You need to ensure members of the Domain Admins group can authenticate only to two privileged access workstations (PAW1 and PAW2) and not to any other computer in the domain. The forest functional level is Windows Server 2012 R2, and all DCs are Windows Server 2019. What should you configure to meet the requirement with centralized enforcement?
Choose an answer
Tap an option to check your answer.
Correct answer: Create an Authentication Policy and an Authentication Policy Silo, add the Domain Admin accounts to the silo, specify PAW1 and PAW2 as permitted computers, and enforce the policy..
Why this is the answer
Authentication Policies and Authentication Policy Silos (APS) provide centralized control over where high-privilege accounts can authenticate. By creating an Authentication Policy that specifies PAW1 and PAW2 as permitted computers for Domain Admins, and then linking this policy to an APS that contains the Domain Admins group, you enforce this restriction across the domain. This method is designed for privileged access management and is centrally enforced by Active Directory. The other options are incorrect because: Linking a GPO to deny logon locally or network access is difficult to manage at scale and can be bypassed. Fine-grained password policies manage password settings, not authentication restrictions. Restricted Admin mode for RDP enhances security for RDP sessions but doesn't restrict where accounts can authenticate across the entire domain.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed