Azure Active Directory Domain Services (Azure AD DS) ドメインをお持ちです。 Admin1という名前の新しいユーザーを作成します。 ドメイン内のすべてのコンピューターにカスタムグループポリシー設定を展開するには、Admin1 権限が必要です。このソリューションは、最小権限の原則に従う必要があります。 解答には何を含めるべきでしょうか?回答するには、回答欄で適切な選択肢を選んでください。 注:正解ごとに1ポイント獲得できます。
正解:
Explanation: The Administering Windows Server Hybrid Core Infrastructure materials explain that in Azure Active Directory Domain Services (Azure AD DS) you don't get traditional Domain Admins or Group Policy Creator Owners rights. Instead, "administration of the managed domain is delegated to the AAD DC Administrators group. Members of this group can manage Group Policy in the managed domain and administer domain-joined computers." The guide furth er notes that Azure AD DS automatically creates two built-in OUs and GPOs : "AADDC Computers and AADDC Users , with the corresponding 'AADDC Computers GPO' and 'AADDC Users GPO' already linked." For computer configuration that should apply to all domain-join ed machines, the materials state that "you apply or customize computer policy by editing the AADDC Computers GPO (or by creating additional GPOs and linking them to the AADDC Computers OU)." They also emphasize least-privilege and supportability guidance: "Do not modify the Default Domain Policy in Azure AD DS; use the AADDC-scoped GPOs/OUs for managed-domain policy." Putting this together: to let Admin1 deploy custom policy to all computers while honoring least privilege, add Admin1 to AAD DC Administrator s (the only group granted GPO management in Azure AD DS) and have them modify the existing 'AADDC Computers GPO' that is al ready linked to the AADDC Computers OU so the settings flow to every domain-joined computer.