exam questions

Exam AZ-800 All Questions

View all questions & answers for the AZ-800 exam

Exam AZ-800 topic 2 question 4 discussion

Actual exam question from Microsoft's AZ-800
Question #: 4
Topic #: 2
[All AZ-800 Questions]

You have an on premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant. The domain contains two servers named Server1 and Server2.
A user named Admin1 is a member of the local Administrators group on Server1 and Server2.
You plan to manage Server1 and Server2 by using Azure Arc. Azure Arc objects will be added to a resource group named RG1.
You need to ensure that Admin1 can configure Server1 and Server2 to be managed by using Azure Arc.
What should you do first?

  • A. From the Azure portal, generate a new onboarding script.
  • B. Assign Admin1 the Azure Connected Machine Onboarding role for RG1.
  • C. Hybrid Azure AD join Server1 and Server2.
  • D. Create an Azure cloud-only account for Admin1.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
MiMojo
Highly Voted 1 year, 12 months ago
Selected Answer: A
The Answer is "A". Hear me out. The question asks that "Admin1", a user account, has the appropriate permissions. The role of Azure Connected Machine Onboarding can only be assigned to a service principal, as confirmed by the link given to justify the wrong answer. Admin1 cannot be assigned this role, it's impossible, check it for yourself. Admin1, as a local server admin, has all the rights he/she needs. The correct answer is "A", generate a new onboarding script. One can onboard more than one server with the same script. Onboarding two certainly doesn't impose an administrative burden to use this method.
upvoted 21 times
phi3nix
1 year, 11 months ago
This is the correct answer. 1. I tested this in LAB. 2. Documentation: https://learn.microsoft.com/en-us/azure/azure-arc/servers/onboard-portal ---snap--- You can enable Azure Arc-enabled servers for one or a small number of Windows or Linux machines in your environment by performing a set of steps manually. Or you can use an automated method by running a template script that we provide. This script automates the download and installation of both agents. This method requires that you have administrator permissions on the machine to install and configure the agent. On Linux, by using the root account, and on Windows, you are member of the Local Administrators group. --snap--
upvoted 9 times
phi3nix
1 year, 11 months ago
A is the answer!
upvoted 2 times
...
...
JPO2021
6 months, 4 weeks ago
OBS: -"Admin1" is user in ADDS, and member of the local Administrators group on Server1 and Server2. -ADDS is domain that syncs with an Azure Active Directory (Azure AD) tenant. Answer is B "Assign Admin1 the Azure Connected Machine Onboarding role for RG1"
upvoted 1 times
...
SantaClaws
1 year, 4 months ago
It's not exclusive to service principals. But more importantly, OptionA simply doesn't satisfy the requirement of the question. The question is not how to add resources to RG1. The question is explicitly about ensuring that Admin1 has the correct permissions. So option A can be completely disregarded as a possibility, because it's answering a completely different question.
upvoted 4 times
...
...
Bojana
Highly Voted 2 years, 11 months ago
Selected Answer: B
correct
upvoted 13 times
...
RobBot
Most Recent 1 month, 2 weeks ago
Selected Answer: D
Although it does say the domain is sync'd the question doesn't mention whether Admin1 is a domain account. Best practice is for privileged users to have separate cloud only admin accounts, so D?
upvoted 1 times
...
ltkiller
2 months, 2 weeks ago
Selected Answer: B
Link from Phi3nix: https://learn.microsoft.com/en-us/azure/azure-arc/servers/onboard-portal States its also best practice, that ends the discussion right there! Follow best security practices and avoid using an Azure account with Owner access to onboard servers. Instead, use an account that only has the Azure Connected Machine onboarding or Azure Connected Machine resource administrator role assignment. See Azure Identity Management and access control security best practices for more information. Role rights: https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles Search for: Azure Connected Machine Onboarding
upvoted 1 times
...
Ksk08
5 months, 3 weeks ago
Correct answer b
upvoted 1 times
...
JPO2021
6 months, 4 weeks ago
Selected Answer: B
-"Admin1" is user in ADDS, and member of the local Administrators group on Server1 and Server2. -ADDS is domain that syncs with an Azure Active Directory (Azure AD) tenant. Answer is B "Assign Admin1 the Azure Connected Machine Onboarding role for RG1"
upvoted 1 times
...
004b54b
7 months ago
Selected Answer: A
https://learn.microsoft.com/en-us/azure/azure-arc/servers/onboard-portal#install-with-the-scripted-method Install with the scripted method 1. Log in to the server. 2. Open an elevated PowerShell command prompt. > local admin rights are required but sufficient 3. Change to the folder or share that you copied the script to, and execute it on the server by running the ./OnboardingScript.ps1 script.
upvoted 1 times
...
starseed
7 months ago
answer is B
upvoted 2 times
...
sardonique
8 months, 1 week ago
Admin1 is an onpremises account, it does not exist in Azure AD therefore it cannot be assigned any role within the Azure Portal. Admin1 has enough power to configure Server1 and Server2 though. So A is the answer IMO
upvoted 1 times
JPO2021
6 months, 4 weeks ago
(AD DS) domain that "syncs" with an Azure Active Directory tenant....(Admin1 exist in Azure AD) Answer is B
upvoted 1 times
...
...
Krayzr
9 months, 2 weeks ago
Selected Answer: B
B. Reason: Azure Arc allows you to manage your servers as if they are running in Azure. To onboard a machine to Azure Arc, the user needs the Azure Connected Machine Onboarding role. This role gives the user the necessary permissions to register the machine with Azure Arc. In this case, Admin1 needs to be assigned this role for the resource group RG1, so they can configure Server1 and Server2 to be managed by Azure Arc. The other options do not directly address the requirement of enabling Admin1 to configure the servers with Azure Arc. Therefore, option B is the most appropriate first step.
upvoted 2 times
...
RemmyT
10 months ago
Selected Answer: B
Tested in lab: Admin1 without Azure Connected Machine onboarding role assigned on RG1 are unable to onboard any server to Azure. Also are unable to see any machine in Azure Arc | Machines and and as a result it cannot manage any server. After assigning it the Azure Connected Machine onboarding role on RG1, Admin1 can see all the machines in Azure Arc, can manage the servers and can onboard the servers with the generated script. Note: Follow best security practices and avoid using an Azure account with Owner access to onboard servers. Instead, use an account that only has the Azure Connected Machine onboarding or Azure Connected Machine resource administrator role assignment. See Azure Identity Management and access control security best practices for more information. https://learn.microsoft.com/en-us/azure/azure-arc/servers/onboard-portal
upvoted 2 times
RemmyT
10 months ago
You have an on premises Active Directory Domain Services (AD DS) domain that syncs with an Azure Active Directory (Azure AD) tenant. That means Admin1 is synced in Azure Entra ID and we can assigned him the role Azure Connected Machine Onboarding on RG1 (where all Azure ARC servers will reside).
upvoted 1 times
...
...
nawtitoo
10 months, 3 weeks ago
Selected Answer: B
with the appropriate role to Admin1 in the RG1 resource group, Admin1 will have the necessary permissions to configure Server1 and Server2 to be managed by Azure Arc.
upvoted 1 times
...
SIAMIANJI
11 months ago
Selected Answer: B
To ensure that Admin1 can configure Server1 and Server2 to be managed by using Azure Arc, the first step should be to assign Admin1 the appropriate role that grants the necessary permissions to onboard machines to Azure Arc. Specifically, Admin1 needs the Azure Connected Machine Onboarding role for the resource group RG1. Here’s the correct step to take: B. Assign Admin1 the Azure Connected Machine Onboarding role for RG1. This role grants the necessary permissions to onboard servers to Azure Arc, allowing Admin1 to generate the required onboarding script and complete the onboarding process.
upvoted 1 times
...
SIAMIANJI
11 months, 3 weeks ago
Selected Answer: B
To ensure that Admin1 can configure Server1 and Server2 to be managed by using Azure Arc, you should first assign Admin1 the necessary permissions in Azure, specifically the Azure Connected Machine Onboarding role for the resource group RG1. Therefore, the correct answer is: B. Assign Admin1 the Azure Connected Machine Onboarding role for RG1.
upvoted 1 times
...
RickySmith
1 year, 3 months ago
Selected Answer: B
B Assign Admin1 the Azure Connected Machine Onboarding role for RG1. https://learn.microsoft.com/en-us/azure/azure-arc/servers/prerequisites#required-permissions https://learn.microsoft.com/en-us/azure/azure-arc/servers/onboard-service-principal refer point 2
upvoted 2 times
...
boapaulo
1 year, 4 months ago
Selected Answer:B Generating a new integration script in the Azure portal is an important step in adding servers to Azure Arc, but it's not the first step when it comes to ensuring that a specific user, such as Admin1, has permission to configure the servers to be managed by Azure Arc. The first step is to ensure that Admin1 has the necessary permissions within the Azure environment. This is done by assigning the correct role to the user. In the case of Admin1, assigning the Azure Connected Machine Integration role to resource group RG1 is essential for them to be able to perform the required actions in Azure Arc.Once Admin1 has the proper permissions, they can then proceed with generating and running the integration script to add Server1 and Server2 to Azure Arc.
upvoted 1 times
...
Payday123
1 year, 5 months ago
Is Admin1 a local user or domain user added to local admins?
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago