
Deploy and manage Active Directory Domain Services in hybrid environments, integrating on-premises and cloud resources with Azure tools to streamline centralized administration and user access.
Explore the difference between logical and physical components in Active Directory, including partitions, schema, forests, domains, and physical assets like domain controllers, sites, and global catalogs.
Explore Active Directory objects including user accounts, service accounts, groups with security and distribution scopes, computer accounts, and organizational units, and learn how groups, GPOs, and delegation streamline administration.
Explore active directory domain services by examining forests, domains, and trees, the forest’s shared schema and global catalog, and how trusts and sites manage authentication and replication.
Explore active directory functional levels and flexible single master operations (FISMO) roles, including schema master, domain naming master, RID, PDC emulator, and infrastructure master, plus role transfer and seizure concepts.
Deploy on-premises domain controllers for a Windows Server Active Directory environment by using Server Manager or PowerShell to install and promote AD DS, configure DNS, and enable a global catalog.
Promote a domain controller in Azure from a web browser, leveraging cloud elasticity and remote management, while configuring static private IP addresses, DNS, and availability sets to ensure resilience.
Explain what a read-only domain controller is and how it enables local authentication and AD queries with unidirectional replication, password caching, and pre-staging or deployment options.
Pre-stage a read-only domain controller by creating the rodc account in active directory, delegating installation to a site user, and configuring dns and global catalog options.
Deploy a read-only domain controller (RODC) by installing the Active Directory domain services role, promoting the server to a domain controller in acilearningdemo.org, and configuring site and password replication group.
Configure a read-only domain controller by caching user passwords at the Rodsy, using the Allow Rodsy Password Replication Group and the Password Replication Policy to add or deny accounts.
Learn how to balance Active Directory performance by transferring FSMO roles—RID, PDC, Infrastructure, domain naming, and schema masters—using GUI tools, command line, and PowerShell, with transfer versus seize guidance.
Learn to use the NTDSUtil command-line tool to manage FSMO roles in an Active Directory environment, including seizing and transferring roles from non-operational domain controllers.
Explore transferring fsmo roles with PowerShell, viewing forest and domain level roles using get-adforest and get-addomain, selecting objects, and moving roles back and forth.
Examine forest and domain trusts, covering two-way transitive and one-way directional trusts, shortcut and realm trusts, and forest trusts, with DNS and conditional forwarders enabling cross-domain authentication and performance.
Demonstrates deploying a child domain in an active directory forest by promoting a domain controller for eastus.acilearningdemo.org, configuring DNS, and reviewing trusts with the parent acilearningdemo.org.
Configure conditional forwarders in DNS to enable cross-forest name resolution between two Active Directory domains. Learn DNS Manager setup on domain controllers and note replication limits with Windows Server 2003.
Configure an external trust between two Active Directory forests, enabling domain-wide authentication and seamless resource access across organizations while explaining two-way trust, DNS forwarding, and the trust wizard.
Configure a shortcut trust within Active Directory domains and trusts between two merged child domains to optimize authentication across them.
Explore how Active Directory sites optimize replication across physical locations, detailing intra-site and inter-site replication, bridgehead servers, site links with costs, DNS subnet mapping, and global catalog recommendations.
Configure Active Directory sites in AD DS using Active Directory sites and services, create sites (Atlanta, Miami) with default IP site links, and verify DNS records in the DNS manager.
Learn to configure Active Directory site links in Active Directory Sites and Services, create descriptive links like Chicago to Atlanta, and connect Chicago, LA, Dallas, Atlanta, and Miami.
Configure site link costs, replication intervals, and change schedules to optimize Active Directory replication across WAN links, prioritizing faster connections and controlled replication windows.
Configure subnets within Active Directory sites and services to map unique subnets to specific sites and optimize replication and site links.
Configure site link bridging to optimize the Active Directory infrastructure, creating named bridges (such as Miami special) and disabling the default that bridges all.
