
Meet the instructor for exam 70-412, Sandra Partagas, as she guides you through Windows Server 2012, highlighting network infrastructure and security features, with real-world field insights.
Explore configuring network services, high availability, and disaster recovery in Windows Server 2012, including DHCP, DNS, IPAM, Active Directory, Federation Services, certificates, rights management, and BranchCache.
Explore how dhcp and dns work together, detailing lease processes, options, super scopes, multi-net planning, and ipam for enterprise address management and name resolution.
Learn to navigate Windows Server 2012 by managing Hyper-V virtual machines, using the start menu and search, and accessing server manager and administrative tools.
Discover how DHCP automates IP address allocation and configuration, prevents overlaps, and centralizes management with scope options and MAC-based reservations, enabling updates to gateways and DNS via the DHCP console.
Examine the dhcp server components, including the server service and dhcp client service with auto start, the dhcp database at system32/dhcp, the dhcp console for administration, and enterprise admin authorization.
Discover how a dhcp scope defines an ip address range with a subnet mask and optional settings like default gateway and dns servers, exclusions, and domain suffixes.
Explore the dhcp lease process: a client requests an IP via broadcast, receives an offer and a lease (default eight days), and renews at 50%, 87.5%, or after reboot.
Explore DHCP options and features in Windows Server 2012, including super scopes, multicast scopes, and IPv6 options, plus high availability, failover, split scopes, and name protection.
Learn how DHCP integrates with DNS to map hostnames to IP addresses and keep those records updated as leases change, including host, pointer, and reverse lookup records.
Group multiple scopes into a single logical subnet using super scopes, and enable multinetting by adding a second scope on a different subnet with routed traffic.
Authorize the DHCP server, create and configure two IPv4 scopes with a /24 subnet, set options like router and DNS, and build a super scope by combining them.
Define multicast scopes with madcap, reserve class D addresses from 224.0.0.0 to 239.255.255.255 for one-to-many delivery, enabling video or live broadcasts and Windows Deployment Services.
Explore DHCPv6 concepts, including stateless and stateful configurations, IPv6 address assignment, and how prefixes, lifetimes, DNS, and exclusions are managed.
Explore how dhcpv6 regional registries allocate ipv6 addresses across regions, from Africa and Asia-Pacific to Aeron, Canada, Caribbean, Europe, and Latin America, for internet-facing use.
Configure dhcp scopes for ipv4 and ipv6, set addresses, lease durations, options like default gateway and dns servers, then authorize as enterprise admin and activate in active directory.
Explore DHCP name protection, which guards DNS registered names—including statically assigned or manually entered ones—by creating a DHCP ID record and ensuring only the original client updates DNS records.
Enable DHCP name protection for IPv4 and IPv6, configure DNS dynamic updates, and secure host and PTR records at the scope or IP version level.
Explore DNS solutions that keep the DNS process running smoothly, including server-level records. Understand delegation, DNS logging, DNS security, recursion, cache locking, and the global names zone.
Delegate dns permissions to manage dns zones and dns backup tasks, and assign domain admins, enterprise admins, and the global dns admins group to balance administrative responsibility.
Enable DNS logging and view logs in Event Viewer. Default logs reside in Windows system32 DNS and cover start/stop, zone signing, config changes; verbose logging reveals packet direction and protocol.
Enable dns debug logging in the dns manager with care, as it can impact server performance and disk space; enable temporarily and log only the required packets and events.
Explore three levels of dns security—dns hiSeq, dns cache locking, and dns socket pool—that work together to protect dns data, addresses, and network location information from unauthorized access.
Enable DNSSEC to digitally sign all DNS records in a zone, so client computers can validate responses from the DNS server and defend against spoofing and cache tampering.
Understand dnssec basics, including trust anchors and authoritative entries represented by public keys. See how a resolver uses the dns key (directory services resource record) to build a trust chain.
Deploy dnssec by configuring server and client sides, signing the dns zone with the dns psec wizard on server 2012, and setting trust anchors and distribution points for client validation.
Configure dnssec zone signing with the wizard, selecting ksk options from 2048 to 4096 bits, rsa sha-256, and 7-day signatures with automatic rollover; set zsk to 90 days at 1024-bit.
Explore dnssec improvements in windows server 2012 r2, including a new key master role for file-backed multi-master zones and a CNG-compliant offline storage module for key management and lifecycle.
Explore DNS key concepts, zone delegation, and the chain of trust between parent and child zones, including resource records signatures and NSEC/NSEC3 protections against alphabet attacks.
Explore signing a zone with three options—manually configure parameters, copy from an existing zone, or use the recommended settings—and learn to unassign zones via DNS management interface to remove signatures.
Deploy DNSSEC by signing the zone and configuring trust anchors, then apply a name resolution policy via a group policy to enforce DNSSEC for the domain suffix.
Examine how DNS cache locking uses the DNS time-to-live value to protect cached entries and prevent overwrites or redirects, with 100 percent locking and 50 percent partial locking.
This demo explains configuring DNS cache locking to prevent overwriting cached entries based on TTL, by setting the DNS cache logging percent (e.g., 75%) and restarting the DNS service.
Leverage the DNS socket pool to randomise source ports for DNS queries; set pool size from 0 to 10000, default 2500, via DNS ACMD /config /socket pool size.
Configure the DNS socket pool to enable DNS port randomisation, set pool size (default 2500; range 0 to 10000), and restart the DNS service; you can configure an exclusion list.
Configure aging and scavenging to remove stale DNS records left by crashes, with clients refreshing on boot or within 24 hours and default 7 days for refresh and non-refresh intervals.
Maintain the DNS database by managing primary zones stored in system32\DNS and Active Directory integrated zones that replicate automatically across domain controllers, or export backups with DNSCMD /zoneexport or Export-DnsServerZone.
Learn to maintain a DNS database by creating a primary zone or an Active Directory integrated zone, and back up or export the zone file with DNS manager and PowerShell.
Explore enterprise name resolution strategies by configuring forwarders, conditional forwards, and stub zones, optimize with netmask ordering and recursion to route queries to nearest authoritative DNS servers.
Plan stub zones carefully, then create them with the wizard and store them in Active Directory. Choose replication scope, domain-only or forest-wide, and designate master servers for initial copy.
Explore the global names zone, single-label names, and forest-wide uniqueness, including the shift from wins, plus manual zones with no dynamic registration and automatic domain name appending on resolution.
Enable global names support by creating a global names zone in DNS to provide single label name resolution across forest domain controllers, with Active Directory integration and replication.
Add an alias (CNAME) to the global names zone by creating a new alias with a fully qualified domain name, selecting the file server, and refreshing the list.
Centralize planning, allocation, and auditing with IPAM (IP address management) for complex networks by linking DHCP and DNS and tracking who has which IP address and when.
Explore how IPAM and DHCP work together to manage IP addresses and scopes, with Windows Server 2012 R2 adding failover policies, super scopes, filters, and DHCP reservations.
Learn role based access control in Windows Server 2012, defining roles as task collections, assigning them to users or groups, and configuring global access scopes and policies.
Review the default role based access control roles including the dns record administrator, ip address record administrator, dhcp server administrator, reservations administrator, and scope administrator under the global access scope.
Explore IPAM monitoring in Windows Server 2012 and R2, offering inventory, DHCP and DNS monitoring, IPv4 and IPv6 support, Hyper-V and System Center integration, and role-based server grouping.
See how the virtual machine manager integrates with System Center 2012 to deliver end-to-end address space automation for Microsoft powered clouds within the System Center environment.
Use a dedicated server with no ad ds, joined to the domain as a member. Logon with a domain account in the local security group and enable auditing and IPv6.
Learn the hardware and software requirements for Windows Server 2012, including dual-core processor, 4 GB RAM, 80 GB disk space, and how the installer handles features and dependencies.
Provide hardware and software requirements for installing EPM on Windows Server 2008/2008 R2, including a dual-core processor, 80 GB disk, Service Pack 2, .NET Framework 4, and WMF 3.
IPAM abilities enable managing 150 DHCP servers, 6000 scopes, 500 DNS servers, 150 DNS zones, with zones replicated across servers, three years of forensics data, and RSAT-based IP planning.
IPAM now supports SQL Server in Server 2012 R2, replacing the Windows internal database. Co-locate or remote SQL Server, enabling scalability, disaster recovery, and improved reporting with CSV data migration.
Explore IPAM users and groups and their permissions for viewing and managing server inventory, address space, operational events, and IP address tracking information, including audit and IBM administrator roles.
Explore ipam modules to manage address space, monitor utilization, and oversee multi-server environments, with operational auditing and ip address tracking of configuration changes and logon activity.
Explore IPAM deployment methods for Windows Server, including centralized, distributed, and hybrid approaches, with one IPAM server per forest and site-specific servers that communicate with a central forest server.
Describe how IBM components operate as a server collecting data into a Windows internal database and delivering a client interface, with PowerShell managing DHCP, DNS monitoring, and remote management.
Provision the ipam role for remote management after install, using group policy or manual provisioning across multiple servers, including network shares, security groups, and firewall rules.
Learn manual provisioning for ipam by configuring a universal group, adding domain controllers and dhcp/dns servers to built-in event log readers, and sharing the dhcp subdirectory with read access.
Configure inbound firewall rules on domain controllers, DHCP servers, DNS servers, and policy servers to enable remote event log management, DNS event log monitoring, and modify the DNS server registry.
Utilize GPO provisioning to create three GPOs that apply to all domain controllers, DHCP, and DNS servers, configuring scripts, network shares, event logs, and DNS administrator permissions.
Explore multiple views of the IP address space, including subnet, ranges, and groupings, to inventory and analyze the same data from different perspectives.
Explore IPAM monitoring and management in Windows Server 2012 R2, covering DNS, DHCP scopes, scope utilization monitoring, zone monitoring, and server groups.
Migrate IPAM data to Windows Server 2012 with a seamless database migration during upgrade to R2, and rest assured the database transfers without issues when upgrading from the prior version.
Explore how PowerShell cmdlets support IPAM tasks, including importing addresses, GPO provisioning, and exporting IP address ranges. Note that R2 adds 55 PowerShell cmdlets for IPAM automation.
Demonstrates installing IPAM by adding the feature, installing prerequisites, and provisioning and discovering servers with group policy and PowerShell to centralize IP address management.
Learn to configure IPAM provisioning, perform server discovery, and manage domain controller permissions via group policy, including refreshing policies to unblock and update IPAM status.
Add an address space to IPAM, creating a container for IP address blocks, subnets, ranges, and addresses, with default values filling required fields automatically or via manual input or import.
Add an IP address block to IPAM by providing the network ID and a /24 prefix, set the RIR for public ranges, and optionally include a description and owner.
Add an IPAM subnet by specifying a friendly name, network ID, and prefix length; set optional site and IP pool details, or use PowerShell with -IPSubnet and -NetworkID.
Add an IP address range to IPAM, including prefix length, network ID, and IP pool name, and specify creation behavior when an address is missing.
Add an IP address to IPAM and associate it with a reservation or map it to a range, using managed by service, address state, assignment type, and custom fields.
Import and update address spaces from a text file using required fields for IP address, space, instance, device type, address state, and assignment type; field names can be quoted.
Create a csv file with quoted headers like ip address, managed by service, service instance, device type, address, state, and assignment types, and ensure records are consistent with comma separators.
Review DHCP and DNS concepts and IP address management (IPAM) to prevent address overlap, ensure correct network configuration, and provide forensic data for compliance and security.
Explore high availability using network load balancing and failover clustering. Learn how load balancing redirects traffic across hosts, while failover clustering automatically takes over after a failure.
Explore how network load balancing on Windows Server 2012 uses a shared IP and a virtual network address to distribute traffic to least utilized node across up to 32 nodes.
Network load balancing primarily distributes traffic across multiple servers, and is most commonly used for stateless applications such as the web tier or multi-tiered apps, not file or database servers.
Ensure all hosts in the network load balancing cluster share the same subnet, have latency under 250 ms, use static IPs, and disable the DACP client on interfaces before joining.
Explain how network load balancing distributes traffic across three hosts via a shared virtual IP, selecting the least utilized node according to port rules and affinity to balance utilization.
Network load balancing distributes load but offers limited fault tolerance; it detects server failures with a one-second heartbeat and removes nodes after five missed heartbeats, not detecting application failures.
Learn to manage network load balancing with the NLB PowerShell cmdlets, including adding or removing cluster nodes and VIPs, configuring port rules, and using common commands.
configure network load balancing port rules to control traffic distribution across cluster nodes by port number, prioritizing nodes by weight or priority, with enable, disable, and set options.
Configure network load balancing networks with unicast, multicast, or igmp, assign management tasks and cluster communication NICs, and ensure same-subnet traffic flows while preventing switch flooding.
Configure network load balancing with virtual machines across separate disks and redundant hosts. Enable unicast mode with multiple virtual network cards and MAC address spoofing to protect the cluster.
Upgrade nlb clusters by migrating to new nodes, decommissioning old ones, and choosing piecemeal or rolling upgrades, with support for mixed operating system environments, though not recommended long term.
Learn to configure a Windows Server network load balancing cluster using PowerShell, DNS records, and the NLB manager, including multicast and TCP/UDP port rules.
Configure an nlb cluster with custom port rules, including port 7878, deploy a test website, and verify host availability by suspending and resuming cluster nodes.
Secure NLB by using port rules to block unnecessary traffic and by configuring firewall rules under network load balancing. Ensure ICMP version 4 and version 6 rules are properly set.
Explain how server 2012 failover clustering handles application level failures, scales to 64 physical nodes or 4000 virtual machines, and supports SNB version 3, active directory integration, and powershell management.
Explore how dynamic witness changes and force quorum resiliency recalibrate quorum during node failures to prevent split brain, with tiebreaker rules ensuring an odd number of votes.
Configure Windows Server 2012 R2 failover clustering with global update manager mode and the cluster database. Understand notifications before changes commit and the majority read/write health detection with subnet thresholds.
Explore clustering and high availability concepts, quantified by uptime nines from two to five, and analyze what downtime means for servers, networks, and critical web applications.
Depreciated cluster features include removal of the cluster automation services component object model and the cluster data EMC tool from defaults; the print server role is no longer supported.
Explore storage options for a three-server cluster with shared storage, including iSCSI storage area networks and fiber channel, and emphasize identical controllers, firmware, and network access.
Clustered shared volumes enable multiple nodes to share read/write access to the same disk, with quick failover and visibility, provisioned as NTFS and supporting SMB 3.0, BitLocker, and storage spaces.
Discover csv for clustered shared volumes with ntfs, a single file namespace, and smb 3.00 support to host vms on a shared folder and scan and repair CSP volumes online.
Explore network considerations for configuring failover cluster networks using NIC teaming, including ensuring identical adapters, IP assignment, QoS and minimum bandwidth policies, and DNS-based name resolution.
Ensure all failover cluster nodes run the same edition of Windows Server 2012, with identical service packs and updates; standard can be full or server core, data center likewise.
