All certifications / AZ-802 / Cheat sheet
AZ-802 AZ-802 cheat sheet
Domain 1: Deploy and manage AD DS (21%)
Exam tips
- For Azure DCs, the static IP is set on the Azure NIC, not in the guest, and NTDS goes on a data disk with caching None. Answers that suggest setting a static IP inside Windows or keeping NTDS on the OS disk are the traps.
- Know which roles are per forest (schema, domain naming) and which are per domain (RID, PDC emulator, infrastructure). A forest with three domains therefore has 2 + (3 x 3) = 11 FSMO roles in total.
- Lower cost wins. If a question gives two paths between sites, add the site link costs along each and pick the smaller. Remember inter-site replication follows the schedule and interval, while intra-site replication uses change notification.
- Access flows opposite the trust arrow: 'A trusts B' means B's users can use A's resources. Forest and shortcut trusts are transitive; external trusts are not; realm trusts can be either.
- If New-ADServiceAccount fails with a key-related error, the answer is almost always that the KDS root key is missing or not yet effective. For group scope questions, remember AGDLP.
- Password policy linked to an OU does not affect domain users, and PSOs cannot be linked to OUs. Also remember the Recycle Bin needs the 2008 R2 forest functional level and cannot be disabled once enabled.
- If a scenario needs on-premises lockout, logon hours or disabled state enforced instantly at sign-in, the answer is PTA. If it needs sign-in to survive an on-premises outage with the least infrastructure, the answer is PHS. Disconnected forests with minimal footprint points to Cloud Sync.
- Enforced wins over Block Inheritance every time. If a filtered GPO stopped applying after removing Authenticated Users, the fix is to give Authenticated Users or Domain Computers Read permission.
- SID history keeps access working; security translation makes it permanent. Functional levels depend on the oldest DC, and raising them is normally one-way, so questions about 'can we still add a Server 2012 R2 DC' turn on the current level.
Key terms
- DSRM
- Directory Services Restore Mode: a special boot mode for offline AD maintenance, protected by a local password set during promotion.
- IFM
- Install from media: promoting a DC from an ntdsutil-created copy of the database so initial replication does not cross the WAN.
- RODC
- Read-only domain controller: holds a read-only directory copy and caches only passwords allowed by its Password Replication Policy.
- Password Replication Policy
- The allow and deny lists that decide which accounts' credentials an RODC may cache.
- Host caching
- An Azure disk setting (None, ReadOnly, ReadWrite); DC data disks holding NTDS should use None.
- FSMO role
- A single-master operation in AD assigned to one DC per forest or domain.
- RID master
- Allocates pools of relative IDs to DCs so each new user, group or computer gets a unique SID.
- PDC emulator
- Domain-wide role handling time synchronization, urgent password changes, lockouts and GPO editing by default.
- Transfer
- A graceful role move while both the old and new holders are online.
- Seize
- A forced role takeover when the old holder is permanently unavailable; the old DC must not return.
- Site
- An AD object representing a set of well-connected subnets, used for client DC selection and replication scheduling.
- Site link cost
- A relative value AD sums along paths; the lowest total cost path is preferred.
- Site link bridge
- A way to make site links transitive; the default Bridge all site links setting makes all links transitive.
- KCC
- Knowledge Consistency Checker: the process on each DC that builds the replication topology automatically.
- repadmin /replsummary
- A command that summarizes replication status, failures and largest deltas for all DCs.
- Trusting domain
- The domain holding resources that accepts authentication from another domain.
- Forest trust
- A transitive trust between two forest root domains covering every domain in both forests.
- Shortcut trust
- A manual transitive trust inside one forest that shortens Kerberos referral paths between distant domains.
- Selective authentication
- A trust setting requiring the Allowed to authenticate permission on each computer before trusted users can reach it.
- SID filtering
- Removing foreign SIDs, including sIDHistory values, from tokens crossing a trust to block privilege escalation.
- Domain local group
- A group whose permissions apply only in its own domain but which can contain members from any trusted domain.
- Global group
- A group containing members only from its own domain that can be used for permissions across the forest.
- Universal group
- A group with members from any domain in the forest, usable anywhere, with membership replicated to the global catalog.
- gMSA
- Group managed service account: a service identity whose password AD rotates and releases only to authorized hosts.
- KDS root key
- The domain key that Key Distribution Services uses to generate gMSA passwords; required once before the first gMSA.
- PSO
- Password Settings Object: a fine-grained password and lockout policy applied to users or global security groups.
- Precedence
- The PSO attribute that resolves conflicts; the lowest value wins, and a directly linked PSO beats group-linked ones.
- Resultant password policy
- The single policy that actually applies to a user, shown by Get-ADUserResultantPasswordPolicy.
- AD Recycle Bin
- An optional forest feature that preserves all attributes of deleted objects so they can be restored online.
- Tombstone
- A deleted object stripped of most attributes, kept only so the deletion can replicate before garbage collection.
- Entra Connect Sync
- An on-premises sync server with the full hybrid feature set; one active server per tenant.
- Staging mode
- A Connect Sync server that imports and syncs but does not export, used for failover and testing changes.
- Entra Cloud Sync
- Sync configured in the cloud using lightweight on-premises provisioning agents; suits multiple or disconnected forests.
- Pass-through authentication
- Sign-in method where on-premises agents validate passwords against AD DS in real time.
