Users frequently move between pooled workstations in an AD DS domain and need their user certificates and private keys to follow them automatically. You do not use roaming profiles. How should you enable certificate and credential synchronization across machines?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable the 'Certificate Services Client - Credential Roaming' user policy in a GPO, configure the target user groups, and link it to the OU containing those users..
Why this is the answer
The 'Certificate Services Client - Credential Roaming' user policy, configured via Group Policy, is the correct solution for synchronizing user certificates and private keys across multiple machines without using roaming profiles. This policy leverages Active Directory to store and retrieve user certificates, ensuring they are available regardless of the workstation. Configuring Microsoft Entra ID for certificate synchronization is for cloud-based scenarios and doesn't directly address on-premises AD DS requirements for this specific feature. Enabling Roaming User Profiles would achieve certificate roaming but was explicitly ruled out by the question. Granting Domain Computers write permissions to msPKI attributes is a security risk and not the intended mechanism for certificate roaming. Deploying AD CS Web Enrollment is for certificate issuance and renewal, not for synchronizing existing certificates across devices.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed