
Upgrade your MCSA Windows Server 2012 skills to 70-417 by installing, configuring, and securing servers, managing Active Directory and Group Policy, and exploring virtualization, high availability, and disaster recovery.
Explore Windows Server 2012 to compare on-premises and cloud deployments, review standard, datacenter, and foundation editions, and learn about Active Directory, DNS, PowerShell, and installation options.
Explore on premise vs. cloud for hosting servers, storage, email, and SharePoint, and learn how cloud centralizes resources, enables remote work, and maintains high availability and version control.
Explore common cloud computing with Microsoft services and hosting options, including 365, Dynamics, and Exchange Server. Learn how you can also host your sequel server and leverage Microsoft System Center.
Discover how cloud computing splits into IaaS, SaaS, and PaaS, hosting virtual machines, applications, and databases. Microsoft services like Windows as a service, Intune, and Office 365 illustrate these models.
On-premises servers provide essential network infrastructure, enabling IP, DNS, and Active Directory logon, while supporting centralized updates through WSUS and local administration. Office 365 AD synchronization enables single sign-on.
Explore Windows Server 2012 editions: standard, datacenter, and foundation, covering licensing, unlimited VM licenses with datacenter, Hyper-V, RAM up to 4 TB, and foundation domain limits.
Windows server 2012 essentials replaces small business server, bundles exchange and sequel with client access licenses, and imposes 25 users, 50 devices, 2 cores, and 64 gb RAM.
Explore the two storage editions of Windows Server 2012 - workgroup and standard - highlighting differences in user connections, Active Directory support, domain membership, and multipoint use with licensing per two sockets.
Explore Windows Server 2012 editions, focusing on multi-point premium to support multiple users on a single host with input and output, expanding RAM, sessions, and network infrastructure.
Explore server 2012's diverse roles, from Active Directory directory services to certificate, federation, and rights management, plus application server, DNS, and file and storage services.
Explore server roles like Hyper-V, network policy server, WDS, and WSUS to secure access, deploy updates, and plan coexisting roles across hardware for efficient licensing.
Learn how Windows Server 2012 features are turned on or off to support roles, with examples like dot net framework, drive encryption, branch office support, and group policy management.
Explore how Windows Server 2012 features web server capabilities, outbound email, telnet, biometrics, PowerShell, and migration tools to plan and configure networks.
Explore server core, a minimal command prompt and powerShell interface with a reduced attack surface. It supports core roles like Active Directory and serves as a small-footprint virtualization platform.
Choose between server core and server core management installation options; server core management provides a GUI without offline conversion, while server core requires an offline image to add GUI.
Explore installation options for Windows Server, from server core to a full server with a modular GUI shell and management, enabling features to be added without a full reinstallation.
Compare DVDs and ISO files for Windows Server installations, noting USB speed advantages. Explore how ISO images can be downloaded, mounted, and used with Hyper-V virtual CDs.
Create and manage windows deployment services images to deploy operating systems to new servers via pxe boot and multicast, using the windows administration kit for light touch installations.
Explore other install options, including the System Center Configuration Manager (NCCAM) for enterprise deployment and Virtual Machine Manager templates to deploy new virtual machines quickly.
Install Windows Server 2012 Enterprise in Hyper-V from an ISO, performing a custom install on a designated drive. Configure Server Manager and set the initial administrator password for first login.
Plan a Windows server installation by choosing fresh install, upgrade, or migration, with fresh install for new hardware, and upgrade or migration to preserve files, shares, permissions, and roles.
Upgrade 64-bit Windows Server by launching setup from the original OS, migrate from 2003 to 2008, and upgrade only to equivalent or higher editions of Server 2012, not across editions.
Migrate from server 2003 to a new 64-bit server using the server migration tool, ensuring source disk space, PowerShell, and .NET framework requirements, and plan role-by-role migrations with TechNet guidance.
Identify the minimum hardware requirements for server core, including a 1.4 GHz processor, 512 MB memory, and a 32 GB hard drive, and distinguish server core from the full version.
Plan carefully before you install, then start from the install source to set language and licensing. Choose upgrade or custom, define the directory structure, and protect the local administrator password.
Learn to complete post installation tasks using server manager, set IP and computer name, join domain, configure time zone and updates, add roles, adjust firewall, and activate Windows.
Explore how to use server manager to configure firewall, time zone, Windows updates, and domain join, rename computers, and manage domains and server groups.
Activate windows by entering the product key at installation or boot, view the product ID in server manager, and re-arm via the server license manager with switches.
Discover how to perform an offline domain join for a server with limited bandwidth by provisioning a join string on a domain controller and applying it offline.
Run the best practice analyzer, configure services from Control Panel to advanced network services, and finalize DNS, Remote Desktop, and remote management settings for round two server installation.
PowerShell serves as a central management tool for Windows Server. It runs behind the scenes via scripts, complementing GUI tasks and supporting core versions without a GUI.
Discover how PowerShell uses verb-noun commands and parameters to manage servers, including setting a new ip address, interface alias, and default gateway using ipv4 and cd-r notation.
Explain features on demand delivery by search order, starting with the user-specified location or image via dism commands, then group policy evaluation, and finally Windows Update.
Override features on demand (default behavior) by using a source path with the Windows feature command in PowerShell, or specify an alternate source path during installation, or via group policy.
Learn to remove Windows feature files with the remove parameter and uninstall commands, manage offline images, and omit features such as Active Directory domain services and group policy management console.
Learn how to migrate roles from older Windows Server versions, from global catalog to file and print server roles, using server migration tools and a four-step deployment process.
Get up and running with Windows Server 2012 by reviewing its overview and basic installation for full server and server core. Preview deep dives into roles, features, dhcp, and dns.
Install and configure server roles and features using a modular, role-based approach, enabling remote management and day-to-day server communication through firewall settings.
Learn how to add roles and features with server manager, install Hyper-V, configure management tools and default locations for virtual hard drives, and manage restarts.
Explore using Event Viewer to filter, view, and drill into events across local servers and server groups, identify errors by severity, and save queries for quick monitoring.
See how to run the Best Practices Analyzer on a domain controller with Active Directory, DHCP, and DNS, and interpret BPA results, warnings, and filters to identify issues and corrections.
Discover Windows Server administrative tools, including Active Directory administration center, Active Directory Users and Computers, DNS tools, Event Viewer, group policy management, performance monitor, resource monitor, and Task Scheduler.
Enable remote management through the Windows server manager interface and PowerShell, configure sm remoting, check local server properties, and open firewall ports with netsh for remote admin.
Delegate administration in Windows servers by using the server operators group or granular permissions in Active Directory, then use the delegation wizard to scope rights by domain or organizational unit.
Plan who receives delegated privileges across forests and domains, organize them into specific groups, and define exact tasks to avoid overreach.
Explore different services in Windows Server, from basic control panel service start/stop and simple configuration to advanced services such as network services and network load balancing.
Explore advanced services in Windows Server, including network teaming, dynamic access control, network load balancing, clustering, disaster recovery, distributed Active Directory, certificate services, rights management, and federation.
Discover NIC teaming, which combines two network cards for bandwidth aggregation and traffic failover to provide fault tolerance, with switch independent and switch dependent options including active standby.
Examine 802.11ac, delivering higher speeds, throughput, and reliability with 5 GHz and 2.4 GHz, wider channels, spatial streams, and MU-MIMO. Benefits rely on hardware and operating system support, evolving.
Explore updated netsh commands in Windows Server 2012 R2 to display 802.11ac wireless support, drivers, networks, and profiles with mode and radio type parameters.
Explore how Windows Server 2012 extends wired and wireless access passwords using EAP with MS-CHAP v2, and learn to configure the registry key disable user password storing for Windows 8.1.
Demonstrate installing Windows Server Core in a virtual machine by booting from an ISO, entering a product key, and selecting the server core option for a command-prompt-driven setup.
Master the power of PowerShell as the core tool for managing Windows Server, using verb-noun commands like get user and set user, dash arguments, and case-insensitive syntax.
Shows how to work on a server core using a command prompt and PowerShell, compare CMD and PowerShell, access help, and install or remove Windows features such as DNS.
Discover how to add a GUI to server core using PowerShell to install the GUI feature, include all sub features, and specify the source.
Remove the graphical user interface from server core using server manager to remove roles and features and restart, with PowerShell as an alternative, noting GUI removal may affect dependent apps.
Install or remove a Windows Server role or feature using an offline wim image, finding the image index with get-windowsimage and applying install-windowsfeature with the proper source path.
Explore server core tools, including cmd.exe, ipconfig, PowerShell, sc config, Notepad, 32-bit registry editor, msinfo32, and Task Manager, with remote administration using graphical tools.
Learn how to list roles on server core using Get-WindowsFeature, piping to Where-Object, and filter by install state to identify installed roles.
Enable remote management to administer server core from your workstation and remotely manage other servers using Server Manager or an elevated PowerShell session to run the remote management configuration.
Explore configuring firewall settings with netsh by stepping through the netsh firewall context to enable remote admin for all, and note deprecated versus newer commands.
Configure server core with ESC and ESC config, plus PowerShell access; use cmd core menu to enable or disable features, requiring local Administrators (domain admins included) for access.
Use sconfig on Windows Server Core to configure network settings, assign a static IP and DNS, join the domain, and enable remote management and remote desktop.
Server core is not a full installation and lacks features such as Windows Deployment Services, Network Policy and Access Services, Active Directory Federation Services, and the application server role.
Discover methods to install domain controllers on server core using DC Promo and unattended answer files, covering DNS, global catalog, domain join or forest creation, and path settings.
Explore PowerShell examples for Active Directory user management: create, modify, delete users; set passwords and expiration; unlock, enable, or disable accounts; manage group memberships and computer accounts.
Explore PowerShell examples for computer management in Active Directory, including domain-joined computers, trust relationships, testing secure channel, and resetting computer accounts and machine passwords.
Explore organizational units in Active Directory as containers for users, groups, and computers, and learn how policies tailor each user’s desktop experience and access.
Explore Hyper-V and virtualization, learning to create and configure virtual machines, networks, and storage, including virtual hard drives, to build your first virtual server.
Enable remote management using a graphical user interface or command line; connect to other computers with remote shell, remote PowerShell, or remote management tools, and manage servers via server manager.
Learn to enable remote management on Windows Server using Server Manager and Server Core, adjust firewall rules, and verify configuration with sconfig and netsh commands.
Export remote management settings by locating server manager files in app data, syncing server lists and user config across roaming profiles or domain joined computers for consistent multi-machine administration.
Enable remote desktop to manage remote servers, noting the one-to-one server connection and potential lockouts. Configure remote desktop services via server manager with a checkbox on the local server node.
Enable remote desktop on standard server and server core. Configure firewall, authorize the Administrators group, and compare with the remote desktop client.
Learn about Server 2012 R2 improvements, including session shadowing for remote desktop monitoring and control, tighter Server Manager integration, and restricted admin mode that protects admin credentials.
Manage multi-server environments by creating server groups in server manager to streamline common tasks and organize servers by role, such as exchange or domain controllers, with RSAT for remote management.
Explore virtualization fundamentals and how it differs from remote desktop, including Hyper-V servers, virtual desktops, desktop virtualization, console sessions, and remote management.
Remote Desktop gateway enables external clients to access remote desktops and apps without a vpn, by installing a role or service and its associated components.
Explore virtualization with Hyper-V, hosting servers and apps on virtual platforms; learn how remote desktop access works across hardware and virtualized environments, focusing on Server 2012.
Install the hyper-v role on server 2012 and plan hardware for virtual machines, ensuring 64-bit support, slat and dep, and enough memory, disk, and network throughput.
Download, install, and configure App-V from the Microsoft Desktop Optimization Pack to isolate applications from the operating system and stream them to clients.
Explore Microsoft enterprise desktop virtualization (MED-V) for centralized management of legacy operating systems, deploying virtual machines on client workstations via Hyper-V through the desktop optimization pack.
Explore how virtualization simulates a complete virtual machine, including its BIOS, memory, processors, and devices such as scuzzy controllers, network adapters, legacy adapters, and fiber channel adapters.
Create virtual machines with Hyper-V, allocate memory, attach virtual disks, and use consistent naming reflecting domain and site for easy management.
Plan Hyper-V with careful defaults for settings, virtual switches, and virtual storage networks to optimize virtual hard disk space. Configure VM settings, Nguma memory, live migrations, and replication.
Understand Hyper-V dynamic memory, setting a minimum memory with startup memory and smart paging to handle spikes, and use PowerShell to configure the parameters.
Load integration services in the virtual machine, insert the integration disk, and install utilities that enable data exchange, heartbeat, backups of snapshots, and improved OS shutdown.
Configure start and stop actions for Hyper-V virtual machines to control automatic startup, save state options, or safe shutdown after interruptions.
Track resource usage across virtual machines by monitoring CPU, memory, disk space, and network traffic, and manage Hyper-V resource metering with PowerShell commands like Enable-VMResourceMetering and Measure-VM.
Explore virtual disk types for Windows Server, including dynamically expanding disks, and fixed-size VHD/VHDX, with pros, cons, overhead, and how compression or compacting affects size and performance.
Discover how pass-through disks provide exclusive access to a physical drive for a VM, using offline disk handling, add-drive settings, and differencing disks to create parent and multiple children.
Convert a fixed virtual hard disk to a dynamic disk, compact the dynamic disk to its minimum size with PowerShell, and optionally convert it back to a fixed disk.
Shrink virtual hard disks via the Hyper-V edit virtual hard disk wizard. Expand dynamic or fixed disks, but apply changes through the wizard rather than a property sheet.
Compare the legacy vhd format with the vhdx format, noting the 2 terabyte limit and up to 64 terabytes, improved performance, and metadata logging for stability on Server 2012.
Explore how differencing disks reuse a parent image to save space and view variations of the operating system with updates, while learning to inspect and relink parent paths in Hyper-V.
Master essential maintenance for virtual hard disks, focusing on backups and snapshots, and converting between fixed and dynamic, plus moving between HD and VHDL X formats.
Explore multiple methods to create virtual hard disks in Hyper-V, from the Hyper-V manager wizard to independent VHD creation, disk management, diskpart, and PowerShell.
Deploy virtual hard disks to a network file share using smb 3.0 on a server that supports it, such as Windows Server 2012.
Explains differencing disks and snapshots. Shows how a base template forms a chain with dynamic disks and writes on the last disk.
Select the virtual network type—private, internal, or external—to control VM visibility; external binds to a physical adapter and stores configuration on the Hyper-V server.
Explore extensions for virtual networks, including capture tools and the Endace driver, to monitor packets across a virtual switch, and apply the Microsoft filtering platform to control data flow.
Explore Hyper-V network settings through the Hyper-V manager, creating and managing virtual switches (internal and external) for classroom lab environments, while planning network isolation and DHCP concerns.
Explore how virtual adapters attach virtual machines to internal, external, or private switches with VLAN IDs, bandwidth control, and dynamic MAC allocation, DHCP guard, and IPsec offload on synthetic adapters.
Enable legacy network adapters to boot a VM from the network via pixie boot, downloading the OS from Windows deployment server; hardware acceleration and VM queue configuration are not supported.
Learn to configure Hyper-V networks using the local administrators group and the Authorization Manager, and understand VM network options, including legacy adapters that work without a VM driver.
Explore how the virtual machine network adapter driver emulates a 10/100 network interface card, supports pixie boots, and does not support legacy 64-bit Server 2003 or Windows XP VMs.
Learn how external virtual networks in Hyper-V affect the physical network adapter and host connectivity, and how to manage internal networks and temporary disruptions during setup.
Master virtualization concepts by configuring Hyper-V memory, smart paging, resource metering, and virtual machine storage, then design virtual networks with MAC addresses, network isolation, and virtual network adapters.
Install and administer Active Directory as a domain controller, manage domain controllers, explore Server Core, and configure DNS resolution and DNS rules within a functioning IP network.
Explore Active Directory as a networked database hosted on domain controllers. Learn how the global catalog enables faster searches and how read-only domain controllers support branch offices.
Explore domain structures and forest concepts, from the root domain and schema master to domain trees, subdomains, and two-way transitive trusts that enable cross-domain access.
Explore the Active Directory schema, covering object classes like user, group, and computer, their attributes such as sid and sam account name, and mandatory vs optional attributes.
Explore the domain container and built-in container, learn where default groups land, and identify the users, computers, and domain controllers OUs with group policy applied to lock down their security.
Explore how sites define replication boundaries in domain structures, enabling controlled updates between domain controllers across offices, with configurable intervals from immediate to daily, including compression.
Explore how users, computers, and resources across sites in the Sandra classroom domain are organized, with site-specific group policies, group memberships, and replication control.
Explore the role of the domain controller as the central secure store for domain objects, replication across domain controllers, and how partitions and forest-wide data govern authentication and domain structure.
Learn how domain controllers host and replicate the directory services database and the SYSVOL share, handling group policy, logon scripts, Kerberos, and global catalog integration through the schema.
Explore deprecated features in Server 2012 related to AD DS, including 80 prep 32, DC promo, and the elham hash used by LAN Manager.
Administrators can be associated with Active Directory to enable second-factor authentication, strengthening identity proof. Users access apps from anywhere via a web application proxy and multi-factor access control.
Learn how workplace join lets users access apps and data from personal devices via the device registration service, without domain join, while enabling single sign-on with AD Federation Services.
Identify forest-wide fsmo roles—the domain naming master and schema master—in the forest root domain; assign infrastructure master and pdc emulator for domain objects, group policy, time, and security tasks.
Explore how to plan and upgrade forest and domain functional levels in Windows Server 2012, including schema upgrades with adprep, forest prep, and aligning domain controllers to 2012 rules.
Explore domain and forest functional level options, understand rollback limits to 2012 and 2008, and emphasize careful planning and backups to avoid fear of rollback.
Enable the Active Directory recycling bin on Windows Server 2012 to limit rollback options to 2012 or 2008. If the bin is not enabled, you gain more rollback choices.
Explore forest and domain functional levels, including two Server 2012 levels, and examine protected users, Kerberos pre-auth, four-hour ticket lifetimes, and force base Active Directory policies shaping authentication isolation.
Upgrade the forest functional level to 2012, ensuring new domains operate at 2012 minimum, with rollback possible only if the Active Directory recycle bin is enabled.
Locate domain controllers using dns service records and log in with domain credentials to obtain an access token, which grants access to local machines, network resources, and active directory.
Explore dns and active directory resource records, including forward lookup zones and service records, to locate domain controllers by site and understand reverse lookup zones mapping ip addresses to names.
Explain how the logon process uses a ticket granting ticket to authorize access to local and network resources, with each server re-validating permissions.
Plan carefully when installing a domain controller, choosing whether to join an existing domain or create a new domain and forest, and ensuring accurate administrator credentials and domain naming.
Collect administrator credentials, the domain name, and the full DNS name of the Active Directory domain, before installing domain services; then plan DNS naming, NetBIOS name, and DNS zones.
Demonstrates installing Active Directory domain services and a domain controller using server manager, following a checklist for a proper computer name, static IP, and DNS.
Upgrade a current domain controller using Windows Server 2008 setup, performing a full upgrade with language selection, license acceptance, and the upgrade option.
Perform a clean installation of Windows Server domain controllers, join to the domain, install the directory services role, create a new domain, and promote to domain controller.
Install a domain controller at a remote site using install from media, backing up Active Directory from a writable domain controller and restoring it via USB media to speed replication.
This demo shows how to demote a domain controller and remove the active directory service and DNS roles from a server, with credential prompts and reboot considerations.
Explore Active Directory management tools for domain controllers, including users and computers, sites and services, domains and trusts, the schema tool, and remote server administration tools.
Create and manage user accounts as security principals in Active Directory, apply naming conventions, and control access across domain and local SAM accounts.
Active Directory prevents duplicate accounts, so define a naming convention and upfront strategy for unique user accounts. Use logon names and forest-wide UPNs to distinguish users across organizational units.
Identify the attributes of users, including login name, password, and account flags. Explain roaming or local profiles, home folders, login scripts, and group membership to shape user configuration.
Understand automatic account lockout from failed password attempts, how an admin can unlock or remove the lock after a policy timeout, and how disabling preserves accounts for future reactivation.
Use directory service command line tools from an elevated command prompt to create, query, edit, move, and remove objects—such as users, computers, or groups—within directory services.
Groups collect users, computers, and nested groups to control access to files and shares across servers; security groups grant permissions, while mail-enabled security groups serve as distribution groups.
Explore group scopes and their use across a forest, creating universal, global, domain local, and local groups to grant permissions and manage rights in multi-domain environments, while considering replication issues.
Explore admin groups in Windows Server, including enterprise admins, schema admins, domain admins, and server, account, backup, and print operators. Learn how protected groups safeguard memberships and enable delegation.
Activate the protected user security group introduced in Server 2012 to limit credentials during network sign-ins from non compromised computers, protecting domain controllers.
Enforce Kerberos-only sign-on for protected users, with no TLM digest authentication or credential SSP, passwords never cached, no weaker encryption, and delegation restrictions, plus a configurable four-hour lifetime.
Identify how special identities determine user rights and permissions across anonymous, authenticated, and guest logins, and distinguish interactive versus network access in Windows Server.
Computer accounts authenticate to the domain with a logon name and a domain password updated about every 30 days, while administrators manage them via Active Directory and organizational units.
Troubleshoot computer accounts by diagnosing trust and password synchronization issues, reset the trust or passwords, and use Active Directory tools or command line to fix missing or deleted accounts.
Reset the trust relationship for a computer in Active Directory using DS, netdom, or PowerShell to re-sync its password and restore group policy access.
Master csvde import practices by using the same syntax, naming the import file, and applying dash k to ignore errors, so the import completes and exposes duplicates in Active Directory.
Learn to use ldifde to import and export Active Directory objects by defining change types, distinguished names, object classes, and attributes such as common name and email.
Manage Active Directory with PowerShell to perform bulk operations, including creating, modifying, importing, and moving user accounts by piping to set commands.
Install and administer Active Directory, configure domain controllers, and add or upgrade a domain controller to secure and manage a new network.
Deploy, manage, and maintain servers as a whole unit, learn to monitor real-time performance, view events and alerts, and troubleshoot to keep any hosted applications or roles running.
Explore the windows deployment services (wds) server roles, including the transport server for multicast image transmission and the deployment server for remote operating system installations, and Pixi for custom setups.
Plan and implement Windows deployment services for network-based installations by pulling full images across the network, using an NTFS partition and managing via Server Manager or PowerShell.
Compare functionality across Windows Server 2008, 2008 R2, and 2012/2012 R2. Highlight image types like WIMs, VHD, and VHDX, plus unattended installs and VHD boot options.
Discover how to deploy Windows images efficiently using WDS, EFI boot images, and IPv6 multicast, reducing deployment time across Windows Server 2008–2012.
Explore driver provisioning improvements from 2008 to 2012, including hardware-based deployment, manufacturer model driver groups, and Pixi providers, with EFI and network boot for Itanium 64-bit systems.
Plan prerequisites for WDS deployment by validating AD DS, DNS, DHCP, and NTFS. Ensure bare metal boots via network with an IP and local admin rights to install the role.
Install WDS deployment and transport server in standalone mode without active directory, and ensure DHCP, PXE, DNS, and an NTFS image volume, with local admin rights.
Install Windows Deployment Services by using the Roles and Features Wizard in Server Manager, then configure deployment or transport servers with prerequisites like Active Directory, DHCP, DNS, and NTFS.
Demonstrates installing a Windows feature on Windows core using PowerShell and WDSUTIL, including adding images, using help for syntax, and enabling remote management tools.
