Microsoft Administering Windows Server AZ-802 Question # 4 Topic 1 Discussion
AZ-802 Exam Topic 1 Question 4 Discussion:
Question #: 4
Topic #: 1
You need to configure the Group Policy settings to ensure that the Azure Virtual Desktop session hosts meet the security requirements. What should you configure?
GPO4 is already linked to the VirtualDesktops OU, which contains the Azure Virtual Desktop session host computer accounts, so it is correctly targeted at the right computers. The requirement is that the idle lockout behavior configured in GPO4 must apply to whichever user is signed in to a session host, and that the user must still be able to adjust the lockout time manually from their own client, which means the relevant setting is a per-user configuration item rather than a strict, non-negotiable computer policy. By default, user-configuration settings inside a GPO apply based on the OU containing the user account, not the computer the user signs in to; Fabrikam ' s users are located in the AllUsers OU, which is governed by GPO1, not GPO4. Group Policy Loopback Processing, enabled in GPO4 and set to Merge (to allow the client-side adjustment) or Replace, forces the user-configuration portion of GPO4 to apply to any user who logs on to a computer in the VirtualDesktops OU, regardless of where that user ' s own account resides. Security filtering and the Enforced property both affect who a GPO applies to or its precedence in conflicts, but neither one makes a GPO ' s user-side settings follow the computer instead of the user, so loopback processing in GPO4 is correct.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit