QuestionQ4
Secure Windows Server on-premises and hybrid infrastructuresExisting Environment
The network contains an Active Directory Domain Services (AD DS) domain named contoso.com.
Domain controllers
| Name | Operating system | Operation master role |
|---|---|---|
| DC1 | Windows Server 2012 R2 | RID master, schema master |
| DC2 | Windows Server 2016 | PDC emulator, infrastructure master |
| DC3 | Windows Server 2016 | Domain naming master |
Users and groups
| Name | Organizational unit (OU)/Container | Member of |
|---|---|---|
| User1 | OU1 | Group2, Group4 |
| User2 | Users | Group2 |
| User3 | OU1 | Group3, Group4 |
| Admin1 | OU1 | Domain Admins |
Password policies
| Name | Minimum password length | Linked to |
|---|---|---|
| Default Domain Policy | 8 | contoso.com |
| GPO1 | 10 | OU1 |
The domain contains the following fine-grained password policies (PSOs):
| Name | Precedence | Minimum password length | Directly applies to |
|---|---|---|---|
| PSO1 | 10 | 9 | Group2 |
| PSO2 | 20 | 11 | Group4 |
Member servers
| Name | Description |
|---|---|
| Server1 | Contains a share named Share1 |
| Server2 | None |
| Server3 | None |
| Server4 | Has Remote Desktop enabled |
Connection security rules
| Name | Endpoint1 | Endpoint2 | Authentication mode |
|---|---|---|---|
| Server1 | Any | Any | Request inbound and outbound |
| Server2 | Any | Any | Require inbound and request outbound |
| Server3 | Any | Any | Require inbound and outbound |
| DC1 | Any | Any | Request inbound and outbound |
| DC2 | Any | Any | Request inbound and outbound |
| DC3 | Any | Any | Request inbound and outbound |
Effective user rights on the servers
| Policy | Security setting |
|---|---|
| Access this computer from the network | Group1, Administrators, Backup Operators, Everyone, Users |
| Deny access to this computer from the network | Group4 |
| Allow log on through Remote Desktop Services | Group2, Administrators, Remote Desktop Users |
| Deny log on through Remote Desktop Services | Group3 |
Server4 disks
| Disk | Volume | Size | File system | Notes |
|---|---|---|---|---|
| Disk 0 | System Reserved | 100 MB | NTFS | System, Active |
| Disk 0 | C: | 126.39 GB | NTFS | Boot, page file, crash dump (operating system volume) |
| Disk 0 | Recovery | 523 MB | — | Recovery partition |
| Disk 1 | D: (Data) | 127.00 GB | NTFS | Primary partition |
| Disk 2 | E: (Data) | 127.00 GB | ReFS | Primary partition |
| Disk 3 | F: (Data) | 127.00 GB | ReFS | Primary partition |
Failover clusters
| Name | Number of nodes | Number of virtual machines |
|---|---|---|
| Cluster1 | 6 | 18 |
| Cluster2 | 4 | 12 |
| Cluster3 | 2 | 6 |
You need to configure BitLocker on Server4.
Choose the volumes on which you can enable BitLocker and those on which you can enable auto-unlock.
Select
BitLocker:
Auto-unlock:
Community Discussion