contoso.com という名前の Azure Active Directory Domain Services (Azure AD DS) ドメインがあります。
グループ ポリシー オブジェクト (GPO) を管理する機能を管理者に提供する必要があります。このソリューションでは、最小特権の原則を使用する必要があります。
管理者をどのグループに追加する必要がありますか?
正解:A
The Azure Active Directory Domain Services (Azure AD DS) section of the AZ-800 materials clarifies the administrative model in a managed domain: " Azure AD DS does not expose Enterprise Admins or Schema Admins. Instead, members of the AAD DC Administrators group are granted delegated privileges to manage the managed domain, including DNS and Group Policy. " It explicitly notes: " To create, edit, and link Group Policy Objects in an Azure AD DS manag ed domain, the user must be a member of the AAD DC Administrators group. " While Group Policy Creator Owners is used in traditional AD to allow GPO creation, in Azure AD DS least-privilege administration for GPOs is delegated through AAD DC Administrators . The built-in Domain Admins , Enterprise Admins , and Schema Admins roles are not applicable/available in the Azure AD DS managed domain context. Therefore, to follow the principle of least privilege and enable GPO management in Azure AD DS, add the administr ator to AAD DC Administrators .