Your network contains an Active Directory forest named contoso.com. The forest contains a member server
named Server1 that runs Windows Server 2016. All domain controllers run Windows Server 2012 R2.
Contoso.com has the following configuration:
You plan to deploy an Active Directory Federation Services (AD FS) farm on Server1 and to configure device registration.
You need to configure Active Directory to support the planned deployment.Solution: You run adprep.exe from the Windows Server 2016 installation media.
Does this meet the goal?
A.
Yes
B.
No
Explanation:
Device registration requires a forest functional level of Windows Server 2012 R2.
New installations of AD FS 2016 require the Active Directory 2016 schema (minimum version 85).
References:
https://technet.microsoft.com/en-us/library/dd464018(v=ws.10).aspx https://technet.microsoft.com/en-us/windows-server-docs/identity/ad-fs/operations/configure-device-basedconditional-access-on-premises
Same question with explanation here: https://www.briefmenow.org/microsoft/does-this-meet-the-goal-303/
0
0
No. Device registration requires a forest functional level of Windows Server 2012 R2. ADPrep doesnt rais the functional level; it only preps the AD for new DCs running Win2016 (=update the schema).
4
4
Actually, I do believe it is YES as indeed I couldn’t find the forest functional level requirements here: https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/overview/ad-fs-requirements
0
1
A. Yes
ANY new ADFS deployment done on WS 2016 requires schema level of 2016. Adprep is the tool who does that. It raises schema version.
https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/dd464018(v=ws.10)
5
1
B: No
No mention in question of a 2016 Domain Controller. All DCs are 2012R2
https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/overview/ad-fs-requirements
Applies To: Windows Server 2016
AD DS requirements
•At least one Windows Server 2016 domain controller is required for Microsoft Passport for Work.
The adprep command would Update the Active Directory Schema making it ready to introduce a Win 2016 domain controller. Once the 2016 DC is installed then the functional forest level can be raised
Schema requirements
•New installations of AD FS 2016 require the Active Directory 2016 schema (minimum version 85).
•Raising the AD FS farm behavior level (FBL) to the 2016 level requires the Active Directory 2016 schema (minimum version 85).
8
0