
Introduce the fundamentals of administering Windows Server 2012 for the exam 70-411, outlining the scope and objectives of the course.
Join this instructor-led tour of planning and maintaining an active directory and Windows Server 2012 infrastructure with insights from a veteran Microsoft expert.
Explore Windows Server 2012 administration, from efficient server deployment with WDS and image management to ongoing monitoring, DNS, DFS, and Active Directory governance through Group Policy.
Learn to deploy servers and workstations with Windows Deployment Services, create and manage boot and install images, and configure server and client prerequisites for image-based deployments.
WDS server role services enable network deployment of workstation images via transport server and deployment server roles; transport handles image transfer and multicast, while deployment installs OS images remotely.
Learn to set up Windows deployment services for network-based operating system installation, plan ntfs storage for deployment images, and install the role via Server Manager or PowerShell.
Compare functionality across Windows Server 2008/2008 R2 and 2012/2012 R2, noting newer images, removal of older OS, and support for WIM, VHD(VHDX), unattended installs, and multicast or boot deployments.
Explore Windows deployment enhancements in Server 2012, including multicast support for install and boot images, no local install.wim copies, EFI boot image support, IPv6 multicast, and PowerShell scripting.
Manage driver provisioning and per-manufacturer driver groups to enable extensibility, enable custom Pixi providers, and support EFI-based network boot and DHCP referrals for Itanium 64-bit deployments from 2008 to 2012.
Leverage PowerShell cmdlets for Windows deployment services to script client actions, enable packages, and create boot images, using familiar MMC and WDSUTIL workflows.
Identify essential prerequisites for installing WDS deployment and transport server, including Active Directory, DHCP with an IP address, DNS, NTFS volumes, and membership in the local Administrators group.
Install the WDS deployment and transport server in standalone mode without active directory. Ensure DHC, Pixi boot to grab an IP address, and DNS with an NTFS image store.
Install and configure Windows Deployment Services through the server manager wizard, meeting prerequisites like Active Directory, DHCP, DNS, and NTFS, and choose deployment server or transport server.
Install Windows features with PowerShell, including management tools, run as administrator, and enable remote management to install the WTS deployment and transport server modules.
Demonstrates installing a Windows feature with PowerShell, using WDSUTIL to manage Windows Deployment Services, add images and image groups for file servers, and navigate help for command syntax.
Configure the wds role using the configuration wizard or wds ui, add a boot image from the server 2012 sources, and ensure clients are PXE-enabled.
Learn about four image types in Windows deployment: pre-installation, capture, install, and discover images used to boot setup, capture a customized OS, deploy standard OS, or enable non-pxe installations.
Configure pixi boot for unknown clients and deploy a boot image first using boot.wim. Add install images with wdsu in verbose mode, specifying the image file and type.
Configure WDS by adding boot and install images from the Windows source, manage boot settings, and deploy Windows using the preinstallation environment and pixi boot files.
Learn to configure Windows Deployment Services install images and image groups, set security and permissions, define client naming policies, and manage boot and unattended deployment options.
Verify clients can boot via pixie boot, meet Pixi operating system ram requirements of at least 512 megabytes, and ensure a local user account on the WDF server enables installation.
Learn client steps to install images: configure pixi boot in the bios, boot with F12, select the image, set locale and keyboard, and connect to the WTS server to install.
Configure the boot menu order for boot images and install images using the WDS MMC snap-in, setting the priority so the lowest value displays first.
Create a capture image by right-clicking a boot image, naming and saving it to a location, and adding the image to the WTS server with a clear description.
Ensure you have adequate disk space and are a member of the local Administrators group NWTS to create custom install images.
Create a reference computer by installing the operating system, updates, apps, and drivers, then run sysprep to generalize. Capture the boot image with the capture wizard and upload to WTS.
Learn to create and use a Discover image to install operating system on non Pixi enabled computers, save the image to CD, DVD, or USB, and deploy from WTS server.
Go to WTS, expand boot images, right-click the image for a discover image, then choose create discover image. Name it, describe it, and browse to the storage location.
Install the Windows assessment and deployment kit and use deployment and imaging tools to create media for the discover image, logging in as a local administrator to run command prompt.
Create a discover image within Windows deployment services to support clients that cannot boot to the WDS server, then copy it to media such as a CD or USB drive.
Learn unattended installations for Windows Server 2012 using two separate files for legacy and modern systems, stored on the WTS server to automate UI prompts with admin and domain credentials.
Create your unattended installation file, copy it to a subdirectory of the remote install folder, and enable unattended installation by selecting properties and browsing to your file.
Explore a sample unattended file for Windows deployment services, detailing credentials, image selection, and installation targets. Learn how disk and partition IDs map to drives, including the C: drive conventions.
Enable multicast transmission on an image and choose the distribution type (auto cast or scheduled cast). Set a queue threshold to multicast to all queued clients at once.
Choose one of the boxes in multicast transmissions; if you don't, it will only start manually, and you must push it out to this client.
demonstrates creating and configuring multicast transmissions for Windows Server 2012 images, assigning image groups, and choosing auto cast or scheduled cast to control deployment timing.
