nerdexam
Broadcom-VMware

2V0-21.20 · Question #84

An administrator is configuring an identity source for Single Sign-On. The administrator will use the machine that Single Sign-on is running on, but does not want all users on the machine to be…

The correct answer is D. Active Directory (Integrated Windows Authentication). To restrict users on the machine visible to single sign-on, you need to employ Active directory and its authentication. If the user account is locked or disabled, authentications and group and group and user searches in the Active Directory domain will fail. The user account…

Installing, Configuring, and Setup

Question

An administrator is configuring an identity source for Single Sign-On. The administrator will use the machine that Single Sign-on is running on, but does not want all users on the machine to be visible to SSO. Which identity Source meets this requirement?

Options

  • ALocalOS
  • BActive Directory as an LDAP service
  • COpenLDAP
  • DActive Directory (Integrated Windows Authentication)

How the community answered

(18 responses)
  • A
    6% (1)
  • B
    11% (2)
  • D
    83% (15)

Explanation

To restrict users on the machine visible to single sign-on, you need to employ Active directory and its authentication. If the user account is locked or disabled, authentications and group and group and user searches in the Active Directory domain will fail. The user account must have read-only access over the User and Group OU, and must be able to read user and group attributes. This is the default Active Directory domain configuration for user permissions.

Topics

#SSO identity source#Active Directory#integrated Windows authentication#user visibility

Community Discussion

No community discussion yet for this question.

Full 2V0-21.20 Practice