QuestionQ5

Deploy and manage AD DS

Overview

Contoso, Ltd. has a main office in Seattle and two branch offices in Los Angeles and Montreal.

Existing Environment

AD DS Environment

The network includes an on-premises Active Directory Domain Services (AD DS) forest named contoso.com. The forest includes two domains: contoso.com and canada.contoso.com.

The forest includes the domain controllers shown in the following table.

Question Image

All domain controllers are global catalog servers.

Server Infrastructure

The network includes the servers shown in the following table.

Question Image

Server4 runs Windows Server and belongs to a workgroup. Windows Defender Firewall on Server4 uses the private profile.

Server2 hosts three virtual machines named VM1, VM2, and VM3.

VM3 is a file server that stores data in the volumes shown in the following table.

Question Image

Group Policies

The contoso.com domain contains the Group Policy Objects (GPOs) shown in the following table.

Question Image

Existing Identities

The forest includes the users shown in the following table.

Question Image

The forest includes the groups shown in the following table.

Question Image

Current Problems

When an administrator signs in to the VM2 console by using Virtual Machine Connection and disconnects without signing out, another administrator can connect to that console session as the currently signed-in user.

Requirements

Technical Requirements

Contoso identifies the following technical requirements:

  • Change the replication schedule for all site links to 30 minutes.
  • Promote Server1 to a domain controller in canada.contoso.com.
  • Install and authorize Server3 as a DHCP server.
  • Ensure that User1 can manage membership of all groups in Contoso\OU3.
  • Ensure that Server4 can be managed from Server1 by using PowerShell remoting.
  • Ensure that virtual machines can run on VM1.
  • Require users to provide credentials when they connect to VM2.
  • On VM3, enable Data Deduplication on every volume that supports the feature.

You need to meet the technical requirements for Server1.

Which users can currently perform the required tasks?

Explanation

Promoting Server1 as an additional domain controller in canada.contoso.com requires administrative permission in that domain or equivalent forest-level rights. Managing the workgroup Server4 through PowerShell remoting requires administrative rights to configure and use the required remoting settings. Admin1 and Admin3 have the necessary permissions for these Server1 requirements; Admin2 does not. Microsoft documents that installing another domain controller in an existing domain requires Domain Admin credentials, and that changing TrustedHosts/remoting configuration requires local administrator permissions.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!