Ensure infrastructure readiness with DNS name resolution in the same Active Directory domain. Grant management permissions on local cluster servers and enable create computer object permission to allow cluster creation.
Understand failover clustering quorum, including voting elements and nodes, how tie-breaking affects cluster startup, and how network connectivity, node capacity, and role priorities impact high availability.
Configure failover clustering with similar hardware, matching network adapters, and identical storage components. Ensure shared storage uses basic disks with NTFS and cluster shared volumes.
Ensure Hyper-V cluster hosts meet the hardware requirements: a 64-bit processor, hardware-assisted virtualization, and hardware DEP, and are validated by Microsoft using the validator configuration wizard or PowerShell test-cluster.
Define quorum and cluster concepts, explain failover clusters, and how voting elements determine if the cluster stays online, including disk and file share witnesses.
Explore how the cluster network enables node communication with clients across public, private, and hybrid networks; resources on nodes surface to clients, can be started or moved, with shared storage.
Learn how quorum witnesses determine majority in Windows Server 2012 clusters, using disk or file share witnesses to resolve ties when node counts are even.
Configure quorum options with typical settings and automatic node votes, dynamic management, and disk witness, or add a warm quorum witness (file share or disk) for site-specific needs.
Explore quorum modes for Windows Server 2012, including no majority and node majority with disk or file share witness, and why disk witness can create a single point of failure.
Identify the three failover cluster networks—private, public, and public-private—and explain their roles in internal communication, client access, and ip address resource records creation.
Discover cluster networking across multi-site clusters on different subnets, including failed over cluster virtual adapters with MAC-based addressing and IPv4/IPv6 support for node-to-node and node-client communication.
Demonstrates configuring fail over clustering on Windows Server 2012, setting up shared storage with iSCSI, validating servers and disks, and creating a cluster with the create a cluster wizard.
Configure a multi-site failover cluster with enough online nodes per site, identical operating systems, storage replication, and high availability of DHCP, IP, DNS, and Active Directory global catalog.
Configure multi-site failover clusters by verifying nodes per site, ensuring network, latency, and storage replication, and validating quorum and cluster roles before testing failover.
Clarify cluster and quorum terminology, configure applications and services by understanding cluster services as roles or applications, resources, failover, and managing shared disks, names, and ip addresses online or offline.
Install the cluster service roles using Server Manager or PowerShell, validate in Failover Cluster Manager, install on cluster nodes, create a clustered application, and configure it.
Deploy highly available file server by adding a clustered role, selecting general use or scale-out for application data, and configuring a cluster name for failover with SMB and NFL protocols.
Discover how cluster aware updating automatically updates Windows Server 2012 cluster nodes using an orchestrator built from the Failover Clustering Administrative Tools, with scheduled and on-demand update modes.
Maintain a cluster as a group of servers rather than a single machine by managing each node, network, and permissions. Plan quorum settings, node majority, service migrations, and cluster removal.
Explore management tools for configuring and monitoring a Windows Server 2012 cluster in the quorum, including Event Viewer, performance and reliability monitor, cluster configuration reports, and the validator configuration wizard.
Back up windows server clusters with server backup, verify backups before joining the cluster, and back up cluster configuration, quorum requirements, and application data separately, such as sequel databases.
Choose an authoritative restore to roll back a cluster to a point in time, or a non-authoritative restore for a damaged node, using system state recovery via Windows Server Backup.
Explore how Windows Server 2012 enables automatic DHCP failover between two servers, reducing manual recovery and redirecting clients on failure while noting IPv4 limitations.
Configure a failover relationship between two DHCP servers with a unique name. Use the failover wizard to define server and scope per relationship; keep time synchronized within one minute.
Learn about DHCP failover modes, including hot standby and load sharing, with primary and secondary servers for multiple subnets and scopes, MC LTE timing, and configurable address percentages.
Demonstrates configuring DHCP failover for a scope with a partner server in Windows Server 2012, using load balancing and hot standby options. Includes verifying replication on the secondary server.
Configure dhcp failover parameters, including the maximum client lead time and auto switch over interval, set 10 minute default, enable message authentication, and apply firewall rules via the failover wizard.
Achieve high availability by balancing network load, avoiding single points of failure, and ensuring ip address configuration and services stay accessible through network load balancing, failover clustering, and dhcp.
Explore Hyper-V high availability by mastering host clustering, failover, and virtual machine movement; configure clustered shared volumes and failover clusters, and use Virtual Machine Manager for migrations.
Cluster Hyper-V hosts to enable high availability and host-based failover. Fail over to a secondary host so all virtual machines are restarted and can be moved during planned maintenance.
Highlight new features in server 2012 vm host clustering, including support for up to 4000 vms, a snap-in for migrations and priorities, and clustered shared volumes with SMB 3.0.
Ensure all Hyper-V cluster servers share identical 64-bit hardware with hardware-assisted virtualization and DEP, same software updates, service packs, and installation type, certified for Windows Server via validate configuration wizard.
Master the prerequisites for Hyper-V clusters on Windows Server 2012, including hardware, dual network adapters for storage traffic, VM files and witness disk on volumes, and basic disks with multipath.
Configure identical IP version, speed, duplex, flow control, and media type across adapters; ensure private subnets, DNS for name resolution, and domain-wide permissions to create computer objects for cluster setup.
Configure a failover cluster on Windows Server 2012 by installing servers, configuring network and domain, setting up shared storage, installing Hyper-V, deploying virtual machines, and validating with cluster manager tests.
Configure Hyper-V clusters with physical nodes connected to dual networks for internal and client communication, and use clustered shared volumes to provide shared storage for highly available virtual machines.
Enable guest clustering for high availability by failover clustering virtual machines across hosts, requiring cluster-aware vms and shared storage via ice Kaze or virtual fiber channel interface on Server 2012.
Learn how Windows Server 2012 R2 enables shared virtual disks in the VHDX format, added as SCSI drives for guest clusters, serving as witness or data disks.
Configure shared virtual disks for guest clusters on a two-node hyper-v failover cluster joined to the same active directory domain, using CSV or scale-out file server clusters with SMB 3.0.
Configure SMB 3.0 for virtual machines on a file share. Migrate VM files to an SMB 3.0 share with Hyper-V on scale-out file servers running Windows Server 2012.
Explore scale-out file servers delivering continuous storage on a shared cluster volume. See how active clustering lets all nodes serve SMB clients with per-file-share connections and RAM caching.
Configure network load balancing for virtual machines, distributing client requests across a two-host cluster, with front-end redirection, and avoid mixing NLB with failover clustering on the same host.
Explore cluster shared volumes (CSVs) and their benefits for virtualization, enabling multiple VHD/VHDX on one LUN, while noting drive letters are removed and shared storage cannot be converted to CSVs.
Configure failover in server cluster by prioritizing preferred and possible owners, with heartbeat checks every second over tcap and udp 3343, initiating takeover of vm resources after five missed heartbeats.
Explore failover and preference settings in a Windows Server 2012 cluster, including possible and preferred owners, anti affinity class names, pause, auto start, and persistent mode to control VM placement.
Master Virtual Machine Manager to manage Hyper-V, VMware, ESX, and Citrix server hosts, deploy and manage virtual machines, and perform physical-to-virtual and virtual-to-virtual migrations.
Explore the DMM components, led by the Vienna manager, that process commands and coordinate the VM database, library server, and hosts as a deployment hub, stored in a sequel database.
Meet prerequisites for VMM 2012: Windows Server 2008 R2 SP2, .NET Framework 3.5 SP1, Windows Administration Kit; enable WinRM, allocate 2 GHz CPU, 4–8 GB RAM, 40–150 GB disk.
Learn how VMM enables a private cloud infrastructure through the fabric workspace, configuring servers, networking, and storage with hosts, ip pools, mac pools, and storage arrays.
Discover enhancements in Windows Server 2012 R2, including Hyper-V improvements, live migration, automatic cluster upgrades, dynamic resizing of virtual hard drives, and multi-tenant cloud provisioning.
Deploy virtual machines with virtual machine manager by importing existing vhd files, using templates or iso images, and configuring host, path, and networks through the vm wizard and library.
Server 2012 supports odx with intelligent storage arrays that offload VM transfers, enabling rapid import and export via a data token copied between servers.
Learn how p2v migrations convert physical machines to virtual machines by creating a disk image with hardware configurations, allowing the virtual machine to take over after disconnecting the physical host.
Explore v2v migration to consolidate virtual machines from different platforms into Hyper-V, and use the virtual machine wizard to create matching VMs with the correct properties.
Explore migration methods for virtual machines, including moving powered-on VMs without shared storage, quick migration with cluster failover, live migrations with no downtime, and import/export options that require powering down.
Migrate a powered virtual machine and its storage without shared storage using live storage migration in Hyper-V, copying data to a new virtual hard drive and synchronizing changes.
Explains how live migration moves a running virtual machine with zero downtime using failover clustering, WMI, and PowerShell, transferring memory and configuration to a target host while the guest runs.
Move virtual machines between hosts quickly using quick migration, which saves the machine state, transfers control to another host, and resets the machine independent of hard drive speed.
Hyper-V replica duplicates a virtual machine, synchronizing changes to provide an up-to-date spare for recovery and snapshots, without moving to another host, enabled via Hyper-V server settings and replication options.
Configure Hyper-V replication to establish failover clustering between two Hyper-V hosts, enable replication, configure authorization, and set up storage folders and firewall rules for port 80.
Configure Hyper-V replica components, including the replication engine, change tracking, and network module, and use the replica broker server role to redirect VM events during quick, live, or storage migrations.
Ensure hardware supports Hyper-V, provide storage on both primary and replica, keep network connectivity on, open tcp ports 80 or 443, and use x.509 v3 certificate authentication.
Export virtual machines to a separate drive for backup, powering them off and creating folders for snapshots, virtual hard disks, and virtual machines; import provides register, restore, and copy options.
Demonstrates exporting and importing a virtual machine with Hyper-V, including register in place, copy with new IDs, and adjusting network settings on new hardware.
Export a powered-off virtual machine to a network or portable drive to move or back up elsewhere, then confirm the exported files can be imported on another server.
Explore how to configure Hyper-V for high availability, monitor virtual machines with System Center VMM, set cluster-aware failover settings, and move virtual machines between hosts.
Explore Active Directory concepts, including forests, domains, trees, trust relationships, sites, and replication, and learn how to configure domain forest structures and subnets with global catalog servers.
Active Directory uses domains as security boundaries for user authentication. A forest groups multiple domains sharing a common schema, featuring domain trees, transitive trusts, and a global catalog index.
Define replication boundaries within a domain where domain controllers replicate and authenticate users. Explain DNS zones, administrative boundaries, group policy, password settings, and auditing across the domain.
Explore the Active Directory forest boundary and its replication within a forest. Learn schema and configuration partitions, global catalog, and forest dns zones for forest-wide resolution and security boundary.
Explore multi-domain configurations within a forest, balancing dns namespace separation, administrative boundaries, and replication traffic. Learn how resource domains let headquarters manage accounts while branches control local resources.
Configure multiple forests by establishing forest trusts to share resources while keeping schemas and namespaces separate, enabling secure extranet access and merger scenarios.
Learn how dns resolves hostnames to ip addresses, supports active directory, and domain controller service locator records, with two dns servers per domain and conditional forwarding for cross-namespace resolution.
Install the Active Directory Domain Services role and promote this server to a domain controller to create a new forest named Mayfield classroom internal with DNS enabled.
Understand domain functional levels and how they govern group types from domain local to universal, nesting groups, SID history, and cross-forest behavior across Windows 2000 to 2012 environments.
Explore Windows Server 2008 replication with DFS, multi-valued and group attributes, per-user logging and password settings. Examine read-only domain controllers for branch offices and federation.
Standardize user logon across multiple Active Directory domains by configuring UPNs with a common suffix in a forest. Use UPN suffixes such as a forest DNS suffix to simplify sign-in.
Explore domain functional levels and UPN suffixes in active directory, including raising functional levels, managing operations masters, and adding a UPN suffix for forest-wide login.
Configure trusts between Active Directory domains and forests using the domain and trusts wizard, choosing external or full forest trusts, and enabling domain-wide or selective authentication.
Upgrade domain controllers to server 2012 from 2008, upgrading via 2003 to 2008 if needed. Automatically upgrade the forest schema with the Active Directory wizard, and prefer clean installs.
Migrate to Server 2012 by using an automation tool to promote a domain controller, update the schema, and configure Server 2012 via the promotion wizard.
Use the Active Directory migration tool to restructure domains and migrate user, group, computer, and server accounts, along with trust relationships and Exchange servers, with reporting and undo the migration.
Prepare the target domain for older cryptographic algorithms and align accounts; establish trust between old and new domains, enable sid history migration, and test migration with rollback and firewall settings.
Explain how sid history preserves a user’s identity across old and new domains during migrations, using a trust relationship and a separate sid history attribute to maintain access to resources.
Plan restructuring and migration by preparing the source and target, managing outgoing and incoming flows, migrating accounts first, then resources, and ensuring proper access rights before final steps.
Explore trust relationships in Windows Server 2012, including parent-child, tree root, external, forest-level, and shortcut trusts, with name suffix routing, SIDs, and the ticket granting ticket system.
Explore forest trusts, sid filtering, and selected authentication to control cross-domain access and permissions across domains.
Explore Active Directory partitions, including the configuration, domain, application, and schema, and how they shape replication, domain controllers, and the forest-wide global catalog.
Discover how Active Directory replication uses multi-master architecture with read/write domain controllers and read-only domain controllers, employing pull and store-and-forward methods, sites, and data partitioning.
Explore multi-master replication in active directory, with readable and writable domain controllers. Understand pull-based replication, read-only branch offices, store-and-forward topology, and data store partitioning across domain and forest.
Explore how active directory sites and replication manage traffic across physical locations and subnets, using connection objects, bridgeheads, and the kcc to shape topology and notifications.
Explains how multi-master replication across domain controllers creates conflicts with concurrent edits. Shows three conflict types and uses globally unique identifier, time stamp, and version number to resolve them.
Explore how the KCC automatically builds forest-wide replication topology across red and blue domains, linking domain controllers, config and schema partitions, and global catalog servers with DNS.
Explain RODC replication and inbound replication, including forwarding password requests to writable domain controllers, referrals, or failures; note RSO enables replication of an object, such as password changes and DNS.
Configure password replication policies for the read-only domain controller using allowed and denied lists and domain local groups to control cached credentials, via Active Directory Users and Computers.
Explore SYSVOL replication and how logon scripts, Group Policy templates, and Group Policy objects replicate to domain controllers, influenced by OS version, domain functional level, migration status, FRS, and DFS.
Discover how DFS replication improves file replication with remote differential compression, scheduling, and bandwidth throttling, and how to migrate from file replication service to DFS using the migration tool.
Configure Active Directory sites to model physical networks and control replication; use site objects in configuration container with service localization to direct logon and DFS referrals to the nearest site.
Explore Active Directory sites and services by creating sites and subnets, linking replication paths, and managing domain controllers to optimize global replication.
Leverage a fast, reliable same-site connection to enable immediate replication of changes and change notifications, so password updates and other alterations propagate instantly to all domain controllers.
Explore site replication between sites, prioritizing limited bandwidth with compression and a replication window during off-peak hours. Learn how domain controllers check for changes on a configurable replication schedule.
Learn to plan replication within sites and services by creating a site and subnet structure, then move servers between sites by dragging them into the servers container.
Explore how Active Directory database and sysvol replicate changes across sites, including group policy objects, and password replication, with immediate and scheduled replication, monitoring between sites, and dfs replication upgrades.
Configure the intersite topology generator (ISTG) to compute the ideal replication topology across sites, with the KCC designating one domain controller per site as the bridgehead server.
Create and name site links to align the Active Directory replication topology, using a default IP site link and costs to define logical replication paths between headquarters and branches.
Create and bridge site links using either ip or smtp transport, ensuring domain names match the physical site structure, and manage default and custom site links for continuous replication.
Explore site link bridging in Windows Server 2012, including automatic site link bridges, transitivity, and hub-and-spoke topology, and learn to enable or disable bridging in the IP transport.
Define site link costs on a 1–100 scale and note that higher costs slow replication. Rely on the lowest-cost route for replication, with administrators shaping dedicated or bridged links.
Configure active directory domain services site replication using sites and services, adjusting the default IP site link properties, costs, and schedules, and bridge all site links for automatic connectivity.
Universal group membership caching stores a copy of universal groups on a domain controller without a global catalog, refreshing every eight hours after login when enabled in NTD site settings.
Explore configuring RODC password replication policies by using allowed and denied RODC password replication groups. See how cached credentials enable logon when the WAN link is down.
Learn to manage replication with DC diag and repadmin, running tests from domain membership to DFS replication events and viewing status and connections with a fully qualified domain name.
Manage replication in Windows Server 2012 by examining KCC events, test names, and REPP admin, and using the fully qualified domain name to view connections and sync status.
Learn to run and interpret DC diag replication tools to diagnose domain controller health, test connectivity, DNS, replication of AD components like DFS, GPOs and schema, and identify replication issues.
Use repadmin to manage and verify replication between domain controllers, run KCC checks, view inbound neighbors, and inspect replication boundaries across sites and dns zones.
Explore how srv resource records map services to domain controller hostnames in dns, including kerberos v5 and legacy app records, with forest-wide replication and domain-level dns zones for domain controllers.
Describe how an SRV record encodes the service name, port, protocol (TCP or UDP), and the host performing the service, mapping to the domain controller in a host-record hierarchy.
Examine how a Kerberos service record relates to domain naming, site registration in DNS, and TCAP over UDP, illustrating how the key distribution center operates within a Windows server environment.
Broadcasts DNS queries for domain controllers, pings responders to pick a suitable controller in the target site, and caches its name and site for the logon process.
Discover two methods to extend active directory to the cloud with server 2012: sync with on-premises AD and cloud-based AD, plus AD DS, AD FS, and AD RMS.
Assess Azure considerations for cloud-based active directory, including virtualization limits, rollback risks, UPN generation ID, time synchronization, and virtual domain controller constraints.
Implement Azure by guiding you through creating a cloud Active Directory, management portal, a trial, domain setup, user creation, and apps and DNS integration with your directory.
Verify and monitor DNS configuration; ensure clients query domain controllers and service records exist. Deploy AD integrated zones and a global names zone to replace WINS and support replication.
Master the core Active Directory structure—forests, domains, domain trees, trust relationships, sites, and replication—while creating user accounts and computer accounts and exploring federation, certificate services, and RMS.
Explore Active Directory Federation Services to connect two organizations, enabling partner and customer collaborations; learn identity federation, claim rules, claim provider trusts, and other federation configurations for forest relationships.
Explore active directory federation services, enabling cross-domain single sign-on, identification, and authorization through federated trusts across domains or forests.
Explain Active Directory Federation Services, identity federation, and claims-based single sign-on for apps. Discuss Windows Server 2012 AD FS version 2, WS-* architecture, and passive and smart client support.
Explore Windows Server 2012 authentication policies for federated services, detailing methods for external and internal access, including Windows-based, forms-based, and certificate-based authentication.
Discover multi-factor authentication, combining username, password, and a certificate to secure web access. Learn how certificates, phone verification, and mobile apps enable internal and external multi-factor authentication, including cloud-based flows.
Configure federated services by applying claim rules—the business logic that governs incoming and outgoing claims and authorization rules for relying parties—while understanding provider trust and relying party trust.
Understand how a claims provider trust links a federated server and a claims provider, defining how claims are processed and credentials issued, and configure it with metadata or manual setup.
Discover claims based identity, separating authentication from authorization across applications and directories. A security token carries user email and group claims to determine access.
Explore how web services connect applications via interfaces, using soap web services description language, and enable developers to create custom tags and register services with UDD within X Files.
Explore new federated services features in Windows Server 2012, including integrated server role installation, PowerShell commands, and dynamic access control integration.
Show how single sign-on works inside an organization, tracing a web login from a perimeter network client to a federation service proxy, federation server, AD authentication, claims, and token delivery.
Explains business-to-business single sign-on using federation servers to redirect via cookies, authenticate via Active Directory with Kerberos or integrated authentication, and issue a digitally signed token with user claims.
Identify prerequisites for adfs deployment: active directory services (ADAM/AD LDS), SQL Server 2005+ or attribute stores, domain-joined federation servers (not domain controllers), a perimeter proxy, DNS, and ports such as 389.
Configure certificate requirements for Windows Server 2012, covering the WCF message service, SSL certificate, and token signing and decrypting certificates.
Learn the AD FS components: the federation server issues and validates claims, a per-forest federation service is required, and an optional perimeter proxy adds security with claims rules.
Explore how the AD FS components interact, including the attribute store, claim provider, home domain token, relaying party, and claims rules, for secure federation across organizations.
Examine AD FS components, including the relaying party trust that provides user claims (names, groups, email), SSL certificates and metadata for token issuing, plus WCF endpoints.
Install and configure Active Directory Federation Services using the wizard, set up the database and certificate, and establish trust with the other domain via relying party and claims trusts.
Enable multi-factor access control using Active Directory Federation Services, issuing authentication claim rules that either permit or deny access based on matching incoming claims.
Configure multi-factor access control in AD FS on Windows Server 2012 R2 to permit or deny per application based on user, device, or network location, using claim language.
Explore the claim types available in AD FS on Windows Server 2012 R2, including operating system version, IP address, group, given name, email, and certificate issuer.
Enable enterprise control over personal devices with workplace join, letting admins manage access to resources by user, device, location, and application via the device registration service.
Register workplace joined devices from any internet location using the device registration service in the Active Directory federated services role. Issue a certificate representing the device identity.
Shows what happens when you don't join a device to workplace join, including credential prompts and no single sign-on.
Join your Windows device to a corporate network by signing in, navigating to PC settings, network, workplace, and entering your user credentials to enable device management.
Learn how to join your iOS device to the workplace by installing a profile via Safari, entering a required PIN to unlock, and viewing the profile in settings general and profiles.
Active Directory Federation Services enables two organizations to securely share a web application by authenticating users, granting a token, and forming a user claim for access.
Delve into file and storage services for Windows Server 2012, covering advanced file services, discretionary and dynamic access control lists, branch cache, file server resource manager, and advanced storage concepts.
Storage services in Windows Server 2012 let you set up and manage one or more file servers as central network locations to store and share files with users.
Enable work folders as a single access point for work files on PCs and devices, with offline access and central server sync, plus security policies like encryption and lock screens.
Configure work folders through the server manager role service for file services, enabling sync shares, monitoring, and management, with Windows 8.1 client integration and a forthcoming device app.
BranchCache offers local caching at branch offices to improve application performance, with hosted cache on a server or a distributed cache where clients share content per subnet.
Explore Windows server 2012 r2 smb enhancements, focusing on smb 3.0 file transfers, performance, and bandwidth management for scaling file server environments, with optional legacy browser services support.
Install the BranchCache feature and configure client computers, either through Group Policy or the shell, to enable BranchCache for network content hosting.
install branch cache feature on server, start the service, enable via group policy for file shares, and configure a hosted cache server with 5 percent disk space using net shell.
Enable the client side branch cache in distributed mode, mindful of firewall rules; configure via group policy (computer configuration) or via netsh and PowerShell bc distributed or bc hosted server.
Configure client firewall rules via the default domain policy to enable branch cache, using predefined inbound rules for content retrieval and peer discovery, then apply policy domain-wide.
Configure the main office domain controller for BranchCache, install the rollover feature on DC1, enable hash publications for BranchCache via local group policy, and verify the feature is installed.
Demonstrates simulating a slow link to a branch office with local group policy editor. Configure policy-based quality of service and outbound throttle to 100 for all apps, any source IP.
Create a group policy object and link it to an organizational unit with client computers to enable distributed cache mode or hosted cache mode, using computer configuration policies or PowerShell.
Apply discretionary access control in Windows Server 2012 using conditional expressions tied to group membership and Active Directory attributes to secure all files organization-wide, not per folder.
Utilize discretionary access control as a central policy to manage and audit access across file servers, enabling reporting and security, with access denied remediation and owner-directed fixes.
Create discretionary access control claims about a user or computer using Active Directory attributes, with user claims from domain controllers and device claims from domain-joined computers across federated services.
Define resource properties to classify files by attributes such as confidential, payroll, or legal, then create classification rules in Active Directory administrative center using the resource properties container.
Explore how discretionary access control uses Kerberos tickets and access tokens, with Active Directory issuing claims based on attributes like title, enabling domain-level access decisions.
Explore domain controller requirements for Kerberos-based device claims in Windows Server 2012, including fsrm, file servers reading claims and device authorization, Windows 8 or newer prerequisites, and token condition evaluation.
Enable KDC support by configuring a group policy object under computer configuration policies, enabling Kerberos armoring, dynamic access control, and the option to provide claims or fail on armored requests.
Create certificate-based claims by using Active Directory Certificate Services and the PowerShell module, storing claims in the AD configuration partition and mapping attributes from computer and user accounts.
Enable pre-defined resource properties such as department and confidentiality, or create your own with value types including date and time, text, number, multivalue, ordered list, single value, or yes/no.
Configure central access control rules by defining a name and description, evaluating conditional expressions for user and device claims, setting a scope with and/or logic, and enabling accidental deletion protection.
Demonstrates enabling a file share for BranchCache in Windows Explorer by creating a folder, using advanced sharing and caching settings, and adding sample documents.
Configure branch cache on branch office file servers by creating an OU, adjusting group policy to block inheritance, enabling branch cache via PowerShell, and verifying status.
Explore how file server resource manager enables dynamic file classification, dynamic access control, and file screening to protect confidential data, manage quotas, and generate reports for storage usage.
Install file server resource manager, create a confidentiality rule on documents with a content classifier, adjust parameters, and verify results via a classification report.
Classify files by applying classification rules that assign properties and values, enabling discretionary access control and re-evaluating classifications on schedule or on demand.
Explore file classification properties to assign values to files, and review data types such as yes/no, date/time, number, and multi string used in databases.
Configure file classification rules by setting scope, based on folder path or content, and using patterns or regex such as three-digit dash two-digit dash four-digit strings, with case sensitivity.
Plan and implement dynamic access control by preparing Active Directory and group policy settings, creating test and management OUs, pre-staging devices, and defining user and computer claims for resource access.
Demonstrate configuring resource property definitions within dynamic access control, enabling department and confidentiality, managing department suggested values, and verifying they appear in resource property lists.
Configure central access rules and policies with dynamic access control in the domain controller's Active Directory administration center, applying department-based conditions and permissions for confidential documents.
Open group policy on the domain controller, enable access denied assistance, customize the denial message for all file types, and require user assistance.
Demonstrate manually applying classification policies to a folder, setting confidentiality and department (IT), and showing how documents inherit the folder's classification automatically.
Publish a central access policy using group policy by creating and linking a GPO, then edit under computer configuration and Windows settings to enable central access policies for documents.
Master classification management by understanding which files cannot be classified, how moves affect properties, and how Microsoft Office documents retain classifications across NTFS and cross-file system moves.
Explore storage optimization features in Windows Server 2012, including data stores for high availability, data deduplication to remove duplicates, features on demand to save space, and enhanced file access auditing.
Implement data deduplication for high-availability data stores, remove duplicates without sacrificing integrity, and schedule dedupe jobs; leverage branch cache, features on demand, and file access auditing for efficient management.
Enable iSCSI components to access storage over an ip network using standard ethernet, with optional switches and host bus adapters, and ensure firewalls accommodate tcp/ip port 30 to 60.
Explore iSCSI security components within a broader security landscape, including policy enforcement, physical and host security, user authentication, and data protection for iSCSI storage and NTFS.
Configure the iSCSI software target in Windows Server 2012, create virtual disks, and connect initiators. Learn to enable multipath IO, authenticate targets, and consolidate storage for test and development environments.
Master iSCSI target management on Windows PowerShell for Windows Server 2012, including discovering commands, connecting targets, creating virtual disks, initializing disks, and partitioning with drive letters.
Bring a 5 GB disk online from the disks page, initialize the partition table, create a volume, format it NTFS or ReFS, and assign a drive letter with a label.
Review file and storage services, focusing on branch cache and file server resource manager to boost access and admin efficiency; cover iSCSI storage access and server manager configuration.
Explore business continuity and disaster recovery strategies, examining backup options and recovery scenarios from file and folder restores to bare metal restores, and assess site-level fault tolerance.
Explore disaster recovery requirements, roll back data to any server when needed, define critical resources, risks, and recovery time objectives to align with service level agreements and business needs.
Define service level agreements by detailing uptime targets, recovery point objective, and recovery time objective, and assess how backup speed, media, and system performance impact availability and data loss tolerance.
Develop recovery plans that cover data, service dependencies, and configuration, including bare metal restores, site and disaster recovery options, and offsite backups to protect servers, services, and backups.
Discover data recovery strategies for Windows Server 2012 by preparing full backups and replication across DNS, Active Directory, and DFS. Use previous versions to restore deleted files or folders.
Learn service-level recovery by reinstalling critical services while preserving data for Active Directory, DNS, DHCP, Exchange Server mailbox, and certificates, using backups, bare-metal images, and redundancy.
Align recovery point and recovery time objectives for full server recovery, determine critical servers, and back up the full server while duplicating essential services and data.
Develop a comprehensive site recovery strategy by ensuring data backups, offsite storage, service continuity, and backed up server configurations across alternate sites.
Compare full backups back up all files and folders, while incremental backups save changes since the last full backup; recovery is slower.
Use volume shadow copy (VSS) to back up from a point-in-time snapshot, delivering a consistent state even when files are in use, and apply streaming backup for older applications.
Manage and inspect volume shadow copies with the VSS admin tool, adding or deleting shadow copy storage, creating point-in-time backups, and reviewing storage associations and shadow copy usage.
Plan backups by calculating space for full and image-based backups, forecasting growth and incremental changes, while setting retention, frequency, and recovery time objectives.
