QuestionQ8

Secure Windows Server infrastructure

Your network includes an Active Directory Domain Services (AD DS) domain.

The domain includes a member server named DNS1 with the DNS Server role installed and PowerShell remoting enabled. The domain also includes a group named DNSOperators.

Members of DNSOperators carry out routine DNS tasks on DNS1 by using PowerShell. DNSOperators members are NOT local administrators on DNS1.

You need to configure remote management for DNSOperators. The solution must meet these requirements:

  • Enable access to DNS1 by using non-admin domain accounts.
  • Permit only the required DNS commands to run on DNS1.
  • Prevent adding DNSOperators to privileged groups.

What should you implement?

Explanation

Just Enough Administration (JEA) creates a restricted PowerShell remoting endpoint for delegated administration. Its role capability specifies exactly which cmdlets, functions, and commands are available, while a temporary virtual account can perform the necessary local privileged actions on behalf of users who connect with ordinary domain accounts. This avoids granting DNSOperators membership in privileged local or domain groups.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!