Description
This 5-day course examines the services and features of Microsoft Windows Server 2022. It covers administering, configuring, troubleshooting, and operating identity services in the Active Directory Domain Services (AD DS) and Entra ID (previously known as Azure AD). Â This course also covers core AD DS identity services such as Group Policy Objects (GPOs), Active Directory Certificate Services (AD CS), Active Directory Federation Services (AD FS) and hybrid solutions with Azure AD.
There are instructor slides and a get-ready guide available to instructors upon request.
Audience profile
This course is intended for IT professionals who work on administering, configuring, troubleshooting, and operating identity services in the AD DS and Entra ID. It is also useful for system or infrastructure administrators with general AD DS experience who want to gain additional insight about Windows Server 2022 identity and access technologies.
Why choose this course?
- Meticulous content relevance, tailored to Windows Server 2022, sets it apart from competitive courses based primarily on previous versions.
-
- Content on obsolete technology, which is present in competitive versions of the course, has been removed.
-
- Includes a focused lesson on Entra ID and the comparison to AD DS.
-
- Offers an array of demonstrations that bolster the learning material.
-
- Expert instructional design ensures a superior learning experience.
-
- Labs are developed by Waypoint in parallel with courseware, so they are 100% aligned.
-
At Course Completion
By completing this course, you’ll achieve the knowledge and skills to:
- Deploy Active Directory services.
-
- Manage directory objects.
-
- Execute advanced Active Directory Domain Services (AD DS) infrastructure management.
-
- Implement and administer AD DS sites and replication.
-
- Implement Group Policy.
-
- Manage user settings with Group Policy.
-
- Secure AD DS.
-
- Deploy and manage Active Directory Certificate Services (AD CS).
-
- Deploy and manage certificates.
-
- Implement and administer Active Directory Federation Services (AD FS).
-
- Implement AD DS synchronization with Microsoft Entra ID.
-
- Monitor, manage, and recover AD DS​.
-
Course Details
Course Duration:Â 5 Days
Module 1 Deploy Active Directory services
Active Directory Domain Services (AD DS) is the cornerstone of on-premises networks for many organizations worldwide. AD DS delivers authentication and authorization by using domain controllers (DCs) for on-premises apps and services. In this module, you’ll learn how to configure DCs to suit your specific organizational needs, and integrate AD DS with Microsoft Azure Active Directory (Azure AD) to provide single sign-on (SSO) for users that access both on-premises and cloud-based apps.
Lesson 1 Components of AD DS
- What is an AD DS forest?
-
- What is an AD DS domain?
-
- What are organizational units (OUs)?
-
- What is the AD DS schema?
-
- Overview of AD DS administration tools
-
- Demonstration: Manage AD DS
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe AD DS forests.Â
-
- Describe AD DS domains.Â
-
- Describe OUs.Â
-
- Describe the AD DS schema.Â
-
- Select appropriate AD DS administration tools.Â
-
- Manage AD DS.Â
-
Lesson 2 AD DS DCs
- What is a DC?
-
- What are the global catalog servers?
-
- Overview of service (SRV) records
-
- Demonstration: Review SRV records in Domain Name System (DNS)
-
- How does the AD DS sign-in process work?
-
- Overview of operations masters
-
- Transfer and seize roles
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe the DC role.
-
- Describe global catalog servers.
-
- Describe SRV records.
-
- Review SRV records in DNS.
-
- Explain how the AD DS sign-in process works.
-
- Describe operations masters.
-
- Transfer and seize roles.
-
Lesson 3 Deploy AD DS DCs
- Install a DC from Server Manager
-
- Install a DC on a Server Core
-
- Upgrade a DC
-
- Install a DC from media
-
- Clone DCs
-
- Best practices for DC virtualization
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Install a DC.
-
- Install a DC on a Server Core.
-
- Upgrade a DC.
-
- Install a DC from media.
-
- Clone DCs.
-
- Describe best practices for DC virtualization.
-
Lesson 4 Azure AD overview
- What is Azure AD?
-
- How does Azure AD compare with AD DS?
-
- Azure AD editions
-
- Azure AD administration tools
-
- Azure AD Domain Services (Azure AD DS)
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe Azure AD.
-
- Compare Azure AD with AD DS.
-
- Describe available Azure AD editions.
-
- Explain the available Azure AD administration tools.
-
- Describe Azure AD DS.
-
Lab 1 Deploy and administer AD DS
- Deploy AD DS.
-
- Deploy DCs by performing DC cloning.
-
- Administer AD DS.
-
By completing this lab, you’ll achieve the knowledge and skills to:
- Deploy AD DS and DCs.
-
- Administer AD DS.
-
By completing this module, you’ll achieve the knowledge and skills to:
- Describe the AD DS components.
-
- Describe the role of DCs.
-
- Deploy DCs.
-
- Describe Azure AD.
-
Module 2 Manage directory objects
Active Directory, at its heart, is a hierarchical database. Unlike a traditional database, however, you can create many different types of records within Active Directory. These records are referred to as objects, which you can create to represent almost anything in your network, from users and groups to printers, shared folders, and computers.
Each object can have many different properties, referred to as attributes. For example, the user object type has attributes in which you can store the user’s sign-in name, and street and email addresses.
Not only does Active Directory allow you to store information about objects, but it also enables you to manage those objects. After you create objects, you can use AD DS to manage and control these objects, which you can group together in containers to easily apply policies to them.
Active Directory is a powerful tool to centrally manage your network. Large organizations might want to distribute management to different teams of administrators. Active Directory enables this by allowing a domain administrator to provide lower-level administrators access to specific objects and containers.
Lesson 1 Manage user accounts
- Create user accounts
-
- Demonstration: Manage user accounts
-
- Disable and delete user accounts
-
- Perform bulk operations on Active Directory objects
-
- Demonstration: Perform bulk operations in Active Directory Users and Computers
-
- User-account templates
-
- Demonstration: Use templates to create accounts
-
- Manage user objects in Azure AD
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Create and manage user accounts.
-
- Configure user attributes.
-
- Manage inactive and disabled user accounts.
-
- Create and manage user profiles.
-
- Use graphical tools to perform bulk operations.
-
- Manage user objects in Azure AD.
-
Lesson 2 Manage groups in AD DS
- Security and distribution groups
-
- Group scopes
-
- Implement group management (IGDLA)
-
- Delegate management of groups in Active Directory
-
- Restricted groups
-
- Default groups
-
- Special identities
-
- Demonstration: Manage groups in Windows Server
-
- Manage groups in Azure AD
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe group types and scopes.
-
- Understand the membership rules of each group scope.
-
- Delegate group management.
-
- Understand different methods to administer groups, including Group Policy.
-
- Understand default, special, and restricted groups.
-
Lesson 3 Manage computer objects in AD DS
- The default Computers container
-
- Create an OU structure for managing computer objects
-
- Control who can create computer objects
-
- Join a computer to a domain
-
- Computer accounts and secure channels
-
- Offline domain joins
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Understand the purpose of the Computers container.
-
- Configure the location of computer accounts.
-
- Control who has permission to create computer accounts.
-
- Join a computer to a domain.
-
- Join a computer to Azure AD to create a hybrid join.
-
- Describe computer accounts and secure channels.
-
- Reset the secure channel.
-
- Perform an offline domain join.
-
Lab 2 Manage AD DS objects
- Create and manage groups in AD DS.
-
- Create and configure user accounts in AD DS.
-
- Manage computer objects in AD DS.
-
By completing this lab, you’ll achieve the knowledge and skills to manage objects in AD DS.
Lesson 4 Administer AD DS by using PowerShell
- Use Windows PowerShell to manage user accounts
-
- Use PowerShell for bulk operations
-
- Demonstration: Use graphical tools to perform bulk operations
-
- Query objects with Windows PowerShell
-
- Use text files for bulk operations
-
- Demonstration: Perform bulk operations with Windows PowerShell
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Use PowerShell to manage user accounts.
-
- Use PowerShell to manage groups.
-
- Use PowerShell to manage computer accounts.
-
- Use PowerShell to manage OUs.
-
- Describe bulk operations.
-
- Use graphical tools to perform bulk operations.
-
- Use PowerShell to query objects.
-
- Use PowerShell to modify objects.
-
- Work with comma-separated value files (CSV files).
-
- Use PowerShell to perform bulk operations.
-
Lesson 5 Implement and manage OUs
- Plan OUs
-
- OU planning strategies
-
- Delegate administrative control
-
- Create OUs
-
- Manage permissions in Active Directory
-
- Demonstration: Delegate administrative permissions on an OU
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Plan OUs.
-
- Describe OU hierarchy considerations.
-
- Describe considerations for using OUs.
-
- Explain ADÂ DS permissions.
-
- Use OUs to delegate administration.
-
Lab 3 Administer Active Directory
- Delegate administration for OUs
-
- Create and modify AD DS objects with Windows PowerShell
-
By completing this lab, you’ll achieve the knowledge and skills to:
- Delegate administration in AD DS.
-
- Use PowerShell to manage AD DS objects.
-
By completing this module, you’ll achieve the knowledge and skills to:
- Manage user accounts.
-
- Manage group objects and understand the different types of groups.
-
- Manage computer objects.
-
- Manage containers, referred to as organizational units (OUs).
-
- Administer Active Directory by using GUI tools and Windows PowerShell.
-
Module 3 Advanced AD DS infrastructure management
This module describes key technologies that serve as the building blocks of more advanced AD DS environments and provides guidance about implementing and managing such environments.
Lesson 1 Overview of advanced AD DS deployments
- Overview of domain and forest boundaries
-
- Implementation of multiple domains and forests
-
- Deploy a DC in an Azure virtual machine (VM)
-
- Manage objects in complex AD DS deployments
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Understand the role of AD DS domains and forests in establishing security and administration boundaries.
-
- Identify scenarios in which having multiple AD DS domains is beneficial or required.
-
- Identify scenarios in which having multiple AD DS forests is beneficial or required.
-
- Understand considerations applicable to deploying AD DS DCs in Microsoft Azure VMs.
-
- Describe considerations applicable to managing users, groups, and computer objects in advanced AD DS deployments.
-
Lesson 2 Deploy a distributed AD DS environment
- AD DS domain and forest-functional levels
-
- Deploy new AD DS domains
-
- Demonstration: Install a DC in a new domain in an existing forest
-
- Upgrade and migrate AD DS domains
-
- Factors to consider when implementing complex AD DS environments
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Understand AD DS domain-functional levels.
-
- Understand AD DS forest-functional levels.
-
- Explain how to create a new AD DS domain.
-
- Install a DC in a new domain in an existing forest.
-
- Explain how to upgrade an AD DS environment.
-
- Explain how to migrate between AD DS environments.
-
- List factors to consider when implementing complex AD DS environments.
-
Lesson 3 Configure AD DS trusts
- Overview of AD DS trust types
-
- How do trusts work in a forest?
-
- How do trusts work between forests?
-
- Configure advanced AD DS trust settings
-
- Demonstration: Configure a forest trust
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Understand the trust types that you can configure in a multi-domain and multi-forest environment.
-
- Explain how trusts work in an AD DS forest.
-
- Explain how trusts work between AD DS forests.
-
- Describe how to configure advanced trust settings.
-
- Configure a forest trust.
-
Lab 4 Domain and trust management in AD DS
- Implement forest trusts.
-
- Implement child domains in AD DS.
-
By completing this lab, you’ll achieve the knowledge and skills to:
- Implement trust relationships in AD DS.
-
- Implement child domains in AD DS.
-
By completing this module, you’ll achieve the knowledge and skills to:
- Describe the technologies that are essential to implementing advanced AD DS environments.
-
- Deploy a distributed AD DS environment.
-
- Implement trusts in multi-domain and multi-forest AD DS environments.
-
Module 4 Implement and administer AD DS sites and replication
In this module, you’ll learn about the technical details of AD DS replication and how you can leverage that knowledge to optimize the design and implementation of AD DS environments that consist of multiple geographically distributed DCs.
Lesson 1 Overview of AD DS replication
- What are AD DS partitions?
-
- Characteristics of AD DS replication
-
- How AD DS replication works within a site
-
- Resolve replication conflicts
-
- How replication topology is generated
-
- How SYSVOL replication works
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe AD DS partitions.
-
- Describe characteristics of AD DS replication.
-
- Explain how AD DS replication works within a site.
-
- Explain how replication conflicts are resolved.
-
- Explain how replication topology is generated.
-
- Explain how SYSVOL replication works.
-
Lesson 2 Configure AD DS sites
- What are AD DS sites?
-
- Why implement additional sites?
-
- Demonstration: Configure AD DS sites
-
- How replication works between sites
-
- What is the intersite topology generator (ISTG)?
-
- Overview of SRV records
-
- How domain-joined computers locate DCs
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe AD DS sites.
-
- Explain reasons to implement additional sites.
-
- Configure additional AD DS sites.
-
- Describe how AD DS replication works between sites.
-
- Describe the intersite topology generator.
-
- Describe SRV resource records.
-
- Describe how domain-joined computers locate DCs.
-
- Explain how to move DCs between sites.
-
Lesson 3 Configure and monitor AD DS replication
- What are AD DS site links?
-
- What is site-link bridging?
-
- Manage site-link replication.
-
- Demonstration: Configure AD DS intersite replication.
-
- Tools for monitoring and managing replication.
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe AD DS site links.
-
- Explain the concept of site-link bridging.
-
- Describe how to manage intersite replication.
-
- Configure AD DS intersite replication.
-
- Describe the tools for monitoring and managing replication.
-
Lab 5 Implement AD DS sites and replication
- Modify the default site.
-
- Create additional sites and subnets.
-
- Configure AD DS replication.
-
- Monitor and troubleshoot AD DS replication.
-
By completing this lab, you’ll achieve the knowledge and skills to:
- Manage sites and subnets in AD DS.
-
- Configure replication options for AD DS.
-
- Monitor and troubleshoot replication.
-
By completing this module, you’ll achieve the knowledge and skills to:
- Understand how AD DS replication works.
-
- Configure AD DS sites to optimize authentication and replication traffic.
-
- Configure and monitor AD DS replication.
-
Module 5 Implement Group Policy
For organizations operating in an on-premises AD DS environment, Group Policy offers centralized management of both user and computer settings. This enables administrators to configure, enforce, and maintain their organization’s on-premises configuration. GPOs are linked to container objects such as sites, domains, and OUs. Users and computers placed in those containers inherit the applicable container’s settings. However, GPOs can be blocked, unlinked, or enforced to override the default application behavior. GPOs can also be filtered based on security-group membership and Windows Management Instrumentation (WMI) filters. When settings don’t apply as you expect, it’s important that you know how to investigate and resolve the issues.
Lesson 1 What is Group Policy?
- What is configuration management?
-
- Select a Group Policy management tool
-
- What are the benefits of Group Policy?
-
- What are GPOs?
-
- Manage GPO scope and inheritance
-
- What are the Group Policy Client service and client-side extensions?
-
- Implement GPOs in Azure AD DS
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe configuration management with Group Policy.
-
- Describe Group Policy tools.
-
- Describe the benefits of Group Policy.
-
- Describe GPOs.
-
- Explain GPO scope and inheritance.
-
- Describe the Group Policy Client service and client-side extensions (CSEs).
-
- Describe Group Policy in Azure AD DS..
-
Lesson 2 Implement and administer Group Policy
- Implement domain-based GPOs
-
- Understand GPO storage and replication
-
- What are Starter GPOs?
-
- Common GPO management tasks
-
- What is Group Policy delegation?
-
- Demonstration: Delegate Group Policy administration
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe domain-based GPOs.
-
- Describe GPO storage and replication.
-
- Describe Starter GPOs.
-
- Describe common GPO management tasks.
-
- Explain how to delegate administration of Group Policies.
-
- Delegate administration of Group Policy.
-
Lesson 3 Group Policy scope and processing
- Link GPOs to containers
-
- Understand Group Policy processing, inheritance, and precedence
-
- Implement security filtering and WMI filtering
-
- Demonstration: Filter Group Policy application
-
- Enable and disable GPOs and GPO nodes
-
- Implement loopback processing
-
- Manage slow links and disconnected systems
-
- Identify when settings become effective
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe GPO links.
-
- Describe Group Policy processing, inheritance, and precedence.
-
- Use security filtering and WMI filtering to modify Group Policy scope.
-
- Filter Group Policy application.
-
- Enable or disable GPOs and GPO nodes.
-
- Describe loopback-policy processing.
-
- Describe considerations for slow links and disconnected systems.
-
- Identify when settings become effective.
-
Lab 6 Implement a Group Policy infrastructure
- Creating and configuring GPOs.
-
- Managing GPO scope.
-
By completing this lab, you’ll achieve the knowledge and skills to:
- Create and configure GPOs.
-
- Manage scope for GPOs.
-
Lesson 4 Troubleshoot the application of GPOs
- What is Resultant Set of Policy (RSoP)?
-
- Demonstration: Generate RSoP reports
-
- Examine Group Policy event logs
-
- Detect issues with the health of GPOs
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe RSoP.
-
- Generate RSoP reports.
-
- Examine Group Policy event logs.
-
- Detect issues with the health of GPOs.
-
Lab 7 Troubleshoot Group Policy infrastructure
- Verify GPO application.
-
- Troubleshoot GPOs.
-
By completing this lab, you’ll achieve the knowledge and skills to:
- Verify when a GPO is applied.
-
- Troubleshoot a GPO.
-
Module 6 Manage user settings with Group Policy
You can use GPOs to create a standard desktop for the entire organization or on a departmental basis. You construct this standard desktop by using features such as administrative templates, Folder Redirection, and Group Policy preferences.
Lesson 1 Implement administrative templates
- What are administrative templates?
-
- Overview of the central store
-
- Demonstration: Configure settings with administrative templates
-
- Import security templates
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe administrative templates.
-
- Describe the central store.
-
- Configure settings with administrative templates.
-
- Import security templates.
-
Lesson 2 Configure Folder Redirection, software installation, and scripts
- What is Folder Redirection?
-
- Settings for configuring Folder Redirection
-
- Security settings for redirected folders
-
- Demonstration: Configure Folder Redirection
-
- Manage software with Group Policy.
-
- Group Policy settings for applying scripts.
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe Folder Redirection.
-
- Explain the Folder Redirection configuration settings.
-
- Explain security requirements for redirected folders.
-
- Configure Folder Redirection.
-
- Manage application software using Group Policy.
-
- Manage scripts using Group Policy.
-
Lesson 3 Configure Group Policy preferences
- What are Group Policy preferences?
-
- Compare Group Policy preferences with settings
-
- Features of Group Policy preferences
-
- Item-level targeting options
-
- Demonstration: Configure Group Policy preferences
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe Group Policy preferences.
-
- Compare Group Policy preferences with settings.
-
- Explain features of Group Policy preferences.
-
- Implement item-level targeting.
-
- Configure Group Policy preferences.
-
Lab 8 Manage user settings with Group Policy
- Use administrative templates to manage user settings.
-
- Implement settings by using Group Policy preferences.
-
- Configure Folder Redirection.
-
By completing this lab, you’ll achieve the knowledge and skills to:
- Use administrative templates for management of user settings.
-
- Use Group Policy preferences.
-
- Configure Folder Redirection by using Group Policy.
-
By completing this module, you’ll achieve the knowledge and skills to:
- Implement administrative templates.
-
- Configure Folder Redirection, software installation, and scripts.
-
- Configure Group Policy preferences.
-
Module 7 Secure AD DS
AD DS contains sensitive information about many parts of your IT infrastructure, such as users and their passwords. An issue with your AD DS security can result in data loss, data leakage, parts of your IT infrastructure being disabled, or even your entire IT infrastructure being compromised. As an AD DS administrator, you need to understand the potential threats to AD DS and how to mitigate them.
Lesson 1 Secure DCs
- What security risks can affect DCs?
-
- Modify security settings of DCs
-
- Implement secure authentication
-
- Secure physical access to DCs
-
- What are RODCs?
-
- Deploy an RODC
-
- Plan and configure an RODC password-replication policy
-
- Demonstration: Configure a password-replication policy
-
- Separate RODC local administration
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe the security risks that can affect DCs.
-
- Modify DC security settings.
-
- Explain how to implement secure authentication.
-
- Secure physical access to DCs.
-
- Describe RODCs.
-
- Deploy an RODC.
-
- Plan password replication for RODCs.
-
- Configure password replication for RODCs.
-
- Explain how to separate RODC local administration.
-
Lesson 2 Implement account security
- Account security in Windows Server
-
- Understand password policies, account lockout policies, and Kerberos authentication policies
-
- Demonstration: Configure domain account policies
-
- Protect groups in AD DS.
-
- Fine-grained password and lockout policies.
-
- Create and manage Password Settings objects (PSOs).
-
- Demonstration: Configure a fine-grained password policy
-
- Enhance password authentication with Windows Hello
-
- Options for securing accounts in Azure AD
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe account security in Windows Server.
-
- Explain password policies, account-lockout policies, and Kerberos authentication policies.
-
- Configure domain-account policies.
-
- Explain how to protect groups in AD DS.
-
- Describe fine-grained password and lockout policies.
-
- Create and manage PSOs.
-
- Configure a fine-grained password policy.
-
- Describe how to enhance password authentication with Windows Hello and the Microsoft Azure AD Multifactor Authentication (MFA) service.
-
- Explain options for securing accounts in Azure.
-
Lesson 3 Implement authentication auditing
- Account logon and logon events
-
- Demonstration: Configure authentication-related audit policies
-
- Scope audit policies
-
- Demonstration: Review logon events
-
By completing this lesson, you’ll achieve the knowledge and skills to:
Audience profile
This course is intended for IT professionals who work on administering, configuring, troubleshooting, and operating identity services in the AD DS and Entra ID. It is also useful for system or infrastructure administrators with general AD DS experience who want to gain additional insight about Windows Server 2022 identity and access technologies.
Why choose this course?
- Meticulous content relevance, tailored to Windows Server 2022, sets it apart from competitive courses based primarily on previous versions.
-
- Content on obsolete technology, which is present in competitive versions of the course, has been removed.
-
- Includes a focused lesson on Entra ID and the comparison to AD DS.
-
- Offers an array of demonstrations that bolster the learning material.
-
- Expert instructional design ensures a superior learning experience.
-
- Labs are developed by Waypoint in parallel with courseware, so they are 100% aligned.
-
At Course Completion
By completing this course, you’ll achieve the knowledge and skills to:
- Deploy Active Directory services.
-
- Manage directory objects.
-
- Execute advanced Active Directory Domain Services (AD DS) infrastructure management.
-
- Implement and administer AD DS sites and replication.
-
- Implement Group Policy.
-
- Manage user settings with Group Policy.
-
- Secure AD DS.
-
- Deploy and manage Active Directory Certificate Services (AD CS).
-
- Deploy and manage certificates.
-
- Implement and administer Active Directory Federation Services (AD FS).
-
- Implement AD DS synchronization with Microsoft Entra ID.
-
- Monitor, manage, and recover AD DS​.
-
Course Details
Course Duration:Â 5 Days
Module 1 Deploy Active Directory services
Active Directory Domain Services (AD DS) is the cornerstone of on-premises networks for many organizations worldwide. AD DS delivers authentication and authorization by using domain controllers (DCs) for on-premises apps and services. In this module, you’ll learn how to configure DCs to suit your specific organizational needs, and integrate AD DS with Microsoft Azure Active Directory (Azure AD) to provide single sign-on (SSO) for users that access both on-premises and cloud-based apps.
Lesson 1 Components of AD DS
- What is an AD DS forest?
-
- What is an AD DS domain?
-
- What are organizational units (OUs)?
-
- What is the AD DS schema?
-
- Overview of AD DS administration tools
-
- Demonstration: Manage AD DS
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe AD DS forests.Â
-
- Describe AD DS domains.Â
-
- Describe OUs.Â
-
- Describe the AD DS schema.Â
-
- Select appropriate AD DS administration tools.Â
-
- Manage AD DS.Â
-
Lesson 2 AD DS DCs
- What is a DC?
-
- What are the global catalog servers?
-
- Overview of service (SRV) records
-
- Demonstration: Review SRV records in Domain Name System (DNS)
-
- How does the AD DS sign-in process work?
-
- Overview of operations masters
-
- Transfer and seize roles
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe the DC role.
-
- Describe global catalog servers.
-
- Describe SRV records.
-
- Review SRV records in DNS.
-
- Explain how the AD DS sign-in process works.
-
- Describe operations masters.
-
- Transfer and seize roles.
-
Lesson 3 Deploy AD DS DCs
- Install a DC from Server Manager
-
- Install a DC on a Server Core
-
- Upgrade a DC
-
- Install a DC from media
-
- Clone DCs
-
- Best practices for DC virtualization
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Install a DC.
-
- Install a DC on a Server Core.
-
- Upgrade a DC.
-
- Install a DC from media.
-
- Clone DCs.
-
- Describe best practices for DC virtualization.
-
Lesson 4 Azure AD overview
- What is Azure AD?
-
- How does Azure AD compare with AD DS?
-
- Azure AD editions
-
- Azure AD administration tools
-
- Azure AD Domain Services (Azure AD DS)
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe Azure AD.
-
- Compare Azure AD with AD DS.
-
- Describe available Azure AD editions.
-
- Explain the available Azure AD administration tools.
-
- Describe Azure AD DS.
-
Lab 1 Deploy and administer AD DS
- Deploy AD DS.
-
- Deploy DCs by performing DC cloning.
-
- Administer AD DS.
-
By completing this lab, you’ll achieve the knowledge and skills to:
- Deploy AD DS and DCs.
-
- Administer AD DS.
-
By completing this module, you’ll achieve the knowledge and skills to:
- Describe the AD DS components.
-
- Describe the role of DCs.
-
- Deploy DCs.
-
- Describe Azure AD.
-
Module 2 Manage directory objects
Active Directory, at its heart, is a hierarchical database. Unlike a traditional database, however, you can create many different types of records within Active Directory. These records are referred to as objects, which you can create to represent almost anything in your network, from users and groups to printers, shared folders, and computers.
Each object can have many different properties, referred to as attributes. For example, the user object type has attributes in which you can store the user’s sign-in name, and street and email addresses.
Not only does Active Directory allow you to store information about objects, but it also enables you to manage those objects. After you create objects, you can use AD DS to manage and control these objects, which you can group together in containers to easily apply policies to them.
Active Directory is a powerful tool to centrally manage your network. Large organizations might want to distribute management to different teams of administrators. Active Directory enables this by allowing a domain administrator to provide lower-level administrators access to specific objects and containers.
Lesson 1 Manage user accounts
- Create user accounts
-
- Demonstration: Manage user accounts
-
- Disable and delete user accounts
-
- Perform bulk operations on Active Directory objects
-
- Demonstration: Perform bulk operations in Active Directory Users and Computers
-
- User-account templates
-
- Demonstration: Use templates to create accounts
-
- Manage user objects in Azure AD
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Create and manage user accounts.
-
- Configure user attributes.
-
- Manage inactive and disabled user accounts.
-
- Create and manage user profiles.
-
- Use graphical tools to perform bulk operations.
-
- Manage user objects in Azure AD.
-
Lesson 2 Manage groups in AD DS
- Security and distribution groups
-
- Group scopes
-
- Implement group management (IGDLA)
-
- Delegate management of groups in Active Directory
-
- Restricted groups
-
- Default groups
-
- Special identities
-
- Demonstration: Manage groups in Windows Server
-
- Manage groups in Azure AD
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe group types and scopes.
-
- Understand the membership rules of each group scope.
-
- Delegate group management.
-
- Understand different methods to administer groups, including Group Policy.
-
- Understand default, special, and restricted groups.
-
Lesson 3 Manage computer objects in AD DS
- The default Computers container
-
- Create an OU structure for managing computer objects
-
- Control who can create computer objects
-
- Join a computer to a domain
-
- Computer accounts and secure channels
-
- Offline domain joins
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Understand the purpose of the Computers container.
-
- Configure the location of computer accounts.
-
- Control who has permission to create computer accounts.
-
- Join a computer to a domain.
-
- Join a computer to Azure AD to create a hybrid join.
-
- Describe computer accounts and secure channels.
-
- Reset the secure channel.
-
- Perform an offline domain join.
-
Lab 2 Manage AD DS objects
- Create and manage groups in AD DS.
-
- Create and configure user accounts in AD DS.
-
- Manage computer objects in AD DS.
-
By completing this lab, you’ll achieve the knowledge and skills to manage objects in AD DS.
Lesson 4 Administer AD DS by using PowerShell
- Use Windows PowerShell to manage user accounts
-
- Use PowerShell for bulk operations
-
- Demonstration: Use graphical tools to perform bulk operations
-
- Query objects with Windows PowerShell
-
- Use text files for bulk operations
-
- Demonstration: Perform bulk operations with Windows PowerShell
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Use PowerShell to manage user accounts.
-
- Use PowerShell to manage groups.
-
- Use PowerShell to manage computer accounts.
-
- Use PowerShell to manage OUs.
-
- Describe bulk operations.
-
- Use graphical tools to perform bulk operations.
-
- Use PowerShell to query objects.
-
- Use PowerShell to modify objects.
-
- Work with comma-separated value files (CSV files).
-
- Use PowerShell to perform bulk operations.
-
Lesson 5 Implement and manage OUs
- Plan OUs
-
- OU planning strategies
-
- Delegate administrative control
-
- Create OUs
-
- Manage permissions in Active Directory
-
- Demonstration: Delegate administrative permissions on an OU
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Plan OUs.
-
- Describe OU hierarchy considerations.
-
- Describe considerations for using OUs.
-
- Explain ADÂ DS permissions.
-
- Use OUs to delegate administration.
-
Lab 3 Administer Active Directory
- Delegate administration for OUs
-
- Create and modify AD DS objects with Windows PowerShell
-
By completing this lab, you’ll achieve the knowledge and skills to:
- Delegate administration in AD DS.
-
- Use PowerShell to manage AD DS objects.
-
By completing this module, you’ll achieve the knowledge and skills to:
- Manage user accounts.
-
- Manage group objects and understand the different types of groups.
-
- Manage computer objects.
-
- Manage containers, referred to as organizational units (OUs).
-
- Administer Active Directory by using GUI tools and Windows PowerShell.
-
Module 3 Advanced AD DS infrastructure management
This module describes key technologies that serve as the building blocks of more advanced AD DS environments and provides guidance about implementing and managing such environments.
Lesson 1 Overview of advanced AD DS deployments
- Overview of domain and forest boundaries
-
- Implementation of multiple domains and forests
-
- Deploy a DC in an Azure virtual machine (VM)
-
- Manage objects in complex AD DS deployments
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Understand the role of AD DS domains and forests in establishing security and administration boundaries.
-
- Identify scenarios in which having multiple AD DS domains is beneficial or required.
-
- Identify scenarios in which having multiple AD DS forests is beneficial or required.
-
- Understand considerations applicable to deploying AD DS DCs in Microsoft Azure VMs.
-
- Describe considerations applicable to managing users, groups, and computer objects in advanced AD DS deployments.
-
Lesson 2 Deploy a distributed AD DS environment
- AD DS domain and forest-functional levels
-
- Deploy new AD DS domains
-
- Demonstration: Install a DC in a new domain in an existing forest
-
- Upgrade and migrate AD DS domains
-
- Factors to consider when implementing complex AD DS environments
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Understand AD DS domain-functional levels.
-
- Understand AD DS forest-functional levels.
-
- Explain how to create a new AD DS domain.
-
- Install a DC in a new domain in an existing forest.
-
- Explain how to upgrade an AD DS environment.
-
- Explain how to migrate between AD DS environments.
-
- List factors to consider when implementing complex AD DS environments.
-
Lesson 3 Configure AD DS trusts
- Overview of AD DS trust types
-
- How do trusts work in a forest?
-
- How do trusts work between forests?
-
- Configure advanced AD DS trust settings
-
- Demonstration: Configure a forest trust
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Understand the trust types that you can configure in a multi-domain and multi-forest environment.
-
- Explain how trusts work in an AD DS forest.
-
- Explain how trusts work between AD DS forests.
-
- Describe how to configure advanced trust settings.
-
- Configure a forest trust.
-
Lab 4 Domain and trust management in AD DS
- Implement forest trusts.
-
- Implement child domains in AD DS.
-
By completing this lab, you’ll achieve the knowledge and skills to:
- Implement trust relationships in AD DS.
-
- Implement child domains in AD DS.
-
By completing this module, you’ll achieve the knowledge and skills to:
- Describe the technologies that are essential to implementing advanced AD DS environments.
-
- Deploy a distributed AD DS environment.
-
- Implement trusts in multi-domain and multi-forest AD DS environments.
-
Module 4 Implement and administer AD DS sites and replication
In this module, you’ll learn about the technical details of AD DS replication and how you can leverage that knowledge to optimize the design and implementation of AD DS environments that consist of multiple geographically distributed DCs.
Lesson 1 Overview of AD DS replication
- What are AD DS partitions?
-
- Characteristics of AD DS replication
-
- How AD DS replication works within a site
-
- Resolve replication conflicts
-
- How replication topology is generated
-
- How SYSVOL replication works
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe AD DS partitions.
-
- Describe characteristics of AD DS replication.
-
- Explain how AD DS replication works within a site.
-
- Explain how replication conflicts are resolved.
-
- Explain how replication topology is generated.
-
- Explain how SYSVOL replication works.
-
Lesson 2 Configure AD DS sites
- What are AD DS sites?
-
- Why implement additional sites?
-
- Demonstration: Configure AD DS sites
-
- How replication works between sites
-
- What is the intersite topology generator (ISTG)?
-
- Overview of SRV records
-
- How domain-joined computers locate DCs
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe AD DS sites.
-
- Explain reasons to implement additional sites.
-
- Configure additional AD DS sites.
-
- Describe how AD DS replication works between sites.
-
- Describe the intersite topology generator.
-
- Describe SRV resource records.
-
- Describe how domain-joined computers locate DCs.
-
- Explain how to move DCs between sites.
-
Lesson 3 Configure and monitor AD DS replication
- What are AD DS site links?
-
- What is site-link bridging?
-
- Manage site-link replication.
-
- Demonstration: Configure AD DS intersite replication.
-
- Tools for monitoring and managing replication.
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe AD DS site links.
-
- Explain the concept of site-link bridging.
-
- Describe how to manage intersite replication.
-
- Configure AD DS intersite replication.
-
- Describe the tools for monitoring and managing replication.
-
Lab 5 Implement AD DS sites and replication
- Modify the default site.
-
- Create additional sites and subnets.
-
- Configure AD DS replication.
-
- Monitor and troubleshoot AD DS replication.
-
By completing this lab, you’ll achieve the knowledge and skills to:
- Manage sites and subnets in AD DS.
-
- Configure replication options for AD DS.
-
- Monitor and troubleshoot replication.
-
By completing this module, you’ll achieve the knowledge and skills to:
- Understand how AD DS replication works.
-
- Configure AD DS sites to optimize authentication and replication traffic.
-
- Configure and monitor AD DS replication.
-
Module 5 Implement Group Policy
For organizations operating in an on-premises AD DS environment, Group Policy offers centralized management of both user and computer settings. This enables administrators to configure, enforce, and maintain their organization’s on-premises configuration. GPOs are linked to container objects such as sites, domains, and OUs. Users and computers placed in those containers inherit the applicable container’s settings. However, GPOs can be blocked, unlinked, or enforced to override the default application behavior. GPOs can also be filtered based on security-group membership and Windows Management Instrumentation (WMI) filters. When settings don’t apply as you expect, it’s important that you know how to investigate and resolve the issues.
Lesson 1 What is Group Policy?
- What is configuration management?
-
- Select a Group Policy management tool
-
- What are the benefits of Group Policy?
-
- What are GPOs?
-
- Manage GPO scope and inheritance
-
- What are the Group Policy Client service and client-side extensions?
-
- Implement GPOs in Azure AD DS
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe configuration management with Group Policy.
-
- Describe Group Policy tools.
-
- Describe the benefits of Group Policy.
-
- Describe GPOs.
-
- Explain GPO scope and inheritance.
-
- Describe the Group Policy Client service and client-side extensions (CSEs).
-
- Describe Group Policy in Azure AD DS..
-
Lesson 2 Implement and administer Group Policy
- Implement domain-based GPOs
-
- Understand GPO storage and replication
-
- What are Starter GPOs?
-
- Common GPO management tasks
-
- What is Group Policy delegation?
-
- Demonstration: Delegate Group Policy administration
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe domain-based GPOs.
-
- Describe GPO storage and replication.
-
- Describe Starter GPOs.
-
- Describe common GPO management tasks.
-
- Explain how to delegate administration of Group Policies.
-
- Delegate administration of Group Policy.
-
Lesson 3 Group Policy scope and processing
- Link GPOs to containers
-
- Understand Group Policy processing, inheritance, and precedence
-
- Implement security filtering and WMI filtering
-
- Demonstration: Filter Group Policy application
-
- Enable and disable GPOs and GPO nodes
-
- Implement loopback processing
-
- Manage slow links and disconnected systems
-
- Identify when settings become effective
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe GPO links.
-
- Describe Group Policy processing, inheritance, and precedence.
-
- Use security filtering and WMI filtering to modify Group Policy scope.
-
- Filter Group Policy application.
-
- Enable or disable GPOs and GPO nodes.
-
- Describe loopback-policy processing.
-
- Describe considerations for slow links and disconnected systems.
-
- Identify when settings become effective.
-
Lab 6 Implement a Group Policy infrastructure
- Creating and configuring GPOs.
-
- Managing GPO scope.
-
By completing this lab, you’ll achieve the knowledge and skills to:
- Create and configure GPOs.
-
- Manage scope for GPOs.
-
Lesson 4 Troubleshoot the application of GPOs
- What is Resultant Set of Policy (RSoP)?
-
- Demonstration: Generate RSoP reports
-
- Examine Group Policy event logs
-
- Detect issues with the health of GPOs
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe RSoP.
-
- Generate RSoP reports.
-
- Examine Group Policy event logs.
-
- Detect issues with the health of GPOs.
-
Lab 7 Troubleshoot Group Policy infrastructure
- Verify GPO application.
-
- Troubleshoot GPOs.
-
By completing this lab, you’ll achieve the knowledge and skills to:
- Verify when a GPO is applied.
-
- Troubleshoot a GPO.
-
Module 6 Manage user settings with Group Policy
You can use GPOs to create a standard desktop for the entire organization or on a departmental basis. You construct this standard desktop by using features such as administrative templates, Folder Redirection, and Group Policy preferences.
Lesson 1 Implement administrative templates
- What are administrative templates?
-
- Overview of the central store
-
- Demonstration: Configure settings with administrative templates
-
- Import security templates
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe administrative templates.
-
- Describe the central store.
-
- Configure settings with administrative templates.
-
- Import security templates.
-
Lesson 2 Configure Folder Redirection, software installation, and scripts
- What is Folder Redirection?
-
- Settings for configuring Folder Redirection
-
- Security settings for redirected folders
-
- Demonstration: Configure Folder Redirection
-
- Manage software with Group Policy.
-
- Group Policy settings for applying scripts.
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe Folder Redirection.
-
- Explain the Folder Redirection configuration settings.
-
- Explain security requirements for redirected folders.
-
- Configure Folder Redirection.
-
- Manage application software using Group Policy.
-
- Manage scripts using Group Policy.
-
Lesson 3 Configure Group Policy preferences
- What are Group Policy preferences?
-
- Compare Group Policy preferences with settings
-
- Features of Group Policy preferences
-
- Item-level targeting options
-
- Demonstration: Configure Group Policy preferences
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe Group Policy preferences.
-
- Compare Group Policy preferences with settings.
-
- Explain features of Group Policy preferences.
-
- Implement item-level targeting.
-
- Configure Group Policy preferences.
-
Lab 8 Manage user settings with Group Policy
- Use administrative templates to manage user settings.
-
- Implement settings by using Group Policy preferences.
-
- Configure Folder Redirection.
-
By completing this lab, you’ll achieve the knowledge and skills to:
- Use administrative templates for management of user settings.
-
- Use Group Policy preferences.
-
- Configure Folder Redirection by using Group Policy.
-
By completing this module, you’ll achieve the knowledge and skills to:
- Implement administrative templates.
-
- Configure Folder Redirection, software installation, and scripts.
-
- Configure Group Policy preferences.
-
Module 7 Secure AD DS
AD DS contains sensitive information about many parts of your IT infrastructure, such as users and their passwords. An issue with your AD DS security can result in data loss, data leakage, parts of your IT infrastructure being disabled, or even your entire IT infrastructure being compromised. As an AD DS administrator, you need to understand the potential threats to AD DS and how to mitigate them.
Lesson 1 Secure DCs
- What security risks can affect DCs?
-
- Modify security settings of DCs
-
- Implement secure authentication
-
- Secure physical access to DCs
-
- What are RODCs?
-
- Deploy an RODC
-
- Plan and configure an RODC password-replication policy
-
- Demonstration: Configure a password-replication policy
-
- Separate RODC local administration
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe the security risks that can affect DCs.
-
- Modify DC security settings.
-
- Explain how to implement secure authentication.
-
- Secure physical access to DCs.
-
- Describe RODCs.
-
- Deploy an RODC.
-
- Plan password replication for RODCs.
-
- Configure password replication for RODCs.
-
- Explain how to separate RODC local administration.
-
Lesson 2 Implement account security
- Account security in Windows Server
-
- Understand password policies, account lockout policies, and Kerberos authentication policies
-
- Demonstration: Configure domain account policies
-
- Protect groups in AD DS.
-
- Fine-grained password and lockout policies.
-
- Create and manage Password Settings objects (PSOs).
-
- Demonstration: Configure a fine-grained password policy
-
- Enhance password authentication with Windows Hello
-
- Options for securing accounts in Azure AD
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe account security in Windows Server.
-
- Explain password policies, account-lockout policies, and Kerberos authentication policies.
-
- Configure domain-account policies.
-
- Explain how to protect groups in AD DS.
-
- Describe fine-grained password and lockout policies.
-
- Create and manage PSOs.
-
- Configure a fine-grained password policy.
-
- Describe how to enhance password authentication with Windows Hello and the Microsoft Azure AD Multifactor Authentication (MFA) service.
-
- Explain options for securing accounts in Azure.
-
Lesson 3 Implement authentication auditing
- Account logon and logon events
-
- Demonstration: Configure authentication-related audit policies
-
- Scope audit policies
-
- Demonstration: Review logon events
-
By completing this lesson, you’ll achieve the knowledge and skills to:
Why choose this course?
- Meticulous content relevance, tailored to Windows Server 2022, sets it apart from competitive courses based primarily on previous versions.
-
- Content on obsolete technology, which is present in competitive versions of the course, has been removed.
-
- Includes a focused lesson on Entra ID and the comparison to AD DS.
-
- Offers an array of demonstrations that bolster the learning material.
-
- Expert instructional design ensures a superior learning experience.
-
- Labs are developed by Waypoint in parallel with courseware, so they are 100% aligned.
-
At Course Completion
By completing this course, you’ll achieve the knowledge and skills to:
- Deploy Active Directory services.
-
- Manage directory objects.
-
- Execute advanced Active Directory Domain Services (AD DS) infrastructure management.
-
- Implement and administer AD DS sites and replication.
-
- Implement Group Policy.
-
- Manage user settings with Group Policy.
-
- Secure AD DS.
-
- Deploy and manage Active Directory Certificate Services (AD CS).
-
- Deploy and manage certificates.
-
- Implement and administer Active Directory Federation Services (AD FS).
-
- Implement AD DS synchronization with Microsoft Entra ID.
-
- Monitor, manage, and recover AD DS​.
-
Course Details
Course Duration:Â 5 Days
Module 1 Deploy Active Directory services
Active Directory Domain Services (AD DS) is the cornerstone of on-premises networks for many organizations worldwide. AD DS delivers authentication and authorization by using domain controllers (DCs) for on-premises apps and services. In this module, you’ll learn how to configure DCs to suit your specific organizational needs, and integrate AD DS with Microsoft Azure Active Directory (Azure AD) to provide single sign-on (SSO) for users that access both on-premises and cloud-based apps.
Lesson 1 Components of AD DS
- What is an AD DS forest?
-
- What is an AD DS domain?
-
- What are organizational units (OUs)?
-
- What is the AD DS schema?
-
- Overview of AD DS administration tools
-
- Demonstration: Manage AD DS
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe AD DS forests.Â
-
- Describe AD DS domains.Â
-
- Describe OUs.Â
-
- Describe the AD DS schema.Â
-
- Select appropriate AD DS administration tools.Â
-
- Manage AD DS.Â
-
Lesson 2 AD DS DCs
- What is a DC?
-
- What are the global catalog servers?
-
- Overview of service (SRV) records
-
- Demonstration: Review SRV records in Domain Name System (DNS)
-
- How does the AD DS sign-in process work?
-
- Overview of operations masters
-
- Transfer and seize roles
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe the DC role.
-
- Describe global catalog servers.
-
- Describe SRV records.
-
- Review SRV records in DNS.
-
- Explain how the AD DS sign-in process works.
-
- Describe operations masters.
-
- Transfer and seize roles.
-
Lesson 3 Deploy AD DS DCs
- Install a DC from Server Manager
-
- Install a DC on a Server Core
-
- Upgrade a DC
-
- Install a DC from media
-
- Clone DCs
-
- Best practices for DC virtualization
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Install a DC.
-
- Install a DC on a Server Core.
-
- Upgrade a DC.
-
- Install a DC from media.
-
- Clone DCs.
-
- Describe best practices for DC virtualization.
-
Lesson 4 Azure AD overview
- What is Azure AD?
-
- How does Azure AD compare with AD DS?
-
- Azure AD editions
-
- Azure AD administration tools
-
- Azure AD Domain Services (Azure AD DS)
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe Azure AD.
-
- Compare Azure AD with AD DS.
-
- Describe available Azure AD editions.
-
- Explain the available Azure AD administration tools.
-
- Describe Azure AD DS.
-
Lab 1 Deploy and administer AD DS
- Deploy AD DS.
-
- Deploy DCs by performing DC cloning.
-
- Administer AD DS.
-
By completing this lab, you’ll achieve the knowledge and skills to:
- Deploy AD DS and DCs.
-
- Administer AD DS.
-
By completing this module, you’ll achieve the knowledge and skills to:
- Describe the AD DS components.
-
- Describe the role of DCs.
-
- Deploy DCs.
-
- Describe Azure AD.
-
Module 2 Manage directory objects
Active Directory, at its heart, is a hierarchical database. Unlike a traditional database, however, you can create many different types of records within Active Directory. These records are referred to as objects, which you can create to represent almost anything in your network, from users and groups to printers, shared folders, and computers.
Each object can have many different properties, referred to as attributes. For example, the user object type has attributes in which you can store the user’s sign-in name, and street and email addresses.
Not only does Active Directory allow you to store information about objects, but it also enables you to manage those objects. After you create objects, you can use AD DS to manage and control these objects, which you can group together in containers to easily apply policies to them.
Active Directory is a powerful tool to centrally manage your network. Large organizations might want to distribute management to different teams of administrators. Active Directory enables this by allowing a domain administrator to provide lower-level administrators access to specific objects and containers.
Lesson 1 Manage user accounts
- Create user accounts
-
- Demonstration: Manage user accounts
-
- Disable and delete user accounts
-
- Perform bulk operations on Active Directory objects
-
- Demonstration: Perform bulk operations in Active Directory Users and Computers
-
- User-account templates
-
- Demonstration: Use templates to create accounts
-
- Manage user objects in Azure AD
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Create and manage user accounts.
-
- Configure user attributes.
-
- Manage inactive and disabled user accounts.
-
- Create and manage user profiles.
-
- Use graphical tools to perform bulk operations.
-
- Manage user objects in Azure AD.
-
Lesson 2 Manage groups in AD DS
- Security and distribution groups
-
- Group scopes
-
- Implement group management (IGDLA)
-
- Delegate management of groups in Active Directory
-
- Restricted groups
-
- Default groups
-
- Special identities
-
- Demonstration: Manage groups in Windows Server
-
- Manage groups in Azure AD
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe group types and scopes.
-
- Understand the membership rules of each group scope.
-
- Delegate group management.
-
- Understand different methods to administer groups, including Group Policy.
-
- Understand default, special, and restricted groups.
-
Lesson 3 Manage computer objects in AD DS
- The default Computers container
-
- Create an OU structure for managing computer objects
-
- Control who can create computer objects
-
- Join a computer to a domain
-
- Computer accounts and secure channels
-
- Offline domain joins
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Understand the purpose of the Computers container.
-
- Configure the location of computer accounts.
-
- Control who has permission to create computer accounts.
-
- Join a computer to a domain.
-
- Join a computer to Azure AD to create a hybrid join.
-
- Describe computer accounts and secure channels.
-
- Reset the secure channel.
-
- Perform an offline domain join.
-
Lab 2 Manage AD DS objects
- Create and manage groups in AD DS.
-
- Create and configure user accounts in AD DS.
-
- Manage computer objects in AD DS.
-
By completing this lab, you’ll achieve the knowledge and skills to manage objects in AD DS.
Lesson 4 Administer AD DS by using PowerShell
- Use Windows PowerShell to manage user accounts
-
- Use PowerShell for bulk operations
-
- Demonstration: Use graphical tools to perform bulk operations
-
- Query objects with Windows PowerShell
-
- Use text files for bulk operations
-
- Demonstration: Perform bulk operations with Windows PowerShell
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Use PowerShell to manage user accounts.
-
- Use PowerShell to manage groups.
-
- Use PowerShell to manage computer accounts.
-
- Use PowerShell to manage OUs.
-
- Describe bulk operations.
-
- Use graphical tools to perform bulk operations.
-
- Use PowerShell to query objects.
-
- Use PowerShell to modify objects.
-
- Work with comma-separated value files (CSV files).
-
- Use PowerShell to perform bulk operations.
-
Lesson 5 Implement and manage OUs
- Plan OUs
-
- OU planning strategies
-
- Delegate administrative control
-
- Create OUs
-
- Manage permissions in Active Directory
-
- Demonstration: Delegate administrative permissions on an OU
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Plan OUs.
-
- Describe OU hierarchy considerations.
-
- Describe considerations for using OUs.
-
- Explain ADÂ DS permissions.
-
- Use OUs to delegate administration.
-
Lab 3 Administer Active Directory
- Delegate administration for OUs
-
- Create and modify AD DS objects with Windows PowerShell
-
By completing this lab, you’ll achieve the knowledge and skills to:
- Delegate administration in AD DS.
-
- Use PowerShell to manage AD DS objects.
-
By completing this module, you’ll achieve the knowledge and skills to:
- Manage user accounts.
-
- Manage group objects and understand the different types of groups.
-
- Manage computer objects.
-
- Manage containers, referred to as organizational units (OUs).
-
- Administer Active Directory by using GUI tools and Windows PowerShell.
-
Module 3 Advanced AD DS infrastructure management
This module describes key technologies that serve as the building blocks of more advanced AD DS environments and provides guidance about implementing and managing such environments.
Lesson 1 Overview of advanced AD DS deployments
- Overview of domain and forest boundaries
-
- Implementation of multiple domains and forests
-
- Deploy a DC in an Azure virtual machine (VM)
-
- Manage objects in complex AD DS deployments
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Understand the role of AD DS domains and forests in establishing security and administration boundaries.
-
- Identify scenarios in which having multiple AD DS domains is beneficial or required.
-
- Identify scenarios in which having multiple AD DS forests is beneficial or required.
-
- Understand considerations applicable to deploying AD DS DCs in Microsoft Azure VMs.
-
- Describe considerations applicable to managing users, groups, and computer objects in advanced AD DS deployments.
-
Lesson 2 Deploy a distributed AD DS environment
- AD DS domain and forest-functional levels
-
- Deploy new AD DS domains
-
- Demonstration: Install a DC in a new domain in an existing forest
-
- Upgrade and migrate AD DS domains
-
- Factors to consider when implementing complex AD DS environments
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Understand AD DS domain-functional levels.
-
- Understand AD DS forest-functional levels.
-
- Explain how to create a new AD DS domain.
-
- Install a DC in a new domain in an existing forest.
-
- Explain how to upgrade an AD DS environment.
-
- Explain how to migrate between AD DS environments.
-
- List factors to consider when implementing complex AD DS environments.
-
Lesson 3 Configure AD DS trusts
- Overview of AD DS trust types
-
- How do trusts work in a forest?
-
- How do trusts work between forests?
-
- Configure advanced AD DS trust settings
-
- Demonstration: Configure a forest trust
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Understand the trust types that you can configure in a multi-domain and multi-forest environment.
-
- Explain how trusts work in an AD DS forest.
-
- Explain how trusts work between AD DS forests.
-
- Describe how to configure advanced trust settings.
-
- Configure a forest trust.
-
Lab 4 Domain and trust management in AD DS
- Implement forest trusts.
-
- Implement child domains in AD DS.
-
By completing this lab, you’ll achieve the knowledge and skills to:
- Implement trust relationships in AD DS.
-
- Implement child domains in AD DS.
-
By completing this module, you’ll achieve the knowledge and skills to:
- Describe the technologies that are essential to implementing advanced AD DS environments.
-
- Deploy a distributed AD DS environment.
-
- Implement trusts in multi-domain and multi-forest AD DS environments.
-
Module 4 Implement and administer AD DS sites and replication
In this module, you’ll learn about the technical details of AD DS replication and how you can leverage that knowledge to optimize the design and implementation of AD DS environments that consist of multiple geographically distributed DCs.
Lesson 1 Overview of AD DS replication
- What are AD DS partitions?
-
- Characteristics of AD DS replication
-
- How AD DS replication works within a site
-
- Resolve replication conflicts
-
- How replication topology is generated
-
- How SYSVOL replication works
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe AD DS partitions.
-
- Describe characteristics of AD DS replication.
-
- Explain how AD DS replication works within a site.
-
- Explain how replication conflicts are resolved.
-
- Explain how replication topology is generated.
-
- Explain how SYSVOL replication works.
-
Lesson 2 Configure AD DS sites
- What are AD DS sites?
-
- Why implement additional sites?
-
- Demonstration: Configure AD DS sites
-
- How replication works between sites
-
- What is the intersite topology generator (ISTG)?
-
- Overview of SRV records
-
- How domain-joined computers locate DCs
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe AD DS sites.
-
- Explain reasons to implement additional sites.
-
- Configure additional AD DS sites.
-
- Describe how AD DS replication works between sites.
-
- Describe the intersite topology generator.
-
- Describe SRV resource records.
-
- Describe how domain-joined computers locate DCs.
-
- Explain how to move DCs between sites.
-
Lesson 3 Configure and monitor AD DS replication
- What are AD DS site links?
-
- What is site-link bridging?
-
- Manage site-link replication.
-
- Demonstration: Configure AD DS intersite replication.
-
- Tools for monitoring and managing replication.
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe AD DS site links.
-
- Explain the concept of site-link bridging.
-
- Describe how to manage intersite replication.
-
- Configure AD DS intersite replication.
-
- Describe the tools for monitoring and managing replication.
-
Lab 5 Implement AD DS sites and replication
- Modify the default site.
-
- Create additional sites and subnets.
-
- Configure AD DS replication.
-
- Monitor and troubleshoot AD DS replication.
-
By completing this lab, you’ll achieve the knowledge and skills to:
- Manage sites and subnets in AD DS.
-
- Configure replication options for AD DS.
-
- Monitor and troubleshoot replication.
-
By completing this module, you’ll achieve the knowledge and skills to:
- Understand how AD DS replication works.
-
- Configure AD DS sites to optimize authentication and replication traffic.
-
- Configure and monitor AD DS replication.
-
Module 5 Implement Group Policy
For organizations operating in an on-premises AD DS environment, Group Policy offers centralized management of both user and computer settings. This enables administrators to configure, enforce, and maintain their organization’s on-premises configuration. GPOs are linked to container objects such as sites, domains, and OUs. Users and computers placed in those containers inherit the applicable container’s settings. However, GPOs can be blocked, unlinked, or enforced to override the default application behavior. GPOs can also be filtered based on security-group membership and Windows Management Instrumentation (WMI) filters. When settings don’t apply as you expect, it’s important that you know how to investigate and resolve the issues.
Lesson 1 What is Group Policy?
- What is configuration management?
-
- Select a Group Policy management tool
-
- What are the benefits of Group Policy?
-
- What are GPOs?
-
- Manage GPO scope and inheritance
-
- What are the Group Policy Client service and client-side extensions?
-
- Implement GPOs in Azure AD DS
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe configuration management with Group Policy.
-
- Describe Group Policy tools.
-
- Describe the benefits of Group Policy.
-
- Describe GPOs.
-
- Explain GPO scope and inheritance.
-
- Describe the Group Policy Client service and client-side extensions (CSEs).
-
- Describe Group Policy in Azure AD DS..
-
Lesson 2 Implement and administer Group Policy
- Implement domain-based GPOs
-
- Understand GPO storage and replication
-
- What are Starter GPOs?
-
- Common GPO management tasks
-
- What is Group Policy delegation?
-
- Demonstration: Delegate Group Policy administration
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe domain-based GPOs.
-
- Describe GPO storage and replication.
-
- Describe Starter GPOs.
-
- Describe common GPO management tasks.
-
- Explain how to delegate administration of Group Policies.
-
- Delegate administration of Group Policy.
-
Lesson 3 Group Policy scope and processing
- Link GPOs to containers
-
- Understand Group Policy processing, inheritance, and precedence
-
- Implement security filtering and WMI filtering
-
- Demonstration: Filter Group Policy application
-
- Enable and disable GPOs and GPO nodes
-
- Implement loopback processing
-
- Manage slow links and disconnected systems
-
- Identify when settings become effective
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe GPO links.
-
- Describe Group Policy processing, inheritance, and precedence.
-
- Use security filtering and WMI filtering to modify Group Policy scope.
-
- Filter Group Policy application.
-
- Enable or disable GPOs and GPO nodes.
-
- Describe loopback-policy processing.
-
- Describe considerations for slow links and disconnected systems.
-
- Identify when settings become effective.
-
Lab 6 Implement a Group Policy infrastructure
- Creating and configuring GPOs.
-
- Managing GPO scope.
-
By completing this lab, you’ll achieve the knowledge and skills to:
- Create and configure GPOs.
-
- Manage scope for GPOs.
-
Lesson 4 Troubleshoot the application of GPOs
- What is Resultant Set of Policy (RSoP)?
-
- Demonstration: Generate RSoP reports
-
- Examine Group Policy event logs
-
- Detect issues with the health of GPOs
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe RSoP.
-
- Generate RSoP reports.
-
- Examine Group Policy event logs.
-
- Detect issues with the health of GPOs.
-
Lab 7 Troubleshoot Group Policy infrastructure
- Verify GPO application.
-
- Troubleshoot GPOs.
-
By completing this lab, you’ll achieve the knowledge and skills to:
- Verify when a GPO is applied.
-
- Troubleshoot a GPO.
-
Module 6 Manage user settings with Group Policy
You can use GPOs to create a standard desktop for the entire organization or on a departmental basis. You construct this standard desktop by using features such as administrative templates, Folder Redirection, and Group Policy preferences.
Lesson 1 Implement administrative templates
- What are administrative templates?
-
- Overview of the central store
-
- Demonstration: Configure settings with administrative templates
-
- Import security templates
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe administrative templates.
-
- Describe the central store.
-
- Configure settings with administrative templates.
-
- Import security templates.
-
Lesson 2 Configure Folder Redirection, software installation, and scripts
- What is Folder Redirection?
-
- Settings for configuring Folder Redirection
-
- Security settings for redirected folders
-
- Demonstration: Configure Folder Redirection
-
- Manage software with Group Policy.
-
- Group Policy settings for applying scripts.
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe Folder Redirection.
-
- Explain the Folder Redirection configuration settings.
-
- Explain security requirements for redirected folders.
-
- Configure Folder Redirection.
-
- Manage application software using Group Policy.
-
- Manage scripts using Group Policy.
-
Lesson 3 Configure Group Policy preferences
- What are Group Policy preferences?
-
- Compare Group Policy preferences with settings
-
- Features of Group Policy preferences
-
- Item-level targeting options
-
- Demonstration: Configure Group Policy preferences
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe Group Policy preferences.
-
- Compare Group Policy preferences with settings.
-
- Explain features of Group Policy preferences.
-
- Implement item-level targeting.
-
- Configure Group Policy preferences.
-
Lab 8 Manage user settings with Group Policy
- Use administrative templates to manage user settings.
-
- Implement settings by using Group Policy preferences.
-
- Configure Folder Redirection.
-
By completing this lab, you’ll achieve the knowledge and skills to:
- Use administrative templates for management of user settings.
-
- Use Group Policy preferences.
-
- Configure Folder Redirection by using Group Policy.
-
By completing this module, you’ll achieve the knowledge and skills to:
- Implement administrative templates.
-
- Configure Folder Redirection, software installation, and scripts.
-
- Configure Group Policy preferences.
-
Module 7 Secure AD DS
AD DS contains sensitive information about many parts of your IT infrastructure, such as users and their passwords. An issue with your AD DS security can result in data loss, data leakage, parts of your IT infrastructure being disabled, or even your entire IT infrastructure being compromised. As an AD DS administrator, you need to understand the potential threats to AD DS and how to mitigate them.
Lesson 1 Secure DCs
- What security risks can affect DCs?
-
- Modify security settings of DCs
-
- Implement secure authentication
-
- Secure physical access to DCs
-
- What are RODCs?
-
- Deploy an RODC
-
- Plan and configure an RODC password-replication policy
-
- Demonstration: Configure a password-replication policy
-
- Separate RODC local administration
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe the security risks that can affect DCs.
-
- Modify DC security settings.
-
- Explain how to implement secure authentication.
-
- Secure physical access to DCs.
-
- Describe RODCs.
-
- Deploy an RODC.
-
- Plan password replication for RODCs.
