
Explore the AZ-801 course overview for configuring Windows Server hybrid advanced services across five modules. Learn prerequisites, exam format, 700/1000 passing score, two-hour time, and open-book policy with learn.microsoft.com documentation.
Configure and manage Defender for Servers within Defender for Cloud, compare plan 1 and plan 2 licensing, and onboard Windows Server across on-premises, AWS, or GCP with the onboarding script.
Configure exploit protection in Windows Defender for Endpoint on Windows Server, using system and program overrides for legacy apps. Deploy exported XML settings via group policy to domain machines.
Configure and manage Windows Defender application control to enforce zero-trust app execution. Deploy XML-based rules via Group Policy, with OS version caveats and hash-based updates.
Learn to configure Windows Defender Credential Guard and SmartScreen via Group Policy, isolating credentials and blocking untrusted apps, while understanding Protected Users and their Kerberos and NTLM protections.
Master OS security with group policies by applying GPOs through local, site, domain, and OU levels. Use GPMC and RSOP to verify policy scope in the Sysvall directory.
Configure traditional on-prem password policies with group policy objects—minimum length, history, age, and complexity—and use Azure Intra ID password protection and block lists in hybrid environments.
Learn to harden domain controllers in hybrid environments with remote desktop restrictions and WSUS patching. Also implement controlled internet access, audit policies, and GPO-based log retention.
Configure authentication policies and silos to protect privileged accounts, using protected users and Kerberos ticket lifetimes to limit lateral movement in Active Directory environments.
Configure account security in Active Directory by implementing password policies, account lockout, and group membership reviews, then enable time-based restrictions and multi-factor authentication.
Manage Active Directory built-in administrative groups with a focus on least privilege, nesting, and delegation. Audit group membership and permissions to support compliance and trace changes.
Deploy Defender for Identity sensors on every domain controller to monitor threats, report alerts to the Defender portal, and require Enterprise Mobility and Security or M365 E5 licensing.
Use Microsoft Sentinel to monitor on-prem servers and VMs by centralizing logs in a Log Analytics workspace, applying analytics rules, and enabling automation with playbooks and notebooks.
Discover how Defender for Cloud provides cloud security posture management, a secure score, data sovereignty guidance, and governance through policies, compliance standards (HIPAA, PCI, NIST), and workflows for remediation.
Manage Windows Defender Firewall with inbound and outbound rules, built-in and custom policies, and profile-specific settings; enable remote management, back up policies, and use flow logs for troubleshooting.
Implement domain isolation and connection security rules across isolation, boundary, and encryption zones, using firewall configurations, IPsec policy, and GPO-based deployment in the Woodgrove Bank scenario.
BitLocker drive encryption protects data at rest on operating system and data drives using a TPM and AES by default, with recovery options stored in Active Directory or Azure AD.
Explore how to enable Azure disk encryption for Windows and Linux VMs using Azure Key Vaults, BitLocker, and DMCrypt; manage keys, disk scope, and compliance considerations.
Learn to implement a Windows Server failover cluster by installing the feature, creating a two-node cluster, and running the validation wizard, then manage the virtual IP and storage.
discover how to implement a stretch cluster across regions for high availability and disaster recovery, with cross-region replication, two storage methods, and joining nodes to active directory domain services.
Configure failover clustering storage by creating a shared Azure disk, attaching it to cluster nodes, and adding it to the cluster, with LRS, ZRS, GRS, and optional encryption.
Configure failover clustering networking by separating client traffic from cluster communication with dedicated NICs, and manage load balancing and interface metrics via failover cluster manager and PowerShell.
Explore how to manage a cluster quorum using cloud witnesses or disk and file share witnesses, including configuring an Azure storage account and failover cluster settings for majority voting.
Learn how cluster aware updating (CAU) minimizes downtime during node updates by draining connections, placing nodes in maintenance mode, validating the cluster, and configuring CAU in the failover cluster manager.
Learn failover and recover a cluster node, including simulating failovers, managing roles and storage, and testing application responses. Understand quorum, node weights, and synchronous versus asynchronous replication options.
Upgrade the cluster by isolating, draining, and evicting a node to Windows Server 2022, while backing up configuration, validating health, avoiding prolonged compatibility mode, and having a rollback plan.
Explore how Windows Admin Center provides centralized, web-based management for failover clusters in Windows Server, covering cluster validation, network and storage settings, and seamless administration from one location.
Storage Spaces Direct pools local disks across 2–16 on-prem nodes to form a shared storage pool for failover and Hyper-V clusters, with tiering and mirrors or parity.
Configure a recovery services vault to back up Windows Server workloads in Azure, with flexible policies, retention up to 99 years, and locally redundant storage or geographically redundant storage.
Configure Azure Backup Server for application backups—SQL Server, Exchange, SharePoint, and VMware and Hyper-V backups—encryption in transit and at rest with Recovery Services Vault.
Migrate on-prem file shares to Azure file shares using Robocopy or Azure File Sync, enabling cloud tiering and encryption in transit and at rest.
Learn how to recover virtual machines using snapshots, including creating full or incremental disk snapshots, restoring OS or data disks, and exporting snapshot VHDs for quick, cost-aware point-in-time recovery.
Configure site recovery for on-prem Hyper-V VMs by deploying the recovery services agent, linking a Hyper-V site, and creating replication policies to Azure.
Explore disaster recovery for Azure VMs using Site Recovery and Recovery Services Vault, detailing network mapping, replication policy, protected items, and recovery plan setup.
Master on-prem Hyper-V live migrations and replication for seamless failover between hosts. Configure Kerberos delegation, firewall rules, and replication frequency to manage primary and extended replicas.
Transfer data and shares from on-prem servers to Azure using RoboCopy, REST API, and file shares, with Azure Data Box and storage account considerations.
Leverage storage migration service to centralize migrations of file shares from on-prem to on-prem or Azure file shares, using inventory, replication transfers, and a test cutover with retries.
Learn to migrate on-prem file shares to Azure File Shares using RoboCopy or Azure File Sync with cloud tiering, SMB/NFS support, and encryption options.
Deploy and configure the Azure Migrate appliance to discover on-prem virtual machines (Hyper-V or VMware), run dependency analyses, generate assessments, and estimate costs with right-sizing for Azure migrations.
Migrate on-prem workloads to Azure IaaS using Azure Migrate, with a Hyper-V host, Recovery Services Vault, and Site Recovery provider to replicate and perform a test migration.
Migrate Internet Information Services (IIS) on Windows servers by backing up configurations and certificates, then use Web Deploy to create migration packages and move apps while testing compatibility.
Learn how to migrate Hyper-V hosts, back up virtual machines, and upgrade VM versions and integration services, while handling hardware compatibility and live migration considerations.
Learn how to migrate Remote Desktop Services host servers, including in-place versus rolling upgrades, and follow the recommended upgrade order: connection broker, licensing, session hosts, and web or gateway servers.
Migrate DHCP by exporting the scope and options from the source server, importing them on the new server, then authorize the new server and deauthorize the old to prevent conflicts.
Learn to migrate print servers by exporting queues and drivers with the printer migration wizard, then importing on the new server and updating clients via group policy.
Explore migrating IIS workloads to Azure Web Apps with Azure Migrate and the App Service, from assessment to deployment, including domain and certificate setup and scaling options.
Explore migrating IIS workloads to containers in Azure, comparing app service with docker containers, Azure Container Apps, and AKS, while noting manual refactoring, testing, and external persistent storage.
Learn to migrate AD DS objects between forests. Establish forest trusts and DNS forwarders, preserve SID history, and use the Active Directory Migration Tool to move users, groups, and computers.
Explore upgrading an Active Directory forest by raising domain and forest functional levels with the Active Directory Domains and Trusts MMC, planning backups and noting upgrades are not reversible.
Explore Windows server performance monitoring with PerfMon, data collector sets, and alerts. Learn to baseline metrics, collect data over time, and export logs to Log Analytics or a SIEM.
Learn to monitor virtual machines with Windows Admin Center from the Azure portal, set up open port and RBAC prerequisites, and build performance dashboards using counters like processor and memory.
Explore System Insights in Windows Admin Center to analyze historical performance data and forecast future CPU, storage, and network trends, with configurable schedules and scriptable actions.
Centralize Windows event logs with the Event Viewer, covering application, security, and system logs and their levels. Configure a collector-initiated subscription to forward events to a central server for analysis.
