AZ-800 · Question #242
You have a Microsoft Entra Domain Services domain named contoso.com. You need to provide an administrator with the ability to manage Group Policy Objects (GPOs). The solution must use the principle…
The correct answer is A. AAD DC Administrators. To grant an administrator the ability to manage Group Policy Objects in a Microsoft Entra Domain Services domain with the principle of least privilege, they should be added to the AAD DC Administrators group.
Question
You have a Microsoft Entra Domain Services domain named contoso.com. You need to provide an administrator with the ability to manage Group Policy Objects (GPOs). The solution must use the principle of least privilege. To which group should you add the administrator?
Options
- AAAD DC Administrators
- BDomain Admins
- CSchema Admins
- DEnterprise Admins
- EGroup Policy Creator Owners
How the community answered
(27 responses)- A78% (21)
- B11% (3)
- D4% (1)
- E7% (2)
Why each option
To grant an administrator the ability to manage Group Policy Objects in a Microsoft Entra Domain Services domain with the principle of least privilege, they should be added to the AAD DC Administrators group.
The AAD DC Administrators group in Microsoft Entra Domain Services provides delegated administrative permissions to perform common management tasks, including Group Policy management, within the managed domain.
The Domain Admins group provides excessive privileges beyond GPO management and is typically not directly manageable in an Azure AD Domain Services environment.
The Schema Admins group has permissions to modify the Active Directory schema, which is not required for GPO management and provides far too many privileges.
The Enterprise Admins group has forest-wide administrative privileges, which is far beyond the scope needed for GPO management within a single domain and is not directly manageable in AAD DS.
The Group Policy Creator Owners group primarily allows users to create new GPOs but does not inherently grant full management rights over all existing GPOs or their linking, which is typically handled by administrators.
Concept tested: Azure AD Domain Services administration, delegated permissions
Source: https://learn.microsoft.com/en-us/azure/active-directory-domain-services/concepts-aadds-security#aad-dc-administrators-group
Topics
Community Discussion
No community discussion yet for this question.