Demonstrates adding a second install image and an additional boot image in Windows Deployment Services, showing how to manage multiple images, rename them, disable unused ones, and plan multicast transmissions.
Add driver packages to boot images via the WTS console or WDSUtil command line. Specify the image, architecture, and driver package name or ID when applying the package.
Configure and monitor DNS servers; manage DHCP, create and update deployment images with drivers and patches, customize boot menus, and pre-stage client computers to auto-join the domain.
Explore the four phases of automated deployments, including the pixi boot policy, default boot image selection, and the Windows setup flow shown by WTS screens.
Identify tools to create and service images, including the WTS snap-in, Server Manager and tools, WDS, Windows EDK, and netsh for managing image and answer files.
Explore Windows deployment services, building boot and install images, plus custom images and menus, and using the deployment kit to update offline and manage repeated deployments hands-off.
Learn to manage servers and workstations from a base install, implement WSUS for automated updates and bandwidth efficiency, and monitor baselines to proactively fix issues and plan upgrades.
Learn how Windows Server Update Services centralizes updates and patch management, reduces bandwidth by approving only approved updates for clients, and serves updates from a central server.
Configure update management with patch management, group policies, and client side targeting for servers and workstations. Set synchronization, approve or remove updates, and manage deployments by WSUS groups.
Identify prerequisites for installing wsus 3.0 sp2 on Windows Server 2012, including compatible operating system versions, .net framework 3.0, report viewer redistributable, and a sql or Windows internal database store.
Organize computers into groups like workstations, servers, departments, and a test group to manage and test wsus updates before release, and assign machines to groups via registry or gpo.
Learn to sync and approve updates in WSUS, deploy them on client schedules through group policy, and rigorously test updates to prevent system-wide issues.
Master the WSUS management process by identifying required products, configuring automatic approvals, scheduling updates, and organizing phased deployments with test groups, reviews, and ongoing optimization.
Configure clients to use a central WSUS server via group policy, set update frequency and restart behavior, organize computers with Active Directory organizational units, and force detection with wuauclt /detect.
Learn to configure DHCP scopes and super scopes in Windows Server 2012, including authorizing the DHCP server, defining IPv4 ranges, subnet masks, DNS settings, and scope activation.
Learn to manage WSUS with PowerShell, performing tasks like adding computers, approving or denying updates, querying classifications and products, cleaning up old updates, and configuring synchronization schedules.
Install and configure the WSUS role, set up the database and data store, complete post-deployment configuration, and start synchronization with Microsoft Update.
Demonstrate how to approve updates in WSUS, manage approval status and group targeting, configure downloads and synchronization, and review update history and reports.
Monitor servers to reveal how hardware and software respond and detect issues before they escalate. Track disk space and misbehaving applications to predict future needs and plan maintenance.
Identify and use a suite of server monitoring tools, including PowerShell commands, Event Viewer, log files, event subscriptions, and network monitoring to supervise servers and virtual machines.
Explore essential Windows Server tools such as Task Manager, Performance Monitor, Resource Monitor, and Event Viewer to monitor real-time data, end hung processes, and diagnose disk, memory, and network issues.
Explore task manager and resource monitor to monitor real-time performance, manage processes and services, analyze memory and CPU usage, and troubleshoot server performance during WSUS synchronization.
watch a demo of performance monitor and add counters for processor, memory, network adapter, and disk. save the data as a report to establish a baseline.
Use performance monitor counters to diagnose Windows server performance. Focus on processor time, processor queue length, pages per second, memory counters, disk counters, and network counters.
Use task manager to view real-time data and end hung processes, and rely on performance monitor, resource monitor, and event viewer to diagnose disk, memory, and network issues.
Explore how virtual machines run on Hyper-V and how to monitor guest virtual machines and the host using host-level performance monitoring to view per-virtual-machine statistics.
Learn to monitor virtual machines with Hyper-V by enabling VM resource metering, collect statistics such as average megahertz and RAM, monitor networking, and reset or disable metering in PowerShell.
Monitor event logs to reveal the real story of network activity and detect unsuccessful logons; create custom views to filter events and use subscriptions to forward logs to a collector.
Explore event viewer to filter and analyze Windows Server logs, including application, security, and system logs; learn to filter by source, event IDs, users, and create custom views.
Configure event forwarding by enabling subscriptions, set up the Windows Event Collector service, and use Event Viewer subscriptions to collect logs via remote management.
Monitor network infrastructure with Performance Monitor to track DNS queries, DHCP traffic, and packet flows; diagnose lost packets, denials, and server placement for optimal performance.
Explore how to monitor network infrastructure with packet-level monitoring and performance counters, focusing on DHCP, DNS, zone transfers, dynamic updates, and related services to diagnose issues.
Examine update management to optimize bandwidth and apply decisions for Windows Server 2012, then establish a baseline and configure monitoring with data collector sets and alerts to fine-tune performance.
Analyze file and print services to control sharing, enforce file types, and prevent unauthorized data through NTFS security, disk encryption, and audit trails.
Configure the file services resource manager (FSRM) to install and manage quotas and soft quotas, monitor thresholds, use file screens to block nonwork files, and generate classification-based reports.
Install file system resource manager, audit server data, auto-create rules; enforce hard quotas with soft limits, run reports on user shares and redirected folders, plan quotas and file screens.
Install fsrm by ensuring ntfs volumes and install it as a rule service within the storage services role, which contains an independent rule service.
Learn how to install the file server resource manager from roles and features, then configure notifications, quotas, reports, classifications, and auditing options to manage file services.
Manage file server resource manager with PowerShell 3.0 using the file server resource manager module and its cmdlets, and use Get-Command to access module-specific commands.
Master managing the file server resource manager with PowerShell 3.0 by using an elevated prompt, exploring commands with Get-Command, filtering to FSRM, and learning via Get-Help.
Explore legacy FSRM commands on a Windows Server 2012 file server, demonstrate running an administrator cmd prompt, and compare deprecated quota, file screen, and store report tools with PowerShell alternatives.
Remotely manage file services by ensuring both servers run Server 2008 R2 or newer with SRM, enable bidirectional traffic through firewalls, and use local administrator rights with remote PowerShell.
Master quota management by applying hard and soft storage limits to folders and users, with email alerts, event logging, and scripts that enforce or notify when limits are reached.
Learn how to manage quotas with templates, set hard and soft limits, and monitor usage using thresholds, notifications, and reports in Windows Server 2012.
Explore quota management in Windows Server 2012 by creating and testing quotas with fsutil, observing how folder hierarchy and redirected folders affect space limits and policy enforcement.
Use file screen management to block unauthorized files and reduce disk space and backup time. Create screens by file groups (audio, video, documents) and apply hard or soft limits.
Explore file screen templates to create screens, define file groups, choose two screening types within the same template, and manage notifications.
Explore file groups as sets of name patterns, including default groups, and tailor include and exclude patterns using extensions like mp*, mpp, to manage files in screens, templates, and reports.
Demonstrates creating and using file groups and file screens to block or monitor file types, configure templates, and notify users with email, event logs, and reports.
Review storage reports to plan quotas, identify large or unused files, and decide what to move or delete; filter by owner or file group, and run scheduled or on-demand reports.
Explore storage report types to identify duplicate and large files, categorize by owner and folders, and optimize placement to reduce network traffic while monitoring quota usage.
Configure report parameters and manage report locations, including the C-Drive store reports folder via the report locations tab. Schedule reports on demand or together to optimize indexing and processing power.
Schedule and manage storage reports to monitor quota usage, identify large and duplicate files, and audit by owner, with email delivery and weekly scheduling.
Create the storage report in the storage management reports node, then schedule a new report task with parameters, volumes, folders, a repository, and optional email delivery.
Define classification properties from file name or contents, tag payroll or confidential via on-demand or scheduled rules, and store classifications as NTFS alternate data streams for retention.
Explore classification properties as strings or patterns and learn how to classify data with yes/no flags, date/time stamps, and types like numbers, multiple choice, ordered lists, and strings.
Learn how classification property conflicts are resolved in Windows Server 2012, prioritizing yes over no and flagging timestamp errors. It covers numbers, strings, multiple-choice merges, ordered-list precedence, and multi-string sets.
Enable and configure classification rule properties by selecting scope and volume, choosing a folder or content classifier, and assigning properties with additional classifications to build robust rules.
Explore classification examples by identifying file name patterns such as log files and social security numbers to tag data as confidential, and apply case sensitivity to digit strings.
Automate file management by scheduling tasks that classify files by location and properties, delete old files, archive after five years, back up confidential files, and notify owners.
Explore new and changed functionality in Windows Server 2012 R2, including reevaluation and clearing of outdated classification property values, and configuring maximum files per search report and storage reports parameters.
Explore how dfs enables folder sharing and automatic failover to the nearest replica while efficiently managing disk space by remapping the unc path to a server with more space.
Explore dfs role services by examining name spaces, replication targets, replication scheduling, remote differential compression, staging, and fault tolerance, and compare standalone versus active directory namespaces.
Explore DFS role services, including creating a single DFS namespace, multi-master replication across servers, bandwidth throttling, and remote differential compression to optimize network performance.
Explore domain-based namespaces for high availability and hidden namespaces using the domain name, compare Windows 2000 and 2008 modes with 5,000 and 50,000 targets, and note access-based enumeration.
Examine standalone namespaces as an alternative when Active Directory isn’t suitable, supporting up to 50,000 folders with targets for DNS name spaces and enabling fault tolerance in failover clusters.
Install and configure DFS in Server Manager, create a namespace, set permissions, and plan replication and namespace type to optimize file sharing across a network.
Enable access-based enumeration in the DFS namespace, add and move folder targets across servers, and control referrals and permissions to reveal only authorized shares.
Explore DFS replication on Windows Server 2012 R2, using WMI for management, enable initial sync by cloning, apply remote differential compression, and tune staging sizes while restoring from conflicts.
Secure files beyond NTFS with file and disk encryption, ensuring only the user with the private key can decrypt; implement recovery, network unlock, and certificate management.
Explain how the Encrypting File System relies on NTFS permissions to encrypt and decrypt files on NTFS volumes, and how to disable it via Group Policy.
Understand how efs works with network shares and dfs, secure client data with encryption on laptops, and manage certificates with trusted delegation for file servers hosting shares.
Learn how encryption keys protect files: symmetric keys encrypt data, while public and private keys safeguard and decrypt, with guidance on backing up keys and helping users.
Explore how EFS file encryption combines a file encryption key with the user's public key to encrypt the EK and header, requiring the matching private key to unlock the file.
Explains the EFS file decryption process, where the file's symmetric key and EFS header are decrypted with private and public keys; users can open or remove encryption.
Understand how EFS recovery ties private keys to user certificates and enables decryption. Set up recovery agents across the forest root and back up the certificates.
Add new recovery agents via group policy for future encrypted files and back up all agents with their private keys and exported certificates in a secure, documented location.
See how encryption preserves file confidentiality by using efs on a marketing share, tying access to the user’s certificate and profile across logins.
Explore BitLocker device encryption in Windows Server 2012, including preinstall provisioning, encryption options for fixed data, operating system, and removable drives, plus group policy, network unlock, and TPM protection.
Apply audit policies to files and folders, cover NTFS permissions and encryption, and practice auditing actions like open, modify, or delete on a file share with real authentication.
Configure advanced audit policies using group policy or the auditpol command to implement expression-based auditing and create policies such as removable device audit policy.
Turn on audit policies by category, then fine-tune file and object access to specify which files and changes to monitor via group policy under computer configuration.
Explore audit policy types in Windows Server 2012, including account logon and logon events (interactive vs remote), focusing on successful vs failed attempts and object access.
Demonstrates configuring file server audit policies via group policy, applying object access auditing to servers, and reviewing audit events in Event Viewer to monitor file activity.
Review and monitor file and print services, including file locations, file screens, and quotas. Encrypt NTFS files with public and private key encryption and audit activity on files, folders, printers.
Explore how DNS provides name and IP resolution and maps the domain namespace, enabling service discovery and server location through DNS records and configurations.
Explore DNS components, including zones, namespace, and records, and how DNS resolvers use recursive and iterative queries to resolve across multiple zones and internet root servers.
Explore how DNS resolves names with authoritative versus non-authoritative responses, and recursive versus iterative queries, using root hints and cache to locate www.sandra classroom dot com.
Explore DNS zones and learn how primary, secondary, and stub zones handle authoritative and read-only copies, delegation, name server records, and glue records, and caching for efficient query resolution.
Explore dns zones on a domain controller using the dns manager, reviewing forward lookup zones, zone transfers, and Active Directory integrated zones with start of authority and glue records.
Compare stub zones and conditional forwarders to clarify their DNS roles: stub zones keep a server aware of authoritative foreign zone servers, while forwarders route specific queries to another server.
Explore common DNS resource records, including A records for IPv4, PTR reverse lookups, SRV service records, CNAME aliases, MX mail exchangers, SOA authority, and text records.
Explore DNS zones and records with the DNS manager, creating forward lookup zones, A, NS, and MX records, plus aliases, including active directory integrated and secondary zones.
Explore using the dns command (dnsCmd) to manage dns servers, add zones (primary or Active Directory integrated), configure records, perform zone transfers, and script exports or imports.
Observe how a client's DNS server consults its cache, then uses route hints or forwarders to query upstream DNS servers, performing iterative and recursive lookups to resolve a domain.
Install DNS as a server role, create a primary zone and reverse lookup, and configure a conditional forwarder to direct queries to a master server for a custom zone.
Explore dns namespaces from the root domain to host names, understanding top level and second level domains, subdomains, and fully qualified domain names and the trailing root dot.
DNS naming context rules: only letters, numbers, and hyphens are allowed; underscores and other special characters are not allowed.
Compare internal and external namespaces, and see how firewalls and DNS resolve internal resources like file servers while external DNS handles web, VPN, and mail with A and MX records.
Understand how DNS zone transfers ensure redundancy by syncing zone data from a primary to a secondary server, including AXFR, IXFR, and fast transfers.
Explore dnscmd commands to view server info, add zones, and configure primary and secondary zones with zone transfers and active directory integrated zones.
Troubleshoot dns name resolution by pinging a machine by name to verify resolution and ip address, and use powershell to query domain records, start of authority, and reverse lookup zones.
Learn how zone scavenging removes stale DNS records through aging and TTL settings, and how dynamic updates from DHCP interact with DNS to keep records current.
Configure zone scavenging to remove unmanaged and stale DNS records, protect against wasted disk space and degraded queries, and enable aging on the DNS server for primary zones.
Explore DNS scavenging options, including zone and record time-to-live, aging and non-refresh/refresh intervals, and the handling of stale records across Active Directory integrated zones.
Enable round robin DNS to balance load across multiple servers by resolving to different IPs in sequence, and configure secure dynamic updates to require domain membership for hostname registration.
DNS caching stores recent resolutions in a local cache for about one hour, speeding lookups for multiple clients; servers act as forwarders and add results to the cache.
learn to view and clear the local dns cache using ipconfig /displaydns and ipconfig /flushdns to troubleshoot dns client configurations.
Store DNS zone information in a text file or in Active Directory; text files show primary or secondary zones in Notepad, while AD integrated DNS replicates zones with AD.
Plan dns deployment by deciding zones to host, locate servers near clients, and optimize for zone transfers and replication while considering traffic volume and client distribution.
