2V0-21.20 · Question #84
An administrator is configuring an identity source for Single Sign-On. The administrator will use the machine that Single Sign-on is running on, but does not want all users on the machine to be…
The correct answer is D. Active Directory (Integrated Windows Authentication). To restrict users on the machine visible to single sign-on, you need to employ Active directory and its authentication. If the user account is locked or disabled, authentications and group and group and user searches in the Active Directory domain will fail. The user account…
Question
An administrator is configuring an identity source for Single Sign-On. The administrator will use the machine that Single Sign-on is running on, but does not want all users on the machine to be visible to SSO. Which identity Source meets this requirement?
Options
- ALocalOS
- BActive Directory as an LDAP service
- COpenLDAP
- DActive Directory (Integrated Windows Authentication)
How the community answered
(18 responses)- A6% (1)
- B11% (2)
- D83% (15)
Explanation
To restrict users on the machine visible to single sign-on, you need to employ Active directory and its authentication. If the user account is locked or disabled, authentications and group and group and user searches in the Active Directory domain will fail. The user account must have read-only access over the User and Group OU, and must be able to read user and group attributes. This is the default Active Directory domain configuration for user permissions.
Topics
Community Discussion
No community discussion yet for this question.