70-243 · Question #170
Your network contains three Active Directory forests named contoso.com, fabrikam.com, and litwareinc.com. All of the forests are untrusted. In contoso.com, you have a System Center 2012 R2…
The correct answer is B. Add a Network Access Account for fabrikam.com and litwareinc.com. In a multi-forest environment with no AD trusts, SCCM Network Access Accounts provide the credentials needed for PXE-booted clients in untrusted forests to authenticate to distribution points and retrieve OS deployment content.
Question
Your network contains three Active Directory forests named contoso.com, fabrikam.com, and litwareinc.com. All of the forests are untrusted. In contoso.com, you have a System Center 2012 R2 Configuration Manager Service Pack 1 (SP1) deployment. In each forest, you deploy a distribution point that will be used to perform PXE-based operating system deployments. Each distribution point has the same configuration. You discover that the operating system deployments can only be performed in contoso.com. You need to ensure that you can perform the operating system deployments in each forest. The solution must minimize security changes to the Active Directory environment. What should you do?
Options
- AEstablish a one-way trust relationship from contoso.com to fabrikam.com and from contoso.com to
- BAdd a Network Access Account for fabrikam.com and litwareinc.com.
- CEstablish a one-way trust relationship from fabrikam.com to contoso.com and from litwareinc.com
- DAdd a client push installation account for fabrikam.com and litwareinc.com.
How the community answered
(26 responses)- A15% (4)
- B73% (19)
- C8% (2)
- D4% (1)
Why each option
In a multi-forest environment with no AD trusts, SCCM Network Access Accounts provide the credentials needed for PXE-booted clients in untrusted forests to authenticate to distribution points and retrieve OS deployment content.
Establishing a one-way trust from contoso.com to fabrikam.com and litwareinc.com introduces Active Directory trust relationships, which are significant security changes that contradict the stated requirement.
The Network Access Account (NAA) supplies credentials that SCCM clients use to access distribution point content when their own machine account lacks the required permissions - a situation that always occurs during PXE boot before domain join. Adding NAAs configured for fabrikam.com and litwareinc.com enables clients in those untrusted forests to download the OS deployment content from their respective distribution points without establishing any Active Directory trust relationships, satisfying the requirement to minimize security changes.
Creating trust relationships from fabrikam.com and litwareinc.com to contoso.com also requires Active Directory trust configuration and does not meet the requirement to minimize security changes to the AD environment.
Client push installation accounts are credentials used specifically for remotely installing the SCCM client agent and play no role in enabling PXE-based OS deployments across untrusted forest boundaries.
Concept tested: SCCM Network Access Account for untrusted forest PXE deployment
Source: https://learn.microsoft.com/en-us/mem/configmgr/core/plan-design/hierarchy/accounts#network-access-account
Topics
Community Discussion
No community discussion yet for this question.