QuestionQ48

Manage virtual machines

Overview -

Contoso, Ltd. is a company that has a main office in Seattle and two branch offices in Los Angeles and Montreal.

Existing Environment -

AD DS Environment -

The network contains an on-premises Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains two domains named contoso.com and canada.contoso.com.

The forest contains the domain controllers shown in the following table.

Question Image

All the domain controllers are global catalog servers.

Server Infrastructure -

The network contains the servers shown in the following table.

Question Image

A server named Server4 runs Windows Server and is in a workgroup. Windows Defender Firewall on Server4 uses the private profile.

Server2 hosts three virtual machines named VM1, VM2, and VM3.

VM3 is a file server that stores data in the volumes shown in the following table.

Question Image

Group Policies -

The contoso.com domain has the Group Policies Objects (GPOs) shown in the following table.

Question Image

Existing Identities -

The forest contains the users shown in the following table.

Question Image

The forest contains the groups shown in the following table.

Question Image

Current Problems -

When an administrator signs in to the console of VM2 by using Virtual Machine Connection, and then disconnects from the session without signing out, another administrator can connect to the console session as the currently signed-in user.

Requirements -

Technical Requirements -

Contoso identifies the following technical requirements:

Change the replication schedule for all site links to 30 minutes.

Promote Server1 to a domain controller in canada.contoso.com.

Install and authorize Server3 as a DHCP server.

Ensure that User1 can manage the membership of all the groups in Contoso\OU3.

Ensure that you can manage Server4 from Server1 by using PowerShell remoting.

Ensure that you can run virtual machines on VM1.

Force users to provide credentials when they connect to VM2.

On VM3, enable Data Deduplication on all volumes that support the feature.

You need to meet the technical requirements for VM2.

What should you do?

Explanation

Hyper-V's Virtual Machine Connection (VMConnect) tool has two console modes. In basic session mode it behaves like a direct connection to physical console hardware: if an administrator is already signed in and simply disconnects without signing out, a second administrator who opens VMConnect lands directly on that same live, already-authenticated console session without being prompted for credentials. Enhanced session mode instead tunnels the console connection over Remote Desktop Services, which requires the connecting user to authenticate with credentials before a session is established, and it creates its own logon session rather than joining whatever session happens to already be active on the console. Turning on enhanced session mode on the host (with Remote Desktop enabled in the guest) therefore forces every user connecting to VM2 to supply credentials, which is not something shielded virtual machines, Credential Guard, or the guest services integration component affect, since those protect VM state from the host, protect credential material on a machine, and enable host-to-guest file copy, respectively, rather than governing how VMConnect authenticates a console connection.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!