Exam
Answer confirmed
Question
You have an Azure subscription.
You plan to deploy five Azure virtual machines that will run Windows Server.
You need to ensure that the virtual machines can be managed by using Group Policy. The solution must meet the following requirements:
- Support Kerberos-based authentication for services.
- Minimize the number of virtual machines that must be deployed.
What should you deploy?
Proposed answer
- a single virtual machine configured as an Active Directory Domain Services (AD DS) domain controller
- A Microsoft Entra tenant
- A Microsoft Entra Domain Services
- This answer is correct.
- two virtual machines configured as Active Directory Domain Services (AD DS) domain controllers
Correct answer
A Microsoft Entra Domain Services
- Incorrect – A Microsoft Entra tenant does not support managing computers by using Group Policy.
- Correct - Microsoft Entra Domain Services provides managed domain services, such as domain join, Group Policy, LDAP, and Kerberos/NTLM authentication, which is fully compatible with Windows Server Active Directory. You consume these domain services without deploying, managing, and patching domain controllers yourself.
- Incorrect - Deploying one or two new domain controllers as Azure virtual machines will achieve the result but with many virtual machines.
Tutorial - Create an Azure Active Directory Domain Services managed domain | Microsoft Learn