Learn to deploy the Azure Monitor agent across Azure, Azure Arc-enabled, and on-prem servers using collection rules, collecting performance counters and event logs into a Log Analytics workspace for analytics.
Configure Azure Monitor metrics and alerts for virtual machines, create reusable action groups, and automate responses with email, logic apps, or scripts, while integrating with Power BI dashboards.
Learn to diagnose hybrid network connectivity between on-prem and Azure using Network Watcher tools, VPN troubleshooter, packet capture, connection monitor, and NSG flow logs for VPN and ExpressRoute issues.
Troubleshoot on-prem connectivity using ping, traceroute, and DNS tools to diagnose DNS resolution and network path issues. Explore how hosts files and firewall settings influence access between devices.
Diagnose azure deployment failures by evaluating quotas and policy restrictions, and resolve errors reported by the portal, CLI, PowerShell, or ARM templates.
Enable boot diagnostics with a storage account to access serial console logs for Azure VMs; use redeploy to a new host to diagnose boot failures and consider backups.
Learn to troubleshoot Azure disk encryption by inspecting key vault permissions, enabling the resource access checkbox, and verifying VM SKUs support for customer managed keys and disk encryption.
Troubleshoot vm connection issues by inspecting Azure VNet topology, using Network Watcher and topology views, and analyzing NSG flow logs and diagnostics to pinpoint blocking traffic between virtual machines.
Enable the on-prem AD recycle bin to retain deleted objects for 30 days, then restore users or OUs with PowerShell using restore-object, noting it complements backups rather than replacing them.
Explore directory services restore mode (dsrm) and how to perform authoritative and non-authoritative restores with ntDSutil, plus restoring ntDS.dit and sysVol and resetting the dsrm password.
Sysvol, the system volume for group policy and scripts, is replicated across domain controllers via dfs; learn connectivity checks, GPT.ini versioning, and dfsr diag troubleshooting.
Diagnose replication between domain controllers using repadmin and dcdiag, review replication topology through sites and site links, and validate DNS resolutions to ensure timely Active Directory updates.
Learn how to troubleshoot hybrid authentication using Cloud Sync in Intra ID, compare Cloud Sync and Connect Sync, and review logs, insights, and configurations in the Azure portal.
Troubleshoot on-premises Active Directory Domain Services by examining the five FISMO roles and using DC-Diag, Repadmin, NetDiag, DNS, and Sites and Services.
Prepare for the AZ-801- Configuring Windows Server Hybrid Advanced Services exam with this comprehensive course covering all the key domains
Master Windows Server management and security with this AZ-801 course. Learn to secure on-premises and hybrid infrastructures, manage failover clusters, integrate with Azure AD, and implement robust networking and storage solutions. Dive into data recovery, Hyper-V Replicas, and disaster recovery with Azure Site Recovery. Seamlessly migrate servers to Azure, upgrade Active Directory, and troubleshoot server issues. Perfect for both beginners and seasoned professionals.
Unlock the full potential of Windows Server management and security with our comprehensive AZ-801 course. This course takes you on a journey through securing your Windows on-premises and hybrid infrastructures, managing high availability with failover clusters, and integrating with Azure AD for unified identification. Learn to implement robust networking, secure storage solutions, and master data recovery tactics.
Throughout this course, you will delve into managing backups, using the Azure Site Recovery service for disaster recovery, and exploring Hyper-V Replicas for real-time VM protection. The course also covers the smooth migration of on-prem Windows servers to Azure, upgrading your Active Directory infrastructure, and moving web applications from IIS to Azure.
You'll gain hands-on strategies for diagnosing and resolving issues with Windows Server VMs in Azure, monitoring and troubleshooting server health, performance, and security. This course is designed to empower both seasoned professionals and newcomers with the skills needed to manage and secure Windows Server environments effectively.
Prepare yourself to master Windows Server management and security with the comprehensive AZ-801 course. Whether you're securing your Windows on-premises or hybrid infrastructures, managing high availability with failover clusters, or integrating with Azure AD for unified identification, this course covers it all.
This course empowers you with the knowledge and tools necessary to navigate the complexities of Windows Server management and security, ensuring you can confidently implement best practices and optimize performance in your organization's IT infrastructure.