Deploy and manage Active Directory Domain Services domain controllers
This module introduces you to the topology of domain controllers within an Active Directory environment. It also starts you down the path of deploying, managing, and migrating a domain controller between servers.
- Define Active Directory Domain Services
- Define Active Directory Domain Services forests and domains
- Deploy Active Directory Domain Services domain controllers
- Migrate a domain controller to a new site
- Manage Active Directory Domain Services operations masters
- Module assessment
Deploy and manage Azure IaaS Active Directory domain controllers in Azure
Learn how to extend your on-premises Active Directory environment into Azure, including deploying replica domain controllers on Azure VMs, creating new AD DS forests in Azure, and configuring VPN or ExpressRoute connectivity, AD DS sites, trust relationships, and FSMO role placement.
- Select an option to implement directory and identity services using Active Directory Domain Services in Azure
- Deploy and configure Active Directory Domain Services domain controllers in Azure VMs
- Install a replica Active Directory domain controller in an Azure VM
- Install a new Active Directory forest on an Azure VNet
- Module assessment
Manage AD DS domain controllers and FSMO roles
Learn how to deploy and manage AD DS domain controllers, maintain availability with backup and recovery, manage the global catalog role, and transfer or seize FSMO roles including schema master, domain-naming master, RID master, infrastructure master, and PDC emulator.
- Deploy AD DS domain controllers
- Maintain AD DS domain controllers
- Manage the AD DS Global Catalog role
- Manage AD DS operations masters
- Manage AD DS schema
- Module assessment
Create and manage Active Directory objects
Learn how to create and manage Active Directory users, groups, organizational units, managed service accounts, and perform bulk management tasks and domain controller backup and restore operations.
- Define users, groups, and computers
- Define organizational units
- Manage objects and their properties in Active Directory
- Create objects in Active Directory
- Configure objects in Active Directory
- Perform bulk management tasks for user accounts
- Maintain Active Directory Domain Services domain controllers
- Module assessment
Implement hybrid identity with Windows Server
Learn how to implement hybrid identity by integrating on-premises AD DS with Microsoft Entra ID using directory synchronization, password hash sync, pass-through authentication, seamless SSO, and Microsoft Entra Domain Services.
- Select a Microsoft Entra integration model
- Plan for Microsoft Entra integration
- Prepare on-premises Active Directory for directory synchronization
- Install and configure directory synchronization with Microsoft Entra Connect
- Implement Seamless Single Sign-On
- Enable Microsoft Entra login in for Windows VM in Azure
- Knowledge check 1
- Describe Microsoft Entra Domain Services
- Implement and configure Microsoft Entra Domain Services
- Manage Windows Server in a Microsoft Entra Domain Services environment
- Create and configure a Microsoft Entra Domain Services instance
- Join a Windows Server VM to a managed domain
- Module assessment
Create and configure Group Policy Objects in Active Directory
This module focuses on Group Policy objects, including using them to enforce a robust password policy.
- Define Group Policy Objects
- Implement Group Policy Object scope and inheritance
- Define domain-based Group Policy Objects
- Create and configure a domain-based Group Policy Object
- Configure a domain password policy
- Configure and apply a fine-grained password policy
- Module assessment
Implement Group Policy Objects
Implement Group Policy Objects
- Define GPOs
- Implement GPO scope and inheritance
- Define domain-based GPOs
- Create and configure a domain-based GPO
- Define GPO storage
- Define administrative templates
- Module assessment
Manage advanced features of AD DS
Learn how to create trust relationships between AD DS forests and domains, implement Enhanced Security Administrative Environment (ESAE) forests, monitor and troubleshoot AD DS replication, and create custom AD DS partitions.
- Create trust relationships
- Implement ESAE forests
- Monitor and troubleshoot AD DS
- Create custom AD DS partitions
- Module assessment
Administer and manage Windows Server IaaS Virtual Machine remotely
Learn how to remotely administer Windows Server IaaS VMs in Azure using the Azure portal, Windows Admin Center, Azure PowerShell, Azure CLI, Azure Bastion for secure RDP/SSH, and Just-In-Time (JIT) VM access.
- Select the appropriate remote administration tool
- Manage Windows Virtual Machines with Azure Bastion
- Create an Azure Bastion host
- Configure just-in-time administration
- Module assessment
Describe Windows Server administration tools
Learn how to select and use Windows Server administration tools including Windows Admin Center, Server Manager, Remote Server Administration Tools (RSAT), and Windows PowerShell remoting for local and remote server management.
