SC-300 · Question #29
You have a Microsoft 365 tenant. The Azure Active Directory (Azure AD) tenant syncs to an on-premises Active Directory domain. The domain contains the servers shown in the following table. The…
The correct answer is D. the Azure AD Password Protection proxy service. The AzureAD Password Protection proxy service initiates an outbound connection (Port 443) to Azure to pull the banned password list. The downloaded banned password list is pulled by the agent installed on DCs…
Question
You have a Microsoft 365 tenant. The Azure Active Directory (Azure AD) tenant syncs to an on-premises Active Directory domain. The domain contains the servers shown in the following table. The domain controllers are prevented from communicating to the internet. You implement Azure AD Password Protection on Server1 and Server2. You deploy a new server named Server4 that runs Windows Server 2019. You need to ensure that Azure AD Password Protection will continue to work if a single server fails. What should you implement on Server4?
Options
- AAzure AD Connect
- BAzure AD Application Proxy
- CPassword Change Notification Service (PCNS)
- Dthe Azure AD Password Protection proxy service
How the community answered
(36 responses)- A3% (1)
- B6% (2)
- C14% (5)
- D78% (28)
Explanation
The AzureAD Password Protection proxy service initiates an outbound connection (Port 443) to Azure to pull the banned password list. The downloaded banned password list is pulled by the agent installed on DCs. https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-password-ban-bad- on-premises-deploy
Topics
Community Discussion
No community discussion yet for this question.