All certifications / AZ-802 / Lessons
AZ-802 AZ-802 lessons
Study AZ-802 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the AZ-802 study planA week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Domain 1: Deploy and manage AD DS
- Deploying domain controllers: Install-ADDSForest / Install-ADDSDomainController, install from media (IFM), read-only DCs, DCs on Azure VMs (static private IP on the NIC, NTDS on a data disk with host caching off)
- FSMO roles (schema master, domain naming master, RID master, PDC emulator, infrastructure master): placement, transfer vs seize
- Sites, subnets, site links, link cost and bridging; replication health with repadmin and dcdiag
- Forest, external, shortcut and realm trusts; transitivity and direction; selective authentication; SID filtering
- Users, groups (domain local, global, universal), OUs and delegation of control; group managed service accounts and the KDS root key
- Default Domain Policy vs fine-grained password policies (PSOs); AD Recycle Bin
- Hybrid identity: Entra Connect Sync (including staging mode) vs Entra Cloud Sync; password hash sync, pass-through authentication, seamless SSO
- Group Policy processing (LSDOU), Enforced and Block Inheritance, security filtering, loopback processing, Central Store, backup and restore
- Migrating AD objects between domains and forests with ADMT and SID history; domain and forest functional levels when upgrading DCs
Domain 2: Manage Windows Server instances and workloads in a hybrid environment
- Windows Admin Center: desktop vs gateway mode, extensions, Kerberos constrained delegation, Windows Admin Center for Azure VMs and Arc-enabled servers
- PowerShell remoting: Enter-PSSession vs Invoke-Command, Just Enough Administration (JEA) role capability and session configuration files
- Azure Arc-enabled servers: Connected Machine agent (azcmagent), at-scale onboarding with a service principal, extensions, tags and RBAC
- Azure Policy and machine configuration for Arc-enabled and Azure servers; audit vs deploy effects
- Azure Update Manager: assessments, one-time updates, maintenance configurations; hotpatching for Windows Server
- Azure Automation runbooks and hybrid runbook workers
- Storage Migration Service: inventory, transfer and cut over of file servers, including identity takeover
- Azure Migrate: discovery and assessment, server migration of Hyper-V, VMware and physical servers to Azure
- Upgrading and migrating server roles (in-place upgrade paths, migrating DHCP, print and IIS workloads)
Domain 3: Manage virtual machines
- Hyper-V VM configuration: generation 1 vs 2, dynamic memory, integration services, enhanced session mode, Secure Boot and virtual TPM
- Nested virtualization requirements; PowerShell Direct
- Virtual disks: VHD vs VHDX, fixed, dynamic and differencing disks; shared VHDX / VHD Set
- Checkpoints: production vs standard; why checkpoints are not backups
- Hyper-V virtual switches (external, internal, private) and Switch Embedded Teaming
- Live migration and storage migration between Hyper-V hosts; Kerberos vs CredSSP authentication
- Hyper-V Replica: primary and replica servers, replication frequency, recovery points, planned and unplanned failover, test failover
- Azure Site Recovery for Hyper-V and Azure VMs: recovery plans, test failover, RPO and failback
- Azure VMs running Windows Server: Azure Hybrid Benefit, Sysprep and Azure Compute Gallery, extensions, Azure Edition hotpatching
Domain 4: Implement and manage an on-premises and hybrid networking infrastructure
- DNS zones: primary, secondary, stub and AD-integrated; replication scope; secure dynamic updates
- Forwarders, conditional forwarders and root hints; DNS policies and zone scopes
- DNSSEC signing, trust anchors and the Name Resolution Policy Table (NRPT)
- Azure DNS private zones, virtual network links and auto-registration; Azure DNS Private Resolver
- DHCP scopes, reservations, options and relay; authorization in AD
- DHCP high availability: failover in load balance and hot standby modes; IPAM
- Azure VNet addressing and static private IPs set on the NIC
- Hybrid connectivity: site-to-site and point-to-site VPN, ExpressRoute, Azure Network Adapter
Domain 5: Manage storage and file services
- Azure File Sync: sync groups, cloud and server endpoints, cloud tiering policies
- Azure Files with AD DS authentication; share-level RBAC vs NTFS permissions
- SMB security: encryption, signing, SMB over QUIC, removing SMBv1
- File Server Resource Manager quotas and file screens; DFS Namespaces and DFS Replication
- Storage Spaces resiliency and provisioning; ReFS vs NTFS; Data Deduplication
- Failover clustering: validation, cluster networks, quorum models and witnesses (disk, file share, cloud), Cluster-Aware Updating
- Storage Spaces Direct: minimum nodes, cache, resiliency; Scale-Out File Server for application data
- Storage Replica: synchronous vs asynchronous, server-to-server and stretch cluster; guest clustering with shared VHDX
Domain 6: Secure Windows Server infrastructure
- Security baselines: OSConfig on Windows Server 2025, Microsoft Security Compliance Toolkit baselines, drift control
- Credential Guard and virtualization-based security; LSA protection
- App Control for Business (WDAC) policies and audit mode; AppLocker differences
- Windows LAPS: backing up local admin passwords to AD DS or Entra ID, rotation and retrieval permissions
- Hardening domain controllers: tiered administration, Protected Users, privileged access workstations, restricting who can log on to DCs
- Windows Defender Firewall profiles, rules and connection security (IPsec) rules
- Microsoft Defender for Servers via Defender for Cloud: onboarding Arc and Azure servers, recommendations, just-in-time VM access
- Encryption: BitLocker on servers and Azure VM disk encryption options; SMB signing and encryption
Domain 7: Monitor and troubleshoot Windows Server environments
- Performance Monitor counters and data collector sets; baselines; Resource Monitor
- Event logs, custom views and event subscriptions (Windows Event Forwarding)
- Windows Admin Center alerts and System Insights predictive capacity
- Azure Monitor agent, data collection rules, VM insights and Log Analytics queries for hybrid servers
- Troubleshooting connectivity and name resolution (Test-NetConnection, Resolve-DnsName, ipconfig /flushdns)
- Windows Update, time service (w32tm) and Kerberos troubleshooting; Arc agent and extension troubleshooting (azcmagent check)
- Azure VM troubleshooting: boot diagnostics, Serial Console, Run Command, redeploy
- AD DS recovery: Directory Services Restore Mode, authoritative vs non-authoritative restore, authoritative SYSVOL (DFSR) restore
- Backup: Windows Server Backup, bare-metal and system state backup, Azure Backup with the MARS agent and MABS