
Explore the Windows Server 2025 edition landscape, learn pay-as-you-go licensing, and compare Essentials, Standard, Data Center, and Azure Edition to optimize virtualization, budgeting, and hybrid cloud deployment.
Explore Windows Server 2025 data center edition's unlimited virtualization, software defined storage, shielded VMs, and software defined networking, alongside Azure Edition's cloud-first, pay as you go licensing for hybrid deployments.
Master core-based licensing in Windows Server 2025: license all physical cores with an eight-per-processor, 16-core minimum, choose per-VM versus data center licensing, and plan before hardware procurement.
Evaluate Windows Server 2025 edition selections through practical scenarios, from essentials for small teams to data center, highlighting storage spaces direct, shielded virtual machines, and pay-as-you-go licensing.
Explore cost-effective Windows Server 2025 licensing strategies, including pay-as-you-go for temporary VMs, Azure Arc integration, and data center Azure edition for hybrid cloud workloads.
Learn Windows Server 2025 hardware requirements for successful deployment, including mandatory 64-bit processors with SSE 4.2 and Popcnt, memory sizing by installation type, and virtualization considerations for production environments.
Assess storage and networking requirements for Windows Server 2025: 32 GB, 64 GB, Server Core vs Desktop Experience, PCIe storage controllers, 1 Gbps Ethernet, Secure Boot, and TPM 2.0.
Engage in a practical knowledge check on Windows Server 2025 hardware requirements, covering processor instruction sets, memory for virtual machines, storage planning, virtualization, deployment requirements, security hardware, and troubleshooting.
Master Windows Server 2025 hardware compatibility via knowledge checks on Popcnt SS 4.2 instruction set, VM memory 800 MB, and 64 GB storage planning.
Explore Windows Server 2025 installation options, comparing server core and server with desktop experience, and learn how nanoserver became a container-focused, minimal-footprint option with features on demand.
Apply a practical decision framework for Windows Server 2025 installation choices, balancing server core and desktop experience with application needs, management tools, and security.
Follow a hands-on walkthrough to download Windows Server 2025 installation media, enable Hyper-V on Windows 10–11, create a virtual machine, and configure server roles and basic networking.
Learn to create and configure a Windows Server 2025 virtual machine in Hyper-V, choosing generation two, enabling dynamic memory, setting a default switch, and installing from an ISO.
Compare Windows Server 2025 core and desktop experience installations, highlighting GUI availability, memory usage, and key post-install steps.
Install Docker on Windows Server 2025 using Git and winget, clone a repo, and demonstrate pulling nano server and server core images, then run a container and view Docker images.
Discover the Windows 11 style desktop and redesigned start menu in Windows Server 25, customize pinned admin tools, and access Windows Tools for streamlined management.
Explore Windows Terminal on Windows Server 2025, a powerful multi-shell interface that integrates with Winget for package management, including PowerShell, Command Prompt, SSH profiles, and theme settings.
Explore Windows Server 2025's modern task manager with Mecca Material Design and improved performance visuals, plus integrated compression to create zip or tar files from File Explorer.
Explore the two primary installation options in Windows Server 2025—server core and server with desktop experience—and understand administration implications and Nanoserver’s evolution into container images with features on demand.
Grasp the permanence of installation choices in Windows Server 2025, the no-conversion rule, and why starting with server core plus Nanoserver’s small container footprint improves security and efficiency.
Master RSAT and server manager fundamentals for Windows Server 2025 to enable secure, centralized remote administration with PowerShell remoting, firewall configurations, and bulk server management.
Master Windows Admin Center as the free, browser-based centerpiece of Windows Server 2025 management and enable seamless PowerShell remoting across servers and VMs.
Master Windows Admin Center for real-time server dashboard, VM, storage, and networking, plus security baselines and extensions. Use WinRS for quick remote command execution alongside PowerShell remoting.
Master secure remote management with RDP and Windows Admin Center, balancing GUI access with PowerShell remoting and DSC, and apply role-based group policies and firewall rules across Windows Server 2025.
Demonstrates installing Windows 11 on a Hyper-V virtual machine with TPM and secure boot enabled, joining a domain, and deploying RSAT tools via PowerShell or GUI for remote server management.
Demonstrate deploying Windows Admin Center on a Windows Server 2025 test VM, installing via MSI with express setup, and configuring a self-signed certificate for testing.
Reinforce remote management with Windows Admin Center for 15 servers, and learn to install only needed tools on Windows 11 while updating Windows Management Framework for PowerShell remoting and Venam.
Deploy Windows Admin Center on Windows Server 2025 with failover clustering for high availability and centralized access, and configure firewall rules for 443, 5985, and 5986.
Master PowerShell 7 on Windows Server 2025, import modules, enable PowerShell remoting, and implement desired state configuration to manage physical, virtual, and headless servers at scale.
Learn how PowerShell direct simplifies VM management by running host cmdlets inside Hyper-V guests, and apply desired state configuration to keep Windows Server 2025 deployments consistent.
Master PowerShell 7 fundamentals for Windows Server 2025, including remote server management, module import, PowerShell direct for virtualized environments, and desired state configuration for consistent deployments.
Explore how to set and verify PowerShell execution policy, manage modules with Get-Module and Import-Module, and establish remoting to test and run commands on Windows Server 2025.
Demonstrates creating multi-line PowerShell scripts in a script block with backticks for line continuation and variables. Shows filtering running services, sorting by CPU, and outputting results while troubleshooting errors.
Learn to use PowerShell direct and interactive sessions to manage remote virtual machines, enter and exit sessions, and run commands like hostname and get location.
Demonstrates PowerShell for system administration, including listing and installing features with Get-WindowsFeature and Install-WindowsFeature (telnet client, IIS), enabling remoting, and using Get-ComputerInfo, Get-Counter, Get-WinEvent, and Get-Service.
Demonstrates basic desired state configuration using a simple dsc configuration to ensure telnet client is present on localhost, including creating and compiling the configuration and applying it with start-dscconfiguration.
Master systematic service troubleshooting with PowerShell in Windows Server 2025 by checking service status, analyzing system events, and validating dependencies with get-service and get-winevent.
Master PowerShell management on Windows Server 2025 through six practical scenarios covering module loading, remote administration, PowerShell remoting enablement, and PowerShell direct for Hyper-V VMs.
Explore scalable remote management on Windows Server 2025 by executing commands in parallel with invoke-command -computername to manage servers, then enforce consistency with PowerShell desired state configuration to prevent drift.
Explore Windows Server 2025 evolution from 2016 to 2025 and breakthroughs exclusive to 2025. Implement practical admin workflows with features like work folders, dhcp failover, ipam, and hybrid cloud integration.
Enhance security with zero trust architecture and automatic credential guard across devices. Automate password management with LAPS and MSAs, and enable hotpatching to minimize reboots.
Leverage Azure Arc integration and built-in Arc agent to unify hybrid cloud management and policy governance for Windows Server 2025 across on-premises, edge, and multi-cloud environments.
Boost administrative efficiency in Windows Server 2025 with Windows Admin Center version two, featuring security baseline enforcement and integrated security compliance tools; consolidate administrative tasks and simplify Azure Arc onboarding.
Review Windows Server 2025 features and hardware requirements, including built-in compression, wireless LAN support, Microsoft Passport passwordless, Azure SQL high-availability for desktop services, five level paging, and Windows Defender integration.
Discover Windows Server 2025 updates that implement zero trust security by default, Credential Guard, automated labs management, and VBS for application protection, plus hotpatching to reduce reboots.
Review Windows Server 2025 security architecture, Credential Guard enabled by default, and hot patching reducing reboots to quarterly, with Azure Arc integration for hybrid cloud management.
Highlight Windows Server 2025 performance gains from NVMe optimizations—up to 90% IOPs and Storage Spaces Direct, plus SMB over QUIC security and CIS/STIG templates in Windows Admin Center.
Explore Windows Server 2025 server core fundamentals, its advantages and trade-offs, and master local management tools like PowerShell, S config, and command prompt to deploy and manage server roles efficiently.
Learn how Windows Server 2025 server core supports all major server roles—from Active Directory to Hyper-V and web services—while enabling remote management via Windows Admin Center and PowerShell remoting.
Explore hands-on sconfig workflows to configure Windows Server 2025 core, including network, computer name, time, updates, remote management, domain join, and PowerShell tasks.
Explore Windows Server 2025 server core edition, its core characteristics, benefits, and local management tools like s config and the server configuration tool for practical deployment.
Learn the practical limitations of Windows Server 2025 server core, focusing on GUI dependencies, remote management, and post-installation planning to optimize deployment and maintenance.
Compare Windows Server 2025 installation options, server core and desktop experience, to choose the right edition based on resource usage, security posture, and management needs.
Assess application compatibility to choose between server core and desktop experience, testing critical apps in server core, and leveraging remote management and PowerShell for efficient, secure server administration.
Explore Windows Server 2025 installation types, compare server core and desktop experience, and apply scenario-based knowledge on security, resource efficiency, and management.
Install Windows Server 2025 efficiently by following pre-installation tasks, selecting server core or desktop experience, and building a test lab with step-by-step deployment and post-installation best practices.
Master the Windows Server 2025 installation process for physical or virtual hardware, including language setup, edition selection, in-place upgrade from 2012 R2 and later, disk choices, and initial post-install configuration.
Explore post-installation tasks and new Windows Server 2025 features, including modern task manager with mica, improved connectivity, built-in dtrace, file compression, hot patching, Azure Arc, and edition differences for virtualization.
Deploy Windows Server 2025 virtual machines with Hyper-V or VMware, covering pre-installation steps and integration services. Plan resources, snapshots, and backups, and storage for rapid deployment and test readiness.
Learn to set up Windows Server 2025 VMs with Hyper-V, from obtaining official installation media to configuring TPM, Secure Boot, and optimized VM settings for secure deployments.
Enable Hyper-V on Windows Server 2025 after confirming hardware requirements, using server manager, PowerShell, or Windows features, then configure global settings, virtual switch manager, and storage locations.
Create and configure Windows 11 or Windows Server 2025 virtual machines with Hyper-V, covering naming, generation two, memory, boot order, security (secure boot, TPM 2.0), networking, ISO installation, and setup.
Master post-installation tasks for Windows Server 2025 virtual machines, including integration services, updates, dynamic memory, checkpoint strategies, network and security configuration, and a post-installation checklist for scalable VM deployments.
Assess Windows Server 2025 installation and Hyper-V memory planning, confirming a four gigabytes minimum RAM for desktop experience installations and adequate memory for host operations and multiple VMs.
Explore flexible usb and other installation media strategies for Windows Server 2025 across multiple sites, and master the PowerShell command to install the Hyper-V role with management tools and restart.
Learn why in Hyper-V, choosing generation two for Windows 11 is essential, because it enables UEFI firmware, Secure Boot, and TPM 2 support, with synthetic devices delivering better performance.
Learn how to enable secure boot and TPM in Hyper-V for Windows 11 installation, and apply dynamic memory with startup 4 GB and max 8 GB for balanced multi-VM performance.
Explore desktop virtualization options for professional lab environments and testing purposes. Compare VirtualBox, VMware Workstation, Proxmox, ESXi alternatives, cloud labs, and nested virtualization to find the best fit.
Explore enterprise grade type one hypervisors and compare open source Proxmox VE with VMware alternatives, highlighting KVM and LXC virtualization, live migration, clustering, and disaster recovery.
Explore cloud lab on AWS and Azure, featuring EC2 virtualization with nested virtualization, VMware cloud on AWS, and Azure lab services for development and testing, with elastic scaling.
Compare containers and VM virtualization, and see how Docker, Kubernetes, and infrastructure as code tools like Terraform, Ansible, and Vagrant enable scalable lab environments for DevOps and microservices.
Explore specialized virtualization platforms such as Unraid, Smart OS, and Illumos-based solutions, Qemu/KVM, and OpenStack, highlighting features like ZFS, DTrace, zones, and GPU passthrough.
Analyze hypervisor performance hierarchy and optimize memory management (dynamic memory, memory ballooning) along with storage, network, and CPU resources across Hyper-V, Proxmox, VMware, VirtualBox, and SR-IOV for Windows Server 2025.
Analyze total cost of ownership and licensing considerations for virtualization, comparing free open source options like VirtualBox and Proxmox with commercial VMware and cloud pay-per-use models.
Master post-installation configuration for Windows Server 2025, covering IP address setup, computer name, AD domain, time zone, automatic updates, Windows Admin Center, PowerShell, and firewall.
Explore the s config tool and PowerShell for server core setup, enable remote management, and leverage Windows Terminal and OpenSSH in Windows Server 2025.
Explore Windows Server 2025 security baselines with AWS config drift control, Windows Admin Center, and automation through PowerShell DSC and answer files for scalable, consistent deployment.
Join Windows Server 2025 to an Active Directory domain, verify DNS, firewall, and time synchronization, then deploy roles and features using wizard, PowerShell, or Windows Admin Center.
Configure windows server 2025 security features, including defender, firewall, group policy, and aws config baselines, and manage updates with windows update settings and endpoint configuration manager.
Configure remote management for Windows Server 2025 with secure RDP, WinRM, OpenSSH, and basic monitoring via Task Manager and Perf Mon.
Master post-installation configuration for Windows Server 2025 by troubleshooting, verifying DNS and firewall settings, and domain join with PowerShell remoting ports; use sfc scannow and dism to repair.
Test your knowledge of Windows Server 2025 post-installation tasks, including streamlined setup, s config use, security features, remote management, and DNS-based domain join.
Master Windows Server 2025 deployment by choosing between upgrade and migration, leveraging expanded upgrade paths from 2012 R2–2022 to 2025, and applying a hardware, backup, and testing checklist.
Migrate to Windows Server 2025 with built-in tools, building new servers and transferring roles, data, and applications across subnets through a phased, risk-aware plan.
Navigate Windows Server 2025 infrastructure decisions by weighing upgrade versus migration, considering stability, hardware needs, downtime, and hybrid options, with storage migration services and PowerShell automation for lab-tested deployments.
Explore practical upgrade path migration strategies and deployment decisions for Windows Server 2025 through real-world scenarios, including in-place upgrades, intermediate steps, and architecture considerations for legacy apps.
Explore Windows server migration tools across subnets to migrate from 2008 through 2016 to Windows Server 2025, and adopt a hybrid approach by upgrading stable systems while migrating problematic ones.
Build a complete Windows Server 2025 Active Directory domain infrastructure from scratch in a Hyper-V lab, promoting a domain controller, configuring DNS, and validating domain connectivity.