-
- Configure password replication for RODCs.
-
- Explain how to separate RODC local administration.
-
Lesson 2 Implement account security
- Account security in Windows Server
-
- Understand password policies, account lockout policies, and Kerberos authentication policies
-
- Demonstration: Configure domain account policies
-
- Protect groups in AD DS.
-
- Fine-grained password and lockout policies.
-
- Create and manage Password Settings objects (PSOs).
-
- Demonstration: Configure a fine-grained password policy
-
- Enhance password authentication with Windows Hello
-
- Options for securing accounts in Azure AD
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe account security in Windows Server.
-
- Explain password policies, account-lockout policies, and Kerberos authentication policies.
-
- Configure domain-account policies.
-
- Explain how to protect groups in AD DS.
-
- Describe fine-grained password and lockout policies.
-
- Create and manage PSOs.
-
- Configure a fine-grained password policy.
-
- Describe how to enhance password authentication with Windows Hello and the Microsoft Azure AD Multifactor Authentication (MFA) service.
-
- Explain options for securing accounts in Azure.
-
Lesson 3 Implement authentication auditing
- Account logon and logon events
-
- Demonstration: Configure authentication-related audit policies
-
- Scope audit policies
-
- Demonstration: Review logon events
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Meticulous content relevance, tailored to Windows Server 2022, sets it apart from competitive courses based primarily on previous versions.
-
- Content on obsolete technology, which is present in competitive versions of the course, has been removed.
-
- Includes a focused lesson on Entra ID and the comparison to AD DS.
-
- Offers an array of demonstrations that bolster the learning material.
-
- Expert instructional design ensures a superior learning experience.
-
- Labs are developed by Waypoint in parallel with courseware, so they are 100% aligned.
-
At Course Completion
By completing this course, you’ll achieve the knowledge and skills to:
- Deploy Active Directory services.
-
- Manage directory objects.
-
- Execute advanced Active Directory Domain Services (AD DS) infrastructure management.
-
- Implement and administer AD DS sites and replication.
-
- Implement Group Policy.
-
- Manage user settings with Group Policy.
-
- Secure AD DS.
-
- Deploy and manage Active Directory Certificate Services (AD CS).
-
- Deploy and manage certificates.
-
- Implement and administer Active Directory Federation Services (AD FS).
-
- Implement AD DS synchronization with Microsoft Entra ID.
-
- Monitor, manage, and recover AD DS​.
-
Course Details
Course Duration:Â 5 Days
Module 1 Deploy Active Directory services
Active Directory Domain Services (AD DS) is the cornerstone of on-premises networks for many organizations worldwide. AD DS delivers authentication and authorization by using domain controllers (DCs) for on-premises apps and services. In this module, you’ll learn how to configure DCs to suit your specific organizational needs, and integrate AD DS with Microsoft Azure Active Directory (Azure AD) to provide single sign-on (SSO) for users that access both on-premises and cloud-based apps.
Lesson 1 Components of AD DS
- What is an AD DS forest?
-
- What is an AD DS domain?
-
- What are organizational units (OUs)?
-
- What is the AD DS schema?
-
- Overview of AD DS administration tools
-
- Demonstration: Manage AD DS
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe AD DS forests.Â
-
- Describe AD DS domains.Â
-
- Describe OUs.Â
-
- Describe the AD DS schema.Â
-
- Select appropriate AD DS administration tools.Â
-
- Manage AD DS.Â
-
Lesson 2 AD DS DCs
- What is a DC?
-
- What are the global catalog servers?
-
- Overview of service (SRV) records
-
- Demonstration: Review SRV records in Domain Name System (DNS)
-
- How does the AD DS sign-in process work?
-
- Overview of operations masters
-
- Transfer and seize roles
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe the DC role.
-
- Describe global catalog servers.
-
- Describe SRV records.
-
- Review SRV records in DNS.
-
- Explain how the AD DS sign-in process works.
-
- Describe operations masters.
-
- Transfer and seize roles.
-
Lesson 3 Deploy AD DS DCs
- Install a DC from Server Manager
-
- Install a DC on a Server Core
-
- Upgrade a DC
-
- Install a DC from media
-
- Clone DCs
-
- Best practices for DC virtualization
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Install a DC.
-
- Install a DC on a Server Core.
-
- Upgrade a DC.
-
- Install a DC from media.
-
- Clone DCs.
-
- Describe best practices for DC virtualization.
-
Lesson 4 Azure AD overview
- What is Azure AD?
-
- How does Azure AD compare with AD DS?
-
- Azure AD editions
-
- Azure AD administration tools
-
- Azure AD Domain Services (Azure AD DS)
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe Azure AD.
-
- Compare Azure AD with AD DS.
-
- Describe available Azure AD editions.
-
- Explain the available Azure AD administration tools.
-
- Describe Azure AD DS.
-
Lab 1 Deploy and administer AD DS
- Deploy AD DS.
-
- Deploy DCs by performing DC cloning.
-
- Administer AD DS.
-
By completing this lab, you’ll achieve the knowledge and skills to:
- Deploy AD DS and DCs.
-
- Administer AD DS.
-
By completing this module, you’ll achieve the knowledge and skills to:
- Describe the AD DS components.
-
- Describe the role of DCs.
-
- Deploy DCs.
-
- Describe Azure AD.
-
Module 2 Manage directory objects
Active Directory, at its heart, is a hierarchical database. Unlike a traditional database, however, you can create many different types of records within Active Directory. These records are referred to as objects, which you can create to represent almost anything in your network, from users and groups to printers, shared folders, and computers.
Each object can have many different properties, referred to as attributes. For example, the user object type has attributes in which you can store the user’s sign-in name, and street and email addresses.
Not only does Active Directory allow you to store information about objects, but it also enables you to manage those objects. After you create objects, you can use AD DS to manage and control these objects, which you can group together in containers to easily apply policies to them.
Active Directory is a powerful tool to centrally manage your network. Large organizations might want to distribute management to different teams of administrators. Active Directory enables this by allowing a domain administrator to provide lower-level administrators access to specific objects and containers.
Lesson 1 Manage user accounts
- Create user accounts
-
- Demonstration: Manage user accounts
-
- Disable and delete user accounts
-
- Perform bulk operations on Active Directory objects
-
- Demonstration: Perform bulk operations in Active Directory Users and Computers
-
- User-account templates
-
- Demonstration: Use templates to create accounts
-
- Manage user objects in Azure AD
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Create and manage user accounts.
-
- Configure user attributes.
-
- Manage inactive and disabled user accounts.
-
- Create and manage user profiles.
-
- Use graphical tools to perform bulk operations.
-
- Manage user objects in Azure AD.
-
Lesson 2 Manage groups in AD DS
- Security and distribution groups
-
- Group scopes
-
- Implement group management (IGDLA)
-
- Delegate management of groups in Active Directory
-
- Restricted groups
-
- Default groups
-
- Special identities
-
- Demonstration: Manage groups in Windows Server
-
- Manage groups in Azure AD
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe group types and scopes.
-
- Understand the membership rules of each group scope.
-
- Delegate group management.
-
- Understand different methods to administer groups, including Group Policy.
-
- Understand default, special, and restricted groups.
-
Lesson 3 Manage computer objects in AD DS
- The default Computers container
-
- Create an OU structure for managing computer objects
-
- Control who can create computer objects
-
- Join a computer to a domain
-
- Computer accounts and secure channels
-
- Offline domain joins
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Understand the purpose of the Computers container.
-
- Configure the location of computer accounts.
-
- Control who has permission to create computer accounts.
-
- Join a computer to a domain.
-
- Join a computer to Azure AD to create a hybrid join.
-
- Describe computer accounts and secure channels.
-
- Reset the secure channel.
-
- Perform an offline domain join.
-
Lab 2 Manage AD DS objects
- Create and manage groups in AD DS.
-
- Create and configure user accounts in AD DS.
-
- Manage computer objects in AD DS.
-
By completing this lab, you’ll achieve the knowledge and skills to manage objects in AD DS.
Lesson 4 Administer AD DS by using PowerShell
- Use Windows PowerShell to manage user accounts
-
- Use PowerShell for bulk operations
-
- Demonstration: Use graphical tools to perform bulk operations
-
- Query objects with Windows PowerShell
-
- Use text files for bulk operations
-
- Demonstration: Perform bulk operations with Windows PowerShell
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Use PowerShell to manage user accounts.
-
- Use PowerShell to manage groups.
-
- Use PowerShell to manage computer accounts.
-
- Use PowerShell to manage OUs.
-
- Describe bulk operations.
-
- Use graphical tools to perform bulk operations.
-
- Use PowerShell to query objects.
-
- Use PowerShell to modify objects.
-
- Work with comma-separated value files (CSV files).
-
- Use PowerShell to perform bulk operations.
-
Lesson 5 Implement and manage OUs
- Plan OUs
-
- OU planning strategies
-
- Delegate administrative control
-
- Create OUs
-
- Manage permissions in Active Directory
-
- Demonstration: Delegate administrative permissions on an OU
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Plan OUs.
-
- Describe OU hierarchy considerations.
-
- Describe considerations for using OUs.
-
- Explain ADÂ DS permissions.
-
- Use OUs to delegate administration.
-
Lab 3 Administer Active Directory
- Delegate administration for OUs
-
- Create and modify AD DS objects with Windows PowerShell
-
By completing this lab, you’ll achieve the knowledge and skills to:
- Delegate administration in AD DS.
-
- Use PowerShell to manage AD DS objects.
-
By completing this module, you’ll achieve the knowledge and skills to:
- Manage user accounts.
-
- Manage group objects and understand the different types of groups.
-
- Manage computer objects.
-
- Manage containers, referred to as organizational units (OUs).
-
- Administer Active Directory by using GUI tools and Windows PowerShell.
-
Module 3 Advanced AD DS infrastructure management
This module describes key technologies that serve as the building blocks of more advanced AD DS environments and provides guidance about implementing and managing such environments.
Lesson 1 Overview of advanced AD DS deployments
- Overview of domain and forest boundaries
-
- Implementation of multiple domains and forests
-
- Deploy a DC in an Azure virtual machine (VM)
-
- Manage objects in complex AD DS deployments
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Understand the role of AD DS domains and forests in establishing security and administration boundaries.
-
- Identify scenarios in which having multiple AD DS domains is beneficial or required.
-
- Identify scenarios in which having multiple AD DS forests is beneficial or required.
-
- Understand considerations applicable to deploying AD DS DCs in Microsoft Azure VMs.
-
- Describe considerations applicable to managing users, groups, and computer objects in advanced AD DS deployments.
-
Lesson 2 Deploy a distributed AD DS environment
- AD DS domain and forest-functional levels
-
- Deploy new AD DS domains
-
- Demonstration: Install a DC in a new domain in an existing forest
-
- Upgrade and migrate AD DS domains
-
- Factors to consider when implementing complex AD DS environments
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Understand AD DS domain-functional levels.
-
- Understand AD DS forest-functional levels.
-
- Explain how to create a new AD DS domain.
-
- Install a DC in a new domain in an existing forest.
-
- Explain how to upgrade an AD DS environment.
-
- Explain how to migrate between AD DS environments.
-
- List factors to consider when implementing complex AD DS environments.
-
Lesson 3 Configure AD DS trusts
- Overview of AD DS trust types
-
- How do trusts work in a forest?
-
- How do trusts work between forests?
-
- Configure advanced AD DS trust settings
-
- Demonstration: Configure a forest trust
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Understand the trust types that you can configure in a multi-domain and multi-forest environment.
-
- Explain how trusts work in an AD DS forest.
-
- Explain how trusts work between AD DS forests.
-
- Describe how to configure advanced trust settings.
-
- Configure a forest trust.
-
Lab 4 Domain and trust management in AD DS
- Implement forest trusts.
-
- Implement child domains in AD DS.
-
By completing this lab, you’ll achieve the knowledge and skills to:
- Implement trust relationships in AD DS.
-
- Implement child domains in AD DS.
-
By completing this module, you’ll achieve the knowledge and skills to:
- Describe the technologies that are essential to implementing advanced AD DS environments.
-
- Deploy a distributed AD DS environment.
-
- Implement trusts in multi-domain and multi-forest AD DS environments.
-
Module 4 Implement and administer AD DS sites and replication
In this module, you’ll learn about the technical details of AD DS replication and how you can leverage that knowledge to optimize the design and implementation of AD DS environments that consist of multiple geographically distributed DCs.
Lesson 1 Overview of AD DS replication
- What are AD DS partitions?