Discover dns as the name to ip resolution and backbone for active directory and internet access. Plan namespaces, place servers, and configure dns to support clients and network services.
Explore how network policy servers manage remote access for telecommuters, including vpn and direct access, with integrated features and network access protection to secure remote work.
Discover remote access methods to connect from outside the network, including direct access, traditional VPN, site-to-site, and the web application proxy working with Active Directory Federation Services.
Explore how routing and remote access enable secure network entry, including direct access and VPN, while leveraging Active Directory, certificates, IPsec, DHCP, and network access protection to enforce health policies.
Install the remote access role and configure either direct access or routing and remote access, noting dependencies on the network location server, Windows internal database, and PowerShell-based management tools.
Install and configure the remote access role, use the wizard to set up vpn, dial-in, and routing policies, and review nat concepts along with authentication and encryption settings.
Install the routing and remote access role, configure direct access and vpn, and set up two network adapters. Complete the post-deployment wizard and group policy updates to enable remote access.
Explore network authentication by verifying user credentials—username and password, smart cards, and biometrics—through protocols like PAP, CHAP, MS-CHAP, MS-CHAPv2, EAP, and IKEv2, including VPN reconnect and the distinction from authorization.
Explore PKI fundamentals, including public and private keys, certificates, and public vs private CAs, with real-world examples of certificate issuance, templates, revocation, and secure enrollment.
Learn how dhcp relates to remote access, including authentication and ip address assignment. A remote access dhcp pool of ten addresses has the server use the first, nine for clients.
Explore vpn access into remote infrastructure, covering site-to-site and remote user connections, using pptp and l2tp, plus ipsec with ike for encrypted, authenticated traffic.
Configure a vpn server with two network cards on external and internal networks, plan IP address allocation, and assess whether you need radius servers and the NPS role.
Describe vpn connection properties, including encapsulation with a header for routing, computer-level authentication via ipsec/ike and certificates, user and mutual authentication, and data origin authentication via checksums.
Examine vpn tunneling protocols, including pptp, gre, and l2tp, with ipsec and ikev2, sstp, and eap authentication. Learn about encryption methods like aes, des, 3des, and related certificate handling.
Enable vpn reconnect to automatically reestablish a dropped vpn as users roam between networks, transparently, using IKE; requires Windows client/server versions, PCI infrastructure, and Radius or Active Directory certificate services.
Explore behind the scenes in the remote access server via the remote access management console, configuring VPN, routing, and IP settings including IPv4/IPv6, logging, ports, and interfaces.
Review firewalls and packet filters to control VPN traffic and who can dial in, adjust logging levels, configure VPN ports, and use the connection manager administration kit to distribute profiles.
Install CMAK as a feature and create VPN profiles and dial-up entries. Configure profile naming, PBK files, and optional phone book updates for deployment.
Learn how to build a network policy with three components—conditions, constraints, and settings—using group membership, health checks, time restrictions, and authentication rules to control remote access.
Create and configure a network policy by naming it, enabling it, setting access permissions, choosing a connection method, and selecting RAS, VPN, DHCP, age cap server, and an HRA.
Explore the flow of network policy processing: default rejection when no policies exist, match-and-deny logic across policies, and final allow only after a policy permits the user and profile.
Explore direct access features in Windows Server 2012, enabling clients to connect to internal resources over the internet with end-to-end authentication and encryption, supporting multiple protocols, most used being ttp.
Explore what's new in direct access, including coexistence with routing and remote access and easy deployment. Leverage NAT64/DNS64, load balancing, multi-domain support, server core, and enhanced diagnostics and tooling.
Explore the deployment phases of direct access, configuring remote access infrastructure, routing, firewalls, certificates, and DNS, then managing with Group Policy and network location service.
Set up a domain-joined Windows 2012 server to accept direct access connections, route clients to internet resources, and use an IP-tunneled mode with a wizard-based setup.
Domain joined Windows clients connect to direct access using IPv4 or IPv6, IPsec, and 6to4 tunneling and IP over SSL; it uses a name resolution policy table to guide behavior.
Learn how the network location server determines client location, enabling internet-based direct access components, which install with required roles and a web server role, and are managed via GPO.
Internal resources form the required infrastructure for direct access, making IPv6 applications immediately accessible. NAT64 and DNS64 support older apps, and Forefront Unified Access Gateway enables backward compatibility.
Explore required infrastructure: active directory domain, group policy, and dns, with a minimum 2003 domain functional level, multiple domains in the forest, and direct access wizard-generated settings.
PKI certificates enable two-factor authentication by pairing a username and password with a certificate, and with NAP for tunneling, security policies, and compliance checks.
Define the DNS namespace and client configuration through the name resolution policy table, applying rules to resolve names and fall back to local or ISP DNS when unmatched.
Explore how the name resolution policy table guides client name lookup from local cache, hosts, policy table, and finally DNS servers, with DNS search suffixes and exceptions.
Describe the six essential steps of internal client interaction with direct access, including dns resolution, certificate retrieval and validation, domain firewall profile activation, and network attachment after domain logon.
Direct access enables external clients to reach internal resources by resolving the domain name via the name resolution policy table and forming an ipsec tunnel through connection security rules.
