exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 2 question 16 discussion

Actual exam question from Microsoft's AZ-500
Question #: 16
Topic #: 2
[All AZ-500 Questions]

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a hybrid configuration of Azure Active Directory (Azure AD).
You have an Azure HDInsight cluster on a virtual network.
You plan to allow users to authenticate to the cluster by using their on-premises Active Directory credentials.
You need to configure the environment to support the planned authentication.
Solution: You deploy Azure Active Directory Domain Services (Azure AD DS) to the Azure subscription.
Does this meet the goal?

  • A. Yes
  • B. No
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Adamasbue
Highly Voted 4 years, 11 months ago
Wrong: https://docs.microsoft.com/en-us/azure/hdinsight/domain-joined/apache-domain-joined-architecture
upvoted 36 times
PlasticMind
4 years, 10 months ago
Azure AD domain Services is the only supported way for HD Insight cluster integration integration with active directory. so AAD connect to synchronise identities from an on-premises active directory to Azure AD and then Azure AD domain services for the HD Insights integration
upvoted 20 times
ochiwi
4 years, 6 months ago
i agree since there's indication that a setup of an Azure AD exists which is a requirement for HD insight, should work...
upvoted 2 times
MKnight25
1 year, 9 months ago
I agree a well, becaus: !Using on-premises Active Directory or Active Directory on IaaS VMs alone, without Azure AD and Azure AD DS, isn't a supported configuration for HDInsight clusters with ESP. https://learn.microsoft.com/en-us/azure/hdinsight/domain-joined/apache-domain-joined-architecture#on-premises-active-directory-or-active-directory-on-iaas-vms
upvoted 3 times
...
...
...
BTAB
2 years, 10 months ago
@Adamasbue is correct. From that URL it states: If HDInsight and Azure AD DS are deployed in the same virtual network, the connectivity is automatically provided, and no further action is needed. The question details that AADDS will be deployed to the Azure subscription. There is still ambiguity in the question, because it doesn't say that AADDS is deployed within the same virtual network of HDInsight. These questions kill me.
upvoted 15 times
...
...
Hemn1990
Highly Voted 4 years, 3 months ago
You have hybrid enviroment so AD DS is alredy in place, you would need site to site vpn so the answer is no.
upvoted 29 times
TJ001
2 years, 9 months ago
Hybrid does not mean AADDS is in place .. it could be just AD connect + hash synch is always have to be separately enable based on the sync method
upvoted 13 times
Lucabrazi999
1 year, 1 month ago
and where would the hash be originally gotten from?
upvoted 2 times
...
...
...
ITFranz
Most Recent 4 months ago
Selected Answer: A
To support the answer: Yes, deploying Azure Active Directory Domain Services (Azure AD DS) to the Azure subscription can be a solution to allow users to authenticate to the HDInsight cluster using their on-premises Active Directory credentials. Here's why: 1. Azure AD DS provides a managed domain service that is compatible with traditional Active Directory Domain Services 2. It enables one-way synchronization from Azure AD to the managed domain, allowing access to a central set of users, groups, and credentials 3. For hybrid environments with on-premises AD, Azure AD Connect can be used to synchronize identity information with Azure AD, which then synchronizes with Azure AD DS 4. This setup allows users to log in to services and applications connected to the managed domain using their existing credentials Set up different domain controllers Answer = A
upvoted 2 times
...
JaridB
4 months, 4 weeks ago
Selected Answer: B
Answer: No According to the Microsoft documentation you referenced, connecting an Azure HDInsight cluster directly to an on-premises Active Directory (AD) domain is not supported. Therefore, the correct answer to the question "You need to configure the environment to support the planned authentication." is No. Deploying Azure Active Directory Domain Services (Azure AD DS) does not directly meet the goal of allowing users to authenticate to the HDInsight cluster using their on-premises AD credentials.
upvoted 2 times
...
Jarid
7 months, 1 week ago
Yes, deploying Azure Active Directory Domain Services (Azure AD DS) to the Azure subscription meets the goal of allowing users to authenticate to the Azure HDInsight cluster using their on-premises Active Directory credentials in a hybrid Azure AD configuration. Azure AD DS provides managed domain services such as domain join, group policy, LDAP, and Kerberos/NTLM authentication that are fully compatible with Windows Server Active Directory. By integrating Azure AD DS with your Azure HDInsight cluster on a virtual network, you can leverage these domain services to enable seamless authentication using on-premises Active Directory credentials. This setup allows users to access the HDInsight cluster with their existing credentials, facilitating a smoother and more secure integration between on-premises and cloud resources. This approach is particularly effective in hybrid environments where organizations wish to extend their on-premises identity infrastructure to Azure services, ensuring that authentication and access control are centrally managed.
