exam questions

Exam MD-100 All Questions

View all questions & answers for the MD-100 exam

Exam MD-100 topic 5 question 28 discussion

Actual exam question from Microsoft's MD-100
Question #: 28
Topic #: 5
[All MD-100 Questions]

HOTSPOT -
You have a Microsoft Azure Active Directory (Azure AD) tenant named contoso.com that contains the users shown in the following table.

You have a computer named Computer1 that runs Windows 10.
Computer1 is in a workgroup and has the local users shown in the following table.

User1 joins Computer1 to Azure AD by using [email protected].
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Anthony_2770
Highly Voted 4 years, 4 months ago
1.Yes https://docs.microsoft.com/en-us/azure/active-directory/devices/assign-local-admin By default, Azure AD adds the user performing the Azure AD join to the local administrator group on the device. User1 joins Computer1 to Azure AD by using [email protected]. 2. No https://docs.microsoft.com/en-us/azure/active-directory/roles/permissions-reference 3.No https://docs.microsoft.com/en-us/azure/active-directory/roles/permissions-reference
upvoted 31 times
JoenardAF
4 years, 4 months ago
I'll trust you
upvoted 1 times
...
daviddahles
4 years, 4 months ago
I do understand that User1 can only join the device if it is in the local administrator group, but how can User1 do this if the role is defined as "none"?
upvoted 1 times
BAbdalla
3 years, 8 months ago
All user that register a computer in Azure AD are registered in local administrators group of computer registered.
upvoted 4 times
...
...
syougun200x
2 years, 9 months ago
I second your answer. Tested on my lab.
upvoted 1 times
...
RodrigoT
3 years, 3 months ago
But locally Admin2 is a member of Power Users that CAN install software. So, I would say 3.YES.
upvoted 1 times
...
...
hokieman91
Highly Voted 4 years, 5 months ago
1. NO - domain [email protected] has no admin access (no role assigned) - only the local User1 account 2. YES - https://docs.microsoft.com/en-us/azure/security-center/security-center-permissions 3. NO - https://docs.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#cloud-device-administrator-permissions
upvoted 16 times
jsblah
4 years, 4 months ago
D'oh! I was basing my answers off the local user names <facepalm> Thanks for posting this.
upvoted 3 times
...
Anthony_2770
4 years, 4 months ago
1.Yes https://docs.microsoft.com/en-us/azure/active-directory/devices/assign-local-admin By default, Azure AD adds the user performing the Azure AD join to the local administrator group on the device. User1 joins Computer1 to Azure AD by using [email protected].
upvoted 4 times
...
...
flabezerra
Most Recent 2 years, 5 months ago
Understand role as a group in Azure AD. In Azure Active Directory (Azure AD), if another administrator or non-administrator needs to manage Azure AD resources, you assign them an Azure AD role that provides the permissions they need. Any of these three roles are able to become a local administrator account: The Azure AD Global Administrator role The Azure AD joined device local administrator role - especially this role is responsible for making a regular user (User1) a local administrator. The user performing the Azure AD join The process is very simple, The role Azure AD joined device local administrator is a role added to the Local Administrators group, so they become local administrators. First statement is a YES.
upvoted 1 times
flabezerra
2 years, 5 months ago
regular user ([email protected]) a local administrator
upvoted 1 times
...
flabezerra
2 years, 5 months ago
Sorry for the typos. Understand user here as an Azure AD user not on-prem user. The user performing the Azure AD join - specially this role is responsible for making a regular user ([email protected]) a local administrator. https://learn.microsoft.com/en-us/azure/active-directory/devices/assign-local-admin#manage-regular-users
upvoted 1 times
...
...
raduM
2 years, 10 months ago
admin2 is member of the power users so he can install software change the time zone and power settings and install active x controls
upvoted 1 times
...
raduM
2 years, 10 months ago
Cloud Device Administrator Users in this role can enable, disable, and delete devices in Azure AD and read Windows 10 BitLocker keys (if present) in the Azure portal. The role does not grant permissions to manage any other properties on the device. therefor yes no no
upvoted 1 times
...
williamzwwu
3 years, 2 months ago
Yes, NO, NO, please refer the roles from below link: https://docs.microsoft.com/en-us/azure/active-directory/roles/permissions-reference
upvoted 1 times
...
adeshtall
3 years, 3 months ago
If computer1 is joined to Azure Ad , why is the securrity admi cannot install firewall, since computer1 is joined to the Ad. question 2 need to be yes.
upvoted 1 times
...
IykeP
3 years, 4 months ago
The Correct answer is Yes, No, No. Cloud Device Administrator can enable, disable, and delete devices in Azure AD and read Windows 10 BitLocker keys (if present) in the Azure portal. The role does not grant permissions to manage any other properties on the device.
upvoted 1 times
RodrigoT
3 years, 3 months ago
But locally Admin2 is a member of Power Users that CAN install software. So YES, NO, YES.
upvoted 1 times
...
...
jaroti2116
3 years, 5 months ago
Is local user and ad users are going to merge after join?
upvoted 1 times
...
rajpatel007
3 years, 5 months ago
YES NO N0
upvoted 1 times
...
KirilA
3 years, 11 months ago
I pass the exam today, In the table it was UserA instead User1 as is shown here, so i choose No
upvoted 2 times
AJCB
3 years, 7 months ago
Nice congrats. How long did you study? I studied for 2+ weeks straight in between work and off. Taking it tomorrow, I think I'm prepared lol
upvoted 2 times
korhann_
3 years, 7 months ago
how it went
upvoted 2 times
AJCB
3 years, 7 months ago
I had to reschedule due to technical errors... The exam has these questions. Definitely get a good understanding of these questions, think we should be good. taking it this weekend, wish me luck.
upvoted 2 times
...
...
...
...
mllerena
4 years, 2 months ago
Yes No No
upvoted 1 times
...
forummj
4 years, 5 months ago
This is a better link giving you the exact role titles and descriptions, which seems to indicate that Cloud Device Administrator cannot install software, which would make this a Yes, No, No answer. https://docs.microsoft.com/en-us/azure/active-directory/roles/permissions-reference
upvoted 6 times
...
Anthony_2770
4 years, 6 months ago
The above is the Azure role for the Security administrator
upvoted 1 times
...
Anthony_2770
4 years, 6 months ago
View and update permissions for Security Center. Same permissions as the Security Reader role and can also update the security policy and dismiss alerts and recommendations.
upvoted 1 times
...
Anthony_2770
4 years, 6 months ago
Ref : https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago