PrepAway - Latest Free Exam Questions & Answers

Which two actions should you perform?

Your network contains an Active Directory forest named contoso.com. The forest contains three domains.All domain controllers run Windows Server 2016.
You deploy a second Active Directory forest named admin.contoso.com.
The forest contains a domain member server named Server1. Server1 has Microsoft Identity Manager (MIM)
2016 deployed.
You need to implement Privileged Access Management (PAM) and to use admin.contoso.com as an
administrative forest.
Which two actions should you perform? Each correct answers presents part of the solution.

PrepAway - Latest Free Exam Questions & Answers

A.
From a domain controller in contoso.com. run the New-PAMTrust cmdlet.

B.
From Server1, run the New-PAMDomainConfiguration cmdlet

C.
From a domain controller in admin.contoso.com, run the New-PAMTrust cmdlet.

D.
From a domain controller in contoso.com, run the New-PAMDomainConfiguration cmdlet.

E.
From a domain controller in admin.contoso.com, run the New-PAMDomainConfiguration cmdlet

F.
From Server1, run the New-PAMTrust cmdlet

Explanation:
https://docs.microsoft.com/en-us/microsoft-identity-manager/pam/configuring-mim-environment-for-pam
https://docs.microsoft.com/en-us/microsoft-identity-manager/pam/step-5-establish-trust-between-priv-corpforests

4 Comments on “Which two actions should you perform?

  1. Tony says:

    Correct answers are D and E
    The New-PamTrust cmdlet is run on the MIM server to create the required trust relationship between the forests. After creating the trust between the forests, the NewPAMDomainConfiguration must be run on each domain in the production forest or forests.




    2



    5
  2. slide101 says:

    The answer is actually DF.
    MIM includes a collection of Windows PowerShell cmdlets, including one called
    NewPAMTrust, which you run on the MIM server to create the required trust relationship
    between the forests. The syntax for the cmdlet is as follows:
    New-PAMTrust -SourceForest “domain.local” -Credentials (Get-
    Credential)

    After you create the trust between the forests, you must also run the New-PAMDomain-
    Configuration cmdlet for each domain in your production forest(s).




    2



    1

Leave a Reply