Q: 12
You have an Azure Active Directory Domain Services (Azure AD DS) domain named contoso.com.
You need to provide an administrator with the ability to manage Group Policy Objects (GPOs). The
solution must use the principle of least privilege.
To which group should you add the administrator?
Options
Discussion
Add-KdsRootKey is the one you need for setting up gMSA support in the domain. Without running that PowerShell cmdlet, AD can't generate the required keys for gMSAs. Pretty sure that's all they're looking for here, unless they want immediate use (then you'd tweak -EffectiveTime). Agree?
Add-KdsRootKey
Add-KdsRootKey
Add-KdsRootKey
Be respectful. No spam.