Understand how Active Directory replication propagates changes across domain controllers using a multi-master topology and the KCC, including intra-site and inter-site topologies.
Learn to manage Active Directory replication from the command line using the Rep Admin and DC Diag tools, including viewing replication partners and replication history.
Create and manage user accounts in Active Directory using ADUC or PowerShell. Configure password policies, account states, and group memberships to support centralized administration and least privilege access.
Explore how Active Directory groups manage permissions, with security and distribution types, and global, universal, and domain local scopes, including conversion and membership rules.
Explore creating and managing Active Directory groups with ADUC and PowerShell, assign members, and apply global, universal, and domain local scopes for permissions and GPOs in OUs.
Explore creating and managing active directory groups via PowerShell, cutting graphical user interface steps and using scripts to batch create, modify, and remove groups with descriptive cmdlets.
Create and manage organizational units in Active Directory using ADUC or PowerShell. Apply group policies at OU levels, distinguish OUs from groups, and delegate control for nested OUs.
Configure cross-forest trusts and manage users and groups with ADUC, adding global and domain local groups to grant cross-domain access to resources.
Explore group managed service accounts in Active Directory, use PowerShell to create a gMSA with a KDS root key, and rely on AD to rotate passwords for services.
Demonstrates creating and managing gMSAs with PowerShell, including adding a KDS root key, creating a servers group, provisioning a gMSA service account, setting DNS host name, and delegating permissions.
Learn how to join Windows Server to Active Directory domain by switching from a work group to acilearningdemo.org, using administrator credentials, restart and verify domain membership in server manager.
Learn how to join a Windows Server to Azure AD Domain Services using Azure credentials, and reset passwords for password sync before rebooting after the join.
Explore the differences between Active Directory, Azure AD DS, and Azure AD, including LDAP vs SAML and how Azure AD Connect integrates on-prem and cloud identities.
Deploy Azure Active Directory Domain Services in the Azure portal by configuring domain name, resource group, forest type, VNet, and one-way Azure AD synchronization, with security, tagging, and automation options.
Deploy a custom Azure AD domain in the Azure portal by adding the domain in Azure Active Directory, creating a registrar DNS TXT record, and verifying ownership amid propagation delays.
Explore how hybrid identities synchronize on-prem AD DS with Azure AD to support managed and federated authentication across cloud and on-premises environments.
Azure AD Connect synchronizes on-prem ADDS with Azure AD to enable hybrid identity, syncing user data every 30 minutes with full sync first and delta syncs thereafter.
Learn how ID fix checks and fixes on-prem AD DS identities to prevent sync errors with Azure AD Connect, spotting issues like spaces in names before pilot synchronization.
Explore implementing the Azure AD Connect tool to synchronize on-premises Active Directory with Azure AD in a hybrid environment, including a pilot synchronization and single sign-on.
Explore Azure AD Connect synchronization, including initial full sync and delta sync, and synchronization service manager statuses. Learn PowerShell commands to manage schedules, password hash sync, and log retention.
Configure Azure AD Connect post deployment from pilot to full synchronization for the acilearningdemo.org domain. Sync all OUs, enable single sign-on, and verify results in the portal.
Explore Azure AD Connect Cloud Sync, deploying agents on domain controllers to sync on-premises Active Directory data to Azure, with options for high availability and on-demand OU synchronization.
Install the Azure AD Connect cloud sync agent from the Azure portal to connect on-premises resources with Azure AD, then configure provisioning and a GMSA.
Install cloud sync agents, create an Azure AD Connect cloud sync configuration in the Azure portal, enable password hash sync, and configure scope, mappings, and test provisioning.
Manage an Azure AD DS domain using familiar Active Directory tools on a member server, after configuring access in the Azure portal's AAD DC administrators group.
Monitor on-premises identity with Azure AD Connect Health, deploy agents on domain controllers or AD FS, and view synchronized health metrics in the Azure AD Connect Health portal.
