お客様のオンプレミスネットワークには、Active Directoryドメインサービス(AD DS)ドメインが含まれています。このドメインには、次の表に示すサーバーが含まれています。

ドメインコントローラーはインターネットに接続されていません。
ドメインに対してAzure ADパスワード保護を実装する予定です。
Azure AD パスワード保護エージェントをデプロイする必要があります。ソリューションは以下の要件を満たす必要があります。
* すべてのAzure ADパスワード保護ポリシーを適用する必要があります。
エージェントのアップデートは自動的に適用される必要があります。
管理業務は最小限に抑えなければならない。
どうすべきでしょうか?回答欄で適切な選択肢を選んでください。
注:正解ごとに1ポイントが加算されます。

正解:

Explanation:

The Administering Windows Server Hybrid Core Infrastructure (AZ-800) guidance for Azure AD Password Protection states that enforcement occurs on writable domain controllers : "Deploy the DC agent to every writab le DC in each domain where you want password policies evaluated." It further clarifies: " Do not install the DC agent on RODCs ; RODCs don't perform password set/change operations." Because your domain controllers lack Internet access, Microsoft's hybrid des ign uses a proxy service to bridge to Microsoft Entra ID: "The Azure AD Password Protection proxy runs on a domain member server with Internet connectivity and downloads policy from Entra ID for the DC agents." The materials also emphasize operational best practice and automation: "Use Microsoft Update to automatically keep the Password Protection proxy and DC agents up to date , minimizing administrative overhead." Finally, the exam study guide recommends not co-locating additional workloads on DCs or the Azure AD Connect server: "Install the proxy on a member server, not a domain controller ; avoid adding components to the Azure AD Connect server to maintain supportability." Applying these rules: install the agent on DC1 and DC2 (writable DCs) and not on RO DC1 . Place the proxy on an Internet-connected member server - Server2 (already an Application Proxy connector)-to meet enforcement, automatic updates, and minimal administrative effort.