Deploy and manage Active Directory Domain Services domain controllers
- Introduction
- Define Active Directory Domain Services
- Define Active Directory Domain Services forests and domains
- Deploy Active Directory Domain Services domain controllers
- Migrate a domain controller to a new site
- Manage Active Directory Domain Services operations masters
- Module assessment
- Summary
Deploy and manage Azure IaaS Active Directory domain controllers in Azure
- Introduction
- Select an option to implement directory and identity services using Active Directory Domain Services in Azure
- Deploy and configure Active Directory Domain Services domain controllers in Azure VMs
- Install a replica Active Directory domain controller in an Azure VM
- Install a new Active Directory forest on an Azure VNet
- Module assessment
- Summary
Manage AD DS domain controllers and FSMO roles
- Introduction
- Deploy AD DS domain controllers
- Maintain AD DS domain controllers
- Manage the AD DS Global Catalog role
- Manage AD DS operations masters
- Manage AD DS schema
- Module assessment
- Summary
Create and manage Active Directory objects
- Introduction
- Define users, groups, and computers
- Define organizational units
- Manage objects and their properties in Active Directory
- Create objects in Active Directory
- Configure objects in Active Directory
- Perform bulk management tasks for user accounts
- Maintain Active Directory Domain Services domain controllers
- Module assessment
- Summary
Implement hybrid identity with Windows Server
- Introduction
- Select a Microsoft Entra integration model
- Plan for Microsoft Entra integration
- Prepare on-premises Active Directory for directory synchronization
- Install and configure directory synchronization with Microsoft Entra Connect
- Implement Seamless Single Sign-On
- Enable Microsoft Entra login in for Windows VM in Azure
- Knowledge check 1
- Describe Microsoft Entra Domain Services
- Implement and configure Microsoft Entra Domain Services
- Manage Windows Server in a Microsoft Entra Domain Services environment
- Create and configure a Microsoft Entra Domain Services instance
- Join a Windows Server VM to a managed domain
- Module assessment
- Summary
Create and configure Group Policy Objects in Active Directory
- Introduction
- Define Group Policy Objects
- Implement Group Policy Object scope and inheritance
- Define domain-based Group Policy Objects
- Create and configure a domain-based Group Policy Object
- Configure a domain password policy
- Configure and apply a fine-grained password policy
- Module assessment
- Summary
Implement Group Policy Objects
- Introduction
- Define GPOs
- Implement GPO scope and inheritance
- Define domain-based GPOs
- Create and configure a domain-based GPO
- Define GPO storage
- Define administrative templates
- Module assessment
- Summary
Manage advanced features of AD DS
- Introduction
- Create trust relationships
- Implement ESAE forests
- Monitor and troubleshoot AD DS
- Create custom AD DS partitions
- Module assessment
- Summary
Administer and manage Windows Server IaaS Virtual Machine remotely
- Introduction
- Select the appropriate remote administration tool
- Manage Windows Virtual Machines with Azure Bastion
- Create an Azure Bastion host
- Configure just-in-time administration
- Module assessment
- Summary
Describe Windows Server administration tools
- Introduction
- Explore Windows Admin Center
- Use Server Manager
- List Remote Server Administration Tools
- Use Windows PowerShell
- Use Windows PowerShell to remotely administer a server
- Module assessment
- Summary
Just Enough Administration in Windows Server
- Introduction
- Explain the concept of Just Enough Administration (JEA)
- Define role capabilities for a JEA endpoint
- Create a session configuration file to register a JEA endpoint
- Describe how JEA endpoints work to limit access to a PowerShell session
- Create and connect to a JEA endpoint
- Demonstration: Connect to a JEA endpoint
- Module assessment
- Summary resources
Perform Windows Server secure administration
- Introduction
- Define least privilege administration
- Implement delegated privileges
- Use privileged access workstations
- Use jump servers
- Module assessment
- Summary
Use advanced Windows PowerShell remoting techniques
- Introduction
- Review common remoting techniques of Windows PowerShell
- Send parameters to remote computers in Windows PowerShell
- Set access protection to variables, aliases, and functions by using the scope modifier
- Enable multi-hop remoting in Windows PowerShell
- Module assessment
- Summary
Manage single and multiple computers by using Windows PowerShell remoting
- Introduction
- Review the remoting feature of Windows PowerShell
- Compare remoting with remote connectivity
- Review the remoting security feature of Windows PowerShell
- Enable remoting by using Windows PowerShell
- Use one-to-one remoting by using Windows PowerShell
- Use one-to-many remoting by using Windows PowerShell
- Compare remoting output with local output
- Module assessment
- Summary
Manage hybrid workloads with Azure Arc
- Introduction
- Describe Azure Arc
- Onboard Windows Server instances
- Connect hybrid machines to Azure from the Azure portal
- Use Azure Arc to manage Windows Server instances
- Restrict access with RBAC
- Module assessment
- Summary
Manage Azure updates
- Introduction
- Describe Azure Update Manager
- Prepare machines for Azure Update Manager
- Deploy updates
- Assess updates
- Manage updates at scale
- Module assessment
- Summary
Automate the configuration of Windows Server IaaS Virtual Machines
- Introduction
- Describe Azure Automation
- Implement Azure Automation with DSC
- Remediate noncompliant servers
- Describe Custom Script Extensions
- Configure a Virtual Machine by using DSC
- Module assessment
- Summary
Enforce VM security configuration with Azure Machine Configuration
- Introduction
- Explore Azure Machine Configuration extension capabilities and modes
- Apply built-in security baseline policies
- Author and assign custom machine configurations
- Knowledge check
- Summary
Explore Azure Automation with DevOps
- Introduction
- Create automation accounts
- What is a runbook?
- Understand automation shared resources
- Explore runbook gallery
- Examine webhooks
- Explore source control integration
- Explore PowerShell workflows
- Create a workflow
- Explore hybrid management
- Examine checkpoint and parallel processing
- Module assessment
- Summary
Configure and manage Hyper-V virtual machines
- Introduction
- List the virtual machine configuration versions
- List the virtual machine generation versions
- List available VHD formats and types
- Create and configure VMs
- Determine storage options for VMs
- Define shared VHDs and VHD Sets
- Implement guest clusters using shared VHDX
- Module assessment
- Summary
Configure and manage Hyper-V
- Introduction
- Define Hyper-V
- Define Hyper-V Manager
- Configure Hyper-V hosts using best practices
- Configure Hyper-V networking
- Assess advanced Hyper-V networking features
- Define nested virtualization
- Module assessment
- Summary
Secure Hyper-V workloads
- Introduction
- Define guarded fabric
- Define the Host Guardian Service
- Explore TPM-trusted attestation
- Define KPS
- Determine key features of shielded VMs
- Compare encryption-supported and shielded VMs in a guarded fabric
- Implement a shielded VM
- Module assessment
- Summary
Implement high availability of Windows Server VMs
- Introduction
- Select high-availability options for Hyper-V
- Consider network load balancing for Hyper-V VMs
- Implement Hyper-V VM live migration
- Implement Hyper-V VMs storage migration
- Module assessment
- Summary
Run containers on Windows Server
- Introduction
- Define containers
- List the differences between containers and VMs
- Define Windows Server and Hyper-V containers and isolation modes
- Explore Docker
- Prepare a Windows Server 2019 host for container deployment
- Security, Storage, and Networking with Windows containers
- Module assessment
- Summary
Plan and deploy Windows Server IaaS Virtual Machines
- Introduction
- Describe Azure compute
- Describe Virtual Machine storage
- Deploy Azure Virtual Machines
- Create a windows Virtual Machine using the portal
- Create a windows Virtual Machine using Azure CLI
- Deploy Azure Virtual Machines using templates
- Describe additional management optimization options
- Module assessment
- Summary
Implement scale and high availability with Windows Server VM
- Introduction
- Describe virtual machine scale sets
- Implement scaling
- Implement load-balancing VMs
- Create a virtual machine scale set in the Azure portal
- Describe Azure Site Recovery
- Implement Azure Site Recovery
- Module assessment
- Summary
Implement Windows Server IaaS VM IP addressing and routing
- Introduction
- Implement a virtual network
- Implement IaaS VM IP addressing
- Assign and manage IP addresses
- Configure a private IP address for a virtual machine using the Azure portal
- Create a virtual machine with a static public IP address using the Azure portal
- Implement IaaS virtual machine IP routing
- Implement IPv6 for Windows Server IaaS virtual machines
- Module assessment
- Summary
Implement Windows Server IaaS VM network security
- Introduction
- Implement network security groups and Windows IaaS VMs
- Implement Azure Firewall and Windows IaaS VMs
- Implement Windows Firewall with Windows Server IaaS VMs
- Choose the appropriate filtering solution
- Deploy and configure Azure firewall using the Azure portal
- Capture network traffic with network watcher
- Log network traffic to and from a VM using the Azure portal
- Module assessment
- Summary
Administer and manage Windows Server IaaS Virtual Machine remotely
- Introduction
- Select the appropriate remote administration tool
- Manage Windows Virtual Machines with Azure Bastion
- Create an Azure Bastion host
- Configure just-in-time administration
- Module assessment
- Summary
Implement Windows Server DNS
- Introduction
- Explore the DNS architecture
- Work with DNS zones and records
- Install and configure the DNS role
- Implement DNS forwarding
- Module assessment
- Summary
Implement DNS for Windows Server IaaS VMs
- Introduction
- Understand Azure DNS
- Implement Azure DNS
- Create an Azure DNS zone and record using the Azure portal
- Implement DNS with Azure IaaS virtual machines
- Implement split-horizon DNS in Azure
- Troubleshoot DNS
- Module assessment
- Summary
Secure Windows Server DNS
- Introduction
- Implement split-horizon DNS
- Create DNS policies
- Implement DNS policies
- Secure Windows Server DNS
- Implement DNSSEC
- Module assessment
- Summary
Deploy and manage DHCP
- Introduction
- Use DHCP to simplify IP configuration
- Install and configure the DHCP role
- Configure DHCP options
- Configure DHCP scopes
- Select DHCP high availability options
- Implement DHCP Failover
- Module assessment
- Summary
Implement IP Address Management
- Introduction
- Define IP Address Management
- Deploy IP Address Management
- Administer IP Address Management
- Configure IP Address Management options
- Manage DNS zones with IP Address Management
- Manage DHCP servers with IP Address Management
- Use IP Address Management to manage IP addressing
- Module assessment
- Summary
Implement Windows Server IaaS VM IP addressing and routing
- Introduction
- Implement a virtual network
- Implement IaaS VM IP addressing
- Assign and manage IP addresses
- Configure a private IP address for a virtual machine using the Azure portal
- Create a virtual machine with a static public IP address using the Azure portal
- Implement IaaS virtual machine IP routing
- Implement IPv6 for Windows Server IaaS virtual machines
- Module assessment
- Summary
Implement a hybrid file server infrastructure
- Introduction
- Describe Azure File services
- Configure Azure Files
- Configure connectivity to Azure Files
- Describe Azure File Sync
- Implement Azure File Sync
- Deploy Azure File Sync
- Deploy Azure File Sync 2
- Manage cloud tiering
- Migrate from DFSR to Azure File Sync
- Module assessment
- Summary
Manage Windows Server file servers
- Introduction
- Define the Windows Server file system
- List the benefits and uses of File Server Resource Manager
- Define SMB and its security considerations
- Configure SMB protocol
- Define Volume Shadow Copy Service
- Module assessment
- Summary
Implement Storage Spaces and Storage Spaces Direct
- Introduction
- Define the Storage Spaces architecture and its components
- List the functionalities, benefits, and use cases of Storage Spaces
- Implement Storage Spaces
- List the functionalities, components, benefits, and use cases of Storage Spaces Direct
- Implement Storage Spaces Direct
- Module assessment
- Summary
Implement Windows Server Data Deduplication
- Introduction
- Define the architecture, components, and functionality of Data Deduplication
- Define the use cases and interoperability of Data Deduplication
- Implement Data Deduplication
- Manage and maintain Data Deduplication
- Module assessment
- Summary
Implement Windows Server iSCSI
- Introduction
- List the functionalities, components, and use cases of iSCSI
- List the considerations for implementing iSCSI
- Implement iSCSI
- Configure high availability for iSCSI
- Module assessment
- Summary
Implement Windows Server Storage Replica
- Introduction
- List the functionalities and components of Storage Replica
- Examine the prerequisites for implementing Storage Replica
- Implement Storage Replica by using Windows Admin Center
- Implement Storage Replica by using Windows PowerShell
- Module assessment
- Summary