Explore how to authenticate across on-prem and cloud in a hybrid environment, comparing password hash synchronization, pass-through authentication, and federated authentication, plus seamless single sign-on and deployment considerations.
Explore how active directory domain services centralizes password management. Learn password policies: length, complexity, age, history, lockout; and how default domain policy and fine-grained policies apply.
Configure and manage passwords in Active Directory domain services by editing the default domain policy in Group Policy Management, covering password history, age, length, complexity, lockout, and Kerberos settings.
Explore how group policy objects in AD DS control user and computer settings via the policy manager, with site, domain, and OU links, LSDOU order, and loopback processing.
Discover how to implement group policy settings in AD DS with the group policy management tool, starter GPOs, and domain and OU links across a forest.
Explore how group policy preferences differ from policies in AD DS, and learn to configure network shares, mapped drives, printers, and power options that users can override.
Learn to implement group policy in Azure AD DS by installing the group policy management tool and reviewing the default GPOs, including the event log policy.
Deploy a Windows Admin Center gateway server to centrally manage servers and clients, configure security options, install updates and extensions, and access resources via a browser-based Azure-like interface.
Configure a Windows Admin Center gateway to bring target machines into its management scope, add devices via Active Directory search, and enable multi-user access for centralized monitoring and control.
Enable PowerShell remoting to run commands on remote Windows machines using the winrm service, enable-ps-remoting, and invoke-command, with Windows Admin Center simplifying remote management. Secure remoting with HTTPS where possible.
Configure PowerShell remoting across domain controllers with Windows Admin Center, verify WinRM is running, and remotely access DC2 to view computer details using the AD domain commandlet.
Explore CredSSP for second-hop remoting in PowerShell, enabling credential delegation from client to a server and onward to a third server, plus setup basics and security considerations.
Explore Kerberos delegation for second-hop remoting, comparing unconstrained, constrained, and resource-based methods, with resource-based delegation recommended for cross-domain and forest security via PowerShell.
Configure CredSSP and Kerberos delegation for PowerShell remoting across client, server, and resources, setting client and server roles and addressing security considerations.
Explore Just Enough Administration (JEA) for PowerShell remoting, defining roles and session configurations to enforce least privilege, enable logging, and limit users to approved commands.
discover how to enable just enough administration for PowerShell remoting by using group policy to log PowerShell activity, including module logging and script block logging, with transcriptions.
Shows how to create a JEA role capability file to implement just enough administration for PowerShell remoting, defining a role and granting access to restart-service, sc.exe, and whoami.
Learn to implement Just Enough Administration (GIA) by creating a PowerShell session configuration file. Define restricted remote server, set transcripts directory, and define user role definitions and role capabilities.
Register the JEA session configuration to constrain admin interfaces, defining a role capability and session file, then verify with a remote pssession and constrained command set.
Manage Windows servers across on-premises, Azure, and other clouds with Azure Arc. Deploy the connected machine agent, generate and run a PowerShell script, and register servers.
Deploy the Azure policy guest configuration to audit and monitor Windows machines, using a system assigned identity and the Azure Connected Machine Agent for per-machine or enterprise-wide deployment.
Learn to deploy Azure services using VM extensions on Azure VMs and Arc-connected servers, including OpenSSH for Windows, Azure Monitor Agent, and the custom script extension.
Discover how Azure Automation reduces admin burden with automation accounts, runbooks, and desired state configuration, plus update management, inventory, change tracking, and scheduled tasks across environments.
Connect Windows servers to Log Analytics by installing the Log Analytics agent, create a Log Analytics workspace, and enable Update Management for on-prem and Azure machines.
Manage updates across on-prem, Azure virtual machines, and other clouds with Azure update management for Windows and Linux, using inventory, periodic assessment, and scheduled maintenance windows.
Discover how to integrate Windows servers with Microsoft Defender for Cloud, leveraging CSPM and CWPP to secure multi-cloud environments with agents, policies, and remediation.
