List of questions
Related questions
Question 167 - SC-100 discussion
You have an Azure AD tenant that contains 10 Windows 11 devices and two groups named Group1 and Group2. The Windows 11 devices are joined to the Azure AD tenant and are managed by using Microsoft Intune.
You are designing a privileged access strategy based on the rapid modernization plan (RaMP). The strategy will include the following configurations:
* Each user in Group1 will be assigned a Windows 11 device that will be configured as a privileged access device.
* The Security Administrator role will be mapped to the privileged access security level.
* The users in Group1 will be assigned the Security Administrator role.
* The users in Group2 will manage the privileged access devices.
You need to configure the local Administrators group for each privileged access device. The solution must follow the principle of least privilege.
What should you include in the solution?
Only add Group2 to the local Administrators group.
Configure Windows Local Administrator Password Solution (Windows LAPS) in legacy Microsoft LAPS emulation mode.
Add Group2 to the local Administrators group.
Add the user that is assigned the Security Administrator role to the local Administrators group of the user's assigned privileged access device.
0 comments
Leave a comment first