70-647 · Question #92
Your network consists of one Active directory domain. The functional level of the domain is Windows Server 2008 R2. You have one organizational unit (OU) named AllUsers that contains all user…
The correct answer is B. Create a new OU for each department. To ensure that the department managers must be allowed to manage the user accounts of only their departments, you need to create a new OU for each department and delegate administration to the department manager of each OU. To ensure that the users of both Sales and Development…
Question
Your network consists of one Active directory domain. The functional level of the domain is Windows Server 2008 R2. You have one organizational unit (OU) named AllUsers that contains all user accounts for the domain. Your company has two departments named Sales and Engineering. Each department has a department manager. Each department has a global security group that contains all department users. You need to prepare the environment to manage all user accounts. The solution must meet the following requirements:
- Sales department users must be required to reset their passwords
every 30 days.
- Department managers must administer only users in their respective
departments.
- Engineering department users must be required to reset their
passwords every 45 days. The solution must be achieved by using the minimum amount of administrative effort. What should you do?
Options
- ADelegate administration of the AllUsers OU to the department manager of each department.
- BCreate a new OU for each department.
- CCreate a child domain for each department.
- DCreate a new OU for each department.
How the community answered
(36 responses)- A3% (1)
- B83% (30)
- C6% (2)
- D8% (3)
Explanation
To ensure that the department managers must be allowed to manage the user accounts of only their departments, you need to create a new OU for each department and delegate administration to the department manager of each OU. To ensure that the users of both Sales and Development departments must change their passwords after the interval of 30 days and 45 days respectively, you need to create a new password policy for each global security group. The organizations that want different password and account lockout settings for different sets of users need to use fine-grained password policies. These policies cannot be applied to an organizational unit (OU) directly. To apply fine-grained password policy to users of an OU, you can use a shadow group, which is a global security group. 4f0bade6cd751033.mspx?mfr=true
Topics
Community Discussion
No community discussion yet for this question.