exam questions

Exam 70-742 All Questions

View all questions & answers for the 70-742 exam

Exam 70-742 topic 1 question 226 discussion

Actual exam question from Microsoft's 70-742
Question #: 226
Topic #: 1
[All 70-742 Questions]

Your network contains an Active Directory forest named contoso.com.
You have an Active Directory Federation Services (AD FS) farm. The farm contains a server named Server1 that runs Windows Server 2012 R2.
You add a server named Server2 to the farm. Server2 runs Windows Server 2016.
You remove Server1 from the farm.
You need to ensure that you can use role separation to manage the farm.
Which cmdlet should you run?

  • A. Set-AdfsFarmInformation
  • B. Update-AdfsRelyingPartyTrust
  • C. Set-AdfsProperties
  • D. Invoke-AdfsFarmBehaviorLevelRaise
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
coleman
Highly Voted 5 years ago
answer D is correct . ADFS in Windows Server 2016 includes a new feature "Access Control Policies" which is not available in Windows Server 2012 R2, this new feature achieves roles separation as demanded by this question. https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/operations/access-control-policies-in-ad-fs https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/deployment/upgrading-to-ad-fs-in-windows-server-2016 Administrators can add new, Windows Server 2016 federation servers to an existing Windows Server 2012 R2 farm. As a result, the farm is in "mixed mode" and operates the Windows Server 2012 R2 farm behavior level. To ensure consistent behavior across the farm, new Windows Server 2016 features cannot be configured or used in this mode. Be aware that while in mixed farm mode, the AD FS farm is not capable of any new features or functionality introduced in AD FS in Windows Server 2016. This means organizations that want to try out new features cannot do this until the Farm Behavior Level is raised. Use the "Invoke-AdfsFarmBahaviorLevelRaise cmdlet to raise the Farm's feature and function as provided by Windows Server 2016
upvoted 15 times
ITGEEK
4 years, 10 months ago
Thanks for the explanation coleman
upvoted 1 times
...
...
MP
Highly Voted 5 years, 11 months ago
Invoke-AdfsFarmBehaviorLevelRaise? Because you want to use the new features?
upvoted 13 times
...
lofzee
Most Recent 3 years, 10 months ago
Invoke-AdfsFarmBehaviorLevelRaise Correct Use this to raise the farm level to 2016, which will allow role separation
upvoted 1 times
...
yesboet
4 years ago
D is correct
upvoted 1 times
...
Kamikazekiller
4 years, 5 months ago
Answer is: D. Invoke-AdfsFarmBehaviorLevelRaise
upvoted 1 times
...
panda
4 years, 12 months ago
Please hepl me. I don't understand the relation between role separation and Invoke-AdfsFarmBehaviorLevelRaise.
upvoted 2 times
simcauley
4 years, 11 months ago
Coleman's explanation above describes it well. The role separation features we are after are in the "Access Control Policies" of ADFS 2016. Because we joined our new 2016 server to an existing 2012 farm it has defaulted to mixed mode and is operating at a 2012 farm level. So we need to raise the level to 2016 which will need give us access to the role separation features and to do that we run Invoke-ADFSFarmBehaviorLevelRaise.
upvoted 2 times
simcauley
4 years, 11 months ago
*then, not need.
upvoted 1 times
...
...
...
renatovieira
5 years, 2 months ago
B and D; AD FS for Windows Server 2016 introduces the ability to have separation between server administrators and AD FS service administrators. After upgrading our ADFS servers to Windows Server 2016, the last step is to raise the Farm Behavior Level using the Invoke-AdfsFarmBehaviorLevelRaise PowerShell cmdlet. To upgrade the farm behavior level from Windows Server 2012 R2 to Windows Server 2016 use the InvokeADFSFarmBehaviorLevelRaise cmdlet. References: https://technet.microsoft.com/en-us/library/mt605334(v=ws.11).aspx
upvoted 1 times
...
Paz
5 years, 3 months ago
Good article spud, but notice in this question it says they removed server 1 from the farm, so you dont have to change owners like in your article, you just have to invoke-adfsfarmbehavior. The anwser would be D.
upvoted 1 times
...
Spud1993
5 years, 3 months ago
I thin the answer is correct - please see following link which gives you steps on moving the primary role https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/deployment/upgrading-to-ad-fs-in-windows-server
upvoted 2 times
Chipper
5 years, 3 months ago
In the link you posted, there is no mention of set-adfsfarminformation command in it. It mentions to use get-adfsfarminformation. The link even says to use the invoke-adfsfarmbehaviorlevel raise in step 8 after removing the 2012 server and running adprep.
upvoted 1 times
...
...
[Removed]
5 years, 5 months ago
Correct answer is : Invoke-AdfsFarmBehaviorLevelRaise The Invoke-AdfsFarmBehaviorLevelRaise cmdlet raises the behavior level of an Active Directory Federation Services (AD FS) farm to enable the new features that are available in later versions of the Windows operating system. https://docs.microsoft.com/en-us/powershell/module/adfs/invoke-adfsfarmbehaviorlevelraise?view=win10-ps
upvoted 3 times
...
noppy
5 years, 6 months ago
"You need to ensure that you can use role separation to manage the farm." Means that need to use (enable) new feature and cmdlet to enable new feature is "Invoke-AdfsFarmBehaviorLevelRaise" Refer to below link for what differences of the cmdlets nvoke-AdfsFarmBehaviorLevelRaise : https://docs.microsoft.com/en-us/powershell/module/adfs/invoke-adfsfarmbehaviorlevelraise?view=win10-ps Set-AdfsFarmInformation : https://docs.microsoft.com/en-us/powershell/module/adfs/set-adfsfarminformation?view=win10-ps
upvoted 7 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago