Microsoft Private Public

Administer Windows Server (AZ-802T00)

Learn to deploy, manage, secure, monitor, and troubleshoot Windows Server workloads across on-premises, hybrid, and Microsoft Azure environments and services.

Register or Request Training

Price per student
$2,935.10
Guaranteed to run
Select a date
Please select a class.
  • Private class for your team
  • Live expert instructor
  • Online or on‑location
  • Customizable agenda
  • Proposal responses same day as request

Course Overview

This course teaches IT professionals to deploy, manage, secure, monitor, and troubleshoot Windows Server workloads across on-premises, hybrid, and cloud environments. It covers Active Directory Domain Services, Hyper-V and Azure virtual machines, networking, storage and file services, security hardening, automation, monitoring, and troubleshooting.

Participants work with administrative technologies including Windows Admin Center, PowerShell, Azure Arc, Azure Monitor, Azure Update Manager, and Microsoft Defender for Cloud. The course is intended for Windows Server administrators responsible for identity, security, compute, networking, storage, and monitoring.

Course Benefits

  • Deploy and manage Active Directory Domain Services domain controllers, objects, Group Policy, and hybrid identity services.
  • Administer Windows Server securely with Windows Admin Center, Server Manager, PowerShell remoting, Just Enough Administration, and least-privilege practices.
  • Manage hybrid Windows Server workloads with Azure Arc, Azure Update Manager, Azure Automation, and Azure Machine Configuration.
  • Configure and secure Hyper-V and Azure infrastructure-as-a-service virtual machines.
  • Implement Windows Server and Azure networking services, including DNS, DHCP, IP addressing, routing, firewalls, and IP Address Management.
  • Deploy and manage file and storage services, including Azure Files, Azure File Sync, Storage Spaces, data deduplication, iSCSI, and Storage Replica.
  • Apply identity, endpoint, server, and cloud security controls with Microsoft Defender technologies, Azure Policy, and Microsoft Entra services.
  • Monitor Windows Server and Azure virtual machines, manage event logs and auditing, and troubleshoot identity, networking, performance, deployment, and storage issues.

Delivery Methods

Public Class
Live expert-led online training from anywhere. Guaranteed to run .
Private Class
Delivered for your team at your site or online.

