70-647 · Question #58
Your network consists of 20 Active directory domains in a single forest. The functional level of the forest is Windows Server 2008 R2. You company has 20 departments. A separate domain exists for…
The correct answer is C. In one domain, create a universal group for all the IT administrators. To consolidate all the IT departments into a single IT department, you need to create a Universal group for all the IT administrators in a domain. The Universal groups allow users (and groups) from multiple domains to have membership in a single group that is available…
Question
Your network consists of 20 Active directory domains in a single forest. The functional level of the forest is Windows Server 2008 R2. You company has 20 departments. A separate domain exists for each department. Each domain has an organizational unit (OU) named DepartmentUsers that contains the respective domain users. Each domain has its own IT department. You need to plan the consolidation of all the IT departments into a single IT department. The solution must meet the following requirements:
- IT administrators must be denied from making domain-wide changes.
- IT administrators must be able to administer users in all
departments. Your solution must use the minimum amount of administrative effort. What should you include in your plan?
Options
- AIn one domain, create a universal group for all the IT administrators.
- BIn one domain, create a global group for all the IT administrators.
- CIn one domain, create a universal group for all the IT administrators.
- DIn each domain, create a domain local group for the IT administrators.
How the community answered
(50 responses)- A2% (1)
- B6% (3)
- C82% (41)
- D10% (5)
Explanation
To consolidate all the IT departments into a single IT department, you need to create a Universal group for all the IT administrators in a domain. The Universal groups allow users (and groups) from multiple domains to have membership in a single group that is available throughout the Active Directory forest. This is useful in a forest with multiple Active Directory domains to simplify resource access permissions. If users or groups from different domains need access to resources that are located in multiple domains, a universal group can be used to allow for that access. Next you need to delegate administration of the DeptUsersOU in each domain to the common group (Universal group) that you have created for IT administrators so that IT administrators are able to administer users in all departments. You cannot add that group \9Universal group that you have created) to the Domain Admins group in each domain because you don't want ID administrators to make domain- wide changes.
Topics
Community Discussion
No community discussion yet for this question.