Explore four image types for Windows deployment: pre installation environment, capture image, install images, and discover images, to boot, capture an installed OS with apps, and install on non-PXE devices.
learn to deploy images with windows deployment services by configuring boot images first, using boot.wim from sources, and adding install images via wdsu with image groups.
Demonstrate configuring Windows Deployment Services, adding a boot image, and managing boot and install images, prerequisites, and server partition choices for a lab environment.
Explore how to set up WDS install images and image groups, configure security permissions, and define client naming policies for Pixi boot deployments.
Identify client prerequisites for installing images, including pixie boot capability, 512 megabytes of RAM for Pixi operating system, and creating a local user account on the WDF server to install.
Configure the boot menu order for boot and install images with the WTS NMC snap-in by setting the image priority; the lowest value displays first.
Drill down through the boot images, right-click to create a capture image, name and locate it, add the image to the WTS server, and provide a clear description.
Create custom install images by ensuring adequate disk space and membership in the local Administrators group NWTS.
Create a reference computer with the OS, updates, apps, and drivers; generalize with sysprep for the out-of-box experience, then capture a boot image via PXE for WDS deployment.
Learn to create and use a Discover image to install the operating system on Pixi-enabled computers, saving it to CD, DVD, or USB, then deploy via the WTS server.
install the Windows assessment and deployment kit, log on as a local administrator, and use deployment and imaging tools to prepare media sources and copy discover.wim and boot.wim.
Demonstrates creating a discover image in Windows Deployment Services, preparing boot media, and using the deployment tools environment to copy the image into a WIM for bootable media.
Master unattended installations by using two files for legacy and newer systems, including cist prepped INF and unattended sml Excel file, stored on the WTS server to automate UI prompts.
Copy your file to a subdirectory of the remote install folder; right-click the image to set its properties and enable unattended installation, then browse to the file you created.
Explore a sample unattended file for Windows deployment services, detailing the credentials, image selection, and install to disk steps like disk 0 and partition 1 (C-Drive).
Choose one of the boxes; if you haven't chosen either of those boxes, it will only start manually, and you must push it out to this client.
Demonstrates configuring multicast transmissions in Windows Server, assigning image groups, choosing auto cast or scheduled transmissions, and organizing images for workstation deployments.
Demonstrates adding a second install image and a new boot image, verifying source integrity, naming variants, and using multicast transmissions to schedule deployments.
Add driver packages to boot images using the WTS console or the WDSUTIL command line; specify the image, type, architecture, and the driver package or package ID, with verbose mode.
Explore tools to create and service images, including the WTS snap-in, server manager, WDS, Windows EDK, and netsh, for managing image and answer files offline or online.
Learn how WSUS optimizes patch management by centralizing updates, preventing all clients from downloading updates at 3 a.m., and enabling the server to approve and distribute only approved updates.
Configure update management to handle patching through group policies and client-side targeting, with test and live groups, phased deployments, and WSUS synchronization, approval, and removal options.
Identify prerequisites for installing wsus 3.0 sp2, including supported server platforms and service packs. Ensure .net framework 3.0, report viewer redistributable, and a sql or windows internal database in place.
Approve updates by syncing WSUS, right-clicking to approve for a group, then rely on client schedules and group policy to deploy, while testing thoroughly to prevent breakages.
Adopt a disciplined WSUS management process: identify required updates, select products, schedule and auto-approve deployments, organize tests and phases, and review status and reports to keep networks up.
Configure clients to use a WSUS server via group policy for automatic updates, set update frequency and restart behavior, and organize computers with organizational units, sites, and domains.
Create a wsus internet group policy object to manage automatic updates, enabling automatic download and schedule install, and specify the update service location for centralized deployment.
Install and configure the Windows Server Update Services role, set up the WSUS database and data path, synchronize with Microsoft Update, and manage updates, groups, and automatic approvals.
Prioritize server monitoring to observe hardware and software responses, detect issues or future problems, and predict needs such as disk space.
Monitor servers with a variety of tools, including virtual machine usage, Event Viewer logs, and network monitoring. Use event subscriptions to forward events and capture packets to analyze server activity.
Explore Performance Monitor to collect, view, and save baseline data by adding counters for memory, processor, network, and disk, and generate reports.
Explore performance monitor to analyze processor, memory, disk, and network counters for troubleshooting. Learn to interpret percent processor time and processor queue length to identify bottlenecks.
Demonstrate how to create data collector sets in performance monitor to collect baseline server data, focusing on processor, memory paging, disk queue length, and network activity.
Demonstrates monitoring virtual machines with Hyper-V by enabling VM resource metering, viewing per-VM statistics like RAM usage and network inbound/outbound, and resetting or disabling metrics via PowerShell.
Discover insights from event logs by filtering with custom views to spotlight unsuccessful logons, then configure event subscriptions to forward logs to a central collector.
Demo shows how to use event viewer to inspect application, security, and system logs, filter by level and source, and create custom views.
Configure event forwarding by enabling WinRM subscriptions, setting up the Windows Event Collector service, and adding collector and source computers to appropriate administrators groups, then view subscriptions in Event Viewer.
Monitor your network infrastructure with performance monitor to track DNS and DHCP traffic, packet loss, and responses, and drill down into infrastructure services for deeper performance insights.
Learn to monitor servers in real time, track performance events across virtual machines, and troubleshoot by benchmarking for optimal performance while staying vigilant for changes.
Explore DNS components like zones, namespace, and records, and how local DNS servers resolve queries with recursive and iterative methods across zones, top level domains, and fully qualified domain names.
Explore how dns queries resolve names through authoritative and non-authoritative responses, using caches and root hints, with recursive and iterative approaches.
Explore DNS zones and Active Directory–integrated zones on Windows Server, troubleshoot DNS replication and zone transfers, and manage primary, secondary, and stub zones with name server configurations.
Compare stub zones and conditional forwarders to explain dns resolution. Stub zones keep a server aware of authoritative for a child zone, while conditional forwarders forward queries to a server.