-
- Characteristics of AD DS replication
-
- How AD DS replication works within a site
-
- Resolve replication conflicts
-
- How replication topology is generated
-
- How SYSVOL replication works
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe AD DS partitions.
-
- Describe characteristics of AD DS replication.
-
- Explain how AD DS replication works within a site.
-
- Explain how replication conflicts are resolved.
-
- Explain how replication topology is generated.
-
- Explain how SYSVOL replication works.
-
Lesson 2 Configure AD DS sites
- What are AD DS sites?
-
- Why implement additional sites?
-
- Demonstration: Configure AD DS sites
-
- How replication works between sites
-
- What is the intersite topology generator (ISTG)?
-
- Overview of SRV records
-
- How domain-joined computers locate DCs
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe AD DS sites.
-
- Explain reasons to implement additional sites.
-
- Configure additional AD DS sites.
-
- Describe how AD DS replication works between sites.
-
- Describe the intersite topology generator.
-
- Describe SRV resource records.
-
- Describe how domain-joined computers locate DCs.
-
- Explain how to move DCs between sites.
-
Lesson 3 Configure and monitor AD DS replication
- What are AD DS site links?
-
- What is site-link bridging?
-
- Manage site-link replication.
-
- Demonstration: Configure AD DS intersite replication.
-
- Tools for monitoring and managing replication.
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe AD DS site links.
-
- Explain the concept of site-link bridging.
-
- Describe how to manage intersite replication.
-
- Configure AD DS intersite replication.
-
- Describe the tools for monitoring and managing replication.
-
Lab 5 Implement AD DS sites and replication
- Modify the default site.
-
- Create additional sites and subnets.
-
- Configure AD DS replication.
-
- Monitor and troubleshoot AD DS replication.
-
By completing this lab, you’ll achieve the knowledge and skills to:
- Manage sites and subnets in AD DS.
-
- Configure replication options for AD DS.
-
- Monitor and troubleshoot replication.
-
By completing this module, you’ll achieve the knowledge and skills to:
- Understand how AD DS replication works.
-
- Configure AD DS sites to optimize authentication and replication traffic.
-
- Configure and monitor AD DS replication.
-
Module 5 Implement Group Policy
For organizations operating in an on-premises AD DS environment, Group Policy offers centralized management of both user and computer settings. This enables administrators to configure, enforce, and maintain their organization’s on-premises configuration. GPOs are linked to container objects such as sites, domains, and OUs. Users and computers placed in those containers inherit the applicable container’s settings. However, GPOs can be blocked, unlinked, or enforced to override the default application behavior. GPOs can also be filtered based on security-group membership and Windows Management Instrumentation (WMI) filters. When settings don’t apply as you expect, it’s important that you know how to investigate and resolve the issues.
Lesson 1 What is Group Policy?
- What is configuration management?
-
- Select a Group Policy management tool
-
- What are the benefits of Group Policy?
-
- What are GPOs?
-
- Manage GPO scope and inheritance
-
- What are the Group Policy Client service and client-side extensions?
-
- Implement GPOs in Azure AD DS
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe configuration management with Group Policy.
-
- Describe Group Policy tools.
-
- Describe the benefits of Group Policy.
-
- Describe GPOs.
-
- Explain GPO scope and inheritance.
-
- Describe the Group Policy Client service and client-side extensions (CSEs).
-
- Describe Group Policy in Azure AD DS..
-
Lesson 2 Implement and administer Group Policy
- Implement domain-based GPOs
-
- Understand GPO storage and replication
-
- What are Starter GPOs?
-
- Common GPO management tasks
-
- What is Group Policy delegation?
-
- Demonstration: Delegate Group Policy administration
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe domain-based GPOs.
-
- Describe GPO storage and replication.
-
- Describe Starter GPOs.
-
- Describe common GPO management tasks.
-
- Explain how to delegate administration of Group Policies.
-
- Delegate administration of Group Policy.
-
Lesson 3 Group Policy scope and processing
- Link GPOs to containers
-
- Understand Group Policy processing, inheritance, and precedence
-
- Implement security filtering and WMI filtering
-
- Demonstration: Filter Group Policy application
-
- Enable and disable GPOs and GPO nodes
-
- Implement loopback processing
-
- Manage slow links and disconnected systems
-
- Identify when settings become effective
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe GPO links.
-
- Describe Group Policy processing, inheritance, and precedence.
-
- Use security filtering and WMI filtering to modify Group Policy scope.
-
- Filter Group Policy application.
-
- Enable or disable GPOs and GPO nodes.
-
- Describe loopback-policy processing.
-
- Describe considerations for slow links and disconnected systems.
-
- Identify when settings become effective.
-
Lab 6 Implement a Group Policy infrastructure
- Creating and configuring GPOs.
-
- Managing GPO scope.
-
By completing this lab, you’ll achieve the knowledge and skills to:
- Create and configure GPOs.
-
- Manage scope for GPOs.
-
Lesson 4 Troubleshoot the application of GPOs
- What is Resultant Set of Policy (RSoP)?
-
- Demonstration: Generate RSoP reports
-
- Examine Group Policy event logs
-
- Detect issues with the health of GPOs
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe RSoP.
-
- Generate RSoP reports.
-
- Examine Group Policy event logs.
-
- Detect issues with the health of GPOs.
-
Lab 7 Troubleshoot Group Policy infrastructure
- Verify GPO application.
-
- Troubleshoot GPOs.
-
By completing this lab, you’ll achieve the knowledge and skills to:
- Verify when a GPO is applied.
-
- Troubleshoot a GPO.
-
Module 6 Manage user settings with Group Policy
You can use GPOs to create a standard desktop for the entire organization or on a departmental basis. You construct this standard desktop by using features such as administrative templates, Folder Redirection, and Group Policy preferences.
Lesson 1 Implement administrative templates
- What are administrative templates?
-
- Overview of the central store
-
- Demonstration: Configure settings with administrative templates
-
- Import security templates
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe administrative templates.
-
- Describe the central store.
-
- Configure settings with administrative templates.
-
- Import security templates.
-
Lesson 2 Configure Folder Redirection, software installation, and scripts
- What is Folder Redirection?
-
- Settings for configuring Folder Redirection
-
- Security settings for redirected folders
-
- Demonstration: Configure Folder Redirection
-
- Manage software with Group Policy.
-
- Group Policy settings for applying scripts.
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe Folder Redirection.
-
- Explain the Folder Redirection configuration settings.
-
- Explain security requirements for redirected folders.
-
- Configure Folder Redirection.
-
- Manage application software using Group Policy.
-
- Manage scripts using Group Policy.
-
Lesson 3 Configure Group Policy preferences
- What are Group Policy preferences?
-
- Compare Group Policy preferences with settings
-
- Features of Group Policy preferences
-
- Item-level targeting options
-
- Demonstration: Configure Group Policy preferences
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe Group Policy preferences.
-
- Compare Group Policy preferences with settings.
-
- Explain features of Group Policy preferences.
-
- Implement item-level targeting.
-
- Configure Group Policy preferences.
-
Lab 8 Manage user settings with Group Policy
- Use administrative templates to manage user settings.
-
- Implement settings by using Group Policy preferences.
-
- Configure Folder Redirection.
-
By completing this lab, you’ll achieve the knowledge and skills to:
- Use administrative templates for management of user settings.
-
- Use Group Policy preferences.
-
- Configure Folder Redirection by using Group Policy.
-
By completing this module, you’ll achieve the knowledge and skills to:
- Implement administrative templates.
-
- Configure Folder Redirection, software installation, and scripts.
-
- Configure Group Policy preferences.
-
Module 7 Secure AD DS
AD DS contains sensitive information about many parts of your IT infrastructure, such as users and their passwords. An issue with your AD DS security can result in data loss, data leakage, parts of your IT infrastructure being disabled, or even your entire IT infrastructure being compromised. As an AD DS administrator, you need to understand the potential threats to AD DS and how to mitigate them.
Lesson 1 Secure DCs
- What security risks can affect DCs?
-
- Modify security settings of DCs
-
- Implement secure authentication
-
- Secure physical access to DCs
-
- What are RODCs?
-
- Deploy an RODC
-
- Plan and configure an RODC password-replication policy
-
- Demonstration: Configure a password-replication policy
-
- Separate RODC local administration
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe the security risks that can affect DCs.
-
- Modify DC security settings.
-
- Explain how to implement secure authentication.
-
- Secure physical access to DCs.
-
- Describe RODCs.
-
- Deploy an RODC.
-
- Plan password replication for RODCs.
-
- Configure password replication for RODCs.
-
- Explain how to separate RODC local administration.
-
Lesson 2 Implement account security
- Account security in Windows Server
-
- Understand password policies, account lockout policies, and Kerberos authentication policies
-
- Demonstration: Configure domain account policies
-
- Protect groups in AD DS.
-
- Fine-grained password and lockout policies.
-
- Create and manage Password Settings objects (PSOs).
-
- Demonstration: Configure a fine-grained password policy
-
- Enhance password authentication with Windows Hello
-
- Options for securing accounts in Azure AD
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Describe account security in Windows Server.
-
- Explain password policies, account-lockout policies, and Kerberos authentication policies.
-
- Configure domain-account policies.
-
- Explain how to protect groups in AD DS.
-
- Describe fine-grained password and lockout policies.
-
- Create and manage PSOs.
-
- Configure a fine-grained password policy.
-
- Describe how to enhance password authentication with Windows Hello and the Microsoft Azure AD Multifactor Authentication (MFA) service.
-
- Explain options for securing accounts in Azure.
-
Lesson 3 Implement authentication auditing
- Account logon and logon events
-
- Demonstration: Configure authentication-related audit policies
-
- Scope audit policies
-
- Demonstration: Review logon events
-
By completing this lesson, you’ll achieve the knowledge and skills to:
- Deploy Active Directory services.
- Manage directory objects.
- Execute advanced Active Directory Domain Services (AD DS) infrastructure management.
- Implement and administer AD DS sites and replication.
- Implement Group Policy.
- Manage user settings with Group Policy.
- Secure AD DS.
- Deploy and manage Active Directory Certificate Services (AD CS).
- Deploy and manage certificates.
- Implement and administer Active Directory Federation Services (AD FS).
- Implement AD DS synchronization with Microsoft Entra ID.
- Monitor, manage, and recover AD DS​.
-
- What is an AD DS forest?
- What is an AD DS domain?
- What are organizational units (OUs)?
- What is the AD DS schema?
- Overview of AD DS administration tools
- Demonstration: Manage AD DS
-
- Describe AD DS forests.Â
- Describe AD DS domains.Â
- Describe OUs.Â
- Describe the AD DS schema.Â
- Select appropriate AD DS administration tools.Â
- Manage AD DS.Â
-
- What is a DC?
- What are the global catalog servers?
- Overview of service (SRV) records
- Demonstration: Review SRV records in Domain Name System (DNS)
- How does the AD DS sign-in process work?
- Overview of operations masters
- Transfer and seize roles
-
- Describe the DC role.
- Describe global catalog servers.
- Describe SRV records.
- Review SRV records in DNS.
- Explain how the AD DS sign-in process works.
- Describe operations masters.
- Transfer and seize roles.
-
- Install a DC from Server Manager
- Install a DC on a Server Core
- Upgrade a DC
- Install a DC from media
- Clone DCs
- Best practices for DC virtualization
-
- Install a DC.
- Install a DC on a Server Core.
- Upgrade a DC.
- Install a DC from media.
- Clone DCs.
- Describe best practices for DC virtualization.
-
- What is Azure AD?
- How does Azure AD compare with AD DS?
- Azure AD editions
- Azure AD administration tools
- Azure AD Domain Services (Azure AD DS)
-
- Describe Azure AD.
- Compare Azure AD with AD DS.
- Describe available Azure AD editions.
- Explain the available Azure AD administration tools.
- Describe Azure AD DS.
-
- Deploy AD DS.
- Deploy DCs by performing DC cloning.
- Administer AD DS.
-
- Deploy AD DS and DCs.
- Administer AD DS.
-
- Describe the AD DS components.
- Describe the role of DCs.
- Deploy DCs.
- Describe Azure AD.
-
- Create user accounts
- Demonstration: Manage user accounts
- Disable and delete user accounts
- Perform bulk operations on Active Directory objects
- Demonstration: Perform bulk operations in Active Directory Users and Computers
- User-account templates
- Demonstration: Use templates to create accounts
- Manage user objects in Azure AD
-
- Create and manage user accounts.
- Configure user attributes.
- Manage inactive and disabled user accounts.
- Create and manage user profiles.
- Use graphical tools to perform bulk operations.
- Manage user objects in Azure AD.
