exam questions

Exam AZ-800 All Questions

View all questions & answers for the AZ-800 exam

Exam AZ-800 topic 1 question 15 discussion

Actual exam question from Microsoft's AZ-800
Question #: 15
Topic #: 1
[All AZ-800 Questions]

HOTSPOT -
Your network contains an Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains a child domain named east.contoso.com.
In the contoso.com domain, you create two users named Admin1 and Admin2.
You need to ensure that the users can perform the following tasks:
✑ Admin1 can create and manage Active Directory sites.
✑ Admin2 can deploy domain controllers to the east.contoso.com domain.
The solution must use the principle of least privilege.
To which group should you add each user? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Reference:
https://docs.microsoft.com/en-us/windows-server/remote/remote-access/ras/multisite/configure/step-2-configure-the-multisite-infrastructure

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
xrisimix
Highly Voted 2 years, 5 months ago
Correct Membership in the Enterprise Admins group in the forest or the Domain Admins group in the forest root domain,
upvoted 9 times
...
MR_Eliot
Highly Voted 1 year, 5 months ago
Correct Answer: Box1: Contoso\Domain Admins -> Tested this, domain admin can manage sites & site links for the current domain & child domains. Box2: Contoso\Enterprise Admins -> Tested this, domain admin cannot enroll domain controllers to child domains. You will need to be an enterprise admin. -> Also, admin 2 user is not a user in child domain, so therefore you will still need to make admin 2 a member of "Contoso\Enterprise Admins" group.
upvoted 7 times
...
KXNG
Most Recent 3 months, 1 week ago
Clarification: Admin 1 can be part of the contoso\domain admin group as the user was created in the forest root domain and using least privilege does not need to be in the enterprise admin group. Admin 2 as per the question was created in the forest root domain contoso.com and not in the child domain. The question also states that admin 2 must deploy domain controllers TO the child domain, meaning that admin 2 is still in contoso.com. To enable admin 2 to be able to carry out this task, admin 2 would need to be in the enterprise admin group
upvoted 2 times
...
monisshk
6 months, 4 weeks ago
This question is valid Exam date - 27-07-2024
upvoted 2 times
...
sardonique
7 months, 1 week ago
east\domain admins is able to modify the settings on the east.contoso.com domain, however has no rights whatsoever on the contoso domain. When you add a domain controller on the child domain, you still need enough rights to do that on the parent domain, so I would say that the least privilege needed is contoso\domain admins for both
upvoted 5 times
...
Vallion
10 months ago
To create domain controllers in the east.contoso domain, an admin from the contoso domain would need to be a member of the “Administrators” domain local group in the east.contoso domain(1). This can be achieved by placing the users from the contoso domain into a global group in the contoso domain, then nesting that global group into the “Administrators” domain local group in the east.contoso domain1. This adheres to the Principle of Least Privilege (PoLP) because it grants only the necessary permissions to create domain controllers in the east.contoso domain, without granting excessive privileges.
upvoted 2 times
Vallion
10 months ago
Here’s why other closely related groups are not correct: Domain Admins: The Domain Admins group in the contoso domain does not have default rights on domain controllers in the east.contoso domain(2). Also, adding the admin to the Domain Admins group of east.contoso would grant them more permissions than necessary, violating the PoLP. Enterprise Admins: The Enterprise Admins group has full admin rights across all domains in the forest(3). However, this would grant the admin excessive privileges across all domains, not just east.contoso, which again violates the PoLP(2). Therefore, membership in the “Administrators” domain local group in the east.contoso domain is the most appropriate and least privilege solution. It provides the necessary rights to create domain controllers in the east.contoso domain, without granting excessive privileges in other areas.
upvoted 1 times
Vallion
10 months ago
1: https://serverfault.com/questions/38268/granting-domain-admins-rights-to-parent-domain-members 2: https://serverfault.com/questions/943769/enterprise-admins-dont-have-admin-permissions-in-child-domain 3: https://serverfault.com/questions/1080567/parent-domain-vs-child-domain Extra info https://www.dispersednet.com/active-directory/module4/create-child-domain.php https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/appendix-b--privileged-accounts-and-groups-in-active-directory
upvoted 1 times
Vallion
10 months ago
Info gathered using co-pilot business, may contain some errors, check yourself like im doing now, never assume anything you read here is correct
upvoted 1 times
...
...
...
...
sardonique
10 months, 2 weeks ago
In this scenario there is 1 single forest. Domain Admins is more than enough to create sites within the root domain. John needs to be enterprise admin to create a site in east.contoso.com which is outside the boundaries of contoso.com
upvoted 1 times
nonoelptirobo
5 days, 1 hour ago
there is a trust relationship between parent and child domains hence east.contoso.com is whithin boundaries of contoso.com the least privilege option for admin 2 is "create domains ONLY in east.contoso.com" the east/domain admin allow to join DC in the child domain whitout giving admin privileges in the main contoso.com domain
upvoted 1 times
...
...
boapaulo
1 year, 2 months ago
Why not, Enterprise Admins? It's important to follow the principle of least privilege when assigning permissions.This helps to minimize the potential for damage if an account is compromised. To ensure that users can perform the tasks mentioned, you must add each user to the following group: Admin1: You must add Admin1 to the ContosoEnterprise Admins group. This group has permissions to create and manage Active Directory sites throughout the forest. Admin2: You must add Admin2 to the EastDomain Admins group. This group has permissions to deploy domain controllers in the east.contoso.com domain. Just a doubt, these questions of the test are quite confusing.
upvoted 3 times
boapaulo
1 year, 2 months ago
* I remind you that it's just a doubt, these questions of the test are quite confusing.
upvoted 1 times
...
...
Dools
1 year, 3 months ago
In the context of Active Directory, Enterprise Admin privileges are generally not required to create domain controllers in a child domain. Enterprise Admins have higher-level permissions that extend across all domains in the forest, including the ability to manage trusts and make changes that affect the entire forest. Domain Admins, on the other hand, have the necessary permissions to manage and administer objects within their specific domain, including the ability to promote domain controllers within that domain. This includes the creation of domain controllers in child domains. While Enterprise Admins can perform tasks related to the entire forest, such as managing trusts between domains, they are not explicitly required for the creation of domain controllers in a child domain. The Domain Admin role is typically sufficient for these tasks within the scope of a specific domain. However, it's essential to consider the principle of least privilege when assigning permissions. If a user or group only needs to perform tasks within a specific domain, granting Domain Admin privileges for that domain is more appropriate than assigning higher-level Enterprise Admin privileges that provide broader access across the entire forest.
upvoted 2 times
sardonique
10 months, 2 weeks ago
read the question carefully, Admin1 needs to be able to add sites on all the domains. Domain Admins cannot go beyond the boundaries of the domain.
upvoted 2 times
...
...
deepg1981
1 year, 8 months ago
admin2 is user of root domain , however answer is wrong. how it can be added in child domain as domain admin
upvoted 1 times
...
leegend
1 year, 8 months ago
Got this question 28-5-23
upvoted 2 times
...
syu31svc
1 year, 11 months ago
Answer is correct Enterprise admin is a higher level than Domain admin
upvoted 2 times
...
smol84
1 year, 11 months ago
Incorrect for both demo\domain admins Domain admins have full admin controllers you can manage AD sites as well as DCs with this permission.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago