Enabling multi-user authorization with Resource Guard to protect backups from a compromised admin

Design a resiliency strategy for ransomware and other attacks based on Microsoft Security Best Practices
Answer Correct answer: A — Resource Guard multi-user authorization requires a second approver for critical backup operations, blocking a compromised admin from stopping backups alone.

You have a Microsoft Entra tenant that syncs with an Active Directory Domain Services (AD DS) domain. You have an on-premises datacenter that contains 100 servers. The servers run Windows Server and are backed up by using Microsoft Azure Backup Server (MABS). You are designing a recovery solution for ransomware attacks. The solution follows Microsoft Security Best Practices. You need to ensure that a compromised local administrator account cannot be used to stop scheduled backups. What should you do?

  1. From Azure Backup, configure multi-user authorization by using Resource Guard. Correct Answer
  2. From Microsoft Entra Privileged Identity Management (PIM), create a role assignment for the Backup Contributor role.
  3. From Microsoft Azure Backup Setup, register MABS with a Recovery Services vault.
  4. From a Recovery Services vault, generate a security PIN for critical operations.

Community Votes

A
50%
D
50%

50% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Resource Guard MUA requires a second authorized identity (often in a separate tenant) to approve critical operations, so a single compromised admin cannot stop backups alone; a security PIN is weaker because it can be entered by the same compromised account.

To ensure a compromised local administrator cannot stop scheduled backups, enable multi-user authorization (MUA) with Resource Guard on the Recovery Services vault, which requires secondary authorization from a separate identity for critical backup operations.

Relying only on a security PIN (D) — it adds a step but can be entered by the same compromised account, whereas MUA requires a distinct authorized approver.

Community Discussion (4 comments)

424ede1 👍 1 Selected: D
From a Recovery Services vault, generate a security PIN for critical operations https://learn.microsoft.com/en-us/azure/backup/backup-azure-security-feature#authentication-to-perform-critical-operations
SMHcalicut 👍 4 Selected: A
Ransomware Protection and Multi-User Authorization Microsoft recommends enabling multi-user authorization (MUA) to protect backup configurations from unauthorized changes. Resource Guard allows you to enforce MUA for critical backup operations, ensuring that a compromised administrator account alone cannot modify or disable backups without additional authorization.
lam_15 👍 4 Selected: D
https://learn.microsoft.com/en-us/azure/backup/multi-user-authorization-concept?tabs=recovery-services-vault
676ae1a 👍 1 Selected: A
Esta configuración agrega una capa adicional de protección a las operaciones críticas en los almacenes de Recovery Services, asegurando que solo las personas autorizadas puedan realizar ciertas acciones.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Microsoft recommends enabling multi-user authorization (MUA) via Resource Guard for critical backup operations. Resource Guard requires a separate authorized identity (typically a security group, often in a separate Entra ID/tenant) to approve changes, so a single compromised local administrator cannot stop scheduled backups or disable protection on their own.

Why the Other Options Are Wrong

A security PIN (D) adds authentication for critical operations but can be entered by the same compromised account, so it does not fully prevent a lone compromised admin. PIM Backup Contributor (B) and registering MABS (C) do not add the second-approver gate that stops a compromised admin.

Community Comment Notes

The community was split (A 50 / D 50). The ransomware-resilience guidance recommends MUA/Resource Guard because it requires a second authorized approver, which is the control that specifically blocks a single compromised admin from stopping backups.

Official Reference

Related Analysis

Practice All SC-100 Questions

Access 110 questions with complete answers and detailed explanations.

View Full SC-100 Practice Test →

← Back to SC-100 Study Guide