You need to prepare the environment to meet the authentication requirements. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
A.
Install the Active Directory Federation Services (AD FS) role on a domain controller in the Miami office.
B.
Allow inbound TCP port 8080 to the domain controllers in the Miami office.
C.
Join the client computers in the Miami office to Azure AD.
D.
Add http://autologon.microsoftazuread-sso.com to the intranet zone of each client computer in the Miami office.
E.
Install Azure AD Connect on a server in the Miami office and enable Pass-through Authentication.
Suggested Answer:DE🗳️
D: You can gradually roll out Seamless SSO to your users. You start by adding the following Azure AD URL to all or selected users' Intranet zone settings by using Group Policy in Active Directory: https://autologon.microsoftazuread-sso.com E: Seamless SSO works with any method of cloud authentication - Password Hash Synchronization or Pass-through Authentication, and can be enabled via Azure AD Connect. Incorrect Answers: A: Seamless SSO is not applicable to Active Directory Federation Services (ADFS). B: Azure AD connect does not port 8080. It uses port 443. C: Seamless SSO needs the user's device to be domain-joined, but doesn't need for the device to be Azure AD Joined. Scenario: Users in the Miami office must use Azure Active Directory Seamless Single Sign-on (Azure AD Seamless SSO) when accessing resources in Azure. Planned Azure AD Infrastructure include: The on-premises Active Directory domain will be synchronized to Azure AD. References: https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-sso-quick-start
From the book Microsoft Certified: Azure Solutions Architect Expert - Exam AZ-300:
You need to prepare the environment to meet the authentication requirements.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
A. Allow inbound TCP port 8080 to the domain controllers in the Miami office.
B. Add http://autologon.microsoftazuread-sso.com to the intranet zone of each client computer in the Miami office.
C. Join the client computers in the Miami office to Azure AD.
D. Install the Active Directory Federation Services (AD FS) role on a domain controller in the Miami office.
E. Install Azure AD Connect on a server in the Miami office and enable Pass-through Authentication.
Answers: BE (Which in this question is DE)
D. Add http://autologon.microsoftazuread-sso.com to the intranet zone of each client computer in the Miami office.
E. Install Azure AD Connect on a server in the Miami office and enable Pass-through Authentication.
Step 1 and Step 3 on the link provided outline why its D&E https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-sso-quick-start
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Kallandor
Highly Voted 2 years, 11 months agochand_
Highly Voted 2 years, 11 months agoThi
Most Recent 2 years, 7 months agokiruthiga
2 years, 11 months agomacco455
2 years, 11 months agosrinu1234
2 years, 12 months ago