Explore post-installation troubleshooting by configuring logging levels, choosing to log only errors or all events, and enabling tracing via net shell commands and registry settings for authentication and tracing components.
Troubleshoot vpn connectivity using logs and ping tests by IP or hostname, diagnose name resolution versus actual connectivity, and verify client properties and Active Directory settings to match authentication protocols.
Learn to diagnose common error codes for Windows server 2012 administration, including error 800 indicating unreachable servers, firewall port issues, and encryption mismatches that prevent VPN handshakes.
Explore how network address translation hides internal IPs by translating them to an external address in a NAT-based firewall, with the router intercepting requests and reversing translations.
Explore how remote dial settings, policies, conditions, and profiles govern access via the dial-in tab with nap-based permissions. Verify caller ID and choose static addresses or routes for remote access.
Master network policy and access services by enforcing health policies that verify clients before network access, centralizing policy management with radius, and securing wireless access.
Learn how Network Policy Server centralizes the RADIUS server, RADIUS proxy, and health policy to manage authentication, authorization, accounting, and remediation for wireless, dial-up, and VPN access.
Install and configure the network policy server to deploy radius services, set connection policies, and enforce network access protection with health validators.
Explore network policy server tools via the NMC console or shell, and export the full configuration with net shell or PowerShell for on-screen display or saving to a text file.
Identify radius clients as the devices that forward authentication requests from wireless access points, VPN, or dial-up servers to the radius server, clarifying they are not workstations.
Explore how a radius proxy aids authentication and authorization for outsourced services like VPN, dial-up, and NAS. Learn how it handles non-Windows databases and scales to high connection request volumes.
Treat certificates as digital identities used for authentication, trusted by location. Rely on a source such as a domain administrator or VeriSign, and support EAP, PEAP over TLS, and MS-CHAPv2.
Identify the required certificates, including the certificate authority within a trusted root CA and the server certificate store, and note client certificate import and EAP-PEAP usage.
Monitor NPS by enabling event logging, logging authentication and accounting requests, adjusting logging levels, and ensuring capacity and log file size, using the radius class attribute for SQL Server logging.
Explore remote access strategies for Windows Server 2012, including dial-up, vpn, and direct access, with emphasis on layered security, client-specific technology choices, and comprehensive internal network protection.
Explains Active Directory as the domain’s database with a forest-wide schema, organizing users, computers, authentication, and password policies across domains, including service accounts and domain controllers.
Learn to clone a virtual domain controller in Hyper-V by creating a clone config file with static IPv4 settings and a new computer name, validating the clone allow list.
Explore how a forest shares a common schema across domains and how the forest root domain sits at the top, housing enterprise administrator groups. Understand domain creation and root domains.
Explore the Active Directory schema, including object classes and attributes, where unique object types like computer and user define properties such as description and name, shaping the forest’s directory structure.
Active Directory domain structure defines the context for users and groups, with replication boundaries, domain administrators, and organizational units guiding password changes, policy deployment, and authentication within the domain.
Domain controllers provide the Active Directory services role, hosting a read-write copy of the NTDS.dit database and system folder, with at least two controllers for availability.
Identify the default AD DS containers: domain container root for users and groups, users container for new user accounts, computers container for new computer accounts, and domain controllers organizational unit.
Organizational units group users, groups, computers, and other objects to apply group policies and manage security and configurations, while enabling delegated administrative rights for department managers.
Virtualized domain controllers enable safe snapshots and cloning in Hyper-V, enabling rapid provisioning and replacement of domain controllers, especially in test environments.
Clone a virtual domain controller by exporting from Hyper-V and importing as a new VM, provided the PDC emulator role is on a Windows Server 2012 DC.
Create a dc clone config sml file with unique server settings, place it in source domain controller's tads subdirectory, export or copy, and import into Hyper-V to create virtual machine.
Explore the DcCloneConfig.xml syntax with an SML example, detailing ip4/ip6 provisioning (dynamic/static), offline execution, and how to set the home computer name to clone new domain controllers.
Cover DcCloneConfig.xml parameters such as WINS server, clone computer name, IP v4 address, DNS resolver, and default gateway; show creating a config file with a 15-character enterprise name via PowerShell.
Safely back up and restore domain controllers with virtual machine snapshots in Windows Server 2012; inbound replication synchronizes AD deltas and full container, preventing replication halts when restoring multiple DCs.
Master PowerShell commands to manage Hyper-V snapshots, including creating, listing, exporting, retrieving, removing, renaming, and restoring VM checkpoints.
Demonstrate Active Directory administration tools as the core for domain-based networks, detailing domain controllers, global catalog server, read-only domain controllers, partitions, schema, domains, forests, sites, and organizational units.
Plan an active directory structure and import large numbers of user accounts by preparing a csv file with consistent headers and using the import utility to create accounts.
Explore common LDAP attributes in Active Directory for user information, including given name, surname, user principal name, and display name, with precise case sensitivity.
Explore common ldap attributes such as postal code, country code, member of, group, title, department, and company, and note hundreds more available in the attribute editor.