- Seamless SSO
- Kerberos-based automatic sign-in to Entra ID for domain-joined devices on the corporate network, using the AZUREADSSOACC account.
- LSDOU
- Group Policy application order: Local, Site, Domain, OU; later GPOs win conflicts.
- Enforced
- A GPO link option that prevents blocking and makes the GPO win over lower-level GPOs.
- Block Inheritance
- An OU or domain setting that stops non-enforced GPOs from parent containers applying.
- Loopback processing
- Applying user settings based on the computer's GPOs, in Replace or Merge mode.
- Central Store
- The PolicyDefinitions folder in SYSVOL that provides shared ADMX templates to all admins.
- ADMT
- Active Directory Migration Tool: migrates users, groups, computers and service accounts between domains or forests.
- SID history
- The sIDHistory attribute holding an account's previous SIDs so old resource permissions keep working after migration.
- Security translation
- ADMT step that replaces old SIDs with new ones in ACLs, profiles and group memberships on resources.
- Password Export Server
- A service installed on a source DC that lets ADMT migrate user passwords.
- Functional level
- Domain- or forest-wide setting that unlocks AD features and limits which DC OS versions may be present.
Domain 2: Manage Windows Server instances and workloads in a hybrid environment (11%)
Exam tips
- Repeated credential prompts through a WAC gateway point to Kerberos constrained delegation. For on-premises servers you want to manage from the Azure portal without opening inbound internet ports, the answer is Azure Arc plus Windows Admin Center.
- Interactive with one server means Enter-PSSession; many servers at once means Invoke-Command. For JEA, the .psrc says what (commands) and the .pssc says who and how (groups, run-as account, transcripts).
- Onboarding many servers without interactive sign-in points to a service principal with the Azure Connected Machine Onboarding role. Arc needs only outbound 443; if a question suggests opening inbound ports for Arc, it is wrong.
- Audit reports, Deny blocks, DINE and Modify change things. If a question says new resources are compliant but old ones are not, the missing step is a remediation task. Anything about settings inside Windows needs machine configuration.
- Scheduled patching on an Azure VM will not work unless the patch orchestration is Customer Managed Schedules. Urgent single fixes point to one-time update; recurring windows point to a maintenance configuration.
- If a runbook must touch on-premises resources, the answer is a hybrid runbook worker. If a runbook change seems ignored, it was probably never published. For authenticating to Azure, choose the managed identity, not Run As.
- If a scenario wants a new file server to keep the old server's name and IP with minimal client changes, the answer is Storage Migration Service with cut over. Remember the orchestrator must be Windows Server 2019 or later.
- Physical servers and other-cloud VMs need the agent-based method with the Mobility service. Hyper-V uses a provider installed on the hosts, not agents in guests. Always do a test migration before the real one.
- A new DHCP server that will not hand out leases in a domain usually has not been authorized in AD. For in-place upgrades, watch for edition changes and Server Core to Desktop Experience switches, which are not allowed.
Key terms
- Gateway mode
- WAC installed on Windows Server and shared by multiple administrators through their browsers.
- Desktop mode
- WAC installed on a Windows client for a single local user.
- Extension
- A plug-in that adds a tool or solution to Windows Admin Center, managed from the extension feed.
- Resource-based constrained delegation
- Kerberos setting on a target computer allowing a named account, such as the WAC gateway, to delegate to it.
- WAC in the Azure portal
- Managing Azure VMs or Arc-enabled servers through Windows Admin Center from the portal, with Entra ID sign-in and Azure RBAC.
- WinRM
- Windows Remote Management: the service and protocol that carries PowerShell remoting on ports 5985 and 5986.
- Invoke-Command
- Runs a script block on one or many remote computers in parallel and returns the results.
- Role capability file
- A .psrc file defining the cmdlets, functions and commands a JEA role may use.
- Session configuration file
- A .pssc file defining a JEA endpoint: session type, run-as identity, transcripts and group-to-role mappings.
- Virtual account
- A temporary local administrator identity created for a JEA session and discarded when it ends.
- Connected Machine agent
- The agent installed on non-Azure servers that connects them to Azure Arc over outbound HTTPS.
- azcmagent
- The command-line tool for connecting, checking and configuring the Arc agent.
- Service principal
- An Entra ID application identity used by scripts to onboard servers without interactive sign-in.
- Azure Connected Machine Onboarding
- A built-in role that allows onboarding Arc machines but not managing them.
- VM extension
- A small add-on application Azure deploys and manages on a VM or Arc-enabled server.
- Policy assignment
- The binding of a policy definition or initiative to a scope with parameters and exclusions.
- Initiative
- A group of policy definitions assigned and tracked together.
- DeployIfNotExists
- A policy effect that deploys a related resource when it is missing; needs a managed identity and remediation for existing resources.
- Remediation task
- A job that applies DeployIfNotExists or Modify changes to resources that already existed when the policy was assigned.
- Machine configuration
- Azure Policy's in-guest auditing and configuration of OS settings on Azure VMs and Arc-enabled servers.
- Periodic assessment
- Automatic recurring check (about every 24 hours) for missing updates on a machine.
- One-time update
- An immediate, ad hoc update installation on selected machines.
- Maintenance configuration
- A scheduled update policy with window, recurrence, update selection and reboot settings, applied to machines or dynamic scopes.
- Dynamic scope
- Rule-based machine selection for a maintenance configuration using subscription, resource group, location, OS or tags.
- Hotpatching
- Applying security updates in memory without a reboot, between quarterly baseline cumulative updates.
- Automation account
- The Azure resource that holds runbooks, schedules, modules and shared assets.
- Runbook
- A PowerShell, Python or graphical script run by Azure Automation; only the published version runs in production.
- Webhook
- An HTTPS URL that starts a specific runbook when called, shown only once at creation.
- Hybrid runbook worker
- A machine you manage that runs Automation jobs locally so runbooks can reach on-premises resources.
- Hybrid worker group
- A set of hybrid workers; jobs targeted to the group run on any available member.
- Orchestrator
- The Windows Server running Storage Migration Service that coordinates inventory, transfer and cutover.
- Inventory
- The SMS phase that collects shares, files, security and configuration from the source server.
- Transfer
- The SMS phase that copies data, shares, permissions and local accounts to the destination, repeatable for deltas.
- Cut over
- The SMS phase that moves the source's name and IP addresses to the destination and renames the source.
- SMS Proxy
- An optional service on the destination that improves transfer performance.
- Azure Migrate project
- The container in Azure that holds discovered servers, assessments and migration status.
- Azure Migrate appliance
- An on-premises VM or server that discovers servers agentlessly and collects performance and dependency data.
- Performance-based sizing
- Assessment sizing from measured utilization rather than allocated resources.
- Mobility service
- The agent installed on physical or other-cloud servers for agent-based replication.
- Test migration
- Creating a copy of the migrated VM in an isolated network to validate before the real cutover.
- In-place upgrade
- Upgrading the OS on the existing server while keeping roles, settings and data.
- Export-DhcpServer
- PowerShell cmdlet exporting DHCP configuration and optionally leases to an XML file.
- Add-DhcpServerInDC
- Authorizes a DHCP server in AD so it may hand out leases in the domain.
- printbrm
- Command-line printer backup and restore tool used for print server migration.
- Web Deploy
- Microsoft tool (msdeploy) that syncs or packages IIS sites, configuration and content between servers.
Domain 3: Manage virtual machines (12%)
Exam tips
- 32-bit guest or legacy PXE means generation 1. BitLocker in the guest, Secure Boot or Windows 11 means generation 2 with vTPM. Generation cannot be converted after creation.
- Nested Hyper-V fails to install inside a VM when ExposeVirtualizationExtensions is not set (and the VM must be off to set it). Inner VMs with no network usually point to missing MAC address spoofing. PowerShell Direct needs guest credentials and must run on the same host.
- Guest cluster shared storage that must support online resize, host backup or replica is a VHD Set, not shared VHDX. Disks over 2 TB or for generation 2 boot must be VHDX.
- If the question needs an application-consistent restore point, choose a production checkpoint. If it asks how to protect against host storage failure or keep 30 days of history, the answer is a backup, never a checkpoint.
- Host access but no physical network means internal; VMs only means private. For teaming on modern Hyper-V hosts, choose SET, which uses switch-independent mode and needs identical NICs, not LBFO.
- Migration fails when started from a remote console: CredSSP is in use; either sign in to the source host or switch to Kerberos with constrained delegation. Moving only disks on the same host is storage migration.
- Test failover never interrupts replication. Planned failover starts on the primary and loses no data; unplanned failover starts on the replica and can lose data. Cross-domain or workgroup hosts need certificate-based authentication.
- Test failover uses an isolated network and does not stop replication. Order of operations after a real failover: commit, reprotect, then fail back. Hyper-V hosts need the ASR provider and the Recovery Services agent.
- Paying for Windows licenses twice is the Azure Hybrid Benefit trap. A captured VM that will be deployed many times must be generalized with Sysprep. No-reboot monthly security patching in Azure points to Azure Edition with hotpatching.
Key terms
- Generation 2 VM
- A UEFI-based Hyper-V VM with SCSI boot, Secure Boot and vTPM support; generation cannot be changed later.
- Dynamic memory
- Hyper-V feature that adjusts VM RAM between minimum and maximum based on demand, with startup memory and buffer settings.
- Integration services
- Guest components such as shutdown, time sync, heartbeat, data exchange, backup and guest services that communicate over VMBus.
- Enhanced session mode
- VMConnect sessions over RDP through the VMBus, adding clipboard, drives and device redirection.
- Virtual TPM
- An emulated TPM 2.0 device for a generation 2 VM, protected by a key protector.
- Nested virtualization
- Running Hyper-V inside a VM so that VM can host its own VMs.
- ExposeVirtualizationExtensions
- Set-VMProcessor parameter that passes hardware virtualization features into a VM.
- MAC address spoofing
- Allowing a VM adapter to send frames with MAC addresses other than its own, needed for inner VM networking.
- PowerShell Direct
- Running PowerShell in a VM from its Hyper-V host over VMBus with no network required.
- VMBus
- The high-speed channel between a Hyper-V host and its guests used by integration services and PowerShell Direct.
- VHDX
- Hyper-V disk format supporting up to 64 TB, 4 KB sectors, corruption-resistant metadata and TRIM.
- Fixed-size disk
- A virtual disk that allocates its full size at creation for predictable performance.
- Dynamically expanding disk
- A virtual disk that grows as data is written, up to its configured maximum.
- Differencing disk
- A child disk storing only changes relative to a read-only parent.
- VHD Set
- A .vhds shared disk format for guest clusters supporting online resize, host backup and Hyper-V Replica.
- Standard checkpoint
- Captures disk plus memory and device state; restores the VM exactly as it was, but not application-consistent.
- Production checkpoint
- Uses VSS or a file system freeze for an application-consistent point in time without memory; restores to a cold boot.
- AVHDX
- The differencing disk file created for each checkpoint to hold new writes.
- Checkpoint merge
- Background process that folds AVHDX changes into the parent when a checkpoint is deleted.
- VM-GenerationID
- A value that lets a virtualized DC detect it has been rolled back and protect AD replication.
- External switch
- A virtual switch bound to a physical NIC so VMs can reach the physical network.
- Internal switch
- A virtual switch connecting VMs and the host, with no physical network access.
- Private switch
- A virtual switch connecting only VMs to each other; the host is excluded.
- Switch Embedded Teaming
- NIC teaming built into the Hyper-V virtual switch, up to eight identical adapters, switch-independent.
- DHCP guard
- A VM adapter setting that blocks DHCP server messages from unauthorized VMs.
- Live migration
- Moving a running VM between Hyper-V hosts with no noticeable downtime.
- Shared-nothing live migration
- Live migration of a VM and its storage between hosts without shared storage.
- Storage migration
- Moving a running VM's disks and files to new storage on the same host.
- CredSSP
- Default live migration authentication; requires signing in to the source host to start the move.
- Kerberos constrained delegation
- AD setting allowing hosts to delegate for cifs and Microsoft Virtual System Migration Service, enabling remote migration starts.
- Replica server
- The Hyper-V host that receives replicated VM changes and can run the VM after failover.
- Replication frequency
- How often changes are sent: every 30 seconds, 5 minutes or 15 minutes.
- Recovery point
- A saved point in time on the replica that you can fail over to; additional hourly points can be kept.
- Planned failover
- Failover initiated from the primary with the VM shut down, sending all changes so no data is lost.
- Hyper-V Replica Broker
- Failover cluster role that allows a cluster to act as a replica server.
- RPO
- Recovery point objective: the maximum tolerable data loss, measured as time.
- RTO
- Recovery time objective: the maximum tolerable time to restore service.
- Recovery Services vault
- The Azure resource that stores Site Recovery and Backup configuration and data.
- Recovery plan
- An ordered set of machine groups with scripts and manual steps that fail over together.
- Reprotect
- Reversing replication after failover so the VM is protected back toward the original site before failback.
- Azure Hybrid Benefit
- Using eligible on-premises Windows Server licenses in Azure to pay only the base compute rate.
- Sysprep /generalize
- Removes machine-specific data such as the SID so an image can be deployed many times.
- Azure Compute Gallery
- A service that stores image definitions and versions, replicates them across regions and shares them.
- Image definition
- The logical grouping in a gallery that describes an image (OS, generation, generalized or specialized).
- Azure Edition
- Windows Server Datacenter: Azure Edition, available on Azure, supporting hotpatching.
Domain 4: Implement and manage an on-premises and hybrid networking infrastructure (12%)
Exam tips
- Secure only dynamic updates require an AD-integrated zone. Secondary zones can never be AD-integrated. A stub zone tracks name server changes automatically; a conditional forwarder does not.
- One partner domain means conditional forwarder; everything else means forwarder. Returning different answers to different client subnets from the same zone means DNS policies with zone scopes.
- Signing is done on the authoritative zone; validation is done by resolvers using trust anchors; the NRPT is what makes Windows clients require validation. DNSSEC gives integrity, not confidentiality.
- Match direction to component: on-premises to Azure uses the inbound endpoint and a conditional forwarder; Azure to on-premises uses the outbound endpoint and a forwarding ruleset. Only one auto-registration zone per VNet.
- Know the option precedence (reservation over scope over server) and that authorization needs Enterprise Admins by default. If a server is installed but hands out nothing, suspect authorization.
- Load balance equals active-active in the same site; hot standby equals active-passive, typical for a central server backing up branches. Failover never covers IPv6 and never more than two servers per relationship.
- If an answer choice says to configure a static IP in the guest OS network adapter of an Azure VM, it's the trap. Set static on the NIC in Azure; keep the guest on DHCP. Also remember 5 reserved addresses per subnet.
- Watch for the word 'encrypted': ExpressRoute alone is private, not encrypted. And the gateway subnet must be named GatewaySubnet. Azure Network Adapter is always one server, point-to-site.
Key terms
- Primary zone
- A zone holding the writable copy of DNS data, in a file or in AD.
- Secondary zone
- A read-only copy of a zone kept current by zone transfers from a master server.
- Stub zone
- A zone holding only SOA, NS and glue A records to locate another zone's authoritative servers.
- Replication scope
- The set of DCs that receive an AD-integrated zone: forest, domain, domain partition or a custom partition.
- Secure dynamic updates
- Dynamic registration allowed only by authenticated domain members, available only on AD-integrated zones.
- Forwarder
- An upstream DNS server that receives all queries the local server cannot resolve itself.
- Conditional forwarder
- A rule sending queries for one specific domain to designated DNS servers.
- Root hints
- The list of root name servers used for iterative resolution when forwarders are absent or unavailable.
- DNS policy
- A rule that allows, denies, ignores or redirects queries based on criteria such as client subnet or time of day.
- Zone scope
- An alternate set of records within a zone, selected by DNS policies.
- DNSSEC
- Extensions that add digital signatures to DNS data so resolvers can verify authenticity and integrity.
- RRSIG
- A record containing the signature over a set of DNS records.
- Trust anchor
- A preconfigured public key or DS record a resolver trusts as the start of a DNSSEC validation chain.
- Key Master
- The DNS server responsible for generating and rolling over keys for a signed zone.
- NRPT
- Name Resolution Policy Table: client rules, delivered by Group Policy, that require DNSSEC validation or direct queries for specific namespaces.
- Private DNS zone
- An Azure DNS zone that resolves only from virtual networks linked to it, not from the internet.
- Virtual network link
- The connection between a private zone and a VNet that lets the VNet resolve the zone and optionally auto-register VM records.
- Auto-registration
- A link setting that makes Azure create and maintain A records for VMs in the linked VNet; allowed for only one private zone per VNet.
- Inbound endpoint
- A Private Resolver IP address in the VNet that on-premises DNS servers forward queries to for Azure private names.
- Outbound endpoint and forwarding ruleset
- The Private Resolver components that forward queries for chosen domains from Azure to other DNS servers, such as on-premises DCs.
- Scope
- A range of IP addresses for one subnet, with a subnet mask, lease duration and options, from which DHCP leases addresses.
- Reservation
- A scope entry that always gives the same IP address to a client identified by its MAC address.
- Exclusion range
- Addresses inside a scope that DHCP will never lease, used for statically configured devices.
- DHCP relay agent
- A router feature or service that forwards broadcast DHCP requests from a remote subnet to a DHCP server as unicast.
- Authorization
- Registering a domain-member DHCP server in AD so it is allowed to lease addresses; requires Enterprise Admins rights by default.
- DHCP failover
- A relationship between two DHCP servers that replicate IPv4 lease information so either can serve the same scopes.
- Load balance mode
- The default failover mode in which both servers actively lease addresses, split by a configurable percentage.
- Hot standby mode
- A failover mode with one active and one standby server; the standby holds a reserve percentage of addresses for immediate use.
- MCLT
- Maximum Client Lead Time: the period a server can extend leases beyond its partner's knowledge, and the wait before full takeover after partner down.
- IPAM
- IP Address Management: a Windows Server feature that centrally discovers, monitors, manages and audits DHCP, DNS and IP address space.
- Address space
- The CIDR range or ranges assigned to a VNet, from which its subnets are allocated.
- Reserved addresses
- The five addresses Azure keeps in every subnet: the network address, the first three host addresses and the broadcast address.
- Static private IP
- A NIC IP configuration setting that pins a chosen private address to the NIC so it never changes until you change it.
- Custom DNS servers
- DNS server addresses configured on a VNet or NIC that Azure's DHCP gives to VMs instead of Azure-provided DNS.
- Site-to-site VPN
- An IPsec/IKE tunnel over the internet between an on-premises VPN device and an Azure VPN gateway, connecting entire networks.
- Local network gateway
- An Azure resource describing the on-premises VPN device's public IP and the on-premises address prefixes.
- Point-to-site VPN
- A VPN from an individual computer to a VNet, authenticated by certificate, Entra ID or RADIUS.
- ExpressRoute
- A private connection to Microsoft through a connectivity provider that bypasses the public internet; not encrypted by default.
- Azure Network Adapter
- A Windows Admin Center feature that connects a single Windows Server to a VNet using a point-to-site VPN it sets up for you.
Domain 5: Manage storage and file services (16%)
Exam tips
- Exactly one cloud endpoint per sync group; one Storage Sync Service per registered server; no cloud tiering on the system volume. If free space and date policies disagree, free space wins.
- Both layers apply and the most restrictive wins. Share access is Azure RBAC on synced Entra identities; fine-grained control is NTFS. Owner or Contributor on the storage account does not give SMB data access.
- Signing equals integrity and anti-relay; encryption equals confidentiality plus integrity. SMB over QUIC means UDP 443, TLS 1.3 and a certificate. Audit SMBv1 before removing it.
- Hard blocks, soft warns; active blocks, passive warns. DFSR has no distributed file locking, so beware answers that use it for files edited simultaneously at multiple sites.
- Know what NTFS has that ReFS doesn't (boot, compression, EFS, disk quotas), and never pick dedup for the system volume. Thin provisioning can run out of real space, so it needs monitoring.
- Two-node or even-node clusters need a witness. No shared storage or multi-site means file share or cloud witness; only the disk witness stores the cluster database. CAU self-updating runs on the cluster, remote-updating from another machine.
- Minimums: 2 nodes for S2D and two-way mirror, 3 for three-way mirror, 4 for dual parity. SOFS is for application data, never the default answer for user home folders.
- Zero data loss equals synchronous and short distance; long distance equals asynchronous. Automatic failover only in a stretch cluster. Shared VHDX for guest clusters goes on CSV or SOFS, attached via SCSI.
Key terms
- Storage Sync Service
- The top-level Azure resource that registered servers join and that holds sync groups.
- Sync group
- A definition of one synchronized data set, made of one cloud endpoint and one or more server endpoints.
- Cloud endpoint
- The Azure file share that acts as the central copy in a sync group; each group has exactly one.
- Server endpoint
- A path on a registered Windows Server that participates in a sync group.
- Cloud tiering
- A server endpoint feature that keeps hot files local and replaces cold files with stubs that recall content from Azure on access.
- AD DS authentication for Azure Files
- A configuration that represents the storage account as an AD object so domain users can access SMB shares with Kerberos.
- Share-level permissions
- Azure RBAC roles assigned on a file share that control whether an identity can connect and with what maximum access.
- Storage File Data SMB Share Elevated Contributor
- The share role that allows read, write, delete and modifying NTFS permissions.
- NTFS permissions
- Directory and file ACLs enforced inside the share, set with Explorer or icacls just as on a Windows file server.
- SMB encryption
- An SMB 3.x feature that encrypts file traffic end to end, enabled per share or server-wide.
- SMB signing
- Cryptographic signing of SMB messages that detects tampering and blocks relay attacks, without hiding content.
- SMB over QUIC
- SMB carried over QUIC on UDP 443 with TLS 1.3, allowing secure file access over the internet without a VPN.
- SMBv1
- The original SMB dialect, insecure and deprecated, which should be audited, disabled and removed.
- Hard vs soft quota
- A hard quota blocks writes at the limit; a soft quota only sends notifications.
- Active vs passive file screen
- An active screen blocks saving matching files; a passive screen allows it but notifies or logs.
- Domain-based namespace
- A DFS namespace stored in AD, accessed via the domain name and hosted on one or more namespace servers.
- Referral
- The list of folder targets a DFS namespace returns to a client, ordered by site cost so the closest target is tried first.
- DFS Replication
- A multi-master engine that replicates folders between servers using remote differential compression and a staging area.
- Storage pool
- A group of physical disks from which Storage Spaces virtual disks are created.
- Two-way vs three-way mirror
- Mirror resiliency keeping two copies (tolerates one disk failure) or three copies (tolerates two).
- Thin provisioning
- Creating a virtual disk larger than available space and allocating capacity only as data is written.
- ReFS
- Resilient File System, which checksums metadata (and data with integrity streams), self-repairs with Storage Spaces mirrors and supports fast block cloning.
- Data Deduplication
- A post-process feature that stores duplicate data chunks once per volume, with usage types Default, HyperV and Backup.
- Validation
- The Test-Cluster checks of hardware and configuration; a passing report is required for a supported cluster.
- Quorum
- The majority of votes (nodes plus witness) a cluster needs to stay running, preventing split brain.
- Disk witness
- A small shared clustered disk that holds a vote and a copy of the cluster database.
- Cloud witness
- An Azure Storage blob used as the quorum tie-breaker, needing only a storage account and outbound HTTPS.
- Cluster-Aware Updating
- A feature that updates cluster nodes one at a time while roles move, in self-updating or remote-updating mode.
- Storage Spaces Direct
- Software-defined storage that pools local drives across 2 to 16 cluster nodes into highly available volumes.
- Cache tier
- The fastest drives in an S2D node, automatically used to cache writes (and reads too when capacity drives are HDDs) for the slower capacity drives.
- Cluster Shared Volume
- A clustered volume that all nodes can read and write at the same time, used by Hyper-V and SOFS.
- Nested resiliency
- A two-node S2D option that survives a node failure and a drive failure simultaneously.
- Scale-Out File Server
- An active-active clustered file server role on CSVs for application data, using continuously available SMB shares.
- Storage Replica
- Block-level volume replication over SMB 3 between servers or clusters, requiring data and log volumes on both sides.
- Synchronous replication
- Writes are acknowledged only after reaching both sites, giving zero RPO but requiring low latency.
- Asynchronous replication
- Writes are acknowledged at the source and sent later, allowing long distances with a non-zero RPO.
- Stretch cluster
- One failover cluster split across two sites with replicated storage, supporting automatic failover between sites.
- VHD Set
- The .vhds shared virtual disk format for guest clusters, stored on CSV or SOFS and supporting online resize and host backup.
Domain 6: Secure Windows Server infrastructure (12%)
Exam tips
- OSConfig is Windows Server 2025 with drift control; SCT is GPO backups plus Policy Analyzer and LGPO for any supported version. Choose the scenario matching the server's role (DC, member or workgroup).
- Credential Guard needs VBS (UEFI, Secure Boot, virtualization extensions) and is not supported on DCs; LSA protection (RunAsPPL) works on DCs and doesn't need VBS.
- Need to block drivers or apply to everyone on the device: App Control. Need rules per user or group: AppLocker. Always audit first, reading event 3076 before enforcing.
- A device backs up to AD DS or Entra ID, never both. Remember the three AD setup cmdlets in order: schema, computer self permission, read permission. DSRM password backup is AD only.
- Protected Users is for human admin accounts only; never add service or computer accounts. Deny-logon rights for Tier 0 groups go on lower-tier machines, not on DCs.
- Block rules beat allow rules, except allow-if-secure with override block rules. Preshared key is for testing only. Domain profile needs the machine to authenticate to a DC on that network.
- On-premises servers reach Defender for Cloud through Azure Arc. JIT and file integrity monitoring mean Plan 2, and JIT applies to Azure VMs via NSG or Azure Firewall rules.
- Where the encryption happens is the key: SSE in storage (always on), encryption at host on the host (covers temp disk and cache), ADE inside the guest via BitLocker. Customer control of keys means customer-managed keys in Key Vault.
Key terms
- Security baseline
- A Microsoft-recommended set of security configuration settings for a product and role.
- Security Compliance Toolkit
- A free set of baselines as GPO backups plus tools such as Policy Analyzer and LGPO.exe.
- OSConfig
- A Windows Server 2025 security configuration platform, managed with PowerShell, that applies role-based baselines.
- Drift control
- OSConfig's periodic check that automatically resets changed baseline settings to their desired values.
- Policy Analyzer
- An SCT tool that compares GPOs or local policy against baselines and flags differences and conflicts.
- Virtualization-based security
- Hyper-V-backed isolation that creates a secure memory region the normal OS kernel cannot access.
- Credential Guard
- A VBS feature that stores NTLM hashes and Kerberos TGTs in the isolated LSAIso process to defeat credential dumping.
- LSA protection
- Running LSASS as a Protected Process Light so unsigned or non-protected code cannot read its memory or inject into it.
- HVCI (memory integrity)
- A VBS feature that validates kernel-mode code integrity inside the secure environment before it runs.
- App Control for Business
- The Windows code integrity based application control feature, formerly WDAC, that governs drivers and user-mode code device-wide.
- Audit mode
- A policy mode that logs what would be blocked (event 3076) without blocking, used to test policies before enforcing.
- Supplemental policy
- An App Control policy that extends a base policy to allow additional applications.
- Managed installer
- A trusted deployment tool whose installed software App Control automatically allows.
- AppLocker
- An older user-mode application control feature with per-user or per-group rules, requiring the Application Identity service.
- Windows LAPS
- A built-in Windows feature that sets unique, rotated local admin passwords and backs them up to AD DS or Entra ID.
- Update-LapsADSchema
- The cmdlet that extends the AD schema with the Windows LAPS attributes.
- Set-LapsADComputerSelfPermission
- Grants computers in an OU permission to write their own LAPS password to AD.
- Password encryption
- An AD backup option that encrypts stored passwords so only authorized decryptors can read them; needs Windows Server 2016 DFL.
- Post-authentication actions
- Automatic reset, sign-out or restart after the managed account is used and a grace period passes.
- Tier 0
- The identity tier: domain controllers, AD and systems that control them; its credentials must never be exposed on lower tiers.
- Protected Users
- A global group whose members cannot use NTLM, DES or RC4, cached credentials or delegation, and get short-lived TGTs.
- Privileged access workstation
- A dedicated hardened device used only for administration of sensitive systems.
- Authentication policy silo
- An AD object that limits where members of a silo can obtain Kerberos tickets, restricting privileged accounts to specified hosts.
- Firewall profile
- Domain, Private or Public: a set of firewall settings chosen per network adapter based on the detected network.
- Allow the connection if it is secure
- A rule action that allows traffic only when protected by IPsec authentication and optionally encryption.
- Connection security rule
- A rule telling Windows when and how to use IPsec between computers, such as isolation or server-to-server.
- Authentication exemption
- A connection security rule that exempts listed hosts from IPsec requirements.
- Main mode and quick mode
- The IPsec negotiation phases: main mode authenticates peers, quick mode sets up protection for data.
- Defender for Cloud
- Azure's security posture management and workload protection service for Azure, hybrid and multicloud resources.
- Defender for Servers Plan 2
- The server protection plan that adds features such as JIT VM access and file integrity monitoring to Plan 1.
- Recommendation
- A Defender for Cloud finding describing a security weakness on a resource and how to remediate it.
- Secure score
- A measure of security posture that rises as you remediate recommendations.
- Just-in-time VM access
- A feature that blocks management ports by default and opens them only for approved requests, source IPs and time windows.
- BitLocker
- Windows full-volume encryption, usually protected by a TPM, with recovery passwords that should be backed up to AD DS.
- BitLocker Network Unlock
- A feature that automatically unlocks BitLocker-protected servers at boot when they are on the trusted wired corporate network.
- Server-side encryption
- Always-on encryption of Azure managed disks at rest, with platform-managed or customer-managed keys.
- Encryption at host
- Azure encryption performed on the VM's host, covering temp disks and disk caches as well as data flowing to storage.
- Azure Disk Encryption
- The older option using BitLocker inside the guest with keys in Key Vault, announced for retirement.
Domain 7: Monitor and troubleshoot Windows Server environments (16%)
Exam tips
- For history and trends use Performance Monitor with data collector sets; for which process is doing it right now use Resource Monitor. Disk latency counters (Avg. Disk sec/Read or Write) are the clearest disk bottleneck signal.
- Collector-initiated equals pull from a listed set; source-initiated equals push configured by Group Policy, better for many computers. WEF rides on WinRM, and forwarded events arrive in the Forwarded Events log.
- System Insights predicts locally and returns OK, Warning, Critical, Error or None; None or Error often just means not enough data yet. WAC alone is not a 24x7 alerting system; pair it with Azure Monitor.
- Hybrid servers need Azure Arc before AMA. DCRs decide what is collected; filter there to control cost. MMA is legacy; any answer that installs it for new work is wrong.
- Works by IP but not by name means DNS. Ping failing does not prove a service is down; test the port. nslookup bypasses the client cache and hosts file, so use Resolve-DnsName to see what apps see.
- Kerberos failure plus clock skew over 5 minutes is a classic exam scenario; the fix is the time hierarchy anchored on the forest root PDC emulator. For Arc disconnected status, run azcmagent show and azcmagent check first.
