Which Users Can Establish Default PowerShell Remoting Sessions?
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains two servers named Server1 and Server2 and the users shown in the following table. Which users can establish a PowerShell remoting session from Server1 to Server2? - 
Community Votes
57% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests knowledge of default WinRM/PSRemoting security boundaries, with the common trap being confusion between the Remote Management Users group and actual PowerShell execution permissions.
PowerShell remoting defaults to restricting access exclusively to local Administrators on the target server. Candidates must distinguish between administrative groups that grant direct remoting access versus those intended for other management consoles.
Selecting Option E (All Users) by assuming Domain Admins and Remote Management Users automatically bypass the local Administrators requirement for PowerShell remoting.
Community Discussion (14 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
By default, Windows PowerShell remoting strictly limits session initiation to members of the local Administrators group on the destination computer. User3 holds the local Server2\Administrators role, granting immediate access. User1 belongs to the contoso\Administrators group; in standard AD deployments, Domain Admins inherit local Administrator privileges on member servers through default domain-wide policies, satisfying the remoting requirement.Why the Other Options Are Wrong
Options including User2 and User4 are incorrect because membership in the Remote Management Users group only permits management via the Server Manager console, not PowerShell remoting. Similarly, the WinRMRemoteWMIUsers_ group is specifically for WMI-based remote commands, not native PSRemoting. Without explicit configuration changes to WinRM ACLs or custom session configurations, non-Administrators cannot initiate sessions.Community Comment Notes
The community debate highlights a frequent point of confusion regarding Domain Admin privileges versus local group memberships. Highly upvoted comments correctly cite Microsoft documentation stating that default permissions require local Administrator status [4][5]. Several users initially chose E, overlooking that Remote Management Users does not equate to PowerShell execution rights. One discussion thread clarifies that while Domain Admins technically possess these rights, exam scenarios expect strict adherence to the documented default requirement for local Administrative group membership.Official Reference
Exam Strategy
Memorize the default permission model for core Windows services: PowerShell remoting requires local Administrators, while Remote Management Users is strictly for Server Manager. When an exam question asks about default behaviors without mentioning explicit WinRM configuration, always filter options through the local Administrators group lens first.