Learn how Azure desired state configuration combats configuration drift for IaaS VMs by using automation accounts, state configuration, and the gallery to enforce compliant service states and environment consistency.
Automate Azure VM tasks with Runbooks in Azure Automation using PowerShell Runbooks. Use Hybrid Worker Groups to offload processing and save costs.
Enable enhanced session mode in Hyper-V to access resources like printers, drives, and USB devices, support copy-paste, and adjust display settings for sessions via Hyper-V Manager or Windows Admin Center.
Explore three VM management approaches from PowerShell—PowerShell direct, PowerShell remoting, and SSH direct for Linux—using Hyper-V VM bus and WinRM, with practical demos on Windows and Linux VMs.
Master nested virtualization with Hyper-V by turning a virtual machine into a Hyper-V host, enabling virtualization extensions, and configuring live migrations and virtual switches for testing on-prem or Azure.
Configure virtual machine memory in Hyper-V Manager by setting minimum and maximum RAM and enabling dynamic memory with a memory buffer and memory weight.
Enable and manage Hyper-V integration services to optimize VM performance, using the Hyper-V manager and PowerShell to configure operating system shutdown, time sync, data exchange, heartbeat, backups, and guest services.
Explore discrete device assignment in Hyper-V to pass PCIe devices from host to a VM using PowerShell, MMIO settings, and location paths for efficient hardware use.
Create and organize virtual machines into VM collection and management collection resource groups using PowerShell, add members, and manage them as a single unit for easier administration.
Explore Hyper-V CPU groups to allocate virtual CPUs to specific VMs, create unique group IDs, and assign a VM to a single CPU group for optimized performance.
Configure hypervisor scheduling types in Hyper-V to control how virtual machines share processing across virtual CPUs, using classic, core, or root modes in Windows Server 2016 or later.
Learn to create and manage Hyper-V checkpoints, including standard and production types, their differencing avhdx disks, and when to revert or merge to preserve VM state and performance.
Enable high availability for virtual machines by configuring Hyper-V replication between domain-matched hosts, using Kerberos or certificates, and tuning frequency and recovery points.
Learn to create and manage VHD, VHDX, and VHDSet files in Hyper-V Manager, including fixed, dynamic, and differencing disks with inspection, editing, merging, and parent relationships.
Configure Hyper-V virtual network adapters to connect VMs via virtual switches, enabling VLAN, bandwidth management, IPsec offloading, and SR-IOV.
Configure NIC teaming in Hyper-V to bond two virtual NICs for higher bandwidth or fault tolerance. Select switch independent, static, or LACP modes, and use address hash for VM traffic.
Configure Hyper-V virtual switches in the switch manager by using external, internal, and private types; external connects VMs to LAN and Internet, internal links VMs to host, private isolates them.
Discover how to create Windows Server container images, understand container versus image concepts, and deploy containers with Docker and Kubernetes, including building, running, and minimizing the attack surface.
Explore managing Windows Server container images using Docker commands and PowerShell, including pulling, listing, and auditing image integrity, then monitor containers with Windows Admin Center extensions.
Learn how container networking assigns each container an IP address and configure it via PowerShell, ipconfig, and get-netadapter, plus the Azure container network interface plug-in for scalable networks.
Azure container instances, a managed service that runs containers in the cloud without virtual machines, with Kubernetes orchestration, automatic scaling, and easy in-portal creation using Quick Start images.
Learn how to manage data disks in Azure by creating and attaching a data disk to a virtual machine, selecting storage type, size, encryption, and host caching for optimal performance.
Resize an Azure VM via portal.azure.com using the size blade to adjust CPU and memory. Note that running status affects options, and costs change with upsize or downsize.
Configure azure vm continuous delivery using azure devops, deployment groups, and build pipelines to automate ci cd workflows with rolling, canary, or blue-green deployment strategies.
Learn to connect to Azure virtual machines using RDP, SSH, and Azure Bastion, with just-in-time access and browser-based, secure access considerations.