Explore advanced Active Directory attributes in Windows Server 2012 by inspecting computer and user properties, utilizing the attribute editor, and managing delegation, location, and group memberships.
Demonstrates importing users into Active Directory with CSVDE, using an Excel CSV featuring sam account name, distinguished name, and object class. Shows assigning users to OUs and verifying entries imported.
Demonstrates exporting Active Directory users with csvde, using -d to set scope and -r filters, exporting a csv containing distinguished name, object class, samAccountName, surname, given name, user principal name.
Demonstrates importing accounts via ldif using a text file, with change type modify versus add, validating organizational units, and editing the file to correct domain and attributes.
Learn how managed service accounts in Windows Server 2012 use MSDS objects to automatically rotate passwords and simplify service principal name management.
Configure service accounts on Windows Server 2008/2012 or newer, with manual service principal name setup for the managed service account, and run forest prep and domain prep to update schema.
Configure a managed service account with PowerShell by creating a key distribution root key, setting effective time for replication, and linking it to computers and services.
Create a payroll managers security group in Active Directory using PowerShell, set the global scope and display name, then move it to the accounting OU and explore bulk object operations.
Explore how Kerberos version 5 enhances authentication in Windows Server 2012, reducing failures from large service tickets and enabling cross-domain access via ticket granting tickets and trust relationships.
Examine Kerberos configurations in Windows Server 2012, noting when claims, compound authentication, and Kerberos armoring are supported, and how Windows 8 clients interact with domain controllers.
Explore Kerberos configurations available, including claims, compound authentication, and Kerberos armoring, within a 2012 domain functional level, and examine fast behavior and armored Kerberos message handling.
Explore service principal names (SPNs) that identify unique service instances in a forest by combining service class, host, optional port, and service name, with Exchange and DNS/MX examples.
Apply a domain-wide password policy from the default domain policy with complex passwords, and tailor group-specific needs using password settings objects for administrators or helpdesk.
Learn to configure password policies and account policies, password settings objects and lockout rules, and assign user rights to control operating system actions like changing system time and loading drivers.
Configure domain-wide password and account lockout policies via the group policy management console, adjusting password history, minimum and maximum password age, complexity requirements, and Kerberos policy.
Link a password settings object one-to-one to a user or group, and let MSDS password settings precedence attribute determine policy; if equal precedence, the object with the smallest grid applies.
Explore how to create a new fine grained password policy using the password settings container, configure precedence, and apply policies to the help desk group within Windows Server 2012.
Enable universal group membership caching (UGMC) on branch sites to cache membership in the global catalog, reducing WAN replication traffic by nesting universal groups inside global groups.
Discover the forest and domain level operations master roles: schema master, domain naming master, RID master, PDC emulator, and infrastructure master, and how they manage SIDs, RIDs, passwords, and moves.
Explore the operations master roles in Windows Server 2012, including naming master, infrastructure master, PDC emulator, and schema master, and learn to transfer or seize them to balance workload.
Learn how to maintain Active Directory like any database, including online and offline backups, stop-and-go maintenance, and authoritative restores, with snapshots, recycling bin, and object recovery across domain controllers.
Enable the Active Directory recycle bin to preserve object attributes, then restore deleted objects as-is after replication; the demo covers PowerShell and AD center setup and MSDS deleted object lifetime.
Demonstrates restoring a deleted Active Directory object by locating it in the deleted objects container, adjusting the isDeleted attribute, and applying an authoritative restore across domain controllers.
Master Active Directory database maintenance, including offline defragmentation and integrity checks, and manage AD snapshots with PowerShell and the AD DS module, scheduling tasks via Task Scheduler.
Implement read-only domain controllers to secure branch offices, enabling administrative separation, password caching control, and local server admins, while pre-staging RODC and completing installation via the domain join wizard.
Demonstrates installing and configuring a read-only domain controller (RODC) in a Windows Server 2012 domain, including domain prep, pre-staging the RODC account, and managing password replication policies.
Configure rodc caching via the password replication policy and populate domain local groups for allowed and denied caching; admins are denied by default.
Manage Active Directory as the backbone of network security, focusing on user accounts, backups, integrity checks, and strict control of who modifies objects. Consider read-only domain controllers for branch offices.
Group Policy provides centralized administration to control users and computers, with policies and preferences that govern installations, environment visibility, files, folders, and registry permissions from one location.
Explore how group policy provides configurable settings for users and computers to customize the environment, including importing policy modules from applications and configuring Internet Explorer behavior.
Define policy options by choosing not configured, enabled, or disabled to control settings changes; not configured leaves the current state, while enabled or disabled apply or lock changes.
Discover how ipv6 gains in windows server, with group policy support for ipv6 printers, item level targeting for ipv6 address ranges, and vpn ipv6 integration.
Explore group policy usage examples, including rolling out applications with specific settings and Internet Explorer configuration, preventing registry editing, folder redirection, hiding control panel items, and login dialog prompts.
Explore the group policy management console, linking and modeling GPOs across domains, OUs, and sites, and simulate the resultant set of policies with security filtering and slow-link scenarios.
Explore group policy objects (GPOs), their scope for users and computers, and how to link them to sites, domains, or organizational units, with security and WMI filters to tailor settings.
