Manage Windows Servers and workloads in a hybrid environment

Thought experiment answers

This section contains the solution to the thought experiment. Each answer explains why the answer choice is correct.

  1. Use an Azure AD Service principal delegated the Azure Connected Machine Onboarding role. An Azure AD Service principal is required to perform onboarding in this manner.

  2. Configure a JEA endpoint that allows Sonia to perform a restricted set of tasks related to DNS management. This will ensure that she is able to perform tasks without unnecessary permissions.

  3. Configure Kerberos delegation that allows Rick’s credentials to be used by the jump server. Kerberos delegation allows the jump server to use Rick’s credentials to run the PowerShell scripts.