In this section, you’ll see one or more sets of questions with the same scenario and problem.
Each question presents a unique solution to the problem, and you must determine whether
the solution meets the stated goals. Any of the solutions might solve the problem. It is also
possible that none of the solutions solve the problem.
Once you answer a question in this section, you will NOT be able to return to it. As a result.
these questions will not appear in the review screen.
Note: This question is part of a series of questions that present the same scenario. Each
question in the series contains a unique solution. Determine whether the solution meets the
stated goals.
Your network contains an Active Directory forest named contoso.com. The forest contains a
member server named Server1 that runs Windows Server 2016. All domain controllers run
Windows Server 2012 R2. Contoso com has the following configuration:
You plan to deploy an Active Directory Federation Services (AD FS) farm on Server1 and to
configure device registration. You need to configure Active Directory to support the planned
deployment.
Solution: You raise the forest functional level to Windows Server 2012 R2.
Does this meet the goal?
A.
Yes
B.
No
The exact same question is asked in question 86
Your Active Directory forest must have the Windows Server 2012 R2 schema to support device registration, see:
https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/deployment/configure-a-federation-server-with-device-registration-service
ANSWER IS NO, because:
Domain functional-level requirements
All user account domains and the domain to which the AD FS servers are joined must be operating at the domain functional level of Windows Server 2003 or higher.
A Windows Server 2008 domain functional level or higher is required for client certificate authentication if the certificate is explicitly mapped to a user’s account in AD DS.
Schema requirements
New installations of AD FS 2016 require the Active Directory 2016 schema (minimum version 85).
Raising the AD FS farm behavior level (FBL) to the 2016 level requires the Active Directory 2016 schema (minimum version 85).
https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/overview/ad-fs-requirements