exam questions

Exam AZ-300 All Questions

View all questions & answers for the AZ-300 exam

Exam AZ-300 topic 4 question 6 discussion

Actual exam question from Microsoft's AZ-300
Question #: 6
Topic #: 4
[All AZ-300 Questions]

You sign up for Azure Active Directory (Azure AD) Premium.
You need to add a user named [email protected] ad an administrator on all the computers that will be joined to the Azure AD domain.
What should you configure in Azure AD?

  • A. Providers from the MFA Server blade
  • B. General settings from the Groups blade
  • C. Device settings from the Devices blade
  • D. User settings from the Users blade
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️
When you connect a Windows device with Azure AD using an Azure AD join, Azure AD adds the following security principles to the local administrators group on the device:
✑ The Azure AD global administrator role
✑ The Azure AD device administrator role
The user performing the Azure AD join
In the Azure portal, you can manage the device administrator role on the Devices page. To open the Devices page:
1. Sign in to your Azure portal as a global administrator or device administrator.
2. On the left navbar, click Azure Active Directory.
3. In the Manage section, click Devices.
4. On the Devices page, click Device settings.
5. To modify the device administrator role, configure Additional local administrators on Azure AD joined devices.
References:
https://docs.microsoft.com/en-us/azure/active-directory/devices/assign-local-admin

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
looker
Highly Voted 5 years, 8 months ago
so the correct answer is : C
upvoted 51 times
bbbb
5 years, 5 months ago
Agree, as per the Devices blade under Device Settings, you can configure "Additional local administrators on Azure AD joined devices" and select members.
upvoted 18 times
Zixxer2Go
5 years, 1 month ago
Note: you want to have an administrator account on all COMPUTERS...definitely a "device" consideration here. "C"
upvoted 5 times
tartar
4 years, 9 months ago
C is ok
upvoted 1 times
...
...
...
praveen97
4 years, 11 months ago
Yes Answer is C. I have checked in the lab, we can add an admin to all the devices only in Azure AD -> Device Settings.
upvoted 3 times
...
A365
4 years, 10 months ago
C is correct. However Azure AD premium is needed for this functionality: https://docs.microsoft.com/en-us/azure/active-directory/devices/assign-local-admin#manage-the-device-administrator-role
upvoted 1 times
...
...
gurby
Highly Voted 5 years, 6 months ago
The answer is C. You must go to device settings to add additional local administrators devices joining Azure AD.
upvoted 11 times
...
BOC
Most Recent 4 years, 9 months ago
Correct answer is C
upvoted 1 times
...
Jend
4 years, 10 months ago
Correct answer is D, because it is for future computers getting added automatically it happens after. While if it was for the current computers you all would have been correct but, the question is deceiving..... Answer D is correct! NOT C.
upvoted 1 times
TP447
4 years, 9 months ago
C and D both achieve the desired outcome - though C provides a route to achieving this without having to add the user account to a sensitive group such as Global Admins. Both methods grant access to existing and future AAD joined machines. My argument to do this and ensure least privilege would be; - Create a group specifically for this purpose - Add the desired user to the group - Add the group to the Device Settings on Devices blade.
upvoted 1 times
...
...
Ausias18
4 years, 11 months ago
This question appeared me in my AZ-104 exam, and I answer C.
upvoted 1 times
...
poohtt
4 years, 11 months ago
There are 2 ways to implement requirements: C and D. You can use device settings to add an admin or you can assign admin role to the user and he will be added to local admins automatically. But I like the C, because the description for D is incorrect. You can assign user roles from "Assigned roles", not from settings.
upvoted 1 times
...
Len
4 years, 11 months ago
Answer is C https://docs.microsoft.com/en-us/azure/active-directory/devices/assign-local-admin
upvoted 1 times
...
gboyega
4 years, 11 months ago
C is the correct answer
upvoted 3 times
...
DeveshSolanki
4 years, 11 months ago
ANS - C. Device settings from the Devices blade
upvoted 1 times
...
Rooh
4 years, 12 months ago
C is the right answer
upvoted 1 times
...
AmarKavita
5 years, 1 month ago
The answer is C. You must go to device settings to add additional local administrators devices joining Azure AD.
upvoted 2 times
...
milind8451
5 years, 2 months ago
Go to Azure AD blade -> Devices -> Device Settings Here you will see option of "Additional local Administrator on Azure AD joined devices", click on selected and add the name of administrator whom you want to add. So option "C" is correct. Tested in lab.
upvoted 6 times
milind8451
5 years, 2 months ago
However if they ask to choose 2 answers then D is also correct as you can assign role "Cloud Device Administrator" from "User"->"Assigned Roles" blade which will also do the same job.
upvoted 2 times
aillusionist
4 years, 8 months ago
Cloud Device Administrator Users in this role can enable, disable, and delete devices in Azure AD and read Windows 10 BitLocker keys (if present) in the Azure portal. The role does not grant permissions to manage any other properties on the device. Hence its not the same as the local Admin on the servers. It must be C
upvoted 1 times
...
...
...
Gorha
5 years, 2 months ago
C is correct: http://www.rebeladmin.com/2017/12/step-step-guide-add-additional-local-administrators-azure-ad-joined-devices/
upvoted 7 times
...
silverdeath
5 years, 2 months ago
The answer is C, under modify the device administrator role, configure Additional local administrators on Azure AD joined devices.
upvoted 2 times
...
HS007
5 years, 5 months ago
Correct answer is C = Additional local administrators on Azure AD joined devices Change to Selected and select the Users or Groups
upvoted 8 times
...
Benkyoujin
5 years, 6 months ago
I don’t see this option in device settings now. Does it require a different license?
upvoted 1 times
wigger
5 years, 4 months ago
"Requires AD Premium tenant" https://docs.microsoft.com/en-us/azure/active-directory/devices/assign-local-admin
upvoted 1 times
...
...
Matt_t
5 years, 6 months ago
The explanation talks about c but the answer is selected as D. Is this correct ?
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...