Question 1
A financial services firm, Proseware, Inc., is deploying Exchange Server 2013. The security team mandates that all Client Access servers must use Kerberos authentication for Outlook Anywhere clients to enhance security. During testing, you discover that clients are failing to connect and are repeatedly prompted for credentials. You have already configured the InternalClientAuthenticationMethod and ExternalClientAuthenticationMethod on the Outlook Anywhere virtual directory to Ntlm. Which PowerShell cmdlet must be run to enable Kerberos authentication and resolve the connection issue?
Answer and explanation
Correct answer: D
For Kerberos authentication to function correctly with a Client Access Server array or load-balanced CAS, the credentials must be shared among the servers. This is accomplished by using a shared alternate service account (ASA) credential. The ms-Exch-EPI-Token-Serialization extended right allows Exchange servers to read and write the service principal name (SPN) and encryption keys from the alternate service account in Active Directory. The other cmdlets configure different aspects of authentication but do not address the core requirement of sharing Kerberos credentials.