Your organization is implementing Privileged Access Workstations (PAWs) for Tier 0 admins. Requirements: Tier 0 accounts must sign in only from PAWs, and PAWs must not be able to browse the Internet or run email clients. Which two configurations should you implement?
Choose an answer
Tap an option to check your answer.
Correct answer: Configure the 'Log On To…' restriction on each Tier 0 admin account to allow interactive and RDP logon only to the PAW computer accounts., Apply a GPO to the PAW OU that uses WDAC/AppLocker to block web browsers and email clients and configures outbound Windows Firewall rules to allow only management/update endpoints (for example, domain controllers, WSUS/proxy)..
Why this is the answer
The 'Log On To…' restriction on user accounts directly enforces that a user can only sign in from specified computers, fulfilling the requirement that Tier 0 accounts sign in only from PAWs. Applying a GPO with WDAC/AppLocker to block web browsers and email clients, combined with outbound Windows Firewall rules, directly addresses the requirement that PAWs cannot browse the Internet or run email clients. Adding Tier 0 admin groups to local Administrators on all user workstations is incorrect because it grants excessive privileges, contradicting the principle of least privilege inherent in PAWs. Placing PAWs and standard user PCs in the same OU is incorrect as it would apply inappropriate policies to PAWs or expose standard PCs to overly restrictive policies. Enabling Internet Explorer Enhanced Security Configuration and allowing email is incorrect because it directly violates the requirement to block email clients and Internet browsing.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed