How to Securely Enable Double-Hop PowerShell Remoting in AD?
Your network contains an on-premises Active Directory Domain Services (AD DS) domain. The domain contains a user named User1 and the servers shown in the following table. User1 is a member of the Protected Users security group. User1 performs the following actions: • From Server1, establishes a remote PowerShell session on Server2 • From the PowerShell session on Server2, attempts to access a resource on Backup1 The request to access the resource on Backup1 is denied. You need to ensure that User1 can access the resources on Backup1 by using the PowerShell session on Server2. The solution must follow the principle of least privilege and minimize administrative effort. What should you configure? - 
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the double-hop remoting problem and the impact of the Protected Users group, trapping candidates who choose CredSSP or unconstrained delegation despite their security flaws and compatibility issues.
Resolves the double-hop authentication challenge in PowerShell remoting by implementing Resource-Based Kerberos Constrained Delegation (RBCD), ensuring secure cross-server resource access while adhering to least privilege principles. Community consensus strongly favors RBCD over CredSSP or unconstrained delegation due to inherent security controls and Protected Users group constraints.
Candidates often select CredSSP (Option B) because it easily bypasses the double-hop limit, but it is explicitly disabled for members of the Protected Users group and poses significant credential theft risks, violating the least privilege requirement.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Resource-based Kerberos constrained delegation (RBCD) is the correct solution because it securely allows Server2 to impersonate User1 when accessing Backup1, resolving the double-hop authentication failure. Unlike traditional constrained delegation, RBCD configures permissions directly on the target resource, specifying exactly which computer accounts are allowed to delegate to it. This approach strictly follows the principle of least privilege by limiting delegation scope to specific services. Additionally, RBCD is fully compatible with the Protected Users security group, which enforces modern authentication standards.Why the Other Options Are Wrong
Unconstrained delegation forwards all service tickets to the delegating server, creating a severe security vulnerability that violates least privilege. CredSSP allows double-hop authentication but is explicitly blocked for users in the Protected Users group and transmits credentials insecurely over the network. PSSessionConfiguration with RunAs changes the local execution context but does not solve the underlying Kerberos delegation requirement across network boundaries.Community Comment Notes
The community overwhelmingly agrees on Option D, emphasizing that RBCD provides granular control without exposing credentials or requiring broad administrative privileges (Comment 1). Commenters highlight that the Protected Users group restriction is a critical hint that eliminates CredSSP as a viable option (Comment 2). Multiple votes confirm that understanding the double-hop limitation alongside modern AD security policies is essential for passing this exam objective.Official Reference
- https://learn.microsoft.com/en-us/powershell/scripting/learn/remoting/ps-remoting-second-hop
- https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/understand-security-groups#protected-users-group
- https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/delegate-access-resource-based-constrained-delegation
Exam Strategy
Focus on recognizing double-hop scenarios in PowerShell remoting questions and immediately filter out CredSSP when Protected Users or modern security policies are mentioned. Prioritize resource-based Kerberos constrained delegation for least-privilege, secure cross-server authentication.