Join a Windows Server 2025 core to a domain using PowerShell, verify network and DNS settings, restart, and install DNS server remotely via a remote PowerShell session.
Join member servers and Windows 11 clients to the domain, ensure proper DNS configuration, and enable remote management with RSAT tools to manage domain resources efficiently.
Install Windows Admin Center on the SVR one member service, set up with a self-signed certificate and express setup, then add the DC one and core one.
Create and configure lab Active Directory objects, including organizational units and a remote access group, then enable remote desktop on a Windows 11 client.
Check post-install hardware and network readiness by verifying drivers with device manager, reviewing system info, testing connectivity, enabling updates, installing language packs, and disabling media player.
Rename the server and join a domain via server manager and network settings, then enable remote desktop for post-installation management, configure firewall and group policies, and learn boot manager repair.
Create a Windows server image with sysprep to capture post-installation changes, including updates, git, firewall, and time and language settings, enabling rapid deployment of new Hyper-V VMs.
Create a base lab with PowerShell scripts to provision VMs from Windows Server 2025 and Windows 11, then configure Active Directory domain services, forest, DNS, and NetBIOS using differencing disks.
Configure a generation two Hyper-V virtual machine with PowerShell direct management, including enabling and disabling checkpoints, initial boot setup, and network configuration for a DNS server and domain controller.
Learn hands-on Windows Server 2025 administration with Git integration, using clone workflows, server activation, licensing checks, feature management, and domain controller setup.
Learn to install Active Directory Domain Services and DNS on Windows Server 2022, promote a domain controller, and configure DNS for a new forest using PowerShell.
Join a Windows client to the domain with a domain administrator account, verify DNS connectivity, install RSAT and Windows Admin Center, promote Active Directory services, and handle self-signed certificates.
Configure a core server as a domain controller using Windows Admin Center to install Active Directory Domain Services. Create the child domain dc2 with a PowerShell oneliner and configure DNS.
Demonstrates creating a child domain Lab1 with PowerShell domain installation, configuring DNS delegation, and entering domain administrator credentials, then adding three domain controllers to Windows Admin Center.
Automate a complete Windows Server lab with base images using PowerShell, creating four virtual machines, a client, and checkpoints to revert changes.
Master Active Directory administration tools, including the Active Directory Administrative Center and MMC snap-ins. Manage domain controllers, create objects, connect multiple domains, and use PowerShell cmdlets to administer AD.
Explore domains, domain trees and forests, and trust relationships, then design sites and subnets for efficient authentication, replication, and security boundaries in Windows Server 2025.
Explore organizational units in Active Directory, enabling precise delegation and group policy objects (GPOs), compare containers and OUs to design geographic or function-based, or hybrid policies, and manage object movement.
Manage domain controllers as physical servers hosting the directory database, enabling replication and high availability through redundancy and capacity planning. Monitor NTDs database and logs, plan backups, and troubleshoot replication.
Explore the logical and physical components of Active Directory Domain Services, including schema, configuration, and domain partitions, and learn how they shape administration, group policy, and replication.
Explore global catalog servers and read-only domain controllers to speed forest-wide searches, cross-domain authentication, and Exchange address book lookups.
Validate your understanding of Active Directory Domain Services components by answering scenario-based questions on organizational units, read-only domain controllers, and NTDS database locations.
Understand how the schema partition stores all Active Directory schema definitions and drives forest-wide replication to domain controllers, and why global catalog servers, trust relationships, and separate forests matter.
Explore the Active Directory domain services schema as the blueprint that defines objects, attributes, and classes, standardizing data storage and ensuring consistent, reliable directory management across domain controllers.
Discover how Windows Server 2025 updates AD schema to version 91, when to extend it, and how to plan, test, and control changes using AD schema snap and Add Prep.
Explore the Active Directory schema, its rules for objects and attributes, and secure schema modification practices in Windows Server 2025, with practical scenarios and best practices guidance.
Explore Windows Server 2025 schema updates, including schema version 91 requiring Windows Server 2016 functional level, 32kB page size with fresh installs, Dmsa support, and lab-based testing before changes.
Explore how an Active Directory forest defines the top security boundary, with the forest root domain, domain trees, replication boundaries, and the global catalog guiding daily administration.
Explore how the forest defines replication and security boundaries for configuration, schema, backups, and global catalog. Review Windows Server 2025 enhancements, including database architecture, security, and performance.
Explore Active Directory forest architecture and security. Learn about forest root domain objects like schema master and domain naming master, and how the Enterprise Admins group enables forest-wide administration.
Discover how forests automatically establish bidirectional trusts to simplify cross-domain access. Identify replication boundaries for configuration, schema, and global catalog, and note Windows Server 2025's 32K pages upgrade.
Explore Active Directory domains as logical containers for users, computers, and groups; understand multi-master replication across domain controllers and the administrative structure, authentication, and security enhancements in Windows Server.
Leverage dynamic access control and central access rules to streamline authorization in Windows Server 2025. Highlight enhancements such as multi-value attributes and delegated managed service accounts.
Apply your Active Directory Domain Services knowledge with a practice test covering domain capacity and multi-master replication, Kerberos authentication, 32-page database pages, and functional level requirements.
Explore Active Directory Domain Services schema concepts and practical tools to view, verify, and manage schema information in Windows Server 2025, including checking schema version and identifying the schema master.
Shows how to identify fsmo role holders and configure the schema snap-in, covering schema master, domain naming master, pdc emulator, rid master, and infrastructure master, using net dom.
Explore ad ds partitions and domain tools, locate the ntds.dit file, and verify the schema version with PowerShell and dsquery, then inspect with ldp and adsi edit.
Explore Active Directory forest details, including domain naming master, forest mode, global catalogs, and schema master, then review functional levels, sites, and organizational units via PowerShell and tools.
See a hands-on demo promoting a Windows Server 2025 domain controller in a legacy environment, upgrading DCs, raising domain and forest functional levels, and troubleshooting post-upgrade issues.
Promote Windows Server 2025 domain controllers in lab to verify functional levels, handle errors when requirements aren't met, and follow a step-by-step process to raise forest and domain functional levels.
Demonstrates adding a Windows Server 2025 domain controller to a Windows Server 2012 R2 forest, explains domain and forest functional levels and why a 2016 DC is required to proceed.
Troubleshoot post-upgrade AD issues by verifying AD prep, checking schema version (87 for 2016), testing DNS with nslookup, forcing IPv4, starting Netlogon, and promote Windows Server 2025 to domain controller.
Learn the build and migrate method for upgrading Active Directory with a new Windows Server 2025 domain controller, transferring Fisma rules, and raising forest and domain levels.
Demonstrates transferring FSMO roles to a newer domain controller and gracefully demoting the legacy Windows Server 2012 R2, while validating domain and forest functional levels.
Demonstrates promoting a Windows Server 2025 domain controller, raising forest and domain functional levels to Windows Server 2016, adjusting DNS, and cleaning up demoted DC metadata.
Demonstrate Windows Server 2025 active directory enhancements, highlighting 32k database page size. Verify forest and domain functional levels and enable the feature on fresh installs, then validate across domain controllers.
Demonstrates enabling the database 32k pages feature in a forest-wide scope using PowerShell, discusses irreversible changes, testing, and updated backup and performance considerations.
Explore organizational units and containers in Active Directory, and how OUs enable group policy deployment and delegated administration. Design OU hierarchies, avoid applying GPOs to containers, and streamline management.
Organize Active Directory with OUs and containers, separate object types, plan delegation, ensure group policy objects link to OUs, and prepare for replication and orphaned objects.
Test your understanding of organizational units and containers with practical scenarios, covering group policy application, OU hierarchy design, default objects, and administrative delegation in Active Directory.
Use the Delegation of Control Wizard in Windows Server 2025 to grant password reset rights to the help desk for a sales OU, following least privilege and proper OU organization.
Demonstrate creating and managing organizational units and containers in Active Directory using graphical interface, PowerShell, and command line tools to structure the organizational units and delegate administration with group policies.
Use PowerShell to create Active Directory organizational units with one-liners, specify distinguished name paths, verify with Get-ADOrganizationalUnit, and export using ldifde.
Shows how to move users and computers from default containers to specific OUs in Active Directory, using GUI operations and PowerShell to apply department policies.
Move users and computers from default containers into organizational units, then apply department-specific policies using GUI and PowerShell to create, move, and verify objects in Active Directory.
Explore how Microsoft Android (Entra ID) provides cloud based identity management, syncing on-premises Active Directory with the cloud and federation, while Microsoft manages infrastructure and you govern users and access.
Understand how Microsoft Entra ID provides cloud-based identity and access management with single sign-on to cloud apps, coexisting with on-premises Active Directory under a managed service model.
Explore essential AD DS administration tools—Active Directory Administrative Center, users and computers, sites and services, and the PowerShell module—to streamline multi-domain management in Windows Server 2025.
Reinforce tool selection for Active Directory administration by practicing with Active Directory Domain Services tools, Active Directory Administrative Center learning, replication topology with sites and services, and multi-domain management.
Explore hands-on Active Directory administration by creating users with GUI (Active Directory Administrative Center), PowerShell, and dsadd command line, and compare interfaces for efficient lab tasks.
Enable advanced features in Active Directory Users and Computers to reveal the Attribute Editor and Distinguished Name, then use PowerShell history viewer and basic command-line tools to query domain controllers.
Navigate Active Directory Administrative Center to administer ads, create objects, view attributes, and use PowerShell history viewer, exploring central access policies, central access rules, resource properties, and global search.
Master domain controllers host Active Directory services, store directory data and Sysvol, and enable Kerberos authentication. Plan high availability with multi-master replication and consider read-only domain controllers for branch offices.
Explore read-only domain controllers for secure local authentication in branch offices, with writable DCs for changes, BitLocker protection, and selective password caching, plus NUMA, replication priority, and DC deployment planning.
Test your domain controller administration skills with practical questions on replication, high availability, and Active Directory security focused on NTDS database and KDC.
Explore hands-on domain controller administration in Windows Server 2025, covering core components, replication verification, and high availability. Learn deploying raw disk domain controllers and using PowerShell and GUI tools.
Promote a second domain controller for high availability, verify replication health and site configuration, and monitor FSMO roles via PowerShell and DC diag.
Learn to monitor authentication across domain controllers, verify load balancing, diagnose replication health with dc diag and powershell, and validate global catalog functionality.
Demonstrates deploying a read-only domain controller for a branch office by creating a branch offices organizational unit and a branch users security group, then promoting the AD DS role.
Demonstrates configuring a read-only domain controller (rodc) with a GUI and a PowerShell one-liner, enabling dns server, global catalog, and dsrm password, and verifies password replication policy.
Explore managing a read-only domain controller status and password replication using PowerShell and AD administration tools to view cached passwords, pre-populate branch office user passwords, and verify inter-dc replication.
Explore how the global catalog speeds cross-domain searches with the partial attribute set, and learn deployment best practices for authentication and forest-wide directory searches.
Place global catalogs on all domain controllers to optimize cross-domain searches for roaming users, ensure the infrastructure master is not a global catalog, and deploy at least one per site.
Demonstrates configuring global catalog status on domain controllers, enabling and disabling GC, using GUI, PowerShell, and command-line tools, and verifying DNS records and GC presence with dsget, dsquery, and nslookup.
Test your understanding of global catalog fundamentals, partial attribute set, and placement decisions for multi-domain and single-domain Active Directory forests, with real-world scenarios and best practices.
Master practical Global Catalog scenarios in Windows Server environments, covering email routing and recipient lookup, universal group authentication, and infrastructure master considerations in multi-domain forests.
Understand how domain controllers advertise services in DNS using SRV records for LDAP and Kerberos lookups. Learn how Active Directory sites influence DC selection and how Netlogon maintains DNS registrations.
Explore how the Netlogon service manages automatic SRV record registration, including site coverage, startup and reregistration timing, and targeted troubleshooting for domain controllers.
Apply srv record naming patterns for Kerberos over TCP and troubleshoot DNS with underscores. Explore site logic and Netlogon DNS registration versus host A records.
Discover advanced SRV record troubleshooting and DNS health checks, using NLTest to force Netlogon reregistration without downtime, and assess site-specific SRV records for authentication traffic patterns.
Demonstrate SRV record verification on Windows Server 2025 using DNS Manager and nslookup to inspect LDAP and Kerberos records, including site-specific and global catalog servers.
Use PowerShell to query DNS SRV records, view LDAP and Kerberos data, and automate domain controller discovery and monitoring, including Netlogon file analysis for Windows server environments.
Master the two-phase Active Directory Domain Services sign-in process, from DNS-driven authentication and LSA-issued access tokens to Kerberos-based authorization with TGT and service tickets for resource access.
Explore the authentication flow in Windows Server 2025, from TGT and service ticket requests to resource access. Track logon events, domain controller interactions, and auditing to troubleshoot across the domain.
Explore two-phase authentication model of Active Directory domain services, including security identifiers (SIDs) and access tokens, plus Kerberos flow with the ticket granting ticket and service tickets, and troubleshooting scenarios.
Master Windows Server 2025 authentication and monitoring security, covering computer accounts, Kerberos, LDAP encryption, and randomized passwords with cryptographic agility.
Observe the Active Directory Domain Services sign-in in a real lab, perform two-phase authentication with Kerberos ticket generation and validation, security identifiers, and authentication events via PowerShell and Event Viewer.
Examine security identifiers across users, groups, and computers, revealing a domain-wide seed and unique reads. Demonstrate real-time authentication flow and Kerberos tickets using PowerShell and Event Viewer.
Demonstrates authentication event monitoring for Kerberos, showing how to view TGT and service tickets, refresh the event viewer, and use Klist to inspect cached tickets during logon and resource access.
Demonstrates how computer accounts authenticate automatically at startup, enabling machine security, service authentication, and group policy application, with hands-on checks of account properties and secure channel health.
Identify and manage the five FSMO roles—schema master, domain naming master, infrastructure master, read master, and PDC emulator—with forest-wide and domain-specific scopes to ensure conflict-free Active Directory operations.
Master the PDC emulator and FSMO roles to ensure accurate time, urgent password changes, and conflict-free group policy edits across domain controllers, with practical PowerShell and GUI monitoring tools.
Identify the five FSMO roles and their forest-wide or domain-specific distribution, including schema master, domain naming master, and the PDC emulator, using get-id forest to locate role holders.
Examine how FSMO roles affect availability, focusing on the read master's read pools for security identifiers seeds and new object creation, and when to seize roles with force.
Discover the five fisma roles, schema master, domain naming master, rid master, pdc emulator, and infrastructure master, and learn to transfer or seize them across domain controllers using PowerShell commands.
Explore deploying domain controllers in Windows Server 2016/19, including cloning for rapid virtualized replication, Azure considerations with rollback and VM generation ID, and installation options via GUI or Server Core.
Install the domain controller role with Server Manager, then promote it via the Active Directory Domain Services Configuration Wizard to add a domain, a new forest, or an existing domain.
Learn to install a domain controller from media to reduce wan traffic. Create an IFM snapshot with NTDS util, copy it to remote server, then promote using server manager.
Demonstrates preparing a source domain controller for cloning, exporting the virtual machine, and importing and starting the cloned domain controller using Hyper-V Manager and Active Directory Administrative Center.
Deploy at least two domain controllers on different hosts and in separate data centers; ensure time synchronization; use generation identifiers; enable cloning safeguards with batches of ten.
Create and manage user accounts in Active Directory using four tools: Active Directory Users and Computers, Active Directory Administrative Center, Windows PowerShell, and dsadd, emphasizing naming conventions, unique names.
Explore essential user account management in Windows Server 2025 with practice questions on unique accounts, bulk creation using PowerShell and New-ADUser, and unique naming rules like the full name attribute.
Explore configuring user principal name (UPN) suffixes to enable email-format logins across a Windows Server forest, aligning domains for seamless authentication and improved user experience.
Demonstrate methods to create user accounts in Windows Server 2025—Active Directory users and computers, AD Administrative Center, PowerShell, and RDS add—using a demo users OU; cover naming and attributes.
Demonstrate creating user accounts in Windows Server 2025 using the Active Directory Administrative Center and PowerShell, covering GUI creation, upn logon, and change password at logon.
Demonstrates bulk PowerShell account creation by looping through names, auto-generating account names, creating users, securing passwords, enabling accounts, forcing password changes at logon, and verifying with Get-ADUser.
Demonstrate creating a James Taylor account with the dsadd tool by specifying the distinguished name and attributes, including UPN, password, must change password, and enabled status.
Learn to configure Active Directory user attributes using Active Directory Administrative Center and users and computers, covering logon controls, account expiration, password policies, and group membership for secure, organized identities.
Apply practical knowledge of configuring user account attributes in Active Directory through realistic scenarios, from temporary access with account expiration to smartcard authentication and service account password management.
Master Active Directory troubleshooting, including opening a user via a group's member list to access Attribute Editor. Apply logon to restrictions for Finance computers and assess reversible password encryption risks.
Demonstrate configuring user account attributes in Active Directory, including account expiration, logon hours, restricted computer access, smartcard requirements, and service account password policies, using GUI, PowerShell, and command-line tools.
Configure logon restrictions to a designated workstation and verify with ad queries, then require smartcard authentication for executives, and manage service account policies including password never expires and gMSA use.
Update information in Active Directory via Active Directory Users and Computers and PowerShell to set Lisa's office, phone, email, address, title, department, and manager, improving directory searches and reporting.
Demonstrates accessing the attribute editor in Active Directory Users and Computers to view and edit advanced attributes, using the member of tab as a workaround and PowerShell for department updates.
Design roaming user profiles in Windows Server 2025 by configuring profile path, UNC path, logon scripts, and home folders with group policy objects to enable mobility, security, and performance.
Manage user profiles at scale with group policy and folder redirection. Choose basic or advanced redirection, use roaming profiles and template users with percent variable, plus backups and version compatibility.
Configure roaming profiles using a template user and the present username variable for automatic home folders; store profiles on a file server and apply advanced redirection for department-specific NFS shares.
Modernize logon drive mappings with group policy preferences, implement roaming profile versioning for Windows 10/11 transitions, and apply folder redirection to reduce sign-in times for large files.
Learn to manage the user account lifecycle by disabling inactive accounts and using templates to speed creation, while distinguishing disable from delete and applying best practices for audits and automation.
Use Active Directory templates to streamline user creation. Copy group memberships, home directories, and profile paths using the percent username percent variable for dynamic paths, excluding unique identifiers.
Explore how to balance immediate security with 90-day retention, disable vs delete decisions, and use PowerShell for bulk AD management, plus three department-specific templates for scalable onboarding.
Demonstrates configuring profile storage in an Active Directory lab by creating a shared folder for profiles on a file server, then demoting a domain controller and cleaning AD metadata.
Configure and share profiles and home directories on a Windows server lab, set NTFS and share permissions, and prepare to configure roaming profiles with Active Directory Administrative Center.
Configure a roaming profile for Sarah Johnson using the Active Directory Administrative Center, setting the profile path and home folder on FS1 so her profile downloads on sign-in.
Learn how to automate configuring multiple user profiles with PowerShell, roaming profiles, profile paths, home drives, ACL-based permissions, and bulk provisioning via Active Directory users and computers.
Demonstrate template user creation using the percent username percent variable to auto-generate profile and home folder paths, enabling efficient, error-free, and consistent user provisioning in Active Directory.
Explore Active Directory group types—security and distribution—and their roles in permissions and email, plus scopes—local, domain, global, and universal—and how conversions and sign-in updates affect access.
Examine local groups for stand-alone servers, stored in the local security account manager. Explore domain local and global groups, with forest-wide membership and universal group conversion.
Explore universal groups and scope conversion in Windows Server 2025, covering domain local, global, and universal scopes, replication to the global catalog, and best-practice conversions for multi-domain environments.
Tests understanding of group types and scopes with six questions on distribution versus security groups and the need to log off and log back on to apply changes.
Master domain local, global, and universal groups to grant cross-domain resource access, using domain local groups for printers and resources, while understanding conversion rules to universal groups.
Explore hands-on group management in Windows Server 2025 by creating distribution and security groups across four scopes, assigning permissions, and testing access in a practical lab setup.
Demonstrate creating a global distribution group and a global security group in Active Directory, verify group properties with PowerShell, and test access to shares and membership updates.
Demonstrate managing group membership on Windows Server 2025 with PowerShell and AD group queries, then grant security group access to a shared folder and test access for multiple users.
Master the DLA framework for group management, identities, global groups, domain local groups, and access. Extend to multi-domain environments with IGUDLA universal groups, and apply a practical shared folder scenario.
Delegate group membership to department heads using the managed by feature and restricted groups, then centralize control with group policy to enforce membership across domain and local groups.
Apply IGDLA framework concepts to manage access: assign business roles to global groups, use universal groups for cross-domain access, and grant domain local group permissions via ACLs.
Delegate group membership using the managed by property so HR can update membership; understand restricted groups, the member vs member of distinction, and test changes in a non-production environment.
Demonstrates finance group setup with GUI methods and PowerShell one-liners, nesting global groups in a domain local resource group, configuring NTFS permissions, and enforcing restricted groups via group policy.
Create domain local groups and assign file permissions using an ACL-based structure to control access to the finance docs folder, using finance users for modify and auditors for read.
Demonstrates how to troubleshoot share and NTFS permissions on a Windows Server, showing the impact of effective permissions and two approaches for granular vs broad control.
Delegate marketing group membership to Sarah M Johnson by enabling 'manager can update membership list,' and show how restricted groups add IT helpdesk to local admins on Windows 11 policy.
Demonstrates implementing a restricted groups policy to add IT help desk to local administrators via a linked GPO, with verification through gpupdate and membership checks, highlighting the additive, safer approach.
Identify the default groups in Active Directory Domain Services, including Enterprise Admins and Schema Admins, and understand their protected status, and how to delegate with Server Operators and Account Operators.
Explore special identities in Active Directory Domain Services, where Windows Server automatically assigns permissions via dynamic, system-controlled memberships such as anonymous logon, authenticated users, and interactive versus network access.
Examine the network identity, everyone, and create-owner permissions to manage remote versus local access, inheritance, and user-specific folders such as home directories on Windows Server 2025.
Leverage special identities in Active Directory to grant access by connection type, with automatic membership and layered permissions across interactive, network, and anonymous logon, creator owner, and everyone identity.
Test your understanding of Active Directory protected groups, admin SD holder mechanics, special identities based on authentication and access methods, and forest versus domain admin scopes.
Learn how the everyone group no longer includes anonymous logon, and how interactive and network identities enable precise access control for Windows Server 2025, including creator-owner and shared folders.
Explore default and protected administrative groups and Admin SD holder concepts in Active Directory through a hands-on lab, test capabilities, and create custom groups with delegated permissions using PowerShell.
Demonstrate how account operators can reset passwords, modify groups, and verify membership with PowerShell and GUI tools, while highlighting built-in security boundaries that prevent changes to protected accounts and groups.
Examine the AdminSDHolder object, its template security descriptor, and the SDPROP process; use PowerShell to query, view ACLs, and troubleshoot protected accounts and groups.
Demonstrates protected account behavior in Active Directory, showing how sdprop sets the admin count to one for Emily Parker and how removal from protected groups affects persistence.
Demonstrates how special identities in Active Directory drive access control by connection and authentication method, with interactive vs network access, creator-owner permissions, and authenticated users vs everyone in a lab.
Demonstrate how a single user receives interactive (local) versus network (remote) identities with differing permissions, using folder ownership, inheritance, and identity verification to illustrate access-based security.
Demonstrate how Create-A-Owner gives users full control of their folders and limits access for others. Compare Everyone versus authenticated users in Windows Server 2025 permissions.
Learn how computer accounts are stored in Active Directory, the default computers container's limitations, and how to use custom OUs and pre-created accounts for targeted policies and domain joins.
Delegate computer account management via the delegation wizard, then perform domain joins with pre-created accounts and secure channels; understand the trust relationship error and related diagnostic details.
Learn to reset secure channels with nltest, netdom, and dsmod, and perform offline domain join with DJoin in two phases to provision and apply domain metadata.
Explore Active Directory fundamentals through practical scenarios on computer accounts, organizational units, and delegation of control, plus secure channel troubleshooting with nltest.
Explore best practices for configuring computer accounts, OU structures, and offline domain join in Windows Server 2025, including pre-creating accounts, location-based ous, and djoin usage.
View the computers container in Active Directory Domain Services, enable advanced view to see the distinguished name, and learn that GPOs link to OUs, not containers, via GUI and PowerShell.
Create a two-location OU structure for computers by using the GUI and PowerShell, organizing main office and branch office into workstations and servers to apply location-specific and device-specific group policies.
Demonstrates redirecting the default computer container in Windows Server 2025 using redo-cmp and, when it fails, pre-creating computer accounts in the correct OU as a practical alternative.
Pre-create computer accounts in a targeted OU before domain join, using GUI and PowerShell, with delegated permissions to ensure immediate group policy objects are applied.
Join a client to the LearnedLessons.com domain, verify the secure channel with test-computer-secure-channel and nltest, then break and reset the trust relationship using Mark Stevens credentials.
Explore hands-on techniques to reset secure channels in Active Directory using nltest, netdom, and PowerShell, including testing, credential use, and domain rejoin considerations.
Learn to use PowerShell commandlets to create, modify, and manage Active Directory objects—users, groups, computers, and OUs—and automate bulk operations with CSV files and provisioning from spreadsheets.
Master PowerShell group management in Windows Server 2025 by creating groups with new-adgroup, managing membership with adgroup-member and ad-principal-group-membership cmdlets, and understanding domain-local, global, and universal scopes.
Master computer accounts and organizational units with PowerShell, using new-ad-computer and new-ad-organizational-unit to deploy objects, while safely performing bulk operations with testing.
Master querying active directory objects with filters and the pipeline using get-ad cmdlets, covering filter vs LDAP filter, search-base and search-scope, and practical examples like disabling inactive accounts.
Develop practical PowerShell skills for bulk active directory automation using csv and text data. Import-csv creates objects from headers; for-each processes rows, and get-content handles simple lists for bulk operations.
Explore five Active Directory organizational unit strategies—location-based, organization-based, resource-based, multi-tenancy-based, and hybrid—and learn to delegate administration and design an OU hierarchy that enhances security.
Design Active Directory organizational units to support administrative tasks, delegation, and gpo design. Plan for change and growth, using inheritance wisely and keeping protection in place.
Explore how moving objects between OUs changes permissions: direct permissions remain, inherited permissions change; grant delete child, delete, and write prop permission on RDN, DN, and CN to enable moves.
Learn how Active Directory security descriptors govern ownership, DACL and SACL, and how to delegate access using object type or role-based models, with the delegation wizard.
Test your OU planning skills with location-based structures and department attributes to manage permissions and delegation. Learn how to handle protection from accidental deletion and related PowerShell steps.
Explore OU permissions and delegation through practical questions on moving objects between OUs, direct vs inherited permissions, and role-based delegation for secure, least-privilege administration.
Understand forest and domain boundaries in Active Directory Domain Services, including replication, administration, policy, and password scopes. Explore when multiple domains or forests are needed and DNS integrated zones' role.
Explore how AD forest boundaries act as the security boundary, with schema and configuration partitions, the global catalog, and forest DNS zones; decide between single and multiple forests.
Deploy AD DS on Asia Azure infrastructure by using Asia domain controllers for disaster recovery and low-latency authentication; plan Asia VNet, site topology, and VPN or ExpressRoute.
Explore managing objects in complex AD deployments with automation, MIM, and identity management, balancing on-premises forests and domains with cloud-first identity solutions.
Learn to deploy Azure domain controllers with static IPs, NTDS.DIT on a separate data disk with host caching disabled, and AD-aware backups, plus forest trusts for cross-forest access.
Automate identity management with Entra ID synchronization and self-service, and optimize hybrid site topology to reduce Azure egress costs while maintaining replication latency.
Explore real-world Active Directory replication troubleshooting, domain partition boundary concepts, and the demotion and repromotion workflow. Verify replication, diagnose failures, and apply tools like repadmin, nltest, w32tm, and PowerShell.
Demonstrates domain controller troubleshooting, including IP configuration corrections, DNS registration, SPN checks, and Kerberos service management to support reliable replication and time synchronization.
Demonstrates troubleshooting an Active Directory replication issue by demoting and re-promoting a domain controller, removing the AD DS feature, and cleaning NTDS records in sites and services.
Learn to troubleshoot domain controller sync and replication by demoting and repromoting a DC, removing old computer accounts, and forcing replication with repadmin to sync configuration and schema data.
Demonstrate the domain partition replication boundary and verify propagation across domain controllers by creating a test user and forcing replication in a Windows Server 2025 environment.
Explore administration boundaries in Active Directory, compare domain admins and enterprise admins, and explain why the forest is the true security boundary.
Explore how domain and forest functional levels shape Active Directory in Windows Server 2025, including upgrades, migrations, and multi-domain deployments, plus new 32-kilobyte page size enhancements.
Explore how forest functional levels govern multi-domain trust and resource sharing. Trace the evolution from 2003 to 2025, including recycle bin, domain level alignment, and 32 kilobyte database support.
Navigate forest root and child and tree domain structures, schema master roles, and automatic trusts across domains; compare upgrade paths to Windows Server 2025, including schema prep.
Promote a new child domain controller EU-DC1 in the LearnItLessons.com forest, configure DNS to the parent LID-DC1, and enable Active Directory Domain Services for Europe.LearnItLessons.com.
Demonstrates diagnosing and resolving replication and DNS issues in a child domain, using repadmin commands, DNS name resolution, and domain controller promotion steps to successfully add eu-dc1 to europe.learnedlessons.com.
Demonstrates cross-domain authentication between the LearnedLessons.com parent domain and the Europe.LearnedLessons.com child domain, and how to grant domain admin rights via enterprise admins and transitive trusts.
Demonstrates configuring DNS delegation for Europe subdomain to 192.168.1.50, validating with resolve-dnsname, and promoting a child domain with PowerShell, plus verifying trusts and replication in Windows Server 2025.
Demonstrates deploying a tree domain within an existing forest by adding leadpartners.net as a separate namespace, verifying domain name system resolution, and promoting the tree domain controller.
Demonstrate configuring conditional forwarders for a tree domain between learnedlessons.com and leadpartners.net to enable cross-forest name resolution and verify forest trusts in Active Directory.
Demonstrates creating a brand-new, isolated Active Directory forest named devlabs.local with its own schema and global catalog, no automatic trusts, and a dedicated DNS server.
Explore real-world scenarios to master Active Directory partitions and replication, including domain partitions, schema replication, KCC-driven topology, and understanding forest-wide versus domain-wide propagation.
Understand inter-site replication timing and conflict resolution: 15-second notification, 45–60-second propagation, latest-timestamp winner, and DFS replication for SysVol in Windows Server 2016.
Explore how SysVol replication works with DFS replication, verify status with dfsmgmt.msc or dfsr diag, and watch logon scripts replicate across domain controllers under domain-systems-volume.
Explore how Active Directory sites manage replication traffic, localize authentication, map subnets, and use SRV records for service location to optimize domain controller placement.
Learn how SRV records in DNS locate domain controllers, publish Kerberos and LDAP services, and how clients locate, authenticate, and move between sites with automatic and manual site coverage.
Explore how subnet-to-site mappings and SRV records drive authentication in AD sites. Diagnose intermittent logins at Austin and review automatic bridgehead selection and RODC SRV behavior.
Demonstrates configuring three gateway network adapters with static IPs for main office, Boston, and Chicago labs, testing connectivity, DNS resolution, and renaming adapters.
Install and configure the routing and remote access role on the gateway server, enable LAN routing, and verify connectivity to support Chicago DC and Boston DC.
Verify domain controllers register site-specific SRV records in DNS, including Kerberos, LDAP, and Global Catalog. Examine replication topology with KCC, then use repadmin to view partners and bridgehead servers.
Design active directory replication with site links, bridging, and site link bridges to align hub-and-spoke topology. Use ISTG paths and universal group membership caching with PowerShell to monitor.
Enable universal group membership caching at the site to authenticate locally, reducing WAN traffic; caches refresh every 8 hours and suits sites under 100 users.
Explore using DCDiag and RepAdmin to diagnose Active Directory replication health, latency, and topology, with enterprise monitoring via the Operation Manager management pack and PowerShell automation for replication tasks.
Configure Active Directory site link costs to prioritize the T1 primary path, fail over to DSL when needed, and optimize replication scheduling with dcdiag and repadmin.
Demonstrates configuring AD site link bridging to control transitivity across sites. Disable automatic bridging, create site link bridges, enable universal group membership caching, and validate replication with GUI and PowerShell.
Discover configuration management as the backbone of group policy, defining settings, scope, and application to centrally manage Windows domains. See how Active Directory integrates to enforce consistent, auditable configurations.
Analyze the core group policy concepts, including policy settings and their three states, the computer versus user configuration split, and core folders like software, Windows, and administrative templates.
Explore the scripts node for startup, shutdown, logon, and logoff automated actions, CSC processing order, and 10-minute timeouts, then review ADMX templates and GPUpdate/GPResult for policy verification.
Learn how Windows Server processes GPOs by default in the lsdou order, and control precedence with link order, enforcement, block inheritance, and link enabled.
Understand how GPO inheritance works in Windows Server 2025, including Enforced, Block Inheritance, and Link Enabled, to control policy precedence, isolation, and troubleshooting.
Explore GPO inheritance in Windows Server 2025: master LSDOU order, last writer wins, and conflicts resolved by link order, enforcement, block inheritance, and link-enabled troubleshooting.
Group policy is a pull process driven by the group policy client service, with two phases where client-side extensions apply settings and reapply them if unchanged, 16-hour security CSE cycle.
Understand the group policy refresh cycle, including foreground refresh at startup and sign-in and background refresh every 90 to 120 minutes with a random offset, and manual refresh options.
Explore how Group Policy evolved across Windows Server, from 2008's policies and templates to 2025's security-focused settings, including Windows Labs enhancements, SMB audit policies, and Windows 11 templates.
Demonstrates configuring a setting on a single machine and applying it via centralized management with the group policy management console, focusing on settings, scope, and automatic policy delivery.
Create the admx central store by creating the policy definitions folder and copying all admx and adml files from C:\Windows\PolicyDefinitions into it, so gpmc reads templates from the central store.
Refresh group policy with gpupdate /force, verify with gpresult /R for user and computer scopes, and generate an HTML report to troubleshoot policy application.
Explore how a GPO has two components—the group policy container in active directory and the group policy template in sysvol—linked by a shared GWT. Understand how version numbers track changes, how GPT.ini stores the GPO version, and why edits route through the PDC emulator for consistent replication.
GPOs have two components—the group policy container in Active Directory and the group policy template in SysVol—that replicate separately via AD replication and DFSR, causing brief out-of-sync and policy errors.
Explore GPO storage and replication across domain controllers, focusing on the two-component structure (group policy container in Active Directory and group policy template in SysVol), versioning, and real-world scenarios.
Discover how starter GPOs serve as templates to create new GPOs with pre-configured administrative template settings and export them as cabinet files with .cap extension for consistent baselines across domains.
Practice test on starter GPOs and distribution explores exporting via .cap, cross-domain templates, and documenting intent with the GPMC commands field.
Back up, restore, import, and copy GPOs with GPMC and PowerShell, manage domain and cross-domain migrations using migration tables, and recover default GPOs with the GDC GPO Fix Utility.
Master GPO lifecycle management by using migration tables to map source to target references during cross-domain imports, backup and restore with GPMC and PowerShell, and safe recovery with dcgpofix.
Practice test on GPO backup and restore, importing and copying GPOs, using migration tables and DCGPOFIX, with PowerShell's Group Policy module, reinforcing why options are right or wrong.
Delegate group policy administration to distribute group policy tasks across teams, covering creating, editing, linking, modeling, results, and WMI filters with role-based permissions for scalable, secure management.
Practice six scenario-based questions to master delegating GPO administration, including creating, editing, linking GPOs, cross-forest delegation, and using GPMC for permissions and modeling.
Explore the major capabilities of group policy, including security settings, firewall rules, auditing, user rights, desktop and application settings, software deployment, folder redirection, and wireless and wired network policies.
Create and link group policy objects with GPMC and PowerShell, compare linked vs unlinked GPOs, verify GPO results on a client, and configure settings like Prohibit Access to Control Panel.
Learn to troubleshoot clock skew in Windows Server 2025 by using w32tm commands, diagnosing policy application with gpupdate/gpresult, and disabling Hyper-V time sync to sync from the domain hierarchy.
Demonstrates GPO inheritance and LSDOU processing by resolving domain and OU conflicts, adjusting link order, enforcing domain settings, blocking inheritance, and using last-writer-wins precedence for screensaver timeouts.
Demonstrates enforced domain-level GPOs, blocking inheritance, and managing link order to control screen saver timeout across OUs, with practical testing using gpupdate and gpresult.
Explore how the group policy client service and client-side extensions drive policy application at sign-in and startup, inspect the CSC registry keys, and verify with gpupdate and gpresult.
Explore the default domain policy and default domain controllers policy in Active Directory, review their scope and auditing settings, and learn about the DC GPO fix recovery tool.
Explore how local group policy editor and domain policies interact, showing that domain GPOs take precedence over local settings, verified using gpresult /r from an elevated session.
Explore how a GPO is stored in Active Directory and Sysvol by inspecting the GPO container and the GPT.ini template, then verify DFSR replication and GPMC linkage.
Demonstrate initializing and reviewing started GPOs in GPMC, create a custom StartedGPO with administrative templates, and export it to a .cap file for import into another domain.
Export and import starter GPOs via the GPMC by creating a new GPO from the Lead Baseline Admin Starter GPO, saving as a .cap file, and importing to another domain.
Backup a GPO, import its settings without altering links, then copy and link a GPO within the same domain using PowerShell cmdlets like get-gpo and new-gplink.
Learn to delegate GPO linking and filters in Windows Server 2025 with the GPMC and delegation wizard. Explore granular container and OU permissions, ACLs, and GP modeling with GetGPPermission.
Explore GPO links, processing order, and inheritance and precedence to see how scope shapes policy application. Learn to block inheritance on an OU and enforce absolute priority for the GPO.
Master block inheritance and enforcement in Active Directory, understanding how blocked inheritance isolates policies and enforcement guarantees a GPO's highest precedence, with the GPMC showing the resulting precedence.
Master practical group policy design by solving real-world scenarios on GPO links, processing order, inheritance, and enforcement across domains, sites, and OUs.
Understand security filtering and WMI filters to target GPOs by managing read and apply permissions, including and excluding groups, denying permissions when needed, and testing in production contexts.
Explore how group policy permissions and security group filtering determine which users and computers receive a GPO, using deny permissions and WMI filters to scope and test deployments.
Learn how to scope group policy with WMI filters and security filtering, compare test OU approaches, and apply server operating system policies with client-side evaluation.
Learn how group policy handles offline machines: settings persist, scripts don't run offline, and reconnect triggers a background refresh to apply registry and security updates.
Explore how GPO replication and security token refresh determine when policy settings become effective, including container and template replication, the always wait for network setting, and GP update.
Master RSOP by using the Group Policy Results Wizard, Group Policy Modeling Wizard, and gpresult.exe to generate and read policy reports, and learn PowerShell Get-GPResultantSetOfPolicy for RSOP analysis.
Navigate RSOP reports using the Summary, Settings, and Policy Event tabs to diagnose applied GPOs, security filtering, scope, and processing errors.
Apply RSOP concepts with a six-question practice, learn how our soap accounts for inheritance, filters, and slow-link processing using the group policy results wizard, modeling wizard, and PowerShell.
Learn how to read RSOP reports in the GPMC, identify the winning GPO with the Settings tab, and use gpresult commands and Get-GPResultingSetOfPolicy for centralized, shareable RSOP results.
Learn to troubleshoot Group Policy by reading event logs and assessing infrastructure health. Use the Group Policy operational log for refresh traces and the application log for drive mapping issues.
Learn to diagnose GPO replication health across domain controllers with the GPMC, using Status tab and Detect Now, and interpret replication results for specific GPOs.
Learn to use GPMC to link GPOs to demo users OU and verify the scope. Master security filtering and WMI filters, adjust read permissions, and validate results on a client.
Demonstrate pre-production GPO testing by linking to production for a GP-Pilot test group with Emily Parker, then use gpupdate and gpresult and set a Windows Server WMI filter.
Verify and validate WMI filters and gp result to ensure correct OU placement, security filtering, computer-side settings, and restart behavior for effective GPO application.
Demonstrate configuring GPO status options and loopback processing in a hands-on lab, showing how loopback in replace mode prioritizes computer policies over user policies in GPMC.
Learn how slow link detection works with group policy, read GPResult outputs, configure the slow link threshold and CSC settings, and understand offline and reconnect behavior in a multi-site domain.
Configure slowlink detection by creating and linking a gpslowlinkconfig GPO, set a 10000 kbps threshold, and verify with gpupdate, gpresult, and a PowerShell registry check.
Explore offline group policy caching and client-side extension behavior, including slow-link processing, local policy caches, and the impact of reconnecting on logon scripts and folder redirection.
Welcome to our comprehensive course on Windows Server 2025! This program is designed for IT professionals, system administrators, and anyone eager to dive into the latest advancements in Windows Server technology. Let's take a sneak peek at what each section has in store for you:
Getting Started with Windows Server 2025
Lecture 1: Getting Installed with Windows Server 2025
Get hands-on experience as we guide you through the installation process of Windows Server 2025. Learn the essential steps to set up your server environment efficiently.
Lecture 2: A Quick Look at Windows Server 2025
Take a swift tour of Windows Server 2025, exploring its interface, features, and improvements over previous versions. Gain insights into what makes this edition stand out.
Lecture 3: AD DS New Functional Levels
Delve into the exciting realm of Active Directory Domain Services (AD DS) and discover the new functional levels introduced in Windows Server 2025. Understand how these levels shape the capabilities of your domain.
Lecture 4: AD DS Domain Functional Levels
Master the intricacies of domain functional levels within AD DS. Learn how to tailor your domain to specific requirements and leverage the latest enhancements for optimal performance.
Lecture 5: AD DS Forest Functional Levels
Uncover the significance of forest functional levels in Windows Server 2025's AD DS environment. Explore the advanced features that come with higher functional levels and how they impact your entire forest.
Lecture 6: A Quick Overview of Windows Schema
Grasp the fundamentals of Windows Schema – the blueprint that defines the structure of Active Directory objects. Gain a foundational understanding of its role in shaping your directory service.
Lecture 7: Working with Schema on Windows Server 2025
Deepen your knowledge by exploring practical scenarios of working with the Windows Server 2025 schema. Learn essential techniques for managing and customizing your directory's schema.
Lecture 8: What is the AD DS Schema?
Demystify the concept of AD DS Schema and understand its pivotal role in the Active Directory infrastructure. Gain insights into how the schema influences object attributes and relationships.
Lecture 9: New 32k Database Page Size Feature
Explore the cutting-edge 32k Database Page Size feature in Windows Server 2025. Understand its impact on database performance and discover how to leverage this new capability effectively.
Enroll now to embark on a journey of skill-building and exploration, ensuring you're at the forefront of Windows Server technology in 2025! Join us and elevate your expertise to new heights.