Group policy application downloads latest policies from domain controller, stores them locally, and applies changes via client-side extensions, with synchronous mode and configure group policy caching controlling reboot reads.
Configure client side extensions to reapply policy settings at refresh, even if the GPO hasn’t changed, by enabling policy processing to reapply every 16 hours, with clients pulling from domain.
Explore Windows client policy processing by enabling always wait for the network on startup and logon, ensuring domain updates arrive, and learn policy refresh timing and gpupdate /force usage.
Assign startup, shutdown, logon, and logoff scripts via group policy, with a 10-minute adjustable timeout; scripts run top to bottom and support vbscript, javascript, perl, bat, and command files.
Explore group policy nodes, including policy based quality of service to manage network traffic, and user configuration options like remote installation services, folder redirection, and Internet Explorer maintenance.
Compare the default domain policy and the default domain controllers policy; the former applies to all users and computers, while the latter secures domain controllers with audit and security settings.
Explore how a group policy stores its data: the group policy container in active directory and the group policy template in the sysvol share, detailing where policies and settings reside.
Replicate the group policy container across domain controllers using the KCC topology, and propagate the group policy template via the file replication service, with DFS replication available for newer systems.
Learn how starter GPOs function as templates containing starter settings from administrative templates. Use them to create, back up, restore, or move to another domain controller.
Explore slow link processing in Windows server 2012, where a default 500 K bandwidth governs policy downloads and some security settings remain fixed for remote workers.
Explore loopback processing to control how server computer policies and user policies apply, choosing replace or merge to determine policy precedence between the server and helpdesk OUs.
Manage security templates with the security configuration and analysis tool, import and apply templates, migrate old Adium files to the new format, and configure administrative template property filters.
Demonstrates configuring group policy folder redirection, creating a root path for per-user folders, and applying settings to redirect documents and desktops for new users.
Learn to create a group policy to install software by sharing a source folder, configuring permissions, and deploying a package via the group policy management console.
Administrative templates extend group policy by locking the Windows interface and configuring settings from control panel to personalization. They enable adding, removing, exporting, and importing templates for use across servers.
Link group policies to multiple containers to deploy subjects like folder redirection and encryption where they belong. Create separate policies and attach them to appropriate OUs, sites, or the domain.
Apply group policy in a defined order: local first, then site, domain, and organizational units, processing synchronously by preference. Higher-level OUs apply before child OUs.
Understand group policy link precedence and how lower numbers mean higher priority. Learn to block inheritance and enforce policies at organizational units to protect sensitive settings like payroll.
Select the container where the GPO link exists. Click on the linked Group Policy Objects, choose the Group Policy, and move the policy to the desired link order.
Explore configuring local policies with the group policy management console, distinguishing domain-wide vs small-scope policies, and applying auditing, user rights, and interactive logon settings to secure Windows Server 2012.
Master group policy options, including force link, block inheritance, and security filtering, plus WMI filters to target machines by disk space, memory, preexisting applications, and OS versions.
Explore Windows Management Instrumentation (WMI) filters to control group policy application using the WMI query language, with examples by OS caption, service pack, free space, and time zone.
Import and manage security templates within the administrative templates model, using custom administrative templates files, converting with DMX, and applying property filters for Group Policy configurations.
Create and link group policy objects to control user and computer configurations, manage scope and inheritance, and use backups and WMI filters for policy deployment.
Explore group policy preferences as non-enforced alternatives to policies, enabling easy setup of network printers, drive mappings, registry settings, and file deployment with simple undo.
Demonstrates configuring group policy preferences to set starter settings, including drive mappings, environment variables, files, folders, and registry values for user and computer configurations.
maintain your group policy objects by backing them up, restoring originals after changes, importing settings from backups, delegating administration, testing in an environment, and managing wmi filters and security filtering.
Learn to manage Windows Server group policies with PowerShell, including creating, copying, importing, and linking new GPOs, backing up and restoring GPOs, and inspecting properties and inheritance.
Configure interactive logon options in group policy to control display of user information and the last user name. Set inactivity limits and cached logons to balance security and accessibility.
Configure a desktop lockdown policy for a department by creating a group policy object and applying display, mapped drives, startup scripts, security settings, and start menu controls.
Power group policy to manage Active Directory with granular control, deploying settings across desktops via linked policies, using security filtering, delegation, and WMI filters to tailor scope.
Explore administering Windows Server 2012 by deploying with images, managing file and print services, DNS and Active Directory, and automating user provisioning with group policies to streamline network operations.
The 70-411: Administering Windows Server 2012 course is a preparatory course for the exam conducted by Microsoft. It covers the exam topics in a great detail and prepares the students on system administration related functions, including deploying, managing, and maintaining servers, configuring file and print services, configuring network services and access, configuring NPS infrastructure, configuring and managing active directory, and configuring and managing group policy.
The 70-411 course is the second course in the three course series required to completely prepare for the Microsoft Certifies Solutions Associate (MCSA) certification. The other two being 70-410 and 70-412. Students are strongly encouraged to take these three courses before taking the corresponding exams from Microsoft. This course covers the administration aspect of a Microsoft Windows Server 2012 environment and prepares the students to effectively manage the users, access, policies and data security features of Windows Server 2012.