Active Directory Issue

Resolve Active Directory Issue

Question

This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.

To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.

At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.

To start the case study -

To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an

All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.

Overview -

Humongous Insurance is an insurance company that has three offices in Miami, Tokyo and Bangkok. Each office has 5.000 users.

Existing Environment -

Active Directory Environment -

Humongous Insurance has a single-domain Active Directory forest named humongousinsurance.com. The functional level of the forest is Windows Server 2012.

You recently provisioned an Azure Active Directory (Azure AD) tenant.

Network Infrastructure -

Each office has a local data center that contains all the servers for that office. Each office has a dedicated connection to the Internet.

Each office has several link load balancers that provide access to the servers.

Active Directory Issue -

Several users in humongousinsurance.com have UPNs that contain special characters.

You suspect that some of the characters are unsupported in Azure AD.

Licensing Issue -

You attempt to assign a license in Azure to several users and receive the following error message: "Licenses not assigned. License agreement failed for one user."

You verify that the Azure subscription has the available licenses.

Requirements -

Planned Changes -

Humongous Insurance plans to open a new office in Paris. The Paris office will contain 1,000 users who will be hired during the next 12 months. All the resources used by the Paris office users will be hosted in Azure.

Planned Azure AD Infrastructure -

The on-premises Active Directory domain will be synchronized to Azure AD.

All client computers in the Paris office will be joined to an Azure AD domain.

Planned Azure Networking Infrastructure

You plan to create the following networking resources in a resource group named All_Resources:

Default Azure system routes that will be the only routes used to route traffic

A virtual network named Paris-VNet that will contain two subnets named Subnet1 and Subnet2

A virtual network named ClientResources-VNet that will contain one subnet named ClientSubnet

A virtual network named AllOffices-VNet that will contain two subnets named Subnet3 and Subnet4

You plan to enable peering between Paris-VNet and AllOffices-VNet. You will enable the Use remote gateways setting for the Paris-VNet peerings.

You plan to create a private DNS zone named humongousinsurance.local and set the registration network to the ClientResources-VNet virtual network.

Planned Azure Computer Infrastructure

Each subnet will contain several virtual machines that will run either Windows Server 2012 R2, Windows Server 2016, or Red Hat Linux.

Department Requirements -

Humongous Insurance identifies the following requirements for the company's departments:

Web administrators will deploy Azure web apps for the marketing department. Each web app will be added to a separate resource group. The initial configuration of the web apps will be identical. The web administrators have permission to deploy web apps to resource groups.

During the testing phase, auditors in the finance department must be able to review all Azure costs from the past week.

Authentication Requirements -

Users in the Miami office must use Azure Active Directory Seamless Single Sign-on (Azure AD Seamless SSO) when accessing resources in Azure.

You need to resolve the Active Directory issue.

What should you do?

Introductory Info

Question

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

B

IdFix is used to perform discovery and remediation of identity objects and their attributes in an on-premises Active Directory environment in preparation for migration to Azure Active Directory. IdFix is intended for the Active Directory administrators responsible for directory synchronization with Azure Active Directory.

Scenario: Active Directory Issue

Several users in humongousinsurance.com have UPNs that contain special characters.

You suspect that some of the characters are unsupported in Azure AD.

https://www.microsoft.com/en-us/download/details.aspx?id=36832

The issue at hand is that several users in the Humongous Insurance Active Directory forest have User Principal Names (UPNs) that contain special characters, and there is suspicion that some of these characters may not be supported in Azure Active Directory (Azure AD). To resolve this issue, we need to ensure that the UPNs are valid for use in Azure AD.

Option A - From Active Directory Users and Computers, select the user accounts, and then modify the UPN suffix value. This option is not the correct solution to the issue. While it is possible to modify the UPN suffix value for user accounts, this may not necessarily resolve the issue of unsupported characters in the UPN. Additionally, this solution would require modifying each affected user account individually, which could be time-consuming and error-prone.

Option B - Run the IdFix tool then use the Update action. This option is a possible solution to the issue. The IdFix tool is a free tool provided by Microsoft that scans an Active Directory environment for errors and provides recommendations for resolving them. Running the tool and using the Update action can help to ensure that the UPNs are valid for use in Azure AD. However, it is important to note that the tool should be used with caution, and any recommended changes should be reviewed carefully before being applied.

Option C - From Active Directory Domains and Trusts, modify the list of UPN suffixes. This option is not the correct solution to the issue. Modifying the list of UPN suffixes in Active Directory Domains and Trusts would not necessarily resolve the issue of unsupported characters in the UPN. Additionally, this solution would not address the specific issue of the users in question.

Option D - From Azure AD Connect, modify the outbound synchronization rule. This option is not the correct solution to the issue. Modifying the outbound synchronization rule in Azure AD Connect would not necessarily resolve the issue of unsupported characters in the UPN. Additionally, this solution would not address the specific issue of the users in question.

In summary, the correct solution to the Active Directory issue of unsupported characters in UPNs is to run the IdFix tool and use the Update action to ensure that the UPNs are valid for use in Azure AD.