- Explore Windows Admin Center
- Use Server Manager
- List Remote Server Administration Tools
- Use Windows PowerShell
- Use Windows PowerShell to remotely administer a server
- Module assessment
Just Enough Administration in Windows Server
Learn how to configure Just Enough Administration (JEA) in Windows Server to restrict PowerShell remoting sessions to specific cmdlets, parameters, and values using role capability files and session configuration files.
- Explain the concept of Just Enough Administration (JEA)
- Define role capabilities for a JEA endpoint
- Create a session configuration file to register a JEA endpoint
- Describe how JEA endpoints work to limit access to a PowerShell session
- Create and connect to a JEA endpoint
- Demonstration: Connect to a JEA endpoint
- Module assessment
- Summary resources
Perform Windows Server secure administration
Learn how to apply the principle of least privilege, delegate administrative control in Active Directory, implement Privileged Access Workstations (PAWs) with Windows Defender security features, and configure jump servers for secure remote administration.
- Define least privilege administration
- Implement delegated privileges
- Use privileged access workstations
- Use jump servers
- Module assessment
Use advanced Windows PowerShell remoting techniques
This module covers some useful advanced techniques that help overcome the limitations of basic Windows PowerShell remoting.
- Review common remoting techniques of Windows PowerShell
- Send parameters to remote computers in Windows PowerShell
- Set access protection to variables, aliases, and functions by using the scope modifier
- Enable multi-hop remoting in Windows PowerShell
- Module assessment
Manage single and multiple computers by using Windows PowerShell remoting
This module explains how to use remoting to perform administration on remote computers.
- Review the remoting feature of Windows PowerShell
- Compare remoting with remote connectivity
- Review the remoting security feature of Windows PowerShell
- Enable remoting by using Windows PowerShell
- Use one-to-one remoting by using Windows PowerShell
- Use one-to-many remoting by using Windows PowerShell
- Compare remoting output with local output
- Module assessment
Manage hybrid workloads with Azure Arc
Learn how to use Azure Arc to manage hybrid workloads by onboarding on-premises Windows Server and Linux machines, deploying extensions, applying Azure Policy guest configuration, and restricting access with RBAC.
- Describe Azure Arc
- Onboard Windows Server instances
- Connect hybrid machines to Azure from the Azure portal
- Use Azure Arc to manage Windows Server instances
- Restrict access with RBAC
- Module assessment
Manage Azure updates
Learn how to assess and deploy updates to Azure virtual machines and Azure Arc-enabled servers by using Azure Update Manager.
- Describe Azure Update Manager
- Prepare machines for Azure Update Manager
- Deploy updates
- Assess updates
- Manage updates at scale
- Module assessment
Automate the configuration of Windows Server IaaS Virtual Machines
Learn how to deploy Desired State Configuration (DSC) extensions, implement those extensions to remediate noncompliant servers, and use custom script extension.
- Describe Azure Automation
- Implement Azure Automation with DSC
- Remediate noncompliant servers
- Describe Custom Script Extensions
- Configure a Virtual Machine by using DSC
- Module assessment
Enforce VM security configuration with Azure Machine Configuration
Audit and enforce OS security configuration on Azure virtual machines and Arc-enabled servers using Azure Machine Configuration. Apply built-in Windows and Linux security baseline policies, configure audit and enforce modes, and author custom machine configurations for organization-specific requirements.
- Explore Azure Machine Configuration extension capabilities and modes
- Apply built-in security baseline policies
- Author and assign custom machine configurations
Explore Azure Automation with DevOps
Learn how to implement Azure Automation with DevOps using runbooks, webhooks, and PowerShell workflows. Understand automation accounts, shared resources, source control integration, and hybrid management for automated cloud operations.
- Create automation accounts
- What is a runbook?
- Understand automation shared resources
- Explore runbook gallery
- Examine webhooks
- Explore source control integration
- Explore PowerShell workflows
- Create a workflow
- Explore hybrid management
- Examine checkpoint and parallel processing
- Module assessment
Configure and manage Hyper-V virtual machines
Learn how to configure Hyper-V virtual machines in Windows Server, including VM generations, VHD and VHDX formats, storage options, shared virtual hard disks, VHD Sets, and guest clustering for high availability.
- List the virtual machine configuration versions
- List the virtual machine generation versions
- List available VHD formats and types
- Create and configure VMs
- Determine storage options for VMs
- Define shared VHDs and VHD Sets
- Implement guest clusters using shared VHDX
- Module assessment
Configure and manage Hyper-V
Learn how to install and configure the Hyper-V role in Windows Server, including virtual switch types, advanced networking features such as NIC Teaming, SR-IOV, and SET, and nested virtualization.
