Which three actions...
 
Notifications
Clear all

Which three actions should you perform? Each correct answer presents part of the solution. NOTE:

1 Posts
1 Users
0 Likes
74 Views
(@tsuchiuramanual)
Posts: 747
Noble Member
Topic starter
 

Your network contains an on-premises Active Directory domain.

You have a Microsoft 365 subscription.

You implement a directory synchronization solution that uses pass-through authentication.

You configure Microsoft Azure Active Directory (Azure AD) smart lockout as shown in the following exhibit.

You discover that Active Directory users can use the passwords in the custom banned passwords list.

You need to ensure that banned passwords are effective for all users.

Which three actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

  • A . From a domain controller, install the Azure AD Password Protection Proxy.
    B. From a domain controller, install the Microsoft AAD Application Proxy connector.
    C. From Custom banned passwords, modify the Enforce custom list setting.
    D. From Password protection for Windows Server Active Directory, modify the Mode setting.
    E. From all the domain controllers, install the Azure AD Password Protection DC Agent.
    F. From Active Directory, modify the Default Domain Policy.

Show Answer Hide Answer

Suggested Answer: ACE

Explanation:

Azure AD password protection is a feature that enhances password policies in an organization. On-premises deployment of password protection uses both the global and custom banned-password lists that are stored in Azure AD. It does the same checks on-premises as Azure AD does for cloud-based changes. These checks are performed during password changes and password reset scenarios.

You need to install the Azure AD Password Protection Proxy on a domain controller and install the Azure AD Password Protection DC Agent on all domain controllers. When the proxy and agent are installed and configured, Azure AD password protection will work.

In the exhibit, the password protection is configured in Audit mode. This is used for testing. To enforce the configured policy, you need to set the password protection setting to Enforced.

Reference:

https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-password-ban-bad-on-premises-deploy

https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-password-ban-bad-on-premises
 
Posted : 23/01/2023 2:27 pm

Latest Microsoft MS-100 Dumps Valid Version

Latest And Valid Q&A | Instant Download | Once Fail, Full Refund
Share: