nerdexam
Microsoft

AZ-801 · Question #14

For each of the following statements, select Yes if the statement is true. Otherwise, select No. Statements: User1 can sign in to Server4 by using Remote Desktop. User2 can sign in to Server4 by…

This question tests whether candidates understand how Windows Server controls Remote Desktop (RDP) access through group memberships, user rights assignments, and Group Policy - specifically which users are granted or denied the 'Allow log on through Remote Desktop Services'…

Secure Windows Server on-premises and hybrid infrastructures

Question

For each of the following statements, select Yes if the statement is true. Otherwise, select No. Statements: User1 can sign in to Server4 by using Remote Desktop. User2 can sign in to Server4 by using Remote Desktop. User3 can sign in to Server4 by using Remote Desktop.

Explanation

This question tests whether candidates understand how Windows Server controls Remote Desktop (RDP) access through group memberships, user rights assignments, and Group Policy - specifically which users are granted or denied the 'Allow log on through Remote Desktop Services' right.

Approach. To answer each Yes/No correctly, evaluate three layered controls: (1) Is Remote Desktop enabled on Server4? (2) Is the user a member of the local 'Remote Desktop Users' group or the local 'Administrators' group - both allow RDP by default? (3) Does Group Policy grant 'Allow log on through Remote Desktop Services' or explicitly set 'Deny log on through Remote Desktop Services' for that user or their security groups? A Deny right always overrides an Allow, even if the user is in the Remote Desktop Users group. Without the full environment details (AD group memberships, GPO settings, local group membership), the canonical rule is: Administrators and members of the Remote Desktop Users local group can sign in via RDP unless an explicit Deny right blocks them.

Concept tested. Remote Desktop Services (RDP) access control: interaction between local group membership (Administrators, Remote Desktop Users), the 'Allow log on through Remote Desktop Services' user right, and the 'Deny log on through Remote Desktop Services' user right as configured via Local Security Policy or Group Policy Object (GPO). Deny always wins over Allow.

Reference. MS-900 / SC-300 / AZ-800 - Windows Server Remote Desktop Services documentation; Group Policy: Computer Configuration > Windows Settings > Security Settings > Local Policies > User Rights Assignment

Topics

#Remote Desktop Protocol (RDP)#User access management#Security groups#Server security

Community Discussion

No community discussion yet for this question.

Full AZ-801 Practice