SK0-004 · Question #430
The purpose of Active Directory Federation Services (AD FS) is to:
The correct answer is B. complement authentication and access management features of AD DS. AD FS extends AD DS with federated identity and single sign-on capabilities, enabling authentication across organizational and application boundaries.
Question
The purpose of Active Directory Federation Services (AD FS) is to:
Options
- Areplace Active Directory Domain Services (AD DS) as a domain management tool in
- Bcomplement authentication and access management features of AD DS
- Ccomplement authentication and access management features of Active Directory Rights
- Dreplace Active Directory Certificate Services (AD CS) in Windows Server 2013
How the community answered
(31 responses)- B94% (29)
- C3% (1)
- D3% (1)
Why each option
AD FS extends AD DS with federated identity and single sign-on capabilities, enabling authentication across organizational and application boundaries.
AD FS does not replace AD DS - it depends on AD DS as the underlying identity store and extends its reach through federation rather than substituting its domain management functions.
AD FS complements AD DS by adding claims-based authentication, federation trusts, and SSO features that AD DS alone does not provide. It works alongside AD DS to extend user authentication to external partners, cloud services, and web applications without replacing the core directory service.
AD FS complements AD DS, not Active Directory Rights Management Services (AD RMS), which is a separate product focused on data protection and document-level access control.
AD FS does not replace AD CS, and Windows Server 2013 is not a valid Microsoft release, making this answer both technically and factually incorrect.
Concept tested: Active Directory Federation Services purpose and integration with AD DS
Source: https://learn.microsoft.com/en-us/windows-server/identity/active-directory-federation-services
Topics
Community Discussion
No community discussion yet for this question.