Course Outline

  1. Deploy and manage Active Directory Domain Services domain controllers
    1. Define AD DS forests and domains.
    2. Deploy domain controllers and migrate a domain controller to a new site.
    3. Manage AD DS operations masters.
  2. Deploy and manage Azure IaaS Active Directory domain controllers in Azure
    1. Select an Azure directory and identity implementation option.
    2. Deploy and configure AD DS domain controllers in Azure virtual machines.
    3. Install a replica domain controller or new AD DS forest in Azure.
  3. Manage AD DS domain controllers and FSMO roles
    1. Deploy and maintain domain controllers.
    2. Manage the Global Catalog and operations master roles.
    3. Manage the AD DS schema.
  4. Create and manage Active Directory objects
    1. Manage users, groups, computers, and organizational units.
    2. Create and configure Active Directory objects and properties.
    3. Perform bulk user-account management tasks.
  5. Implement hybrid identity with Windows Server
    1. Select and plan a Microsoft Entra integration model.
    2. Prepare AD DS and configure synchronization with Microsoft Entra Connect.
    3. Implement Seamless Single Sign-On and Microsoft Entra login for Azure virtual machines.
    4. Configure Microsoft Entra Domain Services and join Windows Server virtual machines to a managed domain.
  6. Create and configure Group Policy Objects in Active Directory
    1. Define Group Policy Objects, scope, and inheritance.
    2. Create and configure domain-based Group Policy Objects.
    3. Configure domain and fine-grained password policies.
  7. Implement Group Policy Objects
    1. Implement GPO scope and inheritance.
    2. Create and configure domain-based GPOs.
    3. Work with GPO storage and administrative templates.
  8. Manage advanced features of AD DS
    1. Create trust relationships and implement ESAE forests.
    2. Monitor and troubleshoot AD DS.
    3. Create custom AD DS partitions.
  9. Administer and manage Windows Server IaaS virtual machines remotely
    1. Select an appropriate remote administration tool.
    2. Manage Windows virtual machines with Azure Bastion.
    3. Configure just-in-time administration.
  10. Describe Windows Server administration tools
    1. Use Windows Admin Center and Server Manager.
    2. Identify Remote Server Administration Tools.
    3. Use Windows PowerShell for local and remote administration.
  11. Just Enough Administration in Windows Server
    1. Explain Just Enough Administration and role capabilities.
    2. Create a session configuration file and register a JEA endpoint.
    3. Connect to a JEA endpoint and understand how it limits PowerShell access.
  12. Perform Windows Server secure administration
    1. Apply least-privilege administration and delegated privileges.
    2. Use privileged access workstations and jump servers.
  13. Use advanced Windows PowerShell remoting techniques
    1. Apply common PowerShell remoting techniques.
    2. Send parameters to remote computers and control scope.
    3. Enable multi-hop remoting.
  14. Manage single and multiple computers with Windows PowerShell remoting
    1. Compare remoting with remote connectivity and review remoting security.
    2. Enable and use one-to-one and one-to-many remoting.
    3. Compare remote output with local output.
  15. Manage hybrid workloads with Azure Arc
    1. Onboard Windows Server instances and connect hybrid machines to Azure.
    2. Manage Windows Server instances through Azure Arc.
    3. Restrict access with role-based access control.
  16. Manage Azure updates
    1. Prepare machines for Azure Update Manager.
    2. Assess and deploy updates.
    3. Manage updates at scale.
  17. Automate the configuration of Windows Server IaaS virtual machines
    1. Implement Azure Automation with Desired State Configuration.
    2. Remediate noncompliant servers.
    3. Use Custom Script Extensions and DSC to configure virtual machines.
  18. Enforce virtual machine security configuration with Azure Machine Configuration
    1. Explore extension capabilities and modes.
    2. Apply built-in security baseline policies.
    3. Author and assign custom machine configurations.
  19. Explore Azure Automation with DevOps
    1. Create automation accounts and work with runbooks and shared resources.
    2. Use webhooks, source control integration, and PowerShell workflows.
    3. Explore hybrid management, checkpoints, and parallel processing.
  20. Configure and manage Hyper-V virtual machines
    1. Review virtual machine versions, generations, and virtual disk formats.
    2. Create and configure virtual machines and storage.
    3. Implement guest clusters with shared VHDX.
  21. Configure and manage Hyper-V
    1. Manage Hyper-V hosts with Hyper-V Manager and recommended practices.
    2. Configure Hyper-V networking and advanced networking features.
    3. Explore nested virtualization.
  22. Secure Hyper-V workloads
    1. Describe guarded fabrics, Host Guardian Service, and attestation.
    2. Compare encryption-supported and shielded virtual machines.
    3. Implement a shielded virtual machine.
  23. Implement high availability for Windows Server virtual machines
    1. Select high-availability and network load-balancing options.
    2. Implement Hyper-V live migration.
    3. Implement virtual machine storage migration.
  24. Plan and deploy Windows Server IaaS virtual machines
    1. Review Azure compute and virtual machine storage.
    2. Deploy Azure virtual machines through the portal, Azure CLI, and templates.
    3. Explore additional management and optimization options.
  25. Implement scale and high availability with Windows Server virtual machines
    1. Implement virtual machine scale sets and scaling.
    2. Load balance virtual machines.
    3. Implement Azure Site Recovery.
  26. Implement Windows Server IaaS virtual machine IP addressing and routing
    1. Implement virtual networks and virtual machine IP addressing.
    2. Assign private, public, and static IP addresses.
    3. Implement IP routing and IPv6.
  27. Implement Windows Server IaaS virtual machine network security
    1. Use network security groups, Azure Firewall, and Windows Firewall.
    2. Select an appropriate traffic-filtering solution.
    3. Capture and log network traffic with Azure Network Watcher.
  28. Administer and manage Windows Server IaaS virtual machines remotely
    1. Select an appropriate remote administration tool.
    2. Manage virtual machines through Azure Bastion.
    3. Configure just-in-time administration.
  29. Implement Windows Server DNS
    1. Explore DNS architecture, zones, and records.