Backups contain all data, and the operator can back up even without full access. Secure backup media and off-site storage to prevent unauthorized restore anywhere, as encryption is not guaranteed.
Learn how Windows Server Backup performs full server and volume backups, system state, and point-in-time configurations, with local, remote, and Windows Azure cloud options, and recover via the recovery environment.
Learn to install and configure Windows server backup, choose between local or remote share storage, set up a backup plan (full server or custom), and perform a restore.
Create a daily system state backup at 9:00 p.m. to a shared network folder, with each backup replacing the previous and the first scheduled backup shown as active.
Learn how Windows Backup uses the VSS writer to back up apps and volumes, perform system state restores via Windows Recovery environment, and back up files on volumes or shares.
Learn to use the recovery wizard to choose the destination, resolve conflicts, and decide if permissions and junction points should be recovered with files and folders.
Perform a bare metal system restore, ensuring the disk is the same size or larger. Restore to similar hardware or create a new virtual machine from a Windows Server backup.
Restore a deleted memo using Windows Server Backup by selecting a backup from a remote shared folder, choosing the date, and recovering the Friday memo and ACL permissions.
Explore Windows Azure online backup, a Microsoft subscription service integrated with Windows Server 2012, featuring block-level incremental backups, data compression, encryption in transit, and post-backup data integrity checks.
Learn to configure Windows Azure Backup by creating a backup vault, uploading certificates, installing the backup agent, and registering the server to start backups in the backup portal.
Discover data protection manager in System Center, enabling centralized backup for servers and clients with disk-based backups, 15-minute snapshots, and protection for Hyper-V, SQL, Exchange, and cloud or remote backups.
Install DPM on a single-purpose server with no other roles. Prepare prerequisites including SQL Server, dotnet 3.5 SP1, PowerShell, Windows Installer 4.5+, single instance storage, and Microsoft application error reporting.
install data protection manager (dpm) by creating a dpm service account in active directory on the domain controller, adding it to local administrators, and running the mini setup.
Single instance storage reduces volume space by storing one copy of each file and linking changes. Use backups with NTFS version 5 or later and single instance storage filter.
Explore the Windows recovery environment, a bootable, customizable toolkit with automatic repair and troubleshooting to repair volumes online, enable image-based or system image recovery.
Discover multiple Windows Recovery Environment entry points, including Shift+restart, the settings path, and command prompt shutdown /o, plus auto-recovery after boot failures or rapid shutdowns for server rebuilding.
Explore how Windows setup integrates with the Windows recovery environment, creating partitions including a hidden one and using a wim image to enable repair during the out-of-box experience.
Explore Windows recovery environment entry points by using Shift+restart, boot from media, or startup settings to perform system repair, safe mode, and advanced troubleshooting.
Learn to boot Windows server 2012 in safe mode to isolate faulty drivers and configurations, using msconfig, f8, or DVD troubleshooting with BCDEdit to display a safe mode option.
Explore how to boot into safe mode and safe mode with networking, access recovery environments, and use msconfig and bcdedit to diagnose boot issues on Windows Server 2012.
Boot configuration data (BCD) stores all boot configurations and boot menus, independent of firmware, with edits possible via BCDEdit to adjust sequence, default, display order, and timeout.
Explore business continuity and disaster recovery for Windows server, including backup and restore, volumes and volume shadow copy, safe mode boot, Windows Recovery Environment, fault tolerance levels, and recover sites.
Install and configure Active Directory certificate services, define key terms, and explore related roles and features, including private versus public space, to roll out certificate services.
Explain how active directory certificate services implement public key infrastructure to encrypt and digitally sign data, enroll devices, verify identities, and manage and revoke certificates via root and subordinate CAs.
Explain how SSL certificates secure data in transit, verify trusted authorities, and show how the client and server derive a shared key and encrypt with the public key.
Configure SSL certificates with precision, ensuring the common name matches the access name and that clients trust them. Use SAN for multiple names or wildcard certificates for subdomains under classroom.com.
Explore issuing ssl certificates from an internal certificate authority using Active Directory Certificate Services, certificate consoles, and enrollment to request, install, and assign certificates with templates and subject alternate names.
Purchase an SSL certificate by following the vendor's identity verification and process, then create a certificate signing request on the server to generate a private key and receive public key.
Encrypts communication between web browser and web server using certificates. Creates digital signatures by encrypting a cryptographic digest with a private key and verifies with a public key.
Learn how certificates enable efs encryption using public and private keys. The system creates a file encryption key, encrypts it with the public key, and decrypts with the private key.
Explore using certificates for user and device authentication, leveraging EAP and smart cards within L2TP/IP VPN environments to secure access for mobile devices and web services.
Master the public key infrastructure, including root and subordinate CAs, certificate templates, and registration authorities, and see how public/private keys enable symmetric and asymmetric encryption with digital certificates.
Discover the certificate services infrastructure in Active Directory, including certification authority, certificate repositories, revocation, registration authority, key backup and recovery, and online responders with AIA and CDP details.
Install the active directory certificate services server role and enable options like certification authority, CA web enrollment, online responder, certificate enrollment services, and certificate enrollment policy web service.
Explore new features in Active Directory certificate services, including Server Manager integration, PowerShell support, and improved certificate requests handling with automatic renewal for non-domain computers. Benefit from virtual smartcard support, renewal enforcement in the same key, and templates up to version 4.
Explore private certificate authorities in an internal network, where administrators issue and revoke certificates with control using Microsoft certificate services; external trust requires export/import and is not by default trusted.
Understand how public certificate authorities issue external certificates, balancing cost and procurement time, and choose between familiar brands and rapid SSL for public facing devices.
Explore certificate authority hierarchies, including two-tier models with root and subordinate CAs, and cross-certification between independent hierarchies to establish mutual trust.
Learn how a standalone CA operates offline and not part of an ad ds domain, handling requests manually or via web enrollment with administrator approval before installation.
Deploy a standalone root certificate authority by installing certificate services, configuring a private key and key length, and setting the distinguished name and database locations.
Explore enterprise certificate authorities within Active Directory, leveraging group policy for certificate distribution, enrollment options (manual, web, enrollment agent, auto enrollment), and manage access via certificate templates and dacl.
Deploy an enterprise root CA by installing Active Directory certificate services, creating a new private key, configuring the enterprise CA, and verifying the certification authority in the dashboard.
Explore root CA deployment options, including offline roots and single-layer enterprise setups with subordinate CAs. Choose hostname immutability, 2048-bit minimum keys, SHA-1, five-year validity, and offline operation for multi-tier hierarchies.
Configure an offline root CA with a long CRL publishing period and publish the root CA certificates via group policy so clients receive them.
Deploy a root certificate authority by installing Active Directory certificate services on a file server, choosing enterprise CA, configuring keys, common name, and post-deployment tools in the Certification Authority MMC.
Subordinate CAs deploy certificates for users and computers, depending on hierarchy; ensure domain membership and issue secure mime certificates while enabling Active Directory sites with load balancing for fault tolerance.
Deploy an enterprise subordinate CA by installing Active Directory Certificate Services on a local server and sending a certificate request to the parent CA for configuration.
Customize CAPolicy.inf before you install certificate services or renew certificates, using optional parameters such as the AIA URL and the certificate file location.
Configure AIA and CDP extensions to publish CA information across Active Directory, web, FTP, and file servers, and order these extensions to optimize certificate lookup for online and offline CAs.
Template a certificate to save time by letting administrators customize distribution, usage, format, and contents; control enrollment with permissions and deploy templates forest-wide in Active Directory.
