Identity with Windows Server 2016 — Question 167

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You deploy a new Active Directory forest.
You need to ensure that you can create a group Managed Service Account (gMSA) for multiple member servers.
Solution: You configure Kerberos constrained delegation on the computer account of each domain controller.
Does this meet the goal?

Answer options

Correct answer: B

Explanation

The solution does not meet the goal because configuring Kerberos constrained delegation on the computer accounts of domain controllers alone does not enable the creation of gMSAs. gMSAs require the Active Directory schema to be extended and the appropriate permissions set, which is not addressed by the proposed solution.