Explore common DNS resource records, including A and IPv6 address records, PTR reverse lookups, CNAME aliases, MX mail exchangers, and service records, along with start of authority concepts.
Navigate dns zones and records in the dns manager to understand forward lookup zones, host and mx records, alias mappings, and primary and secondary zones.
Explore how DNS forwarding resolves queries from a local DNS server using route hints or forwarders, performing iterative and recursive lookups to obtain the final IP.
Learn the dns naming rules: you may use letters and numbers with hyphens, names are case-insensitive, and underscores or other special characters are not allowed, as in examples like sjb-ea.com.
Examine internal versus external namespaces and how internal DNS resolves domain resources, while external DNS handles internet resources like www and mail. Understand how A and MX records prevent conflicts.
Explore DNSCMD basics, create and manage zones, and perform zone transfers between primary and secondary servers, including Active Directory integrated zones and domain controller replication.
Demonstrates troubleshooting DNS name resolution using ping by name and Resolve-DnsName in PowerShell. Shows querying A and start of authority records, reverse lookups, and recursive versus forwarder behavior.
Explore DNS scavenging options, adjust zone and record time to live, enable aging and scavenging, and configure non refresh and refresh intervals to manage stale host records.
Configure DNS round robin to balance a hostname across multiple IP addresses, enabling fault tolerance and resource sharing, and enforce secure dynamic updates so only domain clients can register hostnames.
Learn to view and clear the local DNS cache on Windows using ipconfig /displaydns. Diagnose DNS client configuration with ipconfig /flushdns.
Learn how DNS zone information is stored either in text files or in Active Directory. Experience how Active Directory integrated DNS replicates zone data across the domain.
Explore the network policy server infrastructure and how network access protection uses health validators, health policies, and nap enforcement to ensure vpn clients are cleared before network access.
Explore remote access methods to connect from outside the organization, including direct access, traditional VPN, site-to-site, routing remote access, and the web application proxy.
Navigate routing and remote access, including routing, direct access, and VPN, and see how Active Directory domain services, certificates, IPsec, DHCP, NAP, and health policies govern secure network access.
Install and manage the remote access role, choosing direct access or routing and remote access. Use remote access management tools and PowerShell commands for configuration.
Install and configure the remote access role to enable vpn, dialin, and routing components; use wizard to set vpn, dialin, encryption, authentication settings, and understand nat masking and routing policies.
Install routing and remote access on a server with two network adapters. Configure direct access and VPN using the post-deployment wizard, set IP address ranges, and generate group policies.
Explore PKI components, including public and private keys, digital certificates, certificate authorities, templates, revocation lists, auto enrollment, AIA, distribution points, and HSMs in Windows Server environments.
Understand how DHCP ties remote access to a pool of 10 addresses. The server uses the first address and allocates the remaining nine to clients with certificates enabling domain security.
Explain the properties of a vpn connection: encapsulation with a routing header and authentication at user or computer level via ipsec and ike with computer certificates, and data origin authentication.
Explore tunneling protocols for VPN connections, including PPTP and GRE encapsulation, L2TP, IPsec with DES and 3DES, MPPE encryption, IKE and IKEv2, SSTP SSL, and certificate-based authentication on Windows servers.
Enable VPN reconnect with Internet key exchange to automatically reestablish mobile VPN sessions as users move between networks, transparently across Windows client and server platforms.
Explore advanced routing and remote access configuration in the remote access management console, covering vpn setup, port configuration, ipv4 and ipv6 routing, and detailed logging.
Review firewalls and packet filters, set security policies and logging levels. Configure VPN ports and create and distribute a connection manager profile with the connection manager administration kit.
Explore CMAK setup to create and deploy VPN profiles and dial-up entries, configure security options, and package the kit for easy sharing and Windows feature deployment.
Define a network policy by evaluating conditions, constraints, and settings, checking group membership, health policies, time restrictions, and authentication methods before applying connection settings.
Explore the properties of a network policy, including naming, enabling, access levels, and connection methods, along with dhcp server, vpn, dial-up, health registration authority criteria, and age cap server.
Learn how network policy processing uses a flowchart to determine access: no policies reject; a matching policy may deny; an allowed policy permits the connection.
Direct access, now part of routing and remote access, lets clients reach internal resources over the internet with end-to-end authentication, bidirectional access, and support for multiple protocols.
Explore the first deployment phase of direct access, focusing on configuring remote access infrastructure, including routing, firewalls, certificates, DNS, Active Directory, group policies, and network location service to validate deployment.
Join the server to a Windows 2012 domain, providing direct access for clients to internet resources, with a wizard-based setup that reduces IP addresses to one, unlike DirectAccess 2008 R2.
Describe the required client infrastructure: domain-joined pcs, Windows 7 Enterprise or Windows 8 Enterprise with online domain join, direct access over IPv4/IPv6 with IPsec, and name resolution policy tables.
Identify internal resources as infrastructure, enabling direct access for IP version 6 applications with NAT 64 and DNS 64 support for apps, and Forefront Unified Access Gateway for backward compatibility.
Configure an active directory domain at a 2003 functional level, implement group policy, and deploy dns to support direct access and isatap across the forest.
Examine PKI certificates and Network Access Protection (NAP) to enable two-factor authentication, certificate-based tunneling, and compliance in Windows Server environments.
Explore the name resolution policy table (NRPT) and its DNS namespace; client rules route queries until a match, else route to local DNS servers.
Explain the name resolution policy table and the resolution order—local cache, hosts file, policy table, then DNS servers—plus DNS search suffixes and handling single label versus fully qualified names.
Discover how direct access clients resolve FQDNs, obtain certificates, verify revocation via CRL, switch to domain firewall profiles, and route DNS through the domain after logon.
Direct access lets external clients reach internal resources by resolving fully qualified domain name through name resolution policy table and IPsec over an IP tunnel to the direct access server.
Learn to set logging levels—errors, errors and warnings, or all events—then enable tracing with net shell and registry settings to diagnose Windows Server issues.
