This course runs for a duration of 5 Days.
The class will run daily from 9 AM PT to 5 PM PT.
Class Location: Virtual LIVE Instructor Led - Virtual Live Classroom.
This course teaches IT professionals how to deploy, manage, secure, and troubleshoot Windows Server workloads across on-premises, hybrid, and cloud environments. The course covers Active Directory Domain Services, Hyper-V and Azure virtual machines, on-premises and hybrid networking, storage and file services, Windows Server security hardening, and monitoring and troubleshooting. It highlights administrative tools and technologies including Windows Admin Center, PowerShell, Azure Arc, Azure Monitor, Azure Update Manager, and Microsoft Defender for Cloud.
Who Should Attend?
This course is intended for Windows Server administrators who deploy, implement, manage, and troubleshoot Windows Server as a workload in on-premises, cloud, or hybrid environments. Candidates administer identity, security, compute, networking, storage, and monitoring for Windows Server, and they typically collaborate with architects, administrators, and engineers. Candidates should have experience administering Windows Server using technologies such as Windows Admin Center, Hyper-V, PowerShell, Azure Arc, Azure Monitor, Azure Update Manager, and Microsoft Defender for Cloud, and should be familiar with Active Directory Domain Services (AD DS).
1 - Deploy and Manage Active Directory Domain Services Domain Controllers
Define Active Directory Domain Services
Define Active Directory Domain Services forests and domains
Deploy Active Directory Domain Services domain controllers
Migrate a domain controller to a new site
Manage Active Directory Domain Services operations masters
Module assessment
2 - Deploy and Manage Azure IaaS Active Directory Domain Controllers in Azure
Select an option to implement directory and identity services using Active Directory Domain Services in Azure
Deploy and configure Active Directory Domain Services domain controllers in Azure VMs
Install a replica Active Directory domain controller in an Azure VM
Install a new Active Directory forest on an Azure VNet
Module assessment
3 - Manage AD DS Domain Controllers and FSMO Roles
Deploy AD DS domain controllers
Maintain AD DS domain controllers
Manage the AD DS Global Catalog role
Manage AD DS operations masters
Manage AD DS schema
Module assessment
4 - Create and Manage Active Directory Objects
Define users, groups, and computers
Define organizational units
Manage objects and their properties in Active Directory
Create objects in Active Directory
Configure objects in Active Directory
Perform bulk management tasks for user accounts
Maintain Active Directory Domain Services domain controllers
Module assessment
5 - Implement Hybrid Identity with Windows Server
Select a Microsoft Entra integration model
Plan for Microsoft Entra integration
Prepare on-premises Active Directory for directory synchronization
Install and configure directory synchronization with Microsoft Entra Connect
Implement Seamless Single Sign-On
Enable Microsoft Entra login for Windows VMs in Azure
Describe Microsoft Entra Domain Services
Implement and configure Microsoft Entra Domain Services
Manage Windows Server in a Microsoft Entra Domain Services environment
Create and configure a Microsoft Entra Domain Services instance
Join a Windows Server VM to a managed domain
Module assessment
6 - Create and Configure Group Policy Objects in Active Directory
Define Group Policy Objects
Implement Group Policy Object scope and inheritance
Define domain-based Group Policy Objects
Create and configure a domain-based Group Policy Object
Configure a domain password policy
Configure and apply a fine-grained password policy
Module assessment
7 - Implement Group Policy Objects
Define GPOs
Implement GPO scope and inheritance
Define domain-based GPOs
Create and configure a domain-based GPO
Define GPO storage
Define administrative templates
Module assessment
8 - Manage Advanced Features of AD DS
Create trust relationships
Implement ESAE forests
Monitor and troubleshoot AD DS
Create custom AD DS partitions
Module assessment
9 - Administer and Manage Windows Server IaaS Virtual Machines Remotely
Select the appropriate remote administration tool
Manage Windows Virtual Machines with Azure Bastion
Create an Azure Bastion host
Configure just-in-time administration
Module assessment
10 - Describe Windows Server Administration Tools
Explore Windows Admin Center
Use Server Manager
List Remote Server Administration Tools
Use Windows PowerShell
Use Windows PowerShell to remotely administer a server
Module assessment
11 - Just Enough Administration in Windows Server
Explain the concept of Just Enough Administration (JEA)
Define role capabilities for a JEA endpoint
Create a session configuration file to register a JEA endpoint
Describe how JEA endpoints work to limit access to a PowerShell session
Create and connect to a JEA endpoint
Demonstration: Connect to a JEA endpoint
Module assessment
12 - Perform Windows Server Secure Administration
Define least privilege administration
Implement delegated privileges
Use privileged access workstations
Use jump servers
Module assessment
13 - Use Advanced Windows PowerShell Remoting Techniques
Review common remoting techniques of Windows PowerShell
Send parameters to remote computers in Windows PowerShell
Set access protection to variables, aliases, and functions by using the scope modifier
Enable multi-hop remoting in Windows PowerShell
Module assessment
14 - Manage Single and Multiple Computers by Using Windows PowerShell Remoting
Review the remoting feature of Windows PowerShell
Compare remoting with remote connectivity
Review the remoting security feature of Windows PowerShell
Enable remoting by using Windows PowerShell
Use one-to-one remoting by using Windows PowerShell
Use one-to-many remoting by using Windows PowerShell
Compare remoting output with local output
Module assessment
15 - Manage Hybrid Workloads with Azure Arc
Describe Azure Arc
Onboard Windows Server instances
Connect hybrid machines to Azure from the Azure portal
Use Azure Arc to manage Windows Server instances
Restrict access with RBAC
Module assessment
16 - Manage Azure Updates
Describe Azure Update Manager
Prepare machines for Azure Update Manager
Deploy updates
Assess updates
Manage updates at scale
Module assessment
17 - Automate the Configuration of Windows Server IaaS Virtual Machines
Describe Azure Automation
Implement Azure Automation with DSC
Remediate noncompliant servers
Describe Custom Script Extensions
Configure a Virtual Machine by using DSC
Module assessment
18 - Enforce VM Security Configuration with Azure Machine Configuration
Explore Azure Machine Configuration extension capabilities and modes
Apply built-in security baseline policies
Author and assign custom machine configurations
19 - Explore Azure Automation with DevOps
Create automation accounts
What is a runbook?
Understand automation shared resources
Explore runbook gallery
Examine webhooks
Explore source control integration
Explore PowerShell workflows
Create a workflow
Explore hybrid management
Examine checkpoint and parallel processing
Module assessment
20 - Configure and Manage Hyper-V Virtual Machines
List the virtual machine configuration versions
List the virtual machine generation versions
List available VHD formats and types
Create and configure VMs
Determine storage options for VMs
Define shared VHDs and VHD Sets
Implement guest clusters using shared VHDX
Module assessment
21 - Configure and Manage Hyper-V
Define Hyper-V
Define Hyper-V Manager
Configure Hyper-V hosts using best practices
Configure Hyper-V networking
Assess advanced Hyper-V networking features
Define nested virtualization
Module assessment
22 - Secure Hyper-V Workloads
Define guarded fabric
Define the Host Guardian Service
Explore TPM-trusted attestation
Define KPS
Determine key features of shielded VMs
Compare encryption-supported and shielded VMs in a guarded fabric
Implement a shielded VM
Module assessment
23 - Implement High Availability of Windows Server VMs
Select high-availability options for Hyper-V
Consider network load balancing for Hyper-V VMs
Implement Hyper-V VM live migration
Implement Hyper-V VM storage migration
Module assessment
24 - Plan and Deploy Windows Server IaaS Virtual Machines
Describe Azure compute
Describe Virtual Machine storage
Deploy Azure Virtual Machines
Create a Windows Virtual Machine using the portal
Create a Windows Virtual Machine using Azure CLI
Deploy Azure Virtual Machines using templates
Describe additional management optimization options
Module assessment
25 - Implement Scale and High Availability with Windows Server VM
Describe virtual machine scale sets
Implement scaling
Implement load-balancing VMs
Create a virtual machine scale set in the Azure portal
Describe Azure Site Recovery
Implement Azure Site Recovery
Module assessment
26 - Implement Windows Server IaaS VM IP Addressing and Routing
Implement a virtual network
Implement IaaS VM IP addressing
Assign and manage IP addresses
Configure a private IP address for a virtual machine using the Azure portal
Create a virtual machine with a static public IP address using the Azure portal
Implement IaaS virtual machine IP routing
Implement IPv6 for Windows Server IaaS virtual machines
Module assessment
27 - Implement Windows Server IaaS VM Network Security
Implement network security groups and Windows IaaS VMs
Implement Azure Firewall and Windows IaaS VMs
Implement Windows Firewall with Windows Server IaaS VMs
Choose the appropriate filtering solution
Deploy and configure Azure Firewall using the Azure portal
Capture network traffic with Network Watcher
Log network traffic to and from a VM using the Azure portal
Module assessment
28 - Administer and Manage Windows Server IaaS Virtual Machines Remotely
Select the appropriate remote administration tool
Manage Windows Virtual Machines with Azure Bastion
Create an Azure Bastion host
Configure just-in-time administration
Module assessment
29 - Implement Windows Server DNS
Explore the DNS architecture
Work with DNS zones and records
Install and configure the DNS role
Implement DNS forwarding
Module assessment
30 - Implement DNS for Windows Server IaaS VMs
Understand Azure DNS
Implement Azure DNS
Create an Azure DNS zone and record using the Azure portal
Implement DNS with Azure IaaS virtual machines
Implement split-horizon DNS in Azure
Troubleshoot DNS
Module assessment
31 - Secure Windows Server DNS
Implement split-horizon DNS
Create DNS policies
Implement DNS policies
Secure Windows Server DNS
Implement DNSSEC
Module assessment
32 - Deploy and Manage DHCP
Use DHCP to simplify IP configuration
Install and configure the DHCP role
Configure DHCP options
Configure DHCP scopes
Select DHCP high-availability options
Implement DHCP Failover
Module assessment
33 - Implement IP Address Management
Define IP Address Management
Deploy IP Address Management
Administer IP Address Management
Configure IP Address Management options
Manage DNS zones with IP Address Management
Manage DHCP servers with IP Address Management
Use IP Address Management to manage IP addressing
Module assessment
34 - Implement Windows Server IaaS VM IP Addressing and Routing
Implement a virtual network
Implement IaaS VM IP addressing
Assign and manage IP addresses
Configure a private IP address for a virtual machine using the Azure portal
Create a virtual machine with a static public IP address using the Azure portal
Implement IaaS virtual machine IP routing
Implement IPv6 for Windows Server IaaS virtual machines
Module assessment
35 - Implement a Hybrid File Server Infrastructure
Describe Azure File services
Configure Azure Files
Configure connectivity to Azure Files
Describe Azure File Sync
Implement Azure File Sync
Deploy Azure File Sync
Deploy Azure File Sync 2
Manage cloud tiering
Migrate from DFSR to Azure File Sync
Module assessment
36 - Manage Windows Server File Servers
Define the Windows Server file system
List the benefits and uses of File Server Resource Manager
Define SMB and its security considerations
Configure SMB protocol
Define Volume Shadow Copy Service
Module assessment
37 - Implement Storage Spaces and Storage Spaces Direct
Define the Storage Spaces architecture and its components
List the functionalities, benefits, and use cases of Storage Spaces
Implement Storage Spaces
List the functionalities, components, benefits, and use cases of Storage Spaces Direct
Implement Storage Spaces Direct
Module assessment
38 - Implement Windows Server Data Deduplication
Define the architecture, components, and functionality of Data Deduplication
Define the use cases and interoperability of Data Deduplication
Implement Data Deduplication
Manage and maintain Data Deduplication
Module assessment
39 - Implement Windows Server iSCSI
List the functionalities, components, and use cases of iSCSI
List the considerations for implementing iSCSI
Implement iSCSI
Configure high availability for iSCSI
Module assessment
40 - Implement Windows Server Storage Replica
List the functionalities and components of Storage Replica
Examine the prerequisites for implementing Storage Replica
Implement Storage Replica by using Windows Admin Center
Implement Storage Replica by using Windows PowerShell
Module assessment
41 - Manage Microsoft Defender for Endpoint
Explore Microsoft Defender for Endpoint
Examine key capabilities of Microsoft Defender for Endpoint
Explore Windows Defender Application Control and Device Guard
Explore Microsoft Defender Application Guard
Examine Windows Defender Exploit Guard
Explore Windows Defender System Guard
Module assessment
42 - Manage Microsoft Defender in Windows Client
Explore Windows Security Center
Explore Windows Defender Credential Guard
Manage Microsoft Defender Antivirus
Manage Windows Defender Firewall
Explore Windows Defender Firewall with Advanced Security
Module assessment
43 - Manage Security in Active Directory
Configure user account rights
Configure user account rights to restrict access
Delegate permissions in Active Directory
Protect User Accounts with the Protected Users group
Describe Windows Defender Credential Guard
Block Windows NTLM authentication
Locate problematic accounts
Module assessment
44 - Secure Windows Server User Accounts
Configure user account rights
Protect user accounts with the Protected Users group
Describe Windows Defender Credential Guard
Block NTLM authentication
Locate problematic accounts
Module assessment
45 - Manage Security Controls for Identity and Access
Microsoft cloud security benchmark: Identity management and privileged access
What is Microsoft Entra ID?
Secure Microsoft Entra users
Create a new user in Microsoft Entra ID
Secure Microsoft Entra groups
Recommend when to use external identities
Secure external identities
Implement Microsoft Entra Identity Protection
Microsoft Entra Connect
Microsoft Entra Cloud Sync
Authentication options
Password hash synchronization with Microsoft Entra ID
Microsoft Entra pass-through authentication
Federation with Microsoft Entra ID
What is Microsoft Entra authentication?
Implement multifactor authentication (MFA)
Kerberos authentication
NTLM authentication
Passwordless authentication options for Microsoft Entra ID
Implement passwordless authentication
Implement password protection
Microsoft Entra ID single sign-on
Implement single sign-on (SSO)
Integrate single sign-on (SSO) and identity providers
Configure Microsoft Entra Verified ID
Recommend and enforce modern authentication protocols
Azure management groups
Configure Azure role permissions for management groups, subscriptions, resource groups, and resources
Azure role-based access control
Azure built-in roles
Assign Azure role permissions for management groups, subscriptions, resource groups, and resources
Microsoft Entra built-in roles
Assign built-in roles in Microsoft Entra ID
Microsoft Entra role-based access control
Create and assign a custom role in Microsoft Entra ID
Zero Trust security
Microsoft Entra Privileged Identity Management
Configure Privileged Identity Management
Microsoft Entra ID governance
Identity lifecycle management
Lifecycle workflows
Entitlement management
Delegation and roles in entitlement management
Access reviews
Configure role management and access reviews by using Microsoft Entra ID governance
Implement Conditional Access policies for cloud resources in Azure
Azure Lighthouse overview
Module assessment
46 - Security Monitoring and Governance
Implement pipeline security
Explore Microsoft Defender for Cloud
Examine Microsoft Defender for Cloud usage scenarios
Explore Azure Policy
Understand policies
Explore initiatives
Explore resource locks
Understand Microsoft Defender for Identity
Integrate GitHub Advanced Security with Microsoft Defender for Cloud
Configure GitHub Advanced Security for GitHub and Azure DevOps
Module assessment
47 - Monitor Windows Server IaaS Virtual Machines and Hybrid Instances
Enable Azure Monitor for Virtual Machines
Monitor an Azure Virtual Machine with Azure Monitor
Enable Azure Monitor in hybrid scenarios
Collect data from a Windows computer in a hybrid environment
Integrate Azure Monitor with Microsoft Operations Manager
Module assessment
48 - Monitor Your Azure Virtual Machines with Azure Monitor
Monitoring for Azure VMs
Monitor VM host data
Use Metrics Explorer to view detailed host metrics
Collect client performance counters by using VM Insights
Collect VM client event logs
49 - Monitor Windows Server Performance
Use Performance Monitor to identify performance problems
Use Resource Monitor to review current resource usage
Review reliability with Reliability Monitor
Implement a performance monitoring methodology
Use Data Collector Sets to analyze server performance
Monitor network infrastructure services
Monitor virtual machines running Windows Server
Monitor performance with Windows Admin Center
Use System Insights to help predict future capacity issues
Optimize the performance of Windows Server
Module assessment
50 - Manage and Monitor Windows Server Event Logs
Describe Windows Server event logs
Use Windows Admin Center to review logs
Use Server Manager to review logs
Use custom views
Implement event log subscriptions
Module assessment
51 - Implement Windows Server Auditing and Diagnostics
Describe basic auditing categories
Describe advanced categories
Log user access
Enable setup and boot event collection
Module assessment
52 - Troubleshoot On-Premises and Hybrid Networking
Diagnose DHCP problems
Diagnose DNS problems
Diagnose IP configuration issues
Diagnose routing problems
Use Packet Monitor to help diagnose network problems
Use Azure Network Watcher to help diagnose network problems
Module assessment
53 - Troubleshoot Windows Server Virtual Machines in Azure
Troubleshoot VM deployment
Troubleshoot VM startup
Troubleshoot VM extensions
Troubleshoot VM connectivity
Troubleshoot VM performance
Troubleshoot VM storage
Module assessment
54 - Windows Server Update Management
Explore Windows Update
Outline Windows Server Update Services server deployment options
Define Windows Server Update Services update management process
Describe the process of Update Management
Module assessment
55 - Troubleshoot Active Directory
Recover objects from the AD Recycle Bin
Recover the AD DS database
Recover SYSVOL
Troubleshoot AD DS replication
Troubleshoot hybrid authentication issues
Module assessment