
Explore administering Windows Server 2012 and prepare for the 70-411 certification exam in this virtual training presented by Mark Long.
Explore Windows Server 2012 essentials, history and features, installation basics, and core administration topics like Active Directory, DNS, file services, remote access, deployment services, group policy for 70-411 exam.
Trace the history of Windows Server from July 1992's NT 3.1 through NT 4 and Windows 2000, highlighting security, architecture, and the birth of Active Directory.
Trace the evolution of Windows Server history from Windows 2000 to 2012, highlighting secure by default, 64-bit transitions, and Active Directory updates such as Active Directory Domain Services.
Explore what's new in Windows Server 2012, including the Server Manager overhaul, remote installation of roles, PowerShell 3.0 upgrades, and the IPAM tool for IP address management.
identify deprecated tools in server 2012, including dc promo deprecated and redirected to server manager, storage manager snap-in replacement, snmp deprecation, and dsc promo to watch for.
Prepare for the 70-411 exam by gaining hands-on Windows Server 2012 experience, noting that objective sheets may not cover everything and a passing score demonstrates practical administration.
Understand how Windows Server 2012 works and fits together to tackle exam-style scenarios for the 70-411 administration exam. Get hands-on with a 180-day Microsoft trial (ISO or VHD) for practice.
Master the Windows Server 2012 hardware requirements: 64-bit only, minimum 1.4 GHz processor, recommended 2 GHz dual-core, minimum RAM 512 MB, disk space 32 GB, and standard versus datacenter limits.
Boot from installation media to install windows server 2012, choose gui or server core, enter product key and administrator password, and accept license terms for a custom or upgrade install.
Domain controllers run Windows Server 2012, store and manage Active Directory objects. They use multi-master replication and include a global catalog and key operations masters.
Learn how Kerberos delegation enables a service to impersonate a client across computers, and how to configure delegation on user and computer accounts in Active Directory.
Learn how service principal names map Kerberos identities to Active Directory accounts; use setspn to view, edit, and register SPNs with server class/host/port syntax.
Explore service accounts in Windows Server 2012, including local system and domain user accounts, their auditing and password challenges, and the rise of managed and virtual service accounts.
Learn to configure managed service accounts and virtual accounts in Windows Server 2008+ with automatic password management and SPN handling, including the four steps to deploy them.
Explore group managed service accounts (gMSA) and how they extend MSA functionality across multiple servers, with configuration on Windows Server 2012 and key distribution services prerequisites.
Enable universal group membership caching on domain controllers to locally cache universal group memberships, ensuring fast user logon across a multi-domain forest even when a global catalog is unavailable.
Manage operations masters across domain controllers in a multi-master forest, transferring or seizing roles such as schema master, domain naming master, relative identifier master, pdc emulator, and infrastructure master.
Seize an operations master role by using an elevated command prompt, connecting to the target server, and issuing the appropriate CS commands (naming, schema, infrastructure, PDC, or roadmaster).
Explore read-only domain controllers (RODC) and their use at remote sites with a global catalog option, plus Windows Server 2012 installation steps.
Learn how to clone domain controllers in Windows Server 2012 using Hyper-V, including prerequisites, generating clone configurations, excluding problematic apps, exporting/importing VMs, and joining cloned DCs to the domain.
Learn to install and use Windows Server Backup to back up Active Directory data via the system state in the graphical interface, including creating custom backups and schedules.
Explore active directory database optimization by understanding NTDS.dit, log and temp files, and when to use online versus offline defragmentation to shrink the database.
Set the domain user password policy in the Default Domain Policy using Group Policy Management Editor. Enforce password history, maximum age, minimum length, and complexity, and configure account lockout settings.
Create and apply password settings objects in the active directory administrative center to implement fine-grained password policies in Windows Server 2012 and override domain policies for security groups by precedence.
Explore how the account lockout policy in the default domain policy controls failed logins, including duration, threshold, and reset account lockout counter after, and learn to configure in group policy.
Explore DFS, the distributed file system in Windows Server 2012, which presents multiple server shares as a single namespace and uses RTC to replicate within a forest on NTFS.
Explore DFS terminology, including the DFS namespace and route, folder targets, and the role of referrals in connecting users to the closest target for fault tolerance and site-aware efficiency.
Discover how DFS replication targets create multiple copies of shared folders across servers to provide fault tolerance, automatic synchronization, and location-aware access.
Configure a DFS replication group to manage members, topology, and folders, with a primary authoritative source. Schedule replication with start and end times and bandwidth limits to prevent overload.
Use remote differential compression to replicate only changed file blocks, speeding DFS replication. It replaces the deprecated file replication service and can apply to other replication tasks.
Master dfs staging, a cache for new and changed files awaiting replication, with a default 4 GB quota. Size it by the 32 largest files in the replicated folder (16 for read-only) and set the staging quota near the folder size.
Configure DFS fault tolerance by using a cluster for standalone namespaces, or for domain-based DFS, place at least two route targets on different domain controllers to ensure failover.
Discover FSRM, a file server resource manager in Windows Server 2012, enabling classification-based file management, quota controls, file screening, and comprehensive storage reports.
Configure quotas using the File Server Resource Manager to set hard or soft limits on folders, apply quotas to paths or subfolders, and enable alerts via email and event log.
Compare FSRM quotas and NTFS quotas, focusing on folder or volume level management versus user-level limits. Learn when to use FSRM quotas, plus email alerts, custom reports, and event logging.
Learn how file screens in Windows Server 2012 enforce allowed file types with active and passive modes, on an NTFS volume, via file screen paths and five templates.
Configure SRM storage reports to generate incident, scheduled, or on-demand reports using ten standard reports, including duplicate files, screening audit, and files by group, owner, and property.
Explore the file server resource manager in server manager, configure smtp email notifications, set notification limits, and create file screening rules with exclusions and storage reports.
Create a high security item classification property in file server resource manager and auto-relocate high security files to the expired high security folder.
Configure group policy to restrict removable storage access, including USB drives and SD cards, and enable auditing for object access to log success or failure in the security event log.
learn how BitLocker provides drive encryption and data protection for lost or stolen computers, using the trusted platform module to verify boot integrity.
Learn how network unlock stores the startup master key on a server to unlock BitLocker remotely, enabling patches on unattended Windows 8 and Windows Server 2012 machines.
Explore how bitlocker certificates enable network unlock by encrypting the unlock key with public-private key encryption, and choose between self-signed or PKI certificates.
Explore four DNS zone types in Windows Server 2012: standard primary, standard secondary, Active Directory integrated, and stub zones, and understand how zone transfers and AD replication support redundancy.
Learn how to integrate a conditional forwarder into Active Directory, enabling centralized, replicated DNS forwarding to specific domains across all domain controllers and forests.
Explore zone delegation in DNS by creating a sales.abc.com zone and delegating authority to a new server, with NS, glue, and A/AAAA records.
Learn how zone transfers replicate DNS records from a primary to a secondary zone, including configuring transfers to specific servers via the name servers tab and the notify options.
Discover how zone scavenging cleans stale DNS records by aging and removing dynamically updated entries based on non-zero time stamps, with server and zone-level settings.
Explore aging and scavenging terms in Windows DNS, including the record time stamp, current server time, and no refresh and refresh intervals with default seven days.
Enable aging and scavenging on the DNS server and each zone by configuring default and zone-specific refresh intervals to scavenge stale resource records in Active Directory integrated zones.
Learn how DNS scavenging starts from server events, uses a seven-day no refresh interval, and deletes stale records from DNS and memory.
Enable secure dynamic updates to ensure authenticated computers only modify their own DNS records, with IP address and host name mappings managed by Active Directory integrated zones.
Explore the remote access role in Windows Server 2012, including direct access and RRAS, to securely connect from outside to the internal network.
Network address translation translates private ipv4 addresses to a single public ip at the network boundary, mapping private addresses and ports to the router's public ip for internet access.
Explore how nat components on the routing and remote access service translate ip addresses between private address ranges and public networks, and manage dhcp and dns for remote clients.
Learn how Windows Server 2012 remote access secures VPN connections with encryption and encapsulation over the internet, using two network cards and NPS for client health validation.
Enable and configure remote access on Windows Server 2012 by installing the remote access role, selecting VPN and direct access options, and using the wizard to deploy and manage settings.
Set remote dial-in settings per user via the dial-in tab in Active Directory Users and Computers. Configure network access permissions, caller ID, callback options, static IPs, and static routes.
Explore direct access in Windows Server 2012, an automatic background VPN that securely connects remote users, handles health checks, manages DNS, and splits internet traffic for seamless office-like access.
Learn DirectAccess requirements for Windows Server 2012, including a single NIC behind a firewall, IPv4 rules, IPv6 gateway, and Windows 7 or Windows 8 clients with Kerberos proxy authentication.
Direct access clients must be Windows 7 or Windows 8, with Windows 7 Enterprise/Ultimate or Windows 8 Enterprise, domain joined, and in a dedicated AD security group for GPO configuration.
Explore how split brain DNS affects direct access by using identical internal and external DNS domains, and configure the name resolution policy table to control DNS queries and exceptions.
Follow the Microsoft TechNet step-by-step guide to configure direct access on Windows Server 2012 Essentials, considering network and dns differences, practice in a test environment for success.
Discover network policy server basics, including its roles as a radius server, a radius proxy, and a nap server. Learn how it centralizes authentication, authorization, auditing, and health checks.
Use a radius server to centralize authentication, authorization, and accounting for dial-in, VPN, and wireless clients. It integrates with Active Directory and SQL Server for centralized logging and policy management.
Radius clients are network access servers that remote users connect to, not end-user machines. They forward access request messages to radius servers or proxies for authentication and authorization.
Learn how to create and apply radius templates to standardize server and client configurations, improve security, export/import templates across radius clients, and use templates for health policies and remediation groups.
Explore RADIUS accounting by enabling event logging, user authentication, and accounting requests to a file or a SQL Server database, with four options: SQL only, text only, parallel, and backup.
Configure connection request policies to route authentication and radius accounting across multiple RADIUS servers, using attribute groups—connection properties, day and time restrictions, gateway machine identity, radius client properties, and username.
Explore the six groups for connection request policies and craft detailed policies using framed protocol, service type, tunnel type, day/time restrictions, gateway, machine identity, radius client properties, and username.
Explore the network policy server interface and create a health policy template, then apply it to a policy. Learn to export and import templates for reuse across servers.
Explore how system health validators enforce network access protection by verifying client antivirus and antispyware, firewall status, and updates via the network policy server on Windows Server 2012.
Explore how NAP clients use system health agent to generate a statement of health, compare it with system health validator, and enforce access as restricted, time-limited, or full access.
Explore nap enforcement settings that grant full, limited, or restricted network access for compliant and noncompliant computers, including deferred enforcement and remediation servers with auto remediation.
Remediation server groups provide resources for non-compliant nap clients to remediate health requirements, offering updates, services, and step-by-step instructions to regain network access.
Explore NAP resources and configurations for Windows Server 2012, including design and deployment guides, to understand how NAP supports remote access, security, and administrative requirements.
Learn how Windows deployment services enable network-based deployment of Windows OS, image creation and updating, multicast deployments, and standalone server operation without Active Directory.
Explore the four WDS image types in Windows Server 2012: boot, installation, capture, and discover images, and learn how each enables network deployment and customization of Windows installations.
Update images without booting them using WDS directly or MDT, importing WSUS updates into the deployment work area and applying patches during OS deployment.
Learn how to install roles and features to offline virtual hard disks using Server Manager in Windows Server 2012, without attaching the disk, saving time.
Use data collector sets within performance monitor to establish baselines and monitor servers and networks over time, enabling preventative maintenance and early issue detection.
Explore data collector sets and performance monitor to capture real-time system data, configure memory and page fault counters, and generate reports from system performance data.
Configure event forwarding and collection across multiple remote computers by creating an event subscription and using the Windows Remote Management and Windows Event Collector services.
Master the basics of Windows server update services (wsus) in an Active Directory network. Learn how synchronization, upstream and downstream servers, and automatic update approvals control patch distribution.
Explore three WSUS deployment models for Windows Server Update Services: a single inside-firewall server, multiple servers with upstream and downstream roles, and a disconnected isolated network with offline updates.
Explore installation notes for WSUS on Windows Server 2012, covering required permissions, database options (Windows Internal Database or SQL Server 2008/2012 Express), and configuring computer groups with server- and client-side targeting via group policy.
Configure group policies to manage updates with a dedicated Windows Server Update Services GPO, link it to an Active Directory container, and customize automatic update settings in Windows Update.
Add the WSUS server role via server manager, configure update storage and database, and use the Windows Server Update Services administrative tool to manage synchronization, groups, and reports.
Explore group policy basics and how group policy objects configure security, desktop, and logon settings. Link these policies to sites, domains, and organizational units via the group policy management console.
Explore how group policy processing order governs GPO application from site to domain to OU, and how group policy preferences give users initial settings they can change.
Learn how item level targeting scopes group policy drive maps by user group membership, enabling different mappings within one GPO.
Learn how group policy inheritance works, how to block automatic inheritance on domains or OUs, and how enforced GPOs override blocks to ensure policy application on child containers.
Learn how security filtering with group policy objects confines GPO settings to specific users or groups by using the scope tab in domains, sites, or OUs.
Enable loopback processing to apply computer settings to every user logon, overriding user settings; use replace or merge mode to determine whether only computer settings or a merged result apply.
Identify slow link processing in group policy when network speed drops below 500 kbps, causing security and administrative templates to apply while scripts, software installs, and folder redirection are blocked.
Discover how the ADMX migrator converts legacy templates to the DMX format, splitting settings and locale files to boost GPO processing and enable central store management.
Back up and restore group policy objects (GPOs) using the Group Policy Management Console, store a master copy in a dedicated folder, and perform easy restores when needed.
Reset default group policy objects in Windows Server 2012 by copying GPOs, backing up defaults, or using the DCGPO fix utility to restore the default domain policy.
Microsoft's server operating systems have powered business for over 20 years. In the beginning, it was all about connectivity in the local area network, now it's all about connectivity in the cloud. Microsoft calls Server 2012 "The Cloud OS" and is branding it as being "built from the cloud up." Their goal with this product is to deliver the power of many servers with the simplicity of one. Achieving a Microsoft Certification on this product is an excellent career move. In this VTC course, Mark Long brings 20+ years of experience with Microsoft technologies along to help you understand the features and functionalities of Windows Server 2012 from the standpoint of preparing for certification exam 70-411 Administering Microsoft Windows Server 2012. This title is a self-paced software training course delivered via pre-recorded video. We do not provide additional information outside of the posted content.