it can be entered by the same compromised account.
To ensure a compromised local administrator cannot stop scheduled backups, enable multi-user authorization (MUA) with Resource Guard on the Recovery Services vault, which requires secondary authorization from a separate identity for critical backup operations.
Relying only on a security PIN (D) — it adds a step but can be entered by the same compromised account, whereas MUA requires a distinct authorized approver.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Microsoft recommends enabling multi-user authorization (MUA) via Resource Guard for critical backup operations. Resource Guard requires a separate authorized identity (typically a security group, often in a separate Entra ID/tenant) to approve changes, so a single compromised local administrator cannot stop scheduled backups or disable protection on their own.Why the Other Options Are Wrong
A security PIN (D) adds authentication for critical operations but can be entered by the same compromised account, so it does not fully prevent a lone compromised admin. PIM Backup Contributor (B) and registering MABS (C) do not add the second-approver gate that stops a compromised admin.Community Comment Notes
The community was split (A 50 / D 50). The ransomware-resilience guidance recommends MUA/Resource Guard because it requires a second authorized approver, which is the control that specifically blocks a single compromised admin from stopping backups.Official Reference
Related Analysis
Practice All SC-100 Questions
Access 110 questions with complete answers and detailed explanations.
View Full SC-100 Practice Test →