You have an Azure Active Directory Domain Services (Azure AD DS) domain named contoso.com. You need to provide an administrator with the ability to manage Group Policy Objects (GPOs). The solution must use the principle of least privilege. To which group should you add the administrator?

QuestionsCategory: AZ-800You have an Azure Active Directory Domain Services (Azure AD DS) domain named contoso.com. You need to provide an administrator with the ability to manage Group Policy Objects (GPOs). The solution must use the principle of least privilege. To which group should you add the administrator?
Admin Staff asked 4 months ago
You have an Azure Active Directory Domain Services (Azure AD DS) domain named contoso.com.
You need to provide an administrator with the ability to manage Group Policy Objects (GPOs). The solution must use the principle of least privilege.
To which group should you add the administrator?

A. AAD DC Administrators

B. Domain Admins

C. Schema Admins

D. Enterprise Admins

E. Group Policy Creator Owners






 

Suggested Answer: B

Only the Domain Admins group and the Enterprise Admins group can fully manage GPOs.  Members of the Group Policy Creator Owners group can create new
GPOs but they can't link the GPOs to sites, the domain or OUs and they cannot manage existing GPOs.

This question is in AZ-800 Administering Windows Server Hybrid Core Infrastructure Exam
For getting Microsoft Certified: Windows Server Hybrid Administrator Associate Certificate




Disclaimers:
The website is not related to, affiliated with, endorsed or authorized by Microsoft. 
The website does not contain actual questions and answers from Microsoft's Certification Exams.
Trademarks, certification & product names are used for reference only and belong to Microsoft.

Recommended

Welcome Back!

Login to your account below

Create New Account!

Fill the forms below to register

Retrieve your password

Please enter your username or email address to reset your password.