nerdexam
Microsoft

AZ-800 · Question #242

You have a Microsoft Entra Domain Services domain named contoso.com. You need to provide an administrator with the ability to manage Group Policy Objects (GPOs). The solution must use the principle…

The correct answer is A. AAD DC Administrators. To grant an administrator the ability to manage Group Policy Objects in a Microsoft Entra Domain Services domain with the principle of least privilege, they should be added to the AAD DC Administrators group.

Deploy and manage Active Directory Domain Services (AD DS) in on-premises and cloud environments

Question

You have a Microsoft Entra Domain Services domain named contoso.com. You need to provide an administrator with the ability to manage Group Policy Objects (GPOs). The solution must use the principle of least privilege. To which group should you add the administrator?

Options

  • AAAD DC Administrators
  • BDomain Admins
  • CSchema Admins
  • DEnterprise Admins
  • EGroup Policy Creator Owners

How the community answered

(27 responses)
  • A
    78% (21)
  • B
    11% (3)
  • D
    4% (1)
  • E
    7% (2)

Why each option

To grant an administrator the ability to manage Group Policy Objects in a Microsoft Entra Domain Services domain with the principle of least privilege, they should be added to the AAD DC Administrators group.

AAAD DC AdministratorsCorrect

The AAD DC Administrators group in Microsoft Entra Domain Services provides delegated administrative permissions to perform common management tasks, including Group Policy management, within the managed domain.

BDomain Admins

The Domain Admins group provides excessive privileges beyond GPO management and is typically not directly manageable in an Azure AD Domain Services environment.

CSchema Admins

The Schema Admins group has permissions to modify the Active Directory schema, which is not required for GPO management and provides far too many privileges.

DEnterprise Admins

The Enterprise Admins group has forest-wide administrative privileges, which is far beyond the scope needed for GPO management within a single domain and is not directly manageable in AAD DS.

EGroup Policy Creator Owners

The Group Policy Creator Owners group primarily allows users to create new GPOs but does not inherently grant full management rights over all existing GPOs or their linking, which is typically handled by administrators.

Concept tested: Azure AD Domain Services administration, delegated permissions

Source: https://learn.microsoft.com/en-us/azure/active-directory-domain-services/concepts-aadds-security#aad-dc-administrators-group

Topics

#Microsoft Entra Domain Services#Group Policy#Least Privilege#Active Directory Administration

Community Discussion

No community discussion yet for this question.

Full AZ-800 Practice