Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Active Directory: Advanced AD DS infrastructure management
Rating: 4.4 out of 5(83 ratings)
520 students

Active Directory: Advanced AD DS infrastructure management

Multiple domains and forests, DC in Azure, Complex Active Directory deployments, Domain and Forest Functional levels
Created byVitalii Shumylo
Last updated 7/2026
English

What you'll learn

  • Why implement multiple domains?
  • Why implement multiple forests?
  • Deploying a domain controller in Azure IaaS
  • Managing objects in complex AD DS deployments
  • AD DS domain functional levels
  • AD DS forest functional levels
  • Deploying new AD DS domains
  • Considerations for implementing complex AD DS environments
  • Upgrading a previous version of AD DS to Windows Server 2016
  • Migrating to Windows Server 2016 AD DS from a previous version
  • And more...

Course content

5 sections68 lectures8h 34m total length
  • Course Overview2:18

    Understand the components of advanced Active Directory Domain Services deployments, learn to deploy distributed AD DS across WANs, and configure AD trusts to support complex, multi-domain or multi-forest environments.

  • Section Overview5:57

    Explore the components of an AD DS environment, how domains and forests form security and administration boundaries, and reasons for multi-domain and multi-forest deployments, plus Azure IaaS considerations.

  • Overview of domain and forest boundaries in an AD DS structure8:01

    Explore domain and forest boundaries in an Active Directory environment, including replication, administration, group policy, auditing, and DNS boundaries that shape authentication and resource access.

  • Knowledge Check 1: Overview of domain and forest boundaries7:46

    Learn how domain and forest boundaries shape security, replication, and administration in Active Directory, including why forests are the true security boundary and how domain partitions replicate within a domain.

  • Knowledge Check 2: Overview of domain and forest boundaries9:36

    Explore how domain and forest boundaries shape group policy scope, DNS replication, and forest-wide versus domain-specific partitions, guiding multi-domain administration and policy deployment.

  • Why implement multiple domains?3:55

    Explore why some organizations deploy multiple AD DS domains to meet replication and bandwidth limits, DNS namespace needs, and resource domains or distributed administration, balancing autonomy with isolation.

  • Why implement multiple forests?3:40

    Organizations deploy multiple forests to meet security isolation, administrative isolation, and Pam bastion forest needs, addressing incompatible schema, multinational requirements, extra net security, perimeter network, and merger or divestiture considerations.

  • Knowledge Check 1: Why implement multiple domains and forests?9:04

    Assess when to deploy multiple domains within a forest versus separate forests in Active Directory. Balance administrative autonomy and isolation, network constraints, and DNS namespace preservation during mergers.

  • Knowledge Check 2: Why implement multiple domains and forests?9:46

    Explain how resource domain models isolate application administration for ERP systems, granting full domain admin rights without affecting regular user accounts, via a separate resource domain and cross-domain authentication.

  • Deploying a domain controller in Azure IaaS9:48
  • Knowledge Check 1: Deploying a domain controller in Azure IaaS8:47

    Learn to deploy Active Directory domain services in Azure IaaS within hybrid clouds, covering network topology, site replication, and data protection for domain controllers and disaster recovery.

  • Knowledge Check 2: Deploying a domain controller in Azure IaaS9:54

    Deploy domain controllers in Azure IaaS with VM generation ID protection, proper guest OS shutdown, static IPs, extended on-premises DNS, and data disk configurations with host caching set to none.

  • Managing objects in complex AD DS deployments6:54

    Automate user and group management across multi-forest AD DS deployments using workflows, self-service, and identity syncing with cloud services, powered by Microsoft Identity Manager 2016.

  • Knowledge Check 1: Managing objects in complex AD DS deployments6:53

    Automate user and group management in complex AD DS deployments using HR system data and identity synchronization to scale across forests and improve efficiency.

  • Knowledge Check 2: Managing objects in complex AD DS deployments5:52

    Learn how user self-service with multi-factor authentication for password resets and account unlocks reduces helpdesk workload and speeds access, and how multi-forest certificate management requires independent CA coordination across forests.

  • Knowledge Check 3: Managing objects in complex AD DS deployments7:03

    Coordinate identity synchronization across multiple authentication stores in hybrid AD DS deployments, and examine privileged access management with a bastion forest and time-bound access, MFA and HR data integration.

Requirements

  • Familiarity with general Windows and Microsoft server administration and technologies

Description

This course is aimed to IT Pros and is supposed to give the viewer the information they need to know to get started with Active Directory (AD DS) and its key concepts. The goal is to provide coverage of AD DS components of advanced AD DS deployments, how to deploy a distributed AD DS environment and· Configure AD DS trusts.

The course is targeted to help learning Active Directory and do your job more efficiently. 

After completing this course, you will be able to describe:

Why implement multiple domains?

Why implement multiple forests?

Deploying a domain controller in Azure IaaS

Managing objects in complex AD DS deployments

AD DS domain functional levels

AD DS forest functional levels

Deploying new AD DS domains

Demonstration: Installing a domain controller in a new domain in an existing forest

Considerations for implementing complex AD DS environments

Upgrading a previous version of AD DS to Windows Server 2016

Migrating to Windows Server 2016 AD DS from a previous version

Who this course is for:

  • Active Directory Administrators
  • System Administrators
  • IT Specialists
  • Automation Specialists
  • Power Users