Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam MS-100 topic 4 question 15 discussion

Actual exam question from Microsoft's MS-100
Question #: 15
Topic #: 4
[All MS-100 Questions]

You have a Microsoft 365 subscription.
Your company deploys an Active Directory Federation Services (AD FS) solution.
You need to configure the environment to audit AD FS user authentication.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. From all the AD FS servers, run auditpol.exe.
  • B. From all the domain controllers, run the Set-AdminAuditLogConfig cmdlet and specify the ג€"LogLevel parameter.
  • C. On a domain controller, install Azure AD Connect Health for AD DS.
  • D. From the Azure AD Connect server, run the Register-AzureADConnectHealthSyncAgent cmdlet.
  • E. On an AD FS server, install Azure AD Connect Health for AD FS.
Show Suggested Answer Hide Answer
Suggested Answer: DE 🗳️
To audit AD FS user authentication, you need to install Azure AD Connect Health for AD FS. The agent should be installed on an AD FS server. After the installation, you need to register the agent by running the Register-AzureADConnectHealthSyncAgent cmdlet.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-health-agent-install https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-health-adfs

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Player1
Highly Voted 4 years, 1 month ago
+1, should be A, E. See: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-health-agent-install#enable-auditing-for-ad-fs "Register-AzureADConnectHealthSyncAgent" is only necessary if agent registration fails after installing Azure AD Connect.
upvoted 37 times
DenisRossi
1 year, 9 months ago
You're right!
upvoted 1 times
...
F_M
2 years, 11 months ago
In addition, "Register-AzureADConnectHealthSyncAgent" is only for the sync service, not for the ADFS one.
upvoted 4 times
...
...
[Removed]
Highly Voted 3 years, 8 months ago
Answer: D E Explanation To audit AD FS user authentication, you need to install Azure AD Connect Health for AD FS. The agent should be installed on an AD FS server. After the installation, you need to register the agent by running theRegister-AzureADConnectHealthSyncAgentcmdlet. Reference: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-health-agent-instal l https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-health-adfs
upvoted 8 times
donathon
3 years, 6 months ago
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-health-agent-install#installing-the-azure-ad-connect-health-agent-for-ad-fs >> E is correct because this is AD FS, the agent should be installed on the ADFS server. https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-health-agent-install#to-enable-auditing-for-ad-fs-on-windows-server-2008-r2 >> You will then have to enable auditing using auditpol. D is wrong because this is for Sync not ADFS. B is wrong because this is not done at the DCs. C is wrong because the article states ADFS server not DCs. AD FS server should be different from your Sync server. Do not install AD FS agent to your Sync server.
upvoted 13 times
OneplusOne
3 years, 3 months ago
Donathon is right!
upvoted 2 times
...
...
...
devilcried
Most Recent 1 year ago
Selected Answer: AE
Well explained here: https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-health-agent-install#enable-auditing-for-ad-fs
upvoted 1 times
...
Blagojche
1 year, 1 month ago
It is not A, because the key word that makes it wrong is ALL A. From all the AD FS servers, run auditpol.exe
upvoted 1 times
...
GlennVDB
1 year, 1 month ago
Selected Answer: AE
As player1 has said Health agent for ADFS and enable auditing logs with auditpol.exe The Usage Analytics feature needs to gather and analyze data, so the Azure AD Connect Health agent needs the information in the AD FS audit logs. These logs aren't enabled by default https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-health-agent-install#enable-auditing-for-ad-fs
upvoted 1 times
...
Startkabels
1 year, 4 months ago
Selected Answer: AE
AE it is then
upvoted 1 times
...
Claire91
1 year, 9 months ago
Selected Answer: AE
Explained in this Microsoft Doc https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-health-agent-install#enable-auditing-for-ad-fs
upvoted 2 times
...
LillyLiver
2 years, 2 months ago
Selected Answer: AE
You need to install the audit agent on the ADFS box and enable auditing for it to work.
upvoted 3 times
...
AlexLiourtas
2 years, 4 months ago
Selected Answer: AE
AE https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/troubleshooting/ad-fs-tshoot-logging
upvoted 3 times
Mulder71
2 years, 1 month ago
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-health-agent-install#to-enable-auditing-for-ad-fs-on-windows-server-2012-r2 To enable auditing for AD FS on Windows Server 2012 R2 On the Start screen, open Server Manager, and then open Local Security Policy. Or on the taskbar, open Server Manager, and then select Tools/Local Security Policy. Go to the Security Settings\Local Policies\User Rights Assignment folder. Then double-click Generate security audits. On the Local Security Setting tab, verify that the AD FS service account is listed. If it's not listed, then select Add User or Group, and add it to the list. Then select OK. To enable auditing, open a Command Prompt window with elevated privileges. Then run the following command: auditpol.exe /set /subcategory:{0CCE9222-69AE-11D9-BED3-505054503030} /failure:enable /success:enable
upvoted 1 times
...
...
allesglar
2 years, 5 months ago
Selected Answer: AE
Register-AzureADConnectHealthADFSAgent will be executed automatically on the AD FS after installing the agent. Afterwards, audipol is needed to activate the logging. https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-health-agent-install
upvoted 4 times
...
fofo1960
2 years, 6 months ago
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-health-agent-install#to-enable-auditing-for-ad-fs-on-windows-server-2012-r2 To enable auditing for AD FS on Windows Server 2012 R2: auditpol.exe /set /subcategory:{0CCE9222-69AE-11D9-BED3-505054503030} /failure:enable /success:enable So Yes, its A and E
upvoted 1 times
...
zul_n
2 years, 6 months ago
i'd say the answers are A and E A. From all the AD FS servers, run auditpol.exe https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-health-agent-install#to-enable-auditing-for-ad-fs-on-windows-server-2012-r2 E. On an AD FS server, install Azure AD Connect Health for AD FS.
upvoted 2 times
...
gonick
2 years, 6 months ago
A & E. You only need to register if the service failed to do so after installing AAD Connect, as this is part of the process
upvoted 1 times
...
melatocaroca
2 years, 10 months ago
Correct Answers: A,E Set-AdfsProperties -AuditLevel None Auditing is disabled and no events will be logged. Basic (Default) Set-AdfsProperties -AuditLevel Basic No more than 5 events will be logged for a single request Verbose Set-AdfsProperties -AuditLevel Verbose All events will be logged. This will log a significant amount of information per request. auditpol.exe. Open a command prompt with elevated privileges and run the following command to enable auditing auditpol.exe /set /subcategory:"Application Generated" /failure:enable /success:enable Reference https://dirteam.com/sander/2019/08/15/howto-enable-auditing-and-logging-for-ad-fs-servers-and-the-ad-fs-farm/ https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/troubleshooting/ad-fs-tshoot-logging https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-health-adfs https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-health-agent-install#enable-auditing-for-ad-fs
upvoted 2 times
...
init2winit
3 years ago
+1 for A,E as the valid answer
upvoted 3 times
...
Davood
3 years ago
Correct answer is D,E.
upvoted 2 times
...
[Removed]
3 years, 3 months ago
Agreed - A and E https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-health-agent-install#enable-auditing-for-ad-fs
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...