###BeginCaseStudy###
Topic 5, Alpine Ski
Overview
Alpine Ski House provides vacation travel accommodations. Its main office is in Vancouver. Alpine Ski House
also has branch offices in Montreal, Denver, and New York.
An additional sales office is located in Los Angeles. This office has client devices only.
All servers in each office run Windows Server 2012 R2. All client devices in each office run Windows 8.1.
Alpine Ski House plans to acquire another company named Margie’s Travel. Margies Travel has an AD DS
domain named margiestravel.com.
Danner and New York
The Denver and New York offices have their own child domain named us.alpineskihouse.com. The domain
controllers are displayed in the following table:
Vancouver and Montreal
Alpine Ski House has an Active Directory Domain Services (AD DS) domain named aplineskihouse.com for the
Vancouver and Montreal offices. The forest and domain functional levels are set to Windows Server 2008.
The domain controllers in the domain contain Dynamic Host Configuration Protocol (DHCP) servers and DNS
servers. The domain controllers are displayed in the following table:
The Vancouver office also has a certification authority (CA) installed on a server named ALP-CA01.
Business Requirements
Growth
An additional branch office is planned in an extremely remote, mountainous location that does not have
traditional access to the Internet.
The remote branch office location will use a high-latency, low-bandwidth satellite connection to the Denver
and Vancouver offices.
The Los Angeles office will be expanded to include sales and billing staff. The Los Angeles location will not
contain IT staff.
File Management
Currently, each office has a dedicated file share that is hosted on a domain controller. The company plans to
implement a new file sharing capability to synchronize data between offices and to maximize performance
for locating files that are saved in a different branch office. Sales users in the Los Angeles office must also be
able to retrieve file data from each branch office.
Recovery time objective
The business requires that the data stored in AD DS must be recovered within an hour. This data includes
user accounts, computer accounts, groups, and other objects. Any customized attributes must also be
recovered. The current backup solution uses a tape drive, which requires a minimum of two hours between
notification and recovery.Office 365
Alpine Ski House purchased Office 365 Enterprise E3 licenses for all users in the organization.
Technical Requirements
Existing environment
Users in the Montreal office of Alpine Ski House report slow times to log on to their devices. An
administrator determines that users in the Montreal location occasionally authenticate to a domain
controller with an IP address of 172.16.0.10/24. All authentication requests must first be attempted in the
same location as the client device that is being authenticated.
Growth
The remote branch office must have a single domain controller named REMOTEDC01.us.aplineskihouse.com.
The replication between domains must either use best-effort or low-cost replication. After the expansion,
authentication must occur locally.
Any server placed in the Los Angeles office must not contain cached passwords.
File management
Where possible, the new file management solution must be centralized. If supported, the data must be
stored in a single location in each branch office.
Acquisition
After acquiring Margie’s Travel, all AD DS objects, including user account passwords, must be a migrated to
the alpineskihouse.com domain. Alpine Ski House plans to use the Active Directory Migration Tool (ADMT) to
complete the migration process.
The password complexity requirements for the margiestravel.com domain are unknown. Users should not be
forced to change their passwords after migrating their user accounts. Some computer objects will be
renamed during the migration.
Office 365
Alpine Ski House must use Microsoft Azure to facilitate directory synchronization (DirSync) with Office 365.
The DirSync utility must be installed on a virtual machine in Microsoft Azure.
###EndCaseStudy###
HOTSPOT
You need to design the acquisition strategy for Margie’s Travel.
What should you do? To answer, select the appropriate option for each action in the answer area.
I have a question for this answer: why can’t we install ADMT on ALP-DC02?
Anyone can help me?
Agree with answer.
Wei, see this article.
https://technet.microsoft.com/en-us/library/cc974435(v=ws.10).aspx
In short ADMT uses PES to replicate passwords over from source domain and it recommended that when using PES that it be installed on a writable DC in the target domain that supports 128 bit encryption.
ALP-DC01 was most likely chosen since typically PES is installed on the PDC to ensure no issues with replication. Also usually the PDC has the BuiltIn domain admin account on it, which is typically required for a successful migration.
Because ADMT does not check all settings of the target domain password policy, users need to explicitly set their password after migration unless the Password never expires or Smartcard is required for interactive logon flags are set.
still dont get it, there must be info missing – ALP-DC01 is not specified as the PDC – cannot see any difference between any of the ALP-DCxx servers – all seem equally valid
I did a whole lot of assuming on this one. I was assuming the Margie’s Travel was in Vancouver and that all the FSMO’s were still on the first DC in the domain. So ALP-DC01.
Incorrect all
ADMT is not PES.
Best practice to install ADMT on member server so my choice is ALP-CA01
second – user must change password at next login – because admt set it by default but in the case – Users should not be
forced to change their passwords after migrating their user accounts.
“User must change password at next logon” cannot be correct, as you want the opposite; you do NOT want users to have to change their password.
To migrate the passwords of all users, you require PES, which needs to be installed on a DC. You need to select the option “Password never expires”, as you can read here: https://technet.microsoft.com/en-us/library/cc974435(v=ws.10).aspx
But PES is not ADMT and this question is about ADMT. It is a best practice to install ADMT on a member server. If you would install it on a DC, you would have to follow these steps: https://support.microsoft.com/en-us/help/2266373/admt-3-2-installation-incomplete–mmc-console-error-cannot-open-databa
Also, if you believe that the correct answer is any of the DCs, then there is nothing in the text which would explain why you would specifically choose ALP-DC01 for example. Any DC would be correct and with tests like this, there is always only one correct answer.
So, long story short, the correct answer is: ALP-CA01 and Password never expires.