exam questions

Exam AZ-801 All Questions

View all questions & answers for the AZ-801 exam

Exam AZ-801 topic 12 question 1 discussion

Actual exam question from Microsoft's AZ-801
Question #: 1
Topic #: 12
[All AZ-801 Questions]

HOTSPOT -
You are planning the europe.fabrikam.com migration to support the on-premises migration plan.
Where should you install the Password Export Server (PES) service, where should you generate the encryption key? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: dc2.europe.fabrikam.com -
To migrate passwords, select or install a backup domain controller in the source Windows NT 4.0 domain to act as the Secure Password Export server.
Run the PES service on the dc2 domain controller in source domain europe.fabrikam.com domain.
Scenario:
* Migrate all users, groups, and client computers from europe.fabrikam.com to corp.fabrikam.com.
* The migration will be performed by using the Active Directory Migration Tool (ADMT).
* A computer named ADMTcomputer will be deployed to the corp.fabrikam.com domain to run ADMT migration procedures.
* User accounts will retain their existing password.

Box 2: dc1.corp.fabrikam.com -
dc1.corp.fabrikam.com is the target server, and we generate the encryption key on it.
To migrate passwords, select or install a backup domain controller in the source Windows NT 4.0 domain to act as the Secure Password Export server. This server will communicate with the Active Directory Migration Tool (ADMT) Server in the Target Domain.
Note: Create an encryption key to install on the Password Export server Using an Encryption Key on the Password Export Server.
The Password server encryption key is a key created on the ADMT server and is required to complete the installation of the Password Export Server. The encryption key can be created and stored in one or both of the following methods, by copying to the local floppy disk drive for transport to the password export server or by storing the encryption key in a folder on the local hard drive.
Reference:
https://www.serverbrain.org/secrets-2003/setting-up-an-admt-password-migration-server.html

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
dieymir
Highly Voted 2 years, 6 months ago
Generate encryption key in admtcomputer and install PES in dc2 Reference: https://akhil0087.home.blog/2020/09/10/password-migration-using-admt/
upvoted 14 times
GoforIT21
2 years, 6 months ago
Thanks for providing a source for this!
upvoted 4 times
...
...
syu31svc
Highly Voted 1 year, 11 months ago
https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc974435(v=ws.10)?redirectedfrom=MSDN#to-create-an-encryption-keyhttps://learn.microsoft.com/en-us/answers/questions/130203/admt-pes-password-export-server-31-x64-package-dow.html The PES service can be installed on any writable domain controller in the source domain The PES service installation in the source domain requires an encryption key. However, you must create the encryption key on the computer running the ADMT in the target domain Install PES on dc2.europe.fabrikam.com Generate encryption key on admtcomputer.fabrikam.com
upvoted 6 times
windowsmodulesinstallerworker
1 year, 4 months ago
admtcomputer.fabrikam.com ... fabrikam.com domain does not exist, we only have europe.fabrikam.com and corp.fabrikam.com. I think you should generate the key from dc1.corp.fabrikam.com
upvoted 1 times
jajajaf342
1 year, 2 months ago
The question is malformed. You are incorrect about generating the key from dc1.corp.fabrikam.com - the encryption key needs to be generated from the SOURCE domain, effectively ruling out any machine that's in the corp.fabrikam.com domain. Based on the spirit of the question, I assume the option was supposed to be "admt.europe.fabrikam.com" - this would make sense because any ADMT machine would need to exist on the source domain (europe.fabrikam.com), not in the target domain. So by process of elimination, the answer basically NEEDS to be "admt.fabrikam.com," though what they MEANT was "admt.europe.fabrikam.com"
upvoted 1 times
...
...
...
RemmyT
Most Recent 8 months, 3 weeks ago
Fabrikam Case Study On-Premises Migration Plan Fabrikam has an Active Directory Domain Services (AD DS) forest that syncs with an Azure Active Directory (Azure AD) tenant. The AD DS forest contains two domains named corp.fabrikam.com and europe.fabrikam.com. The office in Paris contains a physical server named dc2.europe.fabrikam.com that runs Windows Server 2016 and is a domain controller for the europe.fabrikam.com domain. Migrate all users, groups, and client computers from europe.fabrikam.com to corp.fabrikam.com. - The migration will be performed by using the Active Directory Migration Tool (ADMT). - A computer named ADMTcomputer will be deployed to the corp.fabrikam.com domain to run ADMT migration procedures. - User accounts will retain their existing password Answer • Install the PES service on: dc2.europe.fabrikam.com • Generate the encryption key on: admtcomputer.fabrikam.com ADMTcomputer will be deployed to the corp.fabrikam.com domain so to name admtcomputer.fabrikam.com more likely is wrong. The right name could be : admtcomputer.corp.fabrikam.com
upvoted 1 times
...
oro_blu
1 year, 10 months ago
admt is used for create key -> https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/supplied-password-not-match-encryption-keys-password becauss admt srv it's in DC1 domain, it's destination , source domain must be DC2, and PES must be installaed in source dom, DC
upvoted 1 times
...
prepper666
2 years ago
If you're using password synchronization, you must install Password Export Server (PES) on a domain controller in the source.
upvoted 2 times
...
joehoesofat
2 years, 4 months ago
Apologies - this was hard to pin down- -I was wrong earlier again - answer is : Source - Dc1.europe ENcryption key- ADMTserver === 1. The Encryption tool can be installed on the ADMT server in the target domain member server 2. The PES is installed on the DC in the source domain controller 3. generate the key in target admt and input into source PES 4. Run PES server to perform the migraiton - https://social.technet.microsoft.com/wiki/contents/articles/13904.how-to-migrate-users-across-forest-cross-forest-using-admt-3-2-with-sid-and-passwords.aspx https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc974435(v=ws.10)?redirectedfrom=MSDN#to-create-an-encryption-key https://learn.microsoft.com/en-us/answers/questions/130203/admt-pes-password-export-server-31-x64-package-dow.html
upvoted 3 times
rimvydukas
2 years, 4 months ago
Be mo consistent :) There is no dc1.europe in the answers :)
upvoted 4 times
...
...
joehoesofat
2 years, 4 months ago
Ok so the answers are backwards- the source is corp and the target is europe- and alos PES must be intalled on a DC - same witht he KEY generations - so its DC1.corp as the source and DC2.eurpoe - https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/supplied-password-not-match-encryption-keys-password
upvoted 2 times
...
joehoesofat
2 years, 4 months ago
So you : 1. Generate the Key on the ADM computer in target 2. DOwnload the PES tool and install in source DC - 3. Run the wizzard and it adds this key 4. Open the ADM tool on the target and complete the migration - the order of the two questions is also backwards get the key first then run the PES. its also not the whole process.
upvoted 1 times
...
GoforIT21
2 years, 6 months ago
The explanation given below the answer and the link provided both state that the encryption key is created on ADMTComputer.fabrikam.com. So that would be the answer to the second question, I assume...
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago