お客様のネットワークには、conto.com という名前の単一ドメインの Active Directory ドメインサービス (AD DS) フォレストが含まれています。 このフォレストには、以下の表に示すサーバーが含まれています。 Server1に基幹業務(LOB)アプリケーションをインストールする予定です。このアプリケーションは、カスタムWindowsサービスをインストールします。 新しい企業セキュリティポリシーでは、すべてのカスタムWindowsサービスはグループ管理サービスアカウント(gMSA)のコンテキストで実行する必要があると規定されています。ルートキーをデプロイします。 新しいアプリケーションで使用するgMSAを作成、構成、インストールする必要があります。 どの2つの行動をとるべきですか?それぞれの正解は、解決策の一部を示しています。 注:正解ごとに1ポイントが加算されます。
正解:B,C
The AZ-800 objectives for securing Windows Server services with group Managed Service Accounts (gMSAs) specify a two-stage process: (1) Create the gMSA in AD DS, and (2) install (make usable) the gMSA on the member server that will run the service. The documentation outlines: first ensure a KDS root key is present (done), then on a domain controller run New-ADServiceAccount to create the gMSA, define SPNs as needed, and se t PrincipalsAllowedToRetrieveManagedPassword to include the target server(s). Next, on each server that will use the account, install the account by running Install-ADServiceAccount , and then configure the Windows service to run under the gMSA ( accountname $ with "Service accounts" logon). Running Install-ADServiceAccount on a DC is incorrect because the account must be installed on the workload host (Server1). Set-ADComputer is not required for gMSA deployment, and Get- ADServiceAccount merely queries object s and does not create or install them. Therefore, the correct actions are B (create the gMSA on DC1) and A (install the gMSA on Server1).