Explain how user template settings separate single purpose certificates for smart card logon, secure e-mail, or s mime, and how multipurpose certificates combine several needs.
Explore computer template settings, including single and multipurpose certificates for web servers and ipsec; view certificates to validate sites and enable multipurpose certificates for fs, secure email, and domain controllers.
Learn how template permissions govern certificate issuance, including read, modify, and enroll rights, and how auto enroll relies on the template's security descriptor in Active Directory.
Explore four certificate template versions from Windows 2000 to Server 2012, and learn how to duplicate, upgrade, and renew templates with advanced cryptographic options.
Modify and enable certificate templates in the certificate templates management console, duplicate and customize an exchange user template, adjust supersede settings, and configure enrollment permissions for authenticated users.
Configure certificate templates in a certification authority to issue web server and smart card user certificates, adjust validity, export keys, set subject names and application policies for secure logon.
Configure certificate auto enrollment by defining permissions and template settings in group policy, enabling automatic certificate requests and renewals for all domain computers without user interaction.
Configure auto enrollment for users via the default domain policy in group policy management, enabling certificate services client auto enrollment, renewing and revoking certificates as needed, and updating certificate templates.
Verify auto enrollment by forcing a group policy update, then check the MMC certificates console to confirm a smart card logon certificate issued to the administrator, valid for one year.
Perform manual enrollment by generating a private key, transferring the hash to the CA via text, and importing the issued certificate for offline or non-auto enrollment.
Enable a web enrollment certificate authority by installing the web enrollment role and active directory directory services. Log in, request certificate template, and receive a certificate if permissions are correct.
Learn how enrollment on behalf uses enrollment agent certificates and accounts to enroll certificates for others, constrained by security groups, with best practice to minimize agents through group accounts.
Demonstrates configuring a restricted enrollment agent by adding an enrollment agent certificate template, setting security permissions in the template management console, and issuing the certificate via the MMC certificates snap-in.
Configure credential roaming to store certificates and private keys in Active Directory. Download them on user logon and remove them on logoff, introduced with Windows 7 and newer OS.
discover how network device enrollment service (ndes) enables x509 certificate deployment for routers, switches, and wireless access points using a one-time password and the simple certificate enrollment protocol.
Understand how revoked certificates get published and how Windows clients verify certificate status using CRL locations, AIA information, and the online certificate services provider. Track the revocation process through the CRL component, path validation, local cache, and online certificate services provider checks to determine if a certificate is revoked.
Configure and publish a certificate revocation location by adding CRL distribution points and delta CRLs, adjust CA properties, and export the certificate using the export wizard.
Configure an online responder to publish certificate status via ocsp validation and support multiple certificate authorities, with prerequisites including a signing certificate and required isis installation.
Configure an online responder in Active Directory certificate services by installing the feature, setting up a certificate, configuring a responder, and managing provider properties and security policies.
Update the web server certificate using a subordinate CA, install certificate services and IIS, create a domain certificate, and bind it to an HTTPS site.
Loss of recovery keys prevents data decryption, often after OS reinstall, bare-metal install, or corrupted user profiles. Back up cryptographic keys stored in the local file system and registry.
Explore key recovery agents (kra) and how they recover a private key during certificate requests, and review key archival with recovery certificates in version 2 systems.
Configure key recovery by enabling the key recovery agent in the certification authority, issue a key recovery certificate template, enroll, archive, and recover keys.
Explore new certificate functionality in Windows Server 2012, with end-user policy to request internet certificates, TPM key ascention for TPM keys, Windows PowerShell certificate services, and backup and restore commands.
Assign a CAA administrator and a certificate manager in the CAA console, designate a backup operator for certificate stores, and configure auditing for certificate security events.
Analyze the policy module and exit module to define post-request workflows for certificate issuance, pending states, notifications, and system events within Forefront Identity Manager certificate management.
Explore the installation and configuration of Active Directory Certificate Services, learn PKI basics, and deploy certificates to users, workstations, and applications within the organization.
Explore Active Directory Rights Management Services, which extends document security to prevent saving, copying, forwarding, or printing confidential content, with emphasis on client-server and licensing requirements.
Learn how AD RMS enables extended rights for documents, controlling reading, writing, forwarding, copying, saving as, and printing across RMS-enabled apps.
Explore real-world RMS examples by safeguarding confidential payroll data with restricted access, copy, print, and forwarding controls, and applying confidential email practices in Outlook.
Install and configure the AD RMS client component via group policy or manual setup, ensuring compatibility with Windows Vista, Server 2008, Exchange 2007, SharePoint 2007, and Office 2003 or newer.
Understand that Windows rights management requires an additional license separate from Windows licenses, with user or device CALs, and note that the RMF external connector license enables unlimited outside users.
Install and configure Active Directory Rights Management Services on file server 1, including DNS, a managed service account, and user groups, then enable licensing and authentication.
Explore RMS infrastructure components, from the RMS server and Active Directory integration to RMS aware applications, certificates, and elements like the SLC, rights account certificates, publishing licenses, and user licenses.
Assign temporary RACs (rights certificates) to users outside the domain or in a trusted forest; default validity is 15 minutes (adjustable), unlike domain licenses that last 365 days.
Learn the RMS rights management process from author to recipient, including certificate issuance, rights configurations, and license exchange with encryption of a symmetric key using the server's public key.
Configure an AD RMS cluster by selecting configuration database, service account, cryptographic mode, cluster storage, and the cluster website, then register the service connection point.
Back up and archive policy rights templates to prevent documents from becoming inaccessible if a template is deleted, and configure document properties, content expiration, and license expiration options.
Configure AD RMS templates for rights management, create read-only access with no copy or printing, and set seven-day licenses; export templates and use PowerShell to manage folders and application exclusions.
Enable offline template use by configuring a registry key and scheduled task, then access templates stored in local app data under Microsoft\DRM\templates.
Discover the super users group in Windows Server 2012, disabled by default but granting full owner rights, and ensure it is an active directory group with an assigned email address.
Enable external users and AD RMS access by configuring trusted user domains, trusted publishing domains, or federated trusts. Export and import BIN files to share licenses across RMS deployments.
Back up AD RMS by securing private keys and certificates, using manual or automated backups, and optionally image the server nightly or back up the entire virtual machine.
Log into the server, modify de-commissioning.asmx file to grant read and execute to everyone, then enable de-commissioning in AD RMS console, export server license or certificate, and remove the role.
Explore active directory rights management services, planning, backups, extended rights, app compliance, and licensing to ensure content remains accessible across trusted domains or Windows Live ID.
Wraps up configuring advanced Windows Server 2012 services, highlighting secure, redundant network services, Active Directory and Federation Services, Certificate Services, Rights Management Server integration, disaster recovery planning, and file services.
The 70-412: Configuring Advanced Windows Server 2012 Services R2 is part of the three course series required to prepare for the MCSA: Windows Server 2012 certification by Microsoft. The course enables the students to gain the skills and knowledge necessary to implement a core Windows Server 2012, including Windows Server 2012 R2 infrastructure in an existing enterprise environment. The course also focuses on the advanced configuration and services tasks needed to implement, manage, and maintain a Windows Server 2012 infrastructure.
The 70-412: Configuring Advanced Windows Server 2012 Services R2 course covers in detail the advanced networking services, Active Directory Domain Services (AD DS), identity management, rights management, Federated services, network load balancing, failover clustering, business continuity, and disaster recovery in purview of a Windows Server 2012 infrastructure. The students also able to prepare for the exam 70-412: Configuring Advanced Windows Server 2012 Services. Exam 70-412 is one of three exams needed for the MCSA: Windows Server 2012 certification.