Explore configuring Azure virtual networks and subnets, connecting VMs with NICs, applying network security groups, and using VNet peering and firewalls to enable hub-and-spoke communication.
Explore how DNS integrates with Active Directory Domain Services to simplify replication and lookup. Understand DNS server types—Active Directory integrated, primary, secondary, and stub—and secure dynamic updates.
Learn to create and manage DNS zones and records, including forward and reverse lookups, SOA/NS, A, CNAME, SRV, and dynamic updates in DNS manager.
Configure dns forwarders and conditional forwarders to control who resolves names, optimizing lookups and delegating queries to trusted external dns servers.
Integrate Windows DNS with Azure DNS private zones by creating a private zone, linking a VNet, and enabling auto registration to publish VM records and private hostnames.
Learn how to implement dnssec to secure dns by using digital signatures, dns zone keys, key signing keys, zone signing keys, and distribute trust anchors to clients.
Learn to implement an on-premises dhcp server, create unique scopes per subnet, use dhcp relay for multi-subnet networks, and authorize servers with security groups to manage ip addresses.
Create and manage DHCP scopes, set address ranges with exclusions and lease duration, and configure scope options such as default gateway and DNS, including super scopes for multi-subnet environments.
Learn how DHCP reservations ensure devices, especially printers, always receive the same IP address by configuring reservations within the DHCP scope, differentiating from static IPs, and avoiding excluded addresses.
Explore how DHCP high availability uses the fellover feature to keep IP address distribution resilient, explaining scope-level failover, load balancing versus hot standby, and quick replication between partner servers.
Discover how IPAM scales DHCP and DNS management by automatic server discovery and IP address inventory, with GPO-based provisioning across sites and forests.
Resolve IP address issues in hybrid environments by ensuring unique on-prem and Azure subnets, planning with IPAM, and using Network Watcher tools to diagnose connectivity.
Learn how to deploy and manage the remote access role for Windows Server, including direct access and vpn options, IKEv2 features, port configuration, NAT, and routing.
Explore site-to-site VPNs, encrypted links between two offices, enabling multiple users to share private networks. Configure RRAS, IKE v2, and persistent connections for always-on, secure tunnels across sites.
implement and manage the network policy server to centralize authentication, authorization, and accounting using radius, vpn, and policies for secure hybrid networks.
Learn how to implement a web application proxy in a dmz, including ADFS integration and SSL certificates, and compare ADFS pre-authentication with SSO/MFA to pass-through authentication.
Learn to implement and manage an Azure network adapter to connect an on-prem server to an Azure virtual network using Windows Admin Center and the Azure Hybrid Center.
Extend on-prem networks into Azure with Azure Extended Network to migrate VMs while preserving original IP addresses and DNS, via paired appliances and site-to-site or express route.
Explore how to implement Azure Relay in a hybrid core infrastructure, using hybrid connections for cross-platform access, and compare with WCF Relays and Azure AD Proxy.
Discover how Azure Virtual WAN centralizes connectivity across sites with VPN gateways or ExpressRoute, enabling secure, bidirectional traffic and reducing dedicated lines.
Publish on-premises apps securely with Azure AD application proxy. It uses a cloud proxy service and an on-prem connector, enabling token-based auth and optional single sign-on, with simpler, cost-efficient setup.
Azure File Sync bridges on-prem file shares and Azure file shares, enabling cloud tiering, multi-site access, and seamless access via SMB, NFS, and FTPS.
Learn to create sync groups and cloud endpoints in Azure file sync, linking a storage account and file share to restrict access and synchronize content across a storage sync service.
Register on-prem servers for Azure file sync by creating a storage account and file share, enabling file sync, then installing and registering the Azure file sync agent in the portal.
Register the on-prem server, create a sync data folder, and add a server endpoint to the azure file sync group to enable on-prem to cloud syncing.
Enable cloud tiering in Azure File Sync to move infrequently accessed files to the cloud while keeping active files on-prem, improving performance and storage efficiency.