Troubleshoot VPN connectivity using logging and ping to distinguish name resolution from actual connectivity, inspect client and dial-in properties, verify password status, and ensure VPN authentication protocols match server configuration.
Identify and troubleshoot common error codes in Windows Server connectivity, including error eight hundred for unreachable servers, wrong IP addresses, blocked firewall ports, and encryption mismatches causing VPN handshakes.
Understand how network address translation hides internal IP addresses by translating outbound requests through a router and using reverse translation to route responses.
Configure remote dial-in settings by applying NAP and NPS policies with conditions and profiles to allow or deny access, and verify caller ID while managing DHCP pool or static routes.
Explore network policy and access services to enforce health policies, verify clients before network access, and centralize policy management using radius for wireless access.
Explore network policy server tools using the NMC console. Export the full configuration with net shell or Windows PowerShell, and display or save it to a text file.
Define radius clients as the devices attaching to the radius server rather than workstations, forwarding VPN, dial-up, and wireless access point requests via authentication switches and remote access servers.
Discover how a radius proxy authenticates and authorizes outsourced services like vpn and dial-up, supports non-domain and trusted-domain accounts, uses a non-windows database, and handles large connection volumes.
Explore how certificates serve as digital identities trusted by sources such as your domain administrator or Verisign, enabling internal or external authentication through EAP-TLS, PEAP over TLS, and MS-CHAPv2.
Import the certificate authority certificate from a trusted root CA into the client’s local certificate store; EAP uses server certificate stores and may use a smart card’s user certificate.
Monitor NPS by enabling event logging to record user authentication, accounting requests, and connection statistics. Set logging levels, capacity, maximum log size, and enable radius class attribute and sequel logging.
Configure and evaluate the network policy server infrastructure, including network access protection, system health validators, and health policies, to ensure external-access machines meet security standards.
Configure and manage Active Directory by deploying domain controllers, enabling universal group membership caching, transferring FSMO roles, using read-only domain controllers and cloning, and backing up and optimizing the database.
Learn how to prepare and clone a virtual domain controller with a clone config file, including setting a static IPv4 address, DNS, and validating the clone allow list with PowerShell.
Discover the ad ds forest structure, where multiple domains share one schema, with the forest root domain at the top and enterprise administrator groups.
Explore how the Active Directory schema defines object classes and attributes, including unique object types like computer and reusable attributes such as description for users, guiding the forest's directory structure.
Explore default containers in Active Directory: domain container for users and groups, computers container for new accounts, and the domain controllers OU for domain controller computer accounts.
Organizational units group users, groups, computers, and other objects within a domain, enabling targeted group policy, desktop design, and security configurations; they also support delegated administrative rights for department-specific tasks.
Explore virtualized domain controllers using Hyper-V, enabling safe snapshots and cloning for rapid deployment and testing. Learn why modern virtualization supports domain controller resilience and easy provisioning.
Clone a virtual domain controller by ensuring the PDC emulator role sits on Windows Server 2012. Export, import via Hyper-V, and boot as new domain controller with automatic save cloning.
Create a dc clone config SML file with server configuration, place it in the source domain controller's TADS subdirectory, export or copy, then import into Hyper-V to create a VM.
Explore DcCloneConfig.xml syntax for cloning domain controllers, including SML file parameters, IP version 4 and 6 dynamic and static settings, offline execution, and home computer name.
Perform safe backup and restore of domain controllers using VM snapshots on Server 2012, synchronizing data and replicating Active Directory changes, restoring controllers at a time to avoid replication loss.
Learn PowerShell commands for Hyper-V snapshot management, including creating and exporting VM snapshots, listing checkpoints, and performing get, remove, rename, and restore operations.
Explore active directory directory services as the domain's core structure, detailing domain controllers, global catalog servers, read-only domain controllers, partitions, schema, domain trees, forest, sites, replication, and organizational units.
Plan the active directory structure and batch-create many user accounts from a spreadsheet turned into a comma separated value (CSV) file, then import them with the import/export utility.
Explore common LDAP attributes used by the Active Directory protocol, including given name, surname, user principal name, display name, and mail, and how case sensitivity shapes attribute mapping.
Explore common LDAP attributes for user objects, such as postal code, country code, member of, expiration, title, department, and company, and discover hundreds more with the attribute editor.
Explore advanced active directory attributes by viewing computer and user properties, using the attribute editor, and examining delegation, password replication, and department and location fields.
Export active directory users with csvde by setting a start point and optional filter, and include distinguished name, object class, samAccountName, surname, given name, and user principal name.
Learn how to import accounts with ldif by preparing a formatted file, selecting add or modify types, and importing via the command prompt while validating domains and organizational units.
Learn to manage active directory with PowerShell by creating a security global group payroll managers, setting its display name and location, and moving it to the accounting organizational unit.
Learn how managed service accounts automate password management, stored as MSDS objects in Active Directory, with simplified service principal name management across a domain.
Ensure a service account runs on a recent Windows Server with Active Directory forest schema of 2008, and manually configure the service principal name for the managed service account.
Explore Kerberos version 5 on server 2012, showing how improved tickets reduce authentication failures, enable cross-domain ticket granting, and support group compression across the forest and its domain trust relationships.
Explore Kerberos configurations available, including claims, compound authentication, and Kerberos armoring. On Server 2012 domain controllers, claims are provided on request, and Kerberos armoring is supported for Windows 8 clients.
Explore Kerberos configurations with claims, compound authentication, and Kerberos armoring at domain functional level 2012, including secure tunneling (FAST) and armored versus unarmored requests for dynamic access control.
Learn how service principal names (SPNs) uniquely identify each service instance in a forest, using the service class/host/port/name format with Exchange and DNS examples.
Enforce a domain-wide password policy through the default domain policy with complex passwords, and use password settings objects to tailor rules for groups such as administrators or helpdesk when needed.
Explore how to create and manage account policies and password settings, including lockout thresholds, password age, and complexity, and assign user rights that control who can modify the operating system.
Link a single password settings object to a user (one-to-one), while allowing multiple group memberships, and use MSDS password settings precedence to determine the effective policy; keep configurations simple.
Discover how universal group membership caching enables branch sites to log on to Active Directory by caching in the global catalog and reducing replication traffic.
Explore how domain controllers host server FSMO roles, including schema master, domain naming master, RID master, PDC emulator, and infrastructure master, and how these roles govern forest and domain operations.
Learn to identify and manage the operations master roles across domain controllers, covering forest root domain, infrastructure, naming, schema, and PDC masters, with transfer or seize options.
Maintain Active Directory like a database with regular backups, offline maintenance, and a restartable service; clean metadata, enable snapshots and the recycle bin, and perform authoritative restores across domain controllers.
Enable the Active Directory recycle bin to preserve object attributes and enable restoration, avoiding attribute re-entry; it requires forest replication, cannot be disabled, and uses MSDS deleted object lifetime.
Demonstrates how to restore a deleted Active Directory object using authoritative restore across domain controllers, with attention to replication and deleted objects.
Learn to maintain the Active Directory database by locating files, restarting domain services, and using PowerShell and DSUtil for integrity checks and offline defragmentation, then create and schedule AD snapshots.
Demonstrates installing and configuring a read-only domain controller in a Windows domain, including pre-staging the account, installing Active Directory Domain Services, joining the domain, and configuring password replication policy.
Manage RODC caching by configuring the password replication policy to specify which user and computer accounts are cached, using domain local groups to allow or deny RODC password replication.
Configure Active Directory and universal group membership caching, and learn how to maintain it, including backing up the Active Directory partition, offline management, and applying strong security.
Learn group policy as configurable settings for users and computers, enabling domain level controls and app policy modules, with Internet Explorer home page and security settings as examples.
Modify a policy by choosing not configured to leave settings alone, enabled to apply changes, or disabled to lock the policy and prevent changes.
Explore how ipv6 gains in Windows Server and how group policy supports ipv6, including ipv6 printers, item-level targeting for ipv6 ranges, and vpn ipv6, highlighting enhancements in Windows Server 2012.
Apply group policy examples to roll out applications and enforce settings across the network, including folder redirection and registry editing restrictions, and hide control panel applets for Internet Explorer deployments.
Explore the group policy management console interface and linking GPO objects. Learn delegation, security filtering, and WMI filters that shape the resultant set of policies.
Explore group policy objects (GPOs), their scope for users and computers, linking to sites, domains, or OUs, and apply security and WMI filters based on disk space or memory.
Apply group policies by refreshing and downloading them from the domain controller, cache them in the local store, and apply changes to the computer and user in synchronous mode.
Enable the 'always wait for the network at startup and logon' policy to ensure domain updates are received; otherwise clients only refresh in background and gpupdate /force applies updates.
Learn how to assign group policy scripts to computers at startup, shutdown, logon, or logoff, manage computer versus user settings, and control script timeout and execution order.
Explore how the default domain policy manages logon behavior, software deployment, and password policies for all users and computers, while the default domain controllers policy secures and audits domain controllers.
Learn how a group policy comprises a container in Active Directory and a shared template stored under system root, with versioned settings inside.
Starter GPOs are templates with starter settings from administrative templates, used to create GPOs. Back them up, restore them, or move them to another domain controller.
master slow link processing in Group Policy deployments; define slow links under 500 K, identify modifiable and non-modifiable settings, and emphasize keeping security-related policies on.
Learn how loopback processing applies server computer and user policies with replace or merge modes, enabling predictable environments on servers and preventing undesired user policy overrides.
Configure folder redirection in group policy by defining a shared storage location, applying per-user paths, and redirecting documents and other folders to centralized roots.
Create a group policy to install software by sharing a source folder, setting permissions, and deploying the package through the group policy management console.
Explore how administrative templates extend group policy by configuring lockdowns for control panel, system and personalization settings, with import/export and template management.
Explore how group policy processing follows a specific order, starting with local policies, then site policies, domain policies, and organizational units, applying synchronously in preference order.
Master group policy inheritance and precedence by GPO link order, where lower numbers take precedence; block inheritance to isolate payroll, and enforce high-level policies when needed.
Select the container with the GPO link, click on the linked group policy objects, choose the Group Policy, and move the policy to the desired link order.
Explore local policies via the group policy management console and design domain-wide and OU-specific policies. Learn to configure auditing, user rights, interactive logon, and domain controller settings.
Learn how to use Windows management instrumentation (WMI) filters to tailor group policies by querying computer properties such as operating system, disk space, time zone, and hardware details.
Learn to create and manage group policy objects, link and scope them, apply WMI filters, disable unused settings, back up and restore policies, and model or verify results.
Explore configuring group policy preferences to set starter settings, such as drive mappings, environment variables, files and registry values, across user and computer configurations for remote management.
Maintain GPOs by backing up, restoring, and importing settings, using migration tables, and delegating administration with testing, WMI filters, and security filtering.
Explore group policy and PowerShell operations, including creating and linking a new GPO, backup and restore with PowerShell, copying GPOs, getting properties, importing a GPO, and setting inheritance.
Explore group policy login options and interactive logon settings, including display of last user name, inactivity limits, and prompts to change passwords for secured Windows workstations.
Learn to configure desktop lockdowns with group policy, using computer and user settings, startup scripts, mapped drives, wallpaper, and security policies to standardize and secure workstations.
The Microsoft’s 70-417: Upgrading Your Skills to MCSA Windows Server 2012 course covers the new features and functionality in Windows Server 2012 and Windows Server 2012 R2 including management, networking infrastructure, storage, access control, Hyper-V, high availability, and identity federation. The course also focuses on the more advanced concepts such as Dynamic Access Control (DAC), failover clustering, Microsoft Online Backup and changes with Active Directory, PowerShell, Hyper-V, and Active Directory Federation Services (AD FS).
This course updates the existing knowledge and skills of IT professionals having hands on experience with the previous Windows Server versions to Windows Server 2012, including Windows Server 2012 R2. In addition to this, the course incorporates the exam objectives of 70-417 exam and prepares the students to appear in this certification exam.