    2. Install and configure the DNS role.
    3. Implement DNS forwarding.
  30. Implement DNS for Windows Server IaaS virtual machines
    1. Implement Azure DNS zones and records.
    2. Configure DNS for Azure IaaS virtual machines and split-horizon DNS.
    3. Troubleshoot DNS.
  31. Secure Windows Server DNS
    1. Implement split-horizon DNS and DNS policies.
    2. Secure Windows Server DNS.
    3. Implement DNSSEC.
  32. Deploy and manage DHCP
    1. Install and configure the DHCP role, options, and scopes.
    2. Select DHCP high-availability options.
    3. Implement DHCP failover.
  33. Implement IP Address Management
    1. Deploy and administer IP Address Management.
    2. Configure IPAM options and manage IP addressing.
    3. Manage DNS zones and DHCP servers with IPAM.
  34. Implement Windows Server IaaS virtual machine IP addressing and routing
    1. Implement virtual networks and virtual machine IP addressing.
    2. Assign private, public, and static IP addresses.
    3. Implement IP routing and IPv6.
  35. Implement a hybrid file server infrastructure
    1. Configure Azure Files and connectivity.
    2. Implement and deploy Azure File Sync.
    3. Manage cloud tiering and migrate from DFS Replication to Azure File Sync.
  36. Manage Windows Server file servers
    1. Review Windows Server file systems and File Server Resource Manager.
    2. Configure SMB and address its security considerations.
    3. Use Volume Shadow Copy Service.
  37. Implement Storage Spaces and Storage Spaces Direct
    1. Review Storage Spaces architecture, functionality, and use cases.
    2. Implement Storage Spaces.
    3. Review and implement Storage Spaces Direct.
  38. Implement Windows Server Data Deduplication
    1. Review Data Deduplication architecture, functionality, and use cases.
    2. Implement Data Deduplication.
    3. Manage and maintain Data Deduplication.
  39. Implement Windows Server iSCSI
    1. Review iSCSI components, use cases, and implementation considerations.
    2. Implement iSCSI.
    3. Configure high availability for iSCSI.
  40. Implement Windows Server Storage Replica
    1. Review Storage Replica functionality, components, and prerequisites.
    2. Implement Storage Replica with Windows Admin Center.
    3. Implement Storage Replica with Windows PowerShell.
  41. Manage Microsoft Defender for Endpoint
    1. Explore Microsoft Defender for Endpoint and its key capabilities.
    2. Review Windows Defender Application Control and Device Guard.
    3. Explore Application Guard, Exploit Guard, and System Guard.
  42. Manage Microsoft Defender in Windows clients
    1. Explore Windows Security Center and Credential Guard.
    2. Manage Microsoft Defender Antivirus.
    3. Manage Windows Defender Firewall and advanced security.
  43. Manage security in Active Directory
    1. Configure account rights and delegate Active Directory permissions.
    2. Protect accounts with the Protected Users group and Credential Guard.
    3. Block NTLM authentication and locate problematic accounts.
  44. Secure Windows Server user accounts
    1. Configure user-account rights.
    2. Use Protected Users and Credential Guard.
    3. Block NTLM authentication and locate problematic accounts.
  45. Manage security controls for identity and access
    1. Secure Microsoft Entra users, groups, external identities, and synchronization.
    2. Implement multifactor, passwordless, Kerberos, and single sign-on authentication.
    3. Configure Azure and Microsoft Entra role-based access control.
    4. Implement Privileged Identity Management, identity governance, lifecycle workflows, entitlement management, and access reviews.
    5. Apply Conditional Access, Zero Trust principles, and Azure Lighthouse.
  46. Security monitoring and governance
    1. Implement pipeline security.
    2. Use Microsoft Defender for Cloud, Defender for Identity, and Azure Policy.
    3. Work with initiatives, resource locks, and GitHub Advanced Security integrations.
  47. Monitor Windows Server IaaS virtual machines and hybrid instances
    1. Enable Azure Monitor for virtual machines.
    2. Monitor Azure virtual machines and hybrid Windows computers.
    3. Integrate Azure Monitor with Microsoft Operations Manager.
  48. Monitor Azure virtual machines with Azure Monitor
    1. Monitor virtual machine and host data.
    2. Use Metrics Explorer and VM insights.
    3. Collect client performance counters and event logs.
  49. Monitor Windows Server performance
    1. Use Performance Monitor, Resource Monitor, and Reliability Monitor.
    2. Use Data Collector Sets and monitor network services and virtual machines.
    3. Monitor through Windows Admin Center and predict capacity with System Insights.
    4. Optimize Windows Server performance.
  50. Manage and monitor Windows Server event logs
    1. Review event logs with Windows Admin Center and Server Manager.
    2. Create custom views.
    3. Implement event log subscriptions.
  51. Implement Windows Server auditing and diagnostics
    1. Review basic and advanced auditing categories.
    2. Log user access.
    3. Enable setup and boot event collection.
  52. Troubleshoot on-premises and hybrid networking
    1. Diagnose DHCP, DNS, IP configuration, and routing problems.
    2. Use Packet Monitor to diagnose network issues.
    3. Use Azure Network Watcher for network diagnostics.
  53. Troubleshoot Windows Server virtual machines in Azure
    1. Troubleshoot virtual machine deployment, startup, and extensions.
    2. Troubleshoot connectivity and performance.
    3. Troubleshoot virtual machine storage.
  54. Windows Server update management
    1. Explore Windows Update.
    2. Review Windows Server Update Services deployment options and update management.
    3. Describe the Update Management process.
  55. Troubleshoot Active Directory
    1. Recover objects with the Active Directory Recycle Bin.
    2. Recover the AD DS database and SYSVOL.
    3. Troubleshoot AD DS replication and hybrid authentication.

Class Materials

Each student receives a comprehensive set of materials, including course notes and all class examples.

Class Prerequisites

Experience in the following would be useful for this Windows Server class:

  • Experience administering Windows Server in on-premises, cloud, or hybrid environments.
  • Familiarity with Active Directory Domain Services.
  • Experience with Windows Admin Center, Hyper-V, and PowerShell.
  • Exposure to Azure Arc, Azure Monitor, Azure Update Manager, and Microsoft Defender for Cloud.

Have questions about this course?

We can help with curriculum details, delivery options, pricing, or anything else. Reach out and we’ll point you in the right direction.