Your organization's security policy requires that service accounts used by IIS application pools have minimal privileges. Which AD account option best enforces this principle of least privilege?
-
A
Add service accounts to the Domain Admins group for full access
-
B
Use a Managed Service Account (MSA) scoped to a single server
-
C
Use a shared domain user account with a never-expiring password
-
D
Create service accounts in the Users container with default permissions