- Define Hyper-V
- Define Hyper-V Manager
- Configure Hyper-V hosts using best practices
- Configure Hyper-V networking
- Assess advanced Hyper-V networking features
- Define nested virtualization
- Module assessment
Secure Hyper-V workloads
Learn how to secure Hyper-V workloads using guarded fabric, Host Guardian Service (HGS) with TPM-trusted and Host Key attestation, Key Protection Service, and shielded virtual machines with BitLocker-encrypted template disks.
- Define guarded fabric
- Define the Host Guardian Service
- Explore TPM-trusted attestation
- Define KPS
- Determine key features of shielded VMs
- Compare encryption-supported and shielded VMs in a guarded fabric
- Implement a shielded VM
- Module assessment
Implement high availability of Windows Server VMs
Learn how to implement high availability for Hyper-V virtual machines using host clustering, guest clustering, Network Load Balancing, live migration with CredSSP or Kerberos authentication, and storage migration.
- Select high-availability options for Hyper-V
- Consider network load balancing for Hyper-V VMs
- Implement Hyper-V VM live migration
- Implement Hyper-V VMs storage migration
- Module assessment
Run containers on Windows Server
Learn how to run Windows containers on Windows Server, including process isolation and Hyper-V isolation modes, Docker container management, container base images from the Microsoft Container Registry, and Windows Admin Center container management.
- Define containers
- List the differences between containers and VMs
- Define Windows Server and Hyper-V containers and isolation modes
- Explore Docker
- Prepare a Windows Server 2019 host for container deployment
- Security, Storage, and Networking with Windows containers
- Module assessment
Plan and deploy Windows Server IaaS Virtual Machines
Learn how to plan and deploy Windows Server IaaS VMs in Azure, including VM sizes and tiers, managed disk storage, and deployment methods using the Azure portal, Azure CLI, and ARM templates.
- Describe Azure compute
- Describe Virtual Machine storage
- Deploy Azure Virtual Machines
- Create a windows Virtual Machine using the portal
- Create a windows Virtual Machine using Azure CLI
- Deploy Azure Virtual Machines using templates
- Describe additional management optimization options
- Module assessment
Implement scale and high availability with Windows Server VM
Learn how to implement scaling and high availability for Windows Server VMs using virtual machine scale sets with horizontal and vertical scaling, Azure Load Balancer, and Azure Site Recovery for disaster recovery.
- Describe virtual machine scale sets
- Implement scaling
- Implement load-balancing VMs
- Create a virtual machine scale set in the Azure portal
- Describe Azure Site Recovery
- Implement Azure Site Recovery
- Module assessment
Implement Windows Server IaaS VM IP addressing and routing
Learn how to implement IP addressing and routing for Windows Server IaaS VMs, including Azure VNets, subnets, public and private IP allocation, network interfaces, system routes, user-defined routes, and IPv6 for Azure VNet.
- Implement a virtual network
- Implement IaaS VM IP addressing
- Assign and manage IP addresses
- Configure a private IP address for a virtual machine using the Azure portal
- Create a virtual machine with a static public IP address using the Azure portal
- Implement IaaS virtual machine IP routing
- Implement IPv6 for Windows Server IaaS virtual machines
- Module assessment
Implement Windows Server IaaS VM network security
Learn how to implement network security for Windows Server IaaS VMs using network security groups (NSGs), Azure Firewall, Windows Defender Firewall, and Azure Network Watcher for traffic capture and flow logging.
- Implement network security groups and Windows IaaS VMs
- Implement Azure Firewall and Windows IaaS VMs
- Implement Windows Firewall with Windows Server IaaS VMs
- Choose the appropriate filtering solution
- Deploy and configure Azure firewall using the Azure portal
- Capture network traffic with network watcher
- Log network traffic to and from a VM using the Azure portal
- Module assessment
Administer and manage Windows Server IaaS Virtual Machine remotely
Learn how to remotely administer Windows Server IaaS VMs in Azure using the Azure portal, Windows Admin Center, Azure PowerShell, Azure CLI, Azure Bastion for secure RDP/SSH, and Just-In-Time (JIT) VM access.
- Select the appropriate remote administration tool
- Manage Windows Virtual Machines with Azure Bastion
- Create an Azure Bastion host
- Configure just-in-time administration
- Module assessment
Implement Windows Server DNS
Learn how to deploy and configure DNS in Windows Server, including DNS architecture, forward and reverse lookup zones, AD-integrated zones, zone transfers, forwarders, conditional forwarding, and stub zones.
- Explore the DNS architecture
- Work with DNS zones and records
- Install and configure the DNS role
- Implement DNS forwarding
- Module assessment
Implement DNS for Windows Server IaaS VMs
Learn how to implement DNS for Windows Server IaaS VMs, including Azure public and private DNS zones, DNS delegation, Windows Server DNS in Azure VMs, split-horizon DNS, and DNS troubleshooting.
- Understand Azure DNS
- Implement Azure DNS
- Create an Azure DNS zone and record using the Azure portal
- Implement DNS with Azure IaaS virtual machines
- Implement split-horizon DNS in Azure
- Troubleshoot DNS
- Module assessment
Secure Windows Server DNS
Learn how to secure Windows Server DNS using split-horizon DNS, DNS policies for traffic management and geo-location routing, DNS cache locking, DNS socket pool, and DNSSEC for cryptographic zone signing.
- Implement split-horizon DNS
- Create DNS policies
- Implement DNS policies
- Secure Windows Server DNS
- Implement DNSSEC
- Module assessment
Deploy and manage DHCP
Learn how to deploy and manage DHCP in Windows Server, including DHCP scopes, options, reservations, lease management, DHCP Failover for high availability, and DHCPv6 for IPv6 environments.
- Use DHCP to simplify IP configuration
- Install and configure the DHCP role
- Configure DHCP options
- Configure DHCP scopes
- Select DHCP high availability options
- Implement DHCP Failover
- Module assessment
Implement IP Address Management
Learn how to deploy and configure IP Address Management (IPAM) in Windows Server to centrally manage DHCP servers, DNS zones, and IP address space with role-based access control and GPO-based provisioning.
- Define IP Address Management
- Deploy IP Address Management
- Administer IP Address Management
- Configure IP Address Management options
- Manage DNS zones with IP Address Management
- Manage DHCP servers with IP Address Management
- Use IP Address Management to manage IP addressing
- Module assessment
Implement Windows Server IaaS VM IP addressing and routing
Learn how to implement IP addressing and routing for Windows Server IaaS VMs, including Azure VNets, subnets, public and private IP allocation, network interfaces, system routes, user-defined routes, and IPv6 for Azure VNet.
- Implement a virtual network
- Implement IaaS VM IP addressing
- Assign and manage IP addresses
- Configure a private IP address for a virtual machine using the Azure portal
- Create a virtual machine with a static public IP address using the Azure portal
- Implement IaaS virtual machine IP routing
- Implement IPv6 for Windows Server IaaS virtual machines
- Module assessment
Implement a hybrid file server infrastructure
Implement a hybrid file server infrastructure using Azure Files and Azure File Sync, including cloud tiering, DFS Replication migration, and Storage Migration Services.
- Describe Azure File services
- Configure Azure Files
- Configure connectivity to Azure Files
- Describe Azure File Sync
- Implement Azure File Sync
- Deploy Azure File Sync
- Deploy Azure File Sync 2
- Manage cloud tiering
- Migrate from DFSR to Azure File Sync
- Module assessment
Manage Windows Server file servers
Learn how to manage the Windows Server File Server role, including NTFS and ReFS file systems, File Server Resource Manager (FSRM) quotas and file screening, SMB protocol configuration and encryption, and Volume Shadow Copy Service (VSS).
- Define the Windows Server file system
- List the benefits and uses of File Server Resource Manager
- Define SMB and its security considerations
- Configure SMB protocol
- Define Volume Shadow Copy Service
- Module assessment
Implement Storage Spaces and Storage Spaces Direct
Learn how to implement Storage Spaces and Storage Spaces Direct in Windows Server, including storage pools, resiliency levels, storage tiers, thin provisioning, Cluster Shared Volumes (CSVs), and the Software Storage Bus.
- Define the Storage Spaces architecture and its components
- List the functionalities, benefits, and use cases of Storage Spaces
- Implement Storage Spaces
- List the functionalities, components, benefits, and use cases of Storage Spaces Direct
- Implement Storage Spaces Direct
- Module assessment
Implement Windows Server Data Deduplication
Learn how to implement Data Deduplication in Windows Server to reduce storage consumption for file shares, VDI deployments, software distribution, and backup volumes.
- Define the architecture, components, and functionality of Data Deduplication
- Define the use cases and interoperability of Data Deduplication
- Implement Data Deduplication
- Manage and maintain Data Deduplication
- Module assessment
Implement Windows Server iSCSI
Learn how to implement iSCSI storage in Windows Server, including iSCSI Target Server, iSCSI initiator configuration, virtual disk creation, and Multipath I/O (MPIO) for network redundancy.
- List the functionalities, components, and use cases of iSCSI
- List the considerations for implementing iSCSI
- Implement iSCSI
- Configure high availability for iSCSI
- Module assessment
Implement Windows Server Storage Replica
Learn how to implement Storage Replica in Windows Server for block-level, synchronous or asynchronous volume replication across servers or sites for disaster recovery and high availability.
- List the functionalities and components of Storage Replica
- Examine the prerequisites for implementing Storage Replica
- Implement Storage Replica by using Windows Admin Center
- Implement Storage Replica by using Windows PowerShell
- Module assessment
Manage Microsoft Defender for Endpoint
This module explores using Microsoft Defender for Endpoint to provide additional protection and monitor devices against threats.
- Explore Microsoft Defender for Endpoint
- Examine key capabilities of Microsoft Defender for Endpoint
- Explore Windows Defender Application Control and Device Guard
- Explore Microsoft Defender Application Guard
- Examine Windows Defender Exploit Guard
- Explore Windows Defender System Guard
- Module assessment
Manage Microsoft Defender in Windows client
This module explains the built-in security features of Windows clients and how to implement them using policies.
- Explore Windows Security Center
- Explore Windows Defender Credential Guard
- Manage Microsoft Defender Antivirus
- Manage Windows Defender Firewall
- Explore Windows Defender Firewall with Advanced Security
- Module assessment
Understand Active Directory Group Policy security settings
Learn how to configure, audit, and manage Group Policy Security Settings in Active Directory environments.
- Configure account policies
- Assign user rights
- Configure security options
- Configure audit policy
- Secure groups, services, registry, files, and logs
- Deploy network and application security policies
- Design, deploy, and manage security settings at scale
Manage security in Active Directory
Learn how to manage security in Active Directory, including configuring user rights with least privilege, delegating permissions, using the Protected Users group and Credential Guard, blocking NTLM authentication, and finding problematic accounts.
- Configure user account rights
- Configure user account rights to restrict access
- Delegate permissions in Active Directory
- Protect User Accounts with the Protected Users group
- Describe Windows Defender Credential Guard
- Block Windows NTLM authentication
- Locate problematic accounts
- Module assessment
Understand Windows Server service accounts
Describe the purpose and common problems of Windows Server service accounts, and select and configure the correct local or managed account type, including the Windows Server 2025 delegated Managed Service Account (dMSA).
- Understand local service account types
- Understand managed service account types
- Service account best practices
Secure Windows Server user accounts
Learn how to secure Active Directory user accounts using least privilege, Protected Users group, authentication policy silos, Windows Defender Credential Guard, NTLM blocking, and account remediation techniques.
- Configure user account rights
- Protect user accounts with the Protected Users group
- Describe Windows Defender Credential Guard
- Block NTLM authentication
- Locate problematic accounts
- Module assessment
Manage security controls for identity and access
This module focuses on effectively managing security controls in Microsoft Entra ID by securing identities, authentication, and authorization to protect users, groups, and external identities against threats while ensuring secure and seamless access to resources.
- Microsoft cloud security benchmark: Identity management and privileged access
- What is Microsoft Entra ID?
- Secure Microsoft Entra users
- Create a new user in Microsoft Entra ID
- Secure Microsoft Entra groups
- Recommend when to use external identities
- Secure external identities
- Implement Microsoft Entra Identity Protection
- Microsoft Entra Connect
- Microsoft Entra Cloud Sync
- Authentication options
- Password hash synchronization with Microsoft Entra ID
- Microsoft Entra pass-through authentication
- Federation with Microsoft Entra ID
- What is Microsoft Entra authentication?
- Implement multifactor authentication (MFA)
- Kerberos authentication
- New Technology Local Area Network Manager (NTLM)
- Passwordless authentication options for Microsoft Entra ID
- Implement passwordless authentication
- Implement password protection
- Microsoft Entra ID single sign-on
- Implement single sign-on (SSO)
- Integrate single sign-on (SSO) and identity providers
Security monitoring and governance
Learn security monitoring and governance with Microsoft Defender for Cloud, Azure Policy, resource locks, Microsoft Defender for Identity, and GitHub Advanced Security integration for comprehensive DevSecOps protection.
- Implement pipeline security
- Explore Microsoft Defender for Cloud
- Examine Microsoft Defender for Cloud usage scenarios
- Explore Azure Policy
- Understand policies
- Explore initiatives
- Explore resource locks
- Understand Microsoft Defender for Identity
- Integrate GitHub Advanced Security with Microsoft Defender for Cloud
- Configure GitHub Advanced Security for GitHub and Azure DevOps
- Module assessment
Monitor Windows Server performance
Learn how to monitor Windows Server performance using Performance Monitor, Resource Monitor, Reliability Monitor, data collector sets, System Insights for capacity forecasting, and Windows Admin Center.
- Use Performance Monitor to identify performance problems
- Use Resource Monitor to review current resource usage
- Review reliability with Reliability Monitor
- Implement a performance monitoring methodology
- Use Data Collector Sets to analyze server performance
- Monitor network infrastructure services
- Monitor virtual machines running Windows Server
- Monitor performance with Windows Admin Center
- Use System Insights to help predict future capacity issues
- Optimize the performance of Windows Server
- Module assessment
- Summary and resources
Manage and monitor Windows Server event logs
Learn how to manage and monitor Windows Server event logs using Event Viewer, Windows Admin Center, Server Manager, custom views, and event subscriptions for centralized log collection.
- Describe Windows Server event logs
- Use Windows Admin Center to review logs
- Use Server Manager to review logs
- Use custom views
- Implement event log subscriptions
- Module assessment
Implement Windows Server auditing and diagnostics
Learn how to implement Windows Server auditing for regulatory compliance and security, including basic and advanced audit policies, User Access Logging (UAL), and Setup and Boot Event Collection.
- Describe basic auditing categories
- Describe advanced categories
- Log user access
- Enable setup and boot event collection
- Module assessment
Monitor Windows Server IaaS Virtual Machines and hybrid instances
Learn how to monitor Windows Server IaaS VMs and hybrid instances using Azure Monitor, Log Analytics workspaces, the Dependency Agent for service maps, and integration with Microsoft Operations Manager.
- Enable Azure Monitor for Virtual Machines
- Monitor an Azure Virtual Machine with Azure Monitor
- Enable Azure Monitor in hybrid scenarios
- Collect data from a Windows computer in a hybrid environment
- Integrate Azure Monitor with Microsoft Operations Manager
- Module assessment
Monitor your Azure virtual machines with Azure Monitor
Learn how to monitor your Azure VMs by using Azure Monitor to collect and analyze VM host and client metrics and logs.
- Monitoring for Azure VMs
- Monitor VM host data
- Use Metrics Explorer to view detailed host metrics
- Collect client performance counters by using VM insights
- Collect VM client event logs
Troubleshoot on-premises and hybrid networking
Learn how to troubleshoot on-premises and hybrid networking issues including DHCP authorization and scopes, DNS zone data and replication, IP configuration and routing tables, Packet Monitor, and Azure Network Watcher.
- Diagnose DHCP problems
- Diagnose DNS problems
- Diagnose IP configuration issues
- Diagnose routing problems
- Use Packet Monitor to help diagnose network problems
- Use Azure Network Watcher to help diagnose network problems
- Module assessment
Troubleshoot Windows Server Virtual Machines in Azure
Learn how to troubleshoot Azure-hosted Windows Server VMs, including provisioning and allocation failures, boot diagnostics, VM Agent and extension issues, RDP connectivity, performance monitoring, and storage tier selection.
- Troubleshoot VM deployment
- Troubleshoot VM startup
- Troubleshoot VM extensions
- Troubleshoot VM connectivity
- Troubleshoot VM performance
- Troubleshoot VM storage
- Module assessment
Windows Server update management
Learn how to deploy and manage Windows Server Update Services (WSUS) for centralized update management, including deployment topologies, computer groups, and integration with Azure Automation Update Management for hybrid environments.
- Explore Windows Update
- Outline Windows Server Update Services server deployment options
- Define Windows Server Update Services update management process
- Describe the process of Update Management
- Module assessment
Troubleshoot Active Directory
Learn how to troubleshoot Active Directory including recovering deleted objects with AD Recycle Bin, managing the AD DS database with NtdsUtil, restoring SYSVOL, troubleshooting replication, and diagnosing hybrid authentication with Microsoft Entra Connect.
- Recover objects from the AD recycle bin
- Recover the AD DS database
- Recover SYSVOL
- Troubleshoot AD DS replication
- Troubleshoot hybrid authentication issues
- Module assessment