nerdexam
Microsoft

AZ-800 · Question #247

Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1. On Server1, you install Windows Admin Center and use Windows Admin Center to…

The correct answer is D. Add a security group to the allowed groups. Removing BUILTIN\Users from the allowed groups in Windows Admin Center is not sufficient on its own to restrict access. Windows Admin Center uses an allowlist model - when the allowed groups list is empty or lacks a valid group, access control may fall back to default behavior…

Manage Windows Servers and workloads in a hybrid environment

Question

Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1. On Server1, you install Windows Admin Center and use Windows Admin Center to remove BUILTIN\Users from the allowed groups. You discover that all users can still sign in to Windows Admin Center. You need to prevent unauthorized users from signing in to Windows Admin Center. What should you do in Windows Admin Center?

Options

  • ASet Performance Profile to On.
  • BSet Require manage-as sessions to re-authenticate to On.
  • CFrom the Proxy settings, configure a bypass list.
  • DAdd a security group to the allowed groups.

How the community answered

(20 responses)
  • A
    5% (1)
  • B
    15% (3)
  • C
    5% (1)
  • D
    75% (15)

Explanation

Removing BUILTIN\Users from the allowed groups in Windows Admin Center is not sufficient on its own to restrict access. Windows Admin Center uses an allowlist model - when the allowed groups list is empty or lacks a valid group, access control may fall back to default behavior. The correct fix is to add a specific, restricted security group (e.g., a group containing only authorized admins) to the allowed groups list. This explicitly defines who is permitted to sign in. Simply removing the built-in Users group without adding a replacement group leaves access control in an undefined state, which is why all users could still sign in.

Topics

#Windows Admin Center (WAC)#Access Control#Security Configuration#Server Management

Community Discussion

No community discussion yet for this question.

Full AZ-800 Practice