Explore Azure File Sync monitoring with the File Sync Service, using activity logs, alerts, and metrics to proactively detect issues and notify via email, SMS, push, or Azure mobile app.
Migrate from DFS to Azure File Sync by orchestrating a sync group, registering on-prem DFSR servers, and creating cloud endpoints, then retire DFSR and test topology.
Configure Windows Server file shares from Server Manager, selecting SMB or NFS shares on a dedicated volume, and apply access based enumeration and encryption to secure centralized storage.
Configure file screens with the File Server Resource Manager (FSRM) to control file types on file shares. Create templates, groups, and exceptions, and enable alerts or event logs for violations.
Configure quotas with file server resource manager using quota templates (hard or soft) applied to centralized shares and subfolders, with smtp email alerts at 85%, 95%, and 100%.
Explore branch cache in Windows Server to cache file data at branch sites, reducing WAN bandwidth using hosted or distributed cache modes, with group policy configuration.
Examine how the distributed file system provides a centralized namespace across multiple servers with transparent access. Learn dfsr replication using rdc and the difference between domain-based and standalone namespaces.
Learn to implement and configure distributed file system by installing dfs roles, creating a domain-based namespace, linking target folders, and setting up a multi purpose replication group with topology options.
Learn to configure disks and volumes on Windows Server using server manager, disk management, diskpart, and PowerShell; compare GPT vs MBR, NTFS vs REFS, allocate units, and drive letters.
Explore storage spaces in Windows Server, including storage pools and virtual disks, to enable software fault tolerance with mirror, parity, or simple layouts and tiered provisioning.
Explore storage replicas in Windows Server to replicate an entire volume, using synchronous or asynchronous replication between a master and a replica partner, and contrast with DFS for folder-level replication.
Discover how data deduplication in Windows Server reduces storage by using a single data copy with pointers. Enable the deduplication role on volumes, configure schedules, and monitor savings with PowerShell.
Enable RDMA on your network adapters to activate SMB Direct, improving throughput and lowering latency with reduced CPU utilization using Device Manager or PowerShell.
Discover how storage quality of service (QoS) in Hyper-V monitors and controls VM storage performance by setting minimum and maximum IOPS.
Explore file systems for Windows servers, including FAT32, exFAT, NTFS, and REFS; compare limitations, journaling, permissions, allocation units, and when to use each for reliable storage.
Prepare for the AZ-800 Administering Windows Server Hybrid Core Infrastructure exam with this comprehensive course. Covering key domains such as deploying and managing AD DS, managing hybrid Windows Servers, virtual machines, networking infrastructure, and storage services, this course is essential for IT professionals.
The AZ-800 Administering Windows Server Hybrid Core Infrastructure exam is a comprehensive certification focusing on various key domains essential for IT professionals. This course is structured to thoroughly prepare you for the exam by covering the following critical areas:
Deploying and Managing Active Directory Domain Services (AD DS):
Covers both on-premises and cloud environments.
Constitutes 30-35% of the exam content.
Managing Windows Servers and Workloads in a Hybrid Environment:
Focuses on managing Windows Servers in a hybrid setup.
Accounts for 10-15% of the exam content.
Managing Virtual Machines and Containers:
Implementing and managing virtual machines and containers.
Makes up 15-20% of the exam content.
Implementing and Managing Hybrid Networking Infrastructures:
Covers networking infrastructures both on-premises and in hybrid scenarios.
Also comprises 15-20% of the exam content.
Managing Storage and File Services:
Essential skills for managing storage and file services.
Another segment that makes up 15-20% of the exam.
This course is designed to be comprehensive and accessible, tailored to fit the busy lifestyles of IT professionals. It aims to enhance your IT expertise across these domains, ensuring you have the knowledge and skills necessary to achieve success in the AZ-800 exam.
Whether you're looking to deepen your understanding of Active Directory, Windows Server management, virtualization, networking, or storage services, this course provides the detailed coverage needed for certification preparation.