This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
A regulated subsidiary must not share the schema, configuration partition, or Enterprise Admins and Schema Admins security boundary with the rest of the organization. Which structure should you choose?
Create a separate forest and connect it with a narrowly scoped trust if cross-forest access is required.
Create another domain in the existing forest and delegate administration to the subsidiary.
Deploy an RODC in the subsidiary's site and deny privileged accounts in its Password Replication Policy.
Users in an acquired company's forest need access to only a defined set of servers in your resource forest. Which trust design provides the narrowest appropriate authentication path?
Create a one-way forest trust in which the resource forest trusts the acquired account forest, enable selective authentication, and grant Allowed to authenticate only on the approved servers.
Create a one-way forest trust in which the acquired account forest trusts the resource forest, then add the acquired users to resource ACLs.
Create a two-way forest trust, disable SID filtering, and rely only on resource ACLs to restrict access.
An RODC is stolen from a branch office. Which Password Replication Policy usage set identifies the domain credentials that are cached on that RODC and must be included in the reset plan?
The revealed list.
The allowed list.
The authenticated-to list.
You must answer all questions before checking your work.
Was this page helpful?
Need help with this topic?
Want to try using Ask Learn to clarify or guide you through this topic?