Identity with Windows Server 2016 — Question 37

Your network contains an Active Directory forest named contoso.com. The forest contains a member server named Server1 that runs Windows Server 2016.
Server1 is located in the perimeter network.
You install the Active Directory Federation Services server role on Server1. You create an Active Directory Federation Services (AD FS) farm by using a certificate that has a subject name of sts.contoso.com.
You need to enable certificate authentication from the Internet on Server1.
Which two inbound TCP ports should you open on the firewall? Each correct answer presents part of the solution.

Answer options

Correct answer: B, E

Explanation

Opening port 443 is essential for HTTPS traffic, which is required for secure communications in AD FS. Port 49443 is specifically used for certificate authentication in AD FS, making it another necessary opening. The other options do not pertain to the requirements for enabling certificate authentication in this scenario.