PrepAway - Latest Free Exam Questions & Answers

Does this meet the goal?

Note: This question is part of a series of a questions that present the same scenario. Each question in the
series contains a unique solution that might meet the stated goals. Some questions sets might have more than
one correct solutions, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will
not appear in the review screen.
Your network contains an Active Directory forest named contoso.com. The forest contains a member server
named Server1 that runs Windows Server 2016. All domain controllers run Windows Server 2012 R2.
Contoso.com has the following configuration.

You plan to deploy an Active Directory Federation Services (AD FS) farm on Server1 and to configure device
registration.
You need to configure Active Directory to support the planned deployment.
Solution: You run adprep.exe from the Windows Server 2016 installation media.
Does this meet the goal?

PrepAway - Latest Free Exam Questions & Answers

A.
Yes

B.
No

Explanation:
Adprep just prepares the domain for Window Server 2016, it does not actually raise the domain functional level
to Windows Server 2016, which is required for Device Registration.
Note: Adprep.exe is a command-line tool that is included on the installation disk of each version of Windows
Server. Adprep.exe performs operations that must be completed on the domain controllers that run in an
existing Active Directory environment before you can add a domain controller that runs that version of Windows
Server.
Adprep.exe commands run automatically as needed as part of the AD DS installation process on servers that
run Windows Server 2012 or later. The commands need to run in the following cases:
* Before you add the first domain controller that runs a version of Windows Server that is later than the latest
version that is running in your existing domain.
* Before you upgrade an existing domain controller to a later version of Windows Server, if that domain
controller will be the first domain controller in the domain or forest to run that version of Windows Server.

https://technet.microsoft.com/en-us/library/dd464018(v=ws.10).aspx
https://technet.microsoft.com/en-us/windows-server-docs/identity/ad-fs/operations/configure-device-basedconditional-access-on-premises

4 Comments on “Does this meet the goal?

  1. PauliusP says:

    Answer is Yes.

    https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/overview/ad-fs-requirements

    Look for Domain functional-level requirements and Schema requirements. 2008 or higher domain functional level required > we have 2008R2.

    adprep.exe will upgrade AD schema to meet the requirement of schema version 85 or higher.

    At least one Windows Server 2016 domain controller is required for Microsoft Passport for Work > we do not have statement that Microsoft Passport for Work is necessary.

    Correct me if I am wrong.




    1



    1
    1. Fact Checker says:

      Your link literally contradicts you. Under AD DS requirements

      “Domain functional-level requirements

      All user account domains and the domain to which the AD FS servers are joined must be operating at the domain functional level of Windows Server 2003 or higher.

      A Windows Server 2008 domain functional level or higher is required for client certificate authentication if the certificate is explicitly mapped to a user’s account in AD DS.”

      The minimun is 2008 for the domain level. The currently level is 2008 R2. This scenario also meets the rest of the requirement (1 2016 server and at least 2008 domain controllers. These are 2012 R2)

      The answer is No




      0



      2
  2. Rgs says:

    So, adprep prepare the domain or raise it? In the case that you prepare the domain, it not means that you have a dc 2016 (with this level)
    Doesn’t say adprep /domainprep or /forestprep
    This questions is very confuse




    1



    0

Leave a Reply