Перейти до основного вмісту
Теґи
Answer confirmed
Question

Your network contains a Microsoft Entra Domain Services domain. The domain contains 20 servers that run Windows Server.

You need to configure the password policy settings for local accounts on the servers. The solution must follow the principle of least privilege.

Which Group Policy Object (GPO) should you use?

Proposed answer
  • a custom-created GPO linked to the domain
  • AADDC Computers
  • This answer is correct.
  • AADDC Users
  • Default Domain Policy 
Correct answer

AADDC Computers

  • Incorrect - A custom-created GPO cannot be linked to the Microsoft Entra Domain Services domain, only to custom-created organizational units (OUs).
  • Correct – AADDC Computers is the only modifiable GPO that has in scope all the domain member servers joined to contoso.com.
  • Incorrect - AADDC Users applies to domain users only, not to local users on the domain member servers.
  • Incorrect – The Default Domain Policy GPO cannot be modified by AAD DC Administrators.

Manage Windows Server 2019 in an Azure Active Directory Domain Services environment - Training | Microsoft Learn