AZ-800 · Question #7
Case Study 1 - Fabrikam, Inc Overview Fabrikam, Inc is a manufacturing company that has a main office in New York and a branch office in Seattle. Existing Environment On-premises Servers The…
The correct answer is Deploy the Azure Connected Machine agent to all the servers. This question assesses understanding of the deployment architecture and component placement for Azure AD Password Protection in a hybrid environment.
Question
Exhibit
Answer Area
Drag items
Correct arrangement
- Deploy the Azure Connected Machine agent to all the servers.
Explanation
This question assesses understanding of the deployment architecture and component placement for Azure AD Password Protection in a hybrid environment.
Approach. 1. The Azure AD Password Protection DC agent: This agent is responsible for enforcing password policies directly on-premises. For comprehensive protection, it must be installed on all writable domain controllers in the on-premises Active Directory domain. Therefore, 'All the domain controllers' is the correct location. 2. The Azure AD Password Protection proxy service: This service acts as a communication bridge between the on-premises domain controllers and Azure AD. It retrieves banned password lists and uploads audit data. It is recommended to install this service on one or more member servers (not domain controllers) for redundancy and security isolation. Given the options, 'VM1 and VM2' represents suitable non-DC member servers for deploying this service. 3. A custom banned password list: Custom banned password lists are configured and managed centrally within the Azure AD tenant. They are then synchronized down to the on-premises environment via the proxy service. Therefore, 'The Azure AD tenant' is the correct location for the list itself.
Common mistakes.
- common_mistake. Drag 'DC1 only' for the DC agent: Installing the DC agent on only one domain controller would leave other domain controllers unprotected, allowing users to set weak passwords if their password change request is handled by an unprotected DC. - Drag 'The Azure AD tenant' for the DC agent or proxy service: The DC agent and proxy service are on-premises components that run on Windows Server instances, not directly within the Azure AD cloud service. - Drag 'All the domain controllers' for the proxy service: While technically possible, it is not best practice to install the proxy service on domain controllers. It is generally recommended to deploy it on separate member servers for security and performance reasons. - Drag 'DC1 only' or 'VM1 and VM2' for a custom banned password list: The custom banned password list is a configuration managed in the cloud (Azure AD) and synchronized to on-premises, it is not stored directly on an individual on-premises server.
Concept tested. Azure AD Password Protection architecture, including the roles and placement of the DC agent, proxy service, and how custom banned password lists are managed in a hybrid Active Directory environment.
Topics
Community Discussion
No community discussion yet for this question.
