Home » Microsoft » 70-346 » Which four actions should you perform in sequence?
DRAG DROP
Contoso, Ltd. has an Office 365 tenant. The company has two servers named Server1 and Server2 that run Windows 2012 R2 Server. The servers are not joined to the contoso.com domain. Server2 is deployed to the perimeter network. You install Secure Sockets Layer (SSL) certificates on both servers.
You deploy internal and external firewalls. All firewalls allow HTTPS traffic.
You must deploy single sign-on (SSO) and Active Directory Federation Services (AD FS). You need to install and configure all AD FS components in the environment.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Select and Place:
Correct Answer:
Explanation/Reference:
Note:
Prepare the Base Servers Box 1, Box 2: AD FS Server
. Basebuild the AD FS server with Windows Server 2012
. Setup a connection to the internal network
. Add the server to the local domain
. Update the server with all Windows Updates
Box 3, Box 4: AD FS Proxy Server
Once the necessary WAP role services are installed,weare then able to launch the Web Application Proxy Wizard to configure WAP. Note:
. Base Build the AD FS Proxy server with Windows Server 2012
. Setup a connection to the DMZ network (verify connectivity to the AD FS server on port 443)
. DO NOTadd the servertothe local domain
. Update the server with all Windows Updates
References:
Maybe my mistake. Apparently you can build a stand-alone AD FS server: https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/deployment/create-a-stand-alone-federation-server. But why would you want to do it that way?
You can’t install AD FS on a server that is not domain-joined. The explanation is correct, but the answer is wrong – steps 1 and 2 are backwards.
Is the answer is correct ? Shouldn’t it be ‘Join’ first ?