The enterprise standard is blunt: no local passwords on infrastructure devices. The new appliance currently knows only locally created administrator accounts. The directory team already has an operations group full of the people who will manage the box. What change brings the appliance into compliance?
Select an answer to reveal the explanation.
Short Explanation
If the rule is 'no local passwords', the fix has to be structural: point the appliance at the corporate directory, map the operations group to a role, and let logins and departures flow from there. You're deleting the local secret instead of babysitting it. That's how you pass the audit and still sleep at night.
Full Explanation
The compliant answer is directory integration: DD OS can authenticate administrative logins against Active Directory or LDAP, and directory groups can be mapped to appliance roles, so credentials, membership and removal all live in the corporate directory while the appliance simply honors the mapping at login. That meets 'no local passwords' at the root - there is no local secret to hold, audit or rotate. Password synchronization by scheduled job keeps two separate credential stores in step and reintroduces exactly the local password the standard forbids, with added drift risk whenever the sync fails or a directory password changes mid-cycle. SSH key login removes passwords from the command-line path but still means device-local identity management: there is no central join, move or leave process behind the keys, GUI administration is not addressed, and someone must still own every key on every device. 'Domain join once routing exists' mistakes network reachability for integration - directory authentication is explicit configuration (servers, search scope, group-to-role mapping) and nothing about credentials is inherited from being reachable. Exam caveat: even with directory authentication proven, one local administrator path stays alive for directory outages - see the break-glass practice elsewhere in this domain. Operational check: a directory user with no local account logs in successfully and receives exactly the role the group mapping promises.