Microsoft AZ-802 Exam Prep
Administering Windows Server (Page 6 )

Updated On: 3-Oct-2026
View Related Case Study

You need to meet the technical requirements for Server3.
Which users can perform the required tasks?

  1. Admin1 only
  2. Admin3 only
  3. Admin1 and Admin2 only
  4. Admin1 and Admin3 only
  5. Admin1, Admin2, and Admin3

Answer(s): D

Explanation:

Scenario: Install and authorize Server3 as a DHCP server. Server3 is in the Member servers OU in canada.contoso.com domain in the Montreal AD site. Admin1 is a member of Contoso\Enterprise Admins Admin2 is a member of Contoso\Domain Admins Admin3 is a member of Canada\Domain Admins
--Admin1 and Admin3 can administer the server while Admin2 cannot, because of how Active Directory group memberships and default built-in permissions operate across domains and forests.
Admin1 is a member of Acme\Enterprise Admins. The Enterprise Admins group exists in the forest root domain and has implicit administrative control over all domains and domain-joined machines across the entire forest.
Admin3 is a member of Cairo\Domain Admins. Because the target server resides specifically within the canada.contoso.com domain, members of that local domain's Domain Admins group are automatically added to the local Administrators group of member servers in that domain.
Incorrect: [Not Admin2] Admin2 is a member of acme\Domain Admins (the root or a peer domain, but not Canada's Domain Admins). Members of a different domain's Domain Admins group do not automatically receive administrative privileges on servers located in the cairo.acme.com domain unless explicitly granted via group policy or local configuration.


Reference:

https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/active-directory-functional-levels



View Related Case Study

HOTSPOT (Drag and Drop is not supported)
Which groups can you add to Group3 and Group5? To answer, select the appropriate options in the answer area.
Note: Each correct selection is worth one point
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:




Scenario:



View Related Case Study

You need to meet the technical requirements for User1. The solution must use the principle of least privilege.
What should you do?

  1. Add User1 to the Account Operators group in contoso.com.
  2. Create a delegation on contoso.com.
  3. Add User1 to the Server Operators group in contoso.com.
  4. Create a delegation on OU3.

Answer(s): D

Explanation:

Scenario: Ensure that User1 can manage the membership of all the groups in Contoso\OU3.
To grant a user the ability to manage membership for all groups in a specific Organizational Unit (OU) with minimal privileges, you should use Delegation of Control in Active Directory to assign "Write member" permissions on all Group objects within that OU, while avoiding full control or generic group management rights.
Scoped to Object Type: The delegation only applies to Group objects, meaning the user cannot modify users, computers, or other objects inside the OU.
Granular Property Access: The Write member permission strictly allows adding and removing members from the group, preventing the user from changing group types, scopes, or renaming the groups themselves.
OU Boundary: The permissions are explicitly inherited or applied only within that single OU, protecting the rest of the AD forest from unintended modifications.


Reference:

https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/delegation-control-wizard



View Related Case Study

You need to meet the technical requirements for Server1.
Which users can currently perform the required tasks?

  1. Admin1 only
  2. Admin3 only
  3. Admin1 and Admin3 only
  4. Admin1, Admin2, and Admin3

Answer(s): C

Explanation:

Scenario: Promote Server1 to a domain controller in canada.contoso.com. Admin1 is a member of Contoso\Enterprise Admins Admin2 is a member of Contoso\Domain Admins Admin3 is a member of Canada\Domain Admins
Admin1 and Admin3 are able to promote the server to a domain controller in the canada.contoso.com domain.
Admin1 (Enterprise Admins): Members of this group have administrative rights across the entire Active Directory forest, allowing them to promote domain controllers in any domain.
Admin3 (canada\Domain Admins): Members of this group have full administrative control over the specific child domain (canada.contoso.com) where the domain controller is being added.
Incorrect: Admin2 (contoso\Domain Admins): Members of this group only have administrative rights within the root domain (contoso.com). Rights do not automatically flow down to child domains.


Reference:

https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/active-directory-functional-levels



View Related Case Study

HOTSPOT (Drag and Drop is not supported)
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
Note: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:





Scenario: The contoso.com domain has the Group Policies Objects (GPOs) shown in the following table.

Admin1 in Contoso\OU1 and is a member of Contoso\Enterprise Admins User1 is in Contoso\OU3 and is member of Contoso\Domain Users. Server1 is in the Member Servers OU.
Box 1: No No, Admin1 does not need to use a password that has at least 14 characters. Admin1 must use a password with a minimum length of 10 characters.
Box 2: Yes Yes, User1 must use a password that has at least 10 characters.
In an on-premises Active Directory Domain Services (AD DS) environment, domain-wide user password policies can only be defined at the domain root level via Group Policy Objects (GPOs). Group Policy account policies (such as minimum password length) linked directly to Organizational Units (OUs) are ignored for domain user accounts.
Box 3: Yes Yes, the password for the new local user account must contain at least 8 characters.
When a GPO containing Account Policies is linked to an OU containing computer objects (like member servers), those settings overwrite the local Security Account Manager (SAM) database rules of those specific machines.
Because Admin1 is creating a local user directly on a server residing within the "Member Servers" OU, the computer-level password policy applied to that specific server takes precedence. The GPO is linked to this OU and mandates a minimum password length of 8 characters, making it the effective rule enforced for any locally created accounts on those servers.


Reference:

https://blog.admindroid.com/configure-and-manage-password-policy-in-active-directory/



Viewing page 6 of 14
Viewing questions 26 - 30 out of 63 questions


Post your Comments and Discuss Microsoft AZ-802 exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!