QuestionQ32

Deploy and manage AD DS

DRAG DROP -

Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains two users named Contractor1 and Admin1.

You need to configure Account options for the users. The solution must meet the following requirements:

Contractor1 must be prevented from signing in to their client computer until an administrator enables their account.

The credentials of Admin1 must NOT be usable by services that access network resources on behalf of users.

What should you select for each user? To answer, drag the appropriate account options to the correct users. Each option may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Drag & Drop
Contractor1:
Admin1:
Explanation

Selecting 'Account is disabled' on a user object sets the ACCOUNTDISABLE bit of userAccountControl, which blocks every sign-in attempt for that account until an administrator explicitly clears the flag -- exactly the behavior needed to keep a contractor's account unusable until deliberately activated by an administrator. Selecting 'Account is sensitive and cannot be delegated' sets the account's UAC flag that instructs Kerberos to refuse to issue a forwardable/delegated ticket for that identity, so no service configured for delegation (constrained or unconstrained) can present that account's credentials to another resource on its behalf -- which is the documented control for ensuring a privileged account's credentials can never be reused by a service acting for the user, independent of how any individual service's delegation is configured.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!