###BeginCaseStudy###
Topic 1, Fabrikam, Inc
OverView
Fabrikam, inc is a financial services organization.
Fabrikam recently purchased another financial services organization named Contoso, Ltd.
Fabrikam has 2000 users. Contoso has 500 users.
Windows 10 and office 2016 are deployed to all computers.
Physical Location:
Fabrikam has an office in the United States. Contoso has an office in the United Kingdom.
The offices connect to each other by using a WAN link. Each office also connects directly to the internet.
Existing Environment:
Active Directory:
The network Fabrikam contains an Active Directory forest.
The Active Directory environment of Contoso was migrated to the Active Directory forest of Fabrikam.
The forest contains three domains named fabrikam.com , contractor.fabrikam.com, and contoso.com.
All domain controllers run Windows Server 2008 R2.
All contractors outsourced by fabrikam use the user principal name (UPN) suffix of
contractor.fabrikam.com. If fabrikam hires the contractor as a permanenet employee, the UPN suffix
changes to fabrikam.com.
Network
The network has the following configurations:
* External IP address for the United States office: 192.168.1.100
* External IP address for the United Kingdom office: 192.168.2.100
* Internal IP address range for the United States office: 10.0.1.0/24
* Internal IP address range for the United Kingdom office : 10.0.2.0/24Active Directory Federation Services (ADFS)
AD FS and web Application Proxies are deployed to support an app for the sales department. The app is
accessed from the Microsoft Azure Portal.
Office 365 Tenant
You have an Office 365 subscription that has the following configurations:
* Organization name: Fabrikam Financial Services.
* Vanity domain: Fabrikamfinancialservices.onmicrosoft.com
* Microsoft SharePoint domain: Fabrikamfinancialservices .sharepoint.com
* Additional domain added to the subscription: Contoso.com and fabrikam.com
Requirements:
Planned Changes:
* Deploy Azure AD connect.
* Move mailboxes from Microsoft Exchange 2016 to Exchange Online.
* Deploy Azure multi-factor authentication for devices that connect from untrusted networks only.
* Customize the AD FS sign-in webpage to include the Fabrikam logo, a helpdesk phone number, and a
sign=in description.
* Once all of the Fabrikam users are replicated to Azure Active Directory (Azure AD), assign an E3 license
to all of the users in the United States office.
Technical Requirements:
Contoso identifies the following technical requirements:
* When a device connects from an untrusted network to https://outlook.office.com, ensure that users
must type a verification code generated from a mobile app.
* Ensure that all users can access office 365 services from a web browser by using either a UPN or their
primary SMTP email address.
* After Azure AD connect is deployed, change the UPN suffix if all the users in the Contoso sales
department to fabrikam.com.
* Ensure that administrator are notified when the health information of Exchange Online changes.
* User Office 365 reports to review previous tasks performed in Office 365.
###EndCaseStudy###
Note: This question is part of a series of questions that present the sonic scenario. Each question in the
series contains a unique solution. Determine whether the solution meets the stated goals.
You need to configure the Office 365 subscription 1o ensure that Active Directory users on conned to
Office 365 resources by using single sign-on (SSO).
Solution: You run Convert-MsolFederatedUser for all users.
Does this meet the goal?
A.
Yes
B.
No
B. No
Convert-MsolFederatedUser
Updates a user in a domain that was recently converted from single sign-on
Convert-MsolDomainToFederated
Converts the domain from using standard authentication to using single sign-on
Convert-MsolDomainToStandard
Converts the domain from using single sign-on to using standard authentication
PS C:\> Convert-MsolFederatedUser -UserPrincipalName “[email protected]”
This command converts a federated user into a standard user.