Identity with Windows Server 2016 — Question 51
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You deploy a new Active Directory forest.
You need to ensure that you can create a group Managed Service Account (gMSA) for multiple member servers.
Solution: You configure Kerberos constrained delegation on the computer account of each member server.
Does this meet the goal?
Answer options
- A. Yes
- B. No
Correct answer: B
Explanation
While configuring Kerberos constrained delegation is important for certain scenarios, it does not directly facilitate the creation of a gMSA. Instead, gMSAs require the use of the Active Directory module and specific permissions, which are not granted simply by setting up delegation on the member servers.