upvoted 3 times
...
flafernan
10 months, 3 weeks ago
Selected Answer: A
Currently, HDInsight only supports Microsoft Entra Domain Services as the primary domain controller that the cluster uses for Kerberos communication. But other complex Active Directory configurations are possible, as long as such configuration leads to enabling Microsoft Entra Domain Services for access to HDInsight.
upvoted 1 times
...
Jkayx94
11 months, 1 week ago
A VPN is required. By Using AD DS, this will convert the AAD Synced (or now Entra ID) synced entities into a one-way sync to AAD DS. But this isn't using the local on-prem account. This is using the Microsoft Hybrid Section of the account. (i.e. AD DS maybe contoso.local, but Entra ID will be contoso.com. AD DS will be Contoso.com (or whatever domain you select when you set it up). It's asking to use the on-prem account (contoso.local), not a converted Microsoft account.
upvoted 2 times
...
Jkayx94
11 months, 1 week ago
I suspect the Answer is B, but the question is worded incorrect. The answer suggests the HDInsight is on-Prem rather than the original question reporting it's in cloud.
upvoted 1 times
...
wardy1983
11 months, 2 weeks ago
Answer: A Explanation: Azure Active Directory Domain Services Azure AD DS provides a managed domain that's fully compatible with Windows Server Active Directory. Microsoft takes care of managing, patching, and monitoring the domain in a highly available (HA) setup. You can deploy your cluster without worrying about maintaining domain controllers. Users, groups, and passwords are synchronized from Azure AD. The one-way sync from your Azure AD instance to Azure AD DS enables users to sign in to the cluster by using the same corporate credentials.
upvoted 1 times
...
Sujeeth
1 year, 1 month ago
Yes is answer, deploying Azure Active Directory Domain Services (Azure AD DS) to the Azure subscription can meet the goal of allowing users to authenticate to the Azure HDInsight cluster using their on-premises Active Directory credentials. Azure AD DS provides the capability to extend your on-premises Active Directory to Azure, allowing seamless authentication for resources hosted in Azure, including HDInsight clusters
upvoted 3 times
...
_fvt
1 year, 3 months ago
Selected Answer: A
Correct answer is A - YES. You don't need a VPN with OnPrem to connect to HDInsights. It would be relevant if you need connection between HDInsights and onPrem servers and/or want to remove/restric public traffic. HDIsights can be accessed from internet no matters of the authentication method. https://learn.microsoft.com/en-us/azure/hdinsight/hdinsight-virtual-network-architecture Now you want to connects HDI with on-prem AD DS identities. The only supported way is to use Azure AD DS (An Azure Service, different from your onprem AD DS). Azure AD DS needs AD connect with PHS from On-Prem AD DS to Azure AD. You are in Hybrid config so already setup AD Connects. Azure AD DS is deplpoyed in a VNEt and needs to be Perred with HDInsights VNet. That's it. https://learn.microsoft.com/en-us/azure/hdinsight/domain-joined/apache-domain-joined-create-configure-enterprise-security-cluster
upvoted 2 times
_fvt
1 year, 3 months ago
The the peering to relevant VNets is a part of the Azure AD DS Deployment.
upvoted 1 times
...
...
kieli
1 year, 4 months ago
https://learn.microsoft.com/en-us/azure/hdinsight/domain-joined/apache-domain-joined-architecture If PHS is confirmed to be configured and Azure ADDS can be reached it will do the work. So I would go for NO on these basis and not that it needs to be connected via VPN.
upvoted 1 times
...
Dev1079
1 year, 4 months ago
Selected Answer: A
https://learn.microsoft.com/en-us/azure/hdinsight/domain-joined/apache-domain-joined-configure-using-azure-adds
upvoted 2 times
...
Andre369
1 year, 5 months ago
Selected Answer: A
Yes, deploying Azure Active Directory Domain Services (Azure AD DS) to the Azure subscription would meet the goal of allowing users to authenticate to the Azure HDInsight cluster using their on-premises Active Directory credentials. Azure AD DS provides managed domain services that can be used to join HDInsight clusters to an Azure AD DS-managed domain. This allows users to authenticate using their on-premises AD credentials seamlessly. Therefore, the solution meets the goal.
upvoted 2 times
...
billo79152718
1 year, 5 months ago
A: YES
upvoted 2 times
...
majstor86
1 year, 7 months ago
Selected Answer: A
A. Yes
upvoted 3 times
...
yassou_123
1 year, 10 months ago
Selected Answer: B
answer should be No, it must use VPN source:https://learn.microsoft.com/en-us/azure/hdinsight/connect-on-premises-network
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago