How to Securely Enable Double-Hop PowerShell Remoting in AD?

Your network contains an on-premises Active Directory Domain Services (AD DS) domain. The domain contains a user named User1 and the servers shown in the following table. User1 is a member of the Protected Users security group. User1 performs the following actions: • From Server1, establishes a remote PowerShell session on Server2 • From the PowerShell session on Server2, attempts to access a resource on Backup1 The request to access the resource on Backup1 is denied. You need to ensure that User1 can access the resources on Backup1 by using the PowerShell session on Server2. The solution must follow the principle of least privilege and minimize administrative effort. What should you configure? - image

  1. Kerberos delegation (unconstrained)
  2. CredSSP
  3. PSSessionConfiguration by using RunAs
  4. resource-based Kerberos constrained delegation Source Reference Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the double-hop remoting problem and the impact of the Protected Users group, trapping candidates who choose CredSSP or unconstrained delegation despite their security flaws and compatibility issues.

Resolves the double-hop authentication challenge in PowerShell remoting by implementing Resource-Based Kerberos Constrained Delegation (RBCD), ensuring secure cross-server resource access while adhering to least privilege principles. Community consensus strongly favors RBCD over CredSSP or unconstrained delegation due to inherent security controls and Protected Users group constraints.

Candidates often select CredSSP (Option B) because it easily bypasses the double-hop limit, but it is explicitly disabled for members of the Protected Users group and poses significant credential theft risks, violating the least privilege requirement.

Community Discussion (3 comments)

stonwall12 👍 1 Selected: D
Answer: D, resource-based Kerberos constrained delegation This scenario requires double-hop authentication from Server1 to Server2 via PowerShell, then from Server2 to Backup1 for resource access. Resource-based Kerberos constrained delegation is the most appropriate solution as it follows the principle of least privilege by configuring delegation at the resource level (Backup1) and minimizes administrative effort without requiring domain admin rights. Reference: https://learn.microsoft.com/en-us/windows-server/security/kerberos/kerberos-constrained-delegation-overview
Krayzr 👍 1 Selected: D
Resource-based Kerberos constrained delegation Resource-based Kerberos constrained delegation allows you to specify which services can delegate to which resources, providing a more secure and controlled delegation compared to unconstrained delegation. This setup ensures that User1 can access the necessary resources without granting excessive permissions
Ksk08 👍 1
Answer: D

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Resource-based Kerberos constrained delegation (RBCD) is the correct solution because it securely allows Server2 to impersonate User1 when accessing Backup1, resolving the double-hop authentication failure. Unlike traditional constrained delegation, RBCD configures permissions directly on the target resource, specifying exactly which computer accounts are allowed to delegate to it. This approach strictly follows the principle of least privilege by limiting delegation scope to specific services. Additionally, RBCD is fully compatible with the Protected Users security group, which enforces modern authentication standards.

Why the Other Options Are Wrong

Unconstrained delegation forwards all service tickets to the delegating server, creating a severe security vulnerability that violates least privilege. CredSSP allows double-hop authentication but is explicitly blocked for users in the Protected Users group and transmits credentials insecurely over the network. PSSessionConfiguration with RunAs changes the local execution context but does not solve the underlying Kerberos delegation requirement across network boundaries.

Community Comment Notes

The community overwhelmingly agrees on Option D, emphasizing that RBCD provides granular control without exposing credentials or requiring broad administrative privileges (Comment 1). Commenters highlight that the Protected Users group restriction is a critical hint that eliminates CredSSP as a viable option (Comment 2). Multiple votes confirm that understanding the double-hop limitation alongside modern AD security policies is essential for passing this exam objective.

Official Reference

Exam Strategy

Focus on recognizing double-hop scenarios in PowerShell remoting questions and immediately filter out CredSSP when Protected Users or modern security policies are mentioned. Prioritize resource-based Kerberos constrained delegation for least-privilege, secure cross-server authentication.

Related Analysis

← Back to AZ-800 Study Guide