- Look at boot diagnostics first to split OS problems from network problems. Serial Console needs boot diagnostics and a local password; Run Command needs a healthy VM agent; redeploy loses the temp disk.
- Deleted objects need authoritative restore (or the Recycle Bin); a corrupt DC needs non-authoritative. SYSVOL is DFSR, restored separately with msDFSR-Enabled and msDFSR-Options on the subscription objects.
- MARS equals files, folders and system state direct to Azure, not app-aware. MABS equals app-aware workloads plus local disk, no tape. A network share target in Windows Server Backup keeps only one version.
Key terms
- Performance counter
- A named measurement (object, instance, counter) such as Processor(_Total)\% Processor Time.
- Data collector set
- A saved configuration that records counters, traces and configuration data to log files on demand or on a schedule.
- Baseline
- A recording of normal performance used as a reference for troubleshooting and capacity planning.
- Performance counter alert
- A DCS type that takes an action when a counter crosses a defined threshold.
- Resource Monitor
- A real-time tool showing CPU, memory, disk and network usage per process, with handle search and wait chain analysis.
- Custom view
- A saved Event Viewer filter across one or more logs, exportable as XML.
- Windows Event Forwarding
- A built-in feature that forwards selected events from source computers to a collector over WinRM.
- Collector-initiated subscription
- A subscription in which the collector pulls events from computers listed in the subscription.
- Source-initiated subscription
- A subscription in which sources, configured by Group Policy, push events to the collector; best for many computers.
- Event Log Readers
- A built-in local group whose members can read event logs, used to grant a collector access.
- Windows Admin Center
- A browser-based, locally deployed tool for managing servers, clusters and hybrid services.
- System Insights
- A Windows Server feature that runs local machine learning models to forecast resource capacity.
- Capability
- A System Insights prediction module, such as CPU capacity forecasting or volume consumption forecasting.
- Capability action
- A script attached with Set-InsightsCapabilityAction that runs automatically when a capability returns a given status.
- Azure Monitor agent
- The current agent that collects guest OS logs and performance data, deployed as an extension on Azure VMs and Arc servers.
- Data collection rule
- An Azure resource defining what data to collect from associated machines and where to send it.
- Log Analytics workspace
- The Azure Monitor data store for logs, queried with KQL and billed mainly by ingestion.
- VM insights
- A prebuilt Azure Monitor solution showing VM and Arc server performance, with an optional dependency map.
- Action group
- A reusable set of notifications and actions triggered by Azure Monitor alerts.
- Test-NetConnection
- A PowerShell cmdlet that tests ping, TCP port connectivity and route tracing to a host.
- Resolve-DnsName
- A PowerShell cmdlet for DNS lookups that can target a specific server, record type or DNS-only resolution.
- DNS client cache
- Locally stored DNS answers, including negative ones, kept until their TTL expires; cleared with ipconfig /flushdns.
- APIPA
- Automatic Private IP Addressing: a 169.254.x.x address Windows assigns when DHCP fails.
- Hosts file
- A local file mapping names to IPs that takes priority over DNS queries in the client resolution path.
- Get-WindowsUpdateLog
- A cmdlet that converts Windows Update trace files into a readable WindowsUpdate.log.
- PDC emulator (forest root)
- The authoritative time source for an AD forest, which should sync with a reliable external time source.
- w32tm
- The command-line tool for configuring, querying and resyncing the Windows Time service.
- klist
- A command that lists or purges the Kerberos tickets cached for the current logon session.
- azcmagent check
- An Arc agent command that tests connectivity to the Azure endpoints required by the agent and its extensions.
- Boot diagnostics
- A feature that captures the VM's screenshot and serial log during boot for troubleshooting.
- Serial Console
- A text console to the VM's serial port, reaching the Windows Special Administration Console without networking.
- Run Command
- A feature that runs scripts inside the VM through the Azure VM agent, without network access.
- Redeploy
- Moving a VM to a new Azure host while keeping its disks; temporary disk data is lost.
- SAC
- Special Administration Console: the Windows text-mode console reachable through Serial Console.
- DSRM
- Directory Services Restore Mode: a DC boot mode without AD DS running, used for database restores with a local DSRM password.
- Non-authoritative restore
- Restoring a DC's AD database that then receives newer changes from replication partners.
- Authoritative restore
- Marking restored objects with higher version numbers via ntdsutil so they replicate out and overwrite partners.
- Tombstone lifetime
- How long deleted objects are kept as tombstones; backups older than this must not be restored.
- msDFSR-Options
- The SYSVOL subscription attribute set to 1 on the DC chosen as authoritative in a DFSR SYSVOL restore.
- Windows Server Backup
- The built-in VSS-based backup feature for full server, volumes, files, system state and bare-metal recovery.
- System state backup
- A backup of the registry, boot files and role databases such as AD DS and SYSVOL, used to recover AD.
- Bare-metal recovery
- A backup containing system state and all volumes required to boot, used to rebuild a server on new hardware.
- MARS agent
- The Azure Recovery Services agent that backs up files, folders and system state from a Windows machine directly to a Recovery Services vault.
- MABS
- Microsoft Azure Backup Server: a DPM-based on-premises backup server with local disk storage and Azure retention for application workloads.
Study AZ-802 for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the AZ-802 study planLessons, quizzes, exam simulations and hands-on labs.