-
- Security and distribution groups
- Group scopes
- Implement group management (IGDLA)
- Delegate management of groups in Active Directory
- Restricted groups
- Default groups
- Special identities
- Demonstration: Manage groups in Windows Server
- Manage groups in Azure AD
-
- Describe group types and scopes.
- Understand the membership rules of each group scope.
- Delegate group management.
- Understand different methods to administer groups, including Group Policy.
- Understand default, special, and restricted groups.
-
- The default Computers container
- Create an OU structure for managing computer objects
- Control who can create computer objects
- Join a computer to a domain
- Computer accounts and secure channels
- Offline domain joins
-
- Understand the purpose of the Computers container.
- Configure the location of computer accounts.
- Control who has permission to create computer accounts.
- Join a computer to a domain.
- Join a computer to Azure AD to create a hybrid join.
- Describe computer accounts and secure channels.
- Reset the secure channel.
- Perform an offline domain join.
-
- Create and manage groups in AD DS.
- Create and configure user accounts in AD DS.
- Manage computer objects in AD DS.
-
- Use Windows PowerShell to manage user accounts
- Use PowerShell for bulk operations
- Demonstration: Use graphical tools to perform bulk operations
- Query objects with Windows PowerShell
- Use text files for bulk operations
- Demonstration: Perform bulk operations with Windows PowerShell
-
- Use PowerShell to manage user accounts.
- Use PowerShell to manage groups.
- Use PowerShell to manage computer accounts.
- Use PowerShell to manage OUs.
- Describe bulk operations.
- Use graphical tools to perform bulk operations.
- Use PowerShell to query objects.
- Use PowerShell to modify objects.
- Work with comma-separated value files (CSV files).
- Use PowerShell to perform bulk operations.
-
- Plan OUs
- OU planning strategies
- Delegate administrative control
- Create OUs
- Manage permissions in Active Directory
- Demonstration: Delegate administrative permissions on an OU
-
- Plan OUs.
- Describe OU hierarchy considerations.
- Describe considerations for using OUs.
- Explain ADÂ DS permissions.
- Use OUs to delegate administration.
-
- Delegate administration for OUs
- Create and modify AD DS objects with Windows PowerShell
-
- Delegate administration in AD DS.
- Use PowerShell to manage AD DS objects.
-
- Manage user accounts.
- Manage group objects and understand the different types of groups.
- Manage computer objects.
- Manage containers, referred to as organizational units (OUs).
- Administer Active Directory by using GUI tools and Windows PowerShell.
-
- Overview of domain and forest boundaries
- Implementation of multiple domains and forests
- Deploy a DC in an Azure virtual machine (VM)
- Manage objects in complex AD DS deployments
-
- Understand the role of AD DS domains and forests in establishing security and administration boundaries.
- Identify scenarios in which having multiple AD DS domains is beneficial or required.
- Identify scenarios in which having multiple AD DS forests is beneficial or required.
- Understand considerations applicable to deploying AD DS DCs in Microsoft Azure VMs.
- Describe considerations applicable to managing users, groups, and computer objects in advanced AD DS deployments.
-
- AD DS domain and forest-functional levels
- Deploy new AD DS domains
- Demonstration: Install a DC in a new domain in an existing forest
- Upgrade and migrate AD DS domains
- Factors to consider when implementing complex AD DS environments
-
- Understand AD DS domain-functional levels.
- Understand AD DS forest-functional levels.
- Explain how to create a new AD DS domain.
- Install a DC in a new domain in an existing forest.
- Explain how to upgrade an AD DS environment.
- Explain how to migrate between AD DS environments.
- List factors to consider when implementing complex AD DS environments.
-
- Overview of AD DS trust types
- How do trusts work in a forest?
- How do trusts work between forests?
- Configure advanced AD DS trust settings
- Demonstration: Configure a forest trust
-
- Understand the trust types that you can configure in a multi-domain and multi-forest environment.
- Explain how trusts work in an AD DS forest.
- Explain how trusts work between AD DS forests.
- Describe how to configure advanced trust settings.
- Configure a forest trust.
-
- Implement forest trusts.
- Implement child domains in AD DS.
-
- Implement trust relationships in AD DS.
- Implement child domains in AD DS.
-
- Describe the technologies that are essential to implementing advanced AD DS environments.
- Deploy a distributed AD DS environment.
- Implement trusts in multi-domain and multi-forest AD DS environments.
-
- What are AD DS partitions?
- Characteristics of AD DS replication
- How AD DS replication works within a site
- Resolve replication conflicts
- How replication topology is generated
- How SYSVOL replication works
-
- Describe AD DS partitions.
- Describe characteristics of AD DS replication.
- Explain how AD DS replication works within a site.
- Explain how replication conflicts are resolved.
- Explain how replication topology is generated.
- Explain how SYSVOL replication works.
-
- What are AD DS sites?
- Why implement additional sites?
- Demonstration: Configure AD DS sites
- How replication works between sites
- What is the intersite topology generator (ISTG)?
- Overview of SRV records
- How domain-joined computers locate DCs
-
- Describe AD DS sites.
- Explain reasons to implement additional sites.
- Configure additional AD DS sites.
- Describe how AD DS replication works between sites.
- Describe the intersite topology generator.
- Describe SRV resource records.
- Describe how domain-joined computers locate DCs.
- Explain how to move DCs between sites.
-
- What are AD DS site links?
- What is site-link bridging?
- Manage site-link replication.
- Demonstration: Configure AD DS intersite replication.
- Tools for monitoring and managing replication.
-
- Describe AD DS site links.
- Explain the concept of site-link bridging.
- Describe how to manage intersite replication.
- Configure AD DS intersite replication.
- Describe the tools for monitoring and managing replication.
-
- Modify the default site.
- Create additional sites and subnets.
- Configure AD DS replication.
- Monitor and troubleshoot AD DS replication.
-
- Manage sites and subnets in AD DS.
- Configure replication options for AD DS.
- Monitor and troubleshoot replication.
-
- Understand how AD DS replication works.
- Configure AD DS sites to optimize authentication and replication traffic.
- Configure and monitor AD DS replication.
-
- What is configuration management?
- Select a Group Policy management tool
- What are the benefits of Group Policy?
- What are GPOs?
- Manage GPO scope and inheritance
- What are the Group Policy Client service and client-side extensions?
- Implement GPOs in Azure AD DS
-
- Describe configuration management with Group Policy.
- Describe Group Policy tools.
- Describe the benefits of Group Policy.
- Describe GPOs.
- Explain GPO scope and inheritance.
- Describe the Group Policy Client service and client-side extensions (CSEs).
- Describe Group Policy in Azure AD DS..
-
- Implement domain-based GPOs
- Understand GPO storage and replication
- What are Starter GPOs?
- Common GPO management tasks
- What is Group Policy delegation?
- Demonstration: Delegate Group Policy administration
-
- Describe domain-based GPOs.
- Describe GPO storage and replication.
- Describe Starter GPOs.
- Describe common GPO management tasks.
- Explain how to delegate administration of Group Policies.
- Delegate administration of Group Policy.
-
- Link GPOs to containers
- Understand Group Policy processing, inheritance, and precedence
- Implement security filtering and WMI filtering
- Demonstration: Filter Group Policy application
- Enable and disable GPOs and GPO nodes
- Implement loopback processing
- Manage slow links and disconnected systems
- Identify when settings become effective
-
- Describe GPO links.
- Describe Group Policy processing, inheritance, and precedence.
- Use security filtering and WMI filtering to modify Group Policy scope.
- Filter Group Policy application.
- Enable or disable GPOs and GPO nodes.
- Describe loopback-policy processing.
- Describe considerations for slow links and disconnected systems.
- Identify when settings become effective.
-
- Creating and configuring GPOs.
- Managing GPO scope.
-
- Create and configure GPOs.
- Manage scope for GPOs.
-
- What is Resultant Set of Policy (RSoP)?
- Demonstration: Generate RSoP reports
- Examine Group Policy event logs
- Detect issues with the health of GPOs
-
- Describe RSoP.
- Generate RSoP reports.
- Examine Group Policy event logs.
- Detect issues with the health of GPOs.
-
- Verify GPO application.
- Troubleshoot GPOs.
-
- Verify when a GPO is applied.
- Troubleshoot a GPO.
-
- What are administrative templates?
- Overview of the central store
- Demonstration: Configure settings with administrative templates
- Import security templates
-
- Describe administrative templates.
- Describe the central store.
- Configure settings with administrative templates.
- Import security templates.
-
- What is Folder Redirection?
- Settings for configuring Folder Redirection
- Security settings for redirected folders
- Demonstration: Configure Folder Redirection
- Manage software with Group Policy.
- Group Policy settings for applying scripts.
-
- Describe Folder Redirection.
- Explain the Folder Redirection configuration settings.
- Explain security requirements for redirected folders.
- Configure Folder Redirection.
- Manage application software using Group Policy.
- Manage scripts using Group Policy.
-
- What are Group Policy preferences?
- Compare Group Policy preferences with settings
- Features of Group Policy preferences
- Item-level targeting options
- Demonstration: Configure Group Policy preferences
-
- Describe Group Policy preferences.
- Compare Group Policy preferences with settings.
- Explain features of Group Policy preferences.
- Implement item-level targeting.
- Configure Group Policy preferences.
-
- Use administrative templates to manage user settings.
- Implement settings by using Group Policy preferences.
- Configure Folder Redirection.
-
- Use administrative templates for management of user settings.
- Use Group Policy preferences.
- Configure Folder Redirection by using Group Policy.
-
- Implement administrative templates.
- Configure Folder Redirection, software installation, and scripts.
- Configure Group Policy preferences.
-
- What security risks can affect DCs?
- Modify security settings of DCs
- Implement secure authentication
- Secure physical access to DCs
- What are RODCs?
- Deploy an RODC
- Plan and configure an RODC password-replication policy
- Demonstration: Configure a password-replication policy
- Separate RODC local administration
-
- Describe the security risks that can affect DCs.
- Modify DC security settings.
- Explain how to implement secure authentication.
- Secure physical access to DCs.
- Describe RODCs.
- Deploy an RODC.
- Plan password replication for RODCs.
- Configure password replication for RODCs.
- Explain how to separate RODC local administration.
-
- Account security in Windows Server
- Understand password policies, account lockout policies, and Kerberos authentication policies
- Demonstration: Configure domain account policies
- Protect groups in AD DS.
- Fine-grained password and lockout policies.
- Create and manage Password Settings objects (PSOs).
- Demonstration: Configure a fine-grained password policy
- Enhance password authentication with Windows Hello
- Options for securing accounts in Azure AD
-
- Describe account security in Windows Server.
- Explain password policies, account-lockout policies, and Kerberos authentication policies.
- Configure domain-account policies.
- Explain how to protect groups in AD DS.
- Describe fine-grained password and lockout policies.
- Create and manage PSOs.
- Configure a fine-grained password policy.
- Describe how to enhance password authentication with Windows Hello and the Microsoft Azure AD Multifactor Authentication (MFA) service.
- Explain options for securing accounts in Azure.
-
- Account logon and logon events
- Demonstration: Configure authentication-related audit policies
- Scope audit policies
- Demonstration: Review logon events
-
By completing this lesson, you’ll achieve the knowledge and skills to:
Lesson 3 Implement authentication auditing
By completing this lesson, you’ll achieve the knowledge and skills to:
Lesson 2 Implement account security
By completing this lesson, you’ll achieve the knowledge and skills to:
Module 7 Secure AD DS
AD DS contains sensitive information about many parts of your IT infrastructure, such as users and their passwords. An issue with your AD DS security can result in data loss, data leakage, parts of your IT infrastructure being disabled, or even your entire IT infrastructure being compromised. As an AD DS administrator, you need to understand the potential threats to AD DS and how to mitigate them.
Lesson 1 Secure DCs
By completing this module, you’ll achieve the knowledge and skills to:
By completing this lab, you’ll achieve the knowledge and skills to:
Lab 8 Manage user settings with Group Policy
By completing this lesson, you’ll achieve the knowledge and skills to:
Lesson 3 Configure Group Policy preferences
By completing this lesson, you’ll achieve the knowledge and skills to:
Lesson 2 Configure Folder Redirection, software installation, and scripts
By completing this lesson, you’ll achieve the knowledge and skills to:
Module 6 Manage user settings with Group Policy
You can use GPOs to create a standard desktop for the entire organization or on a departmental basis. You construct this standard desktop by using features such as administrative templates, Folder Redirection, and Group Policy preferences.
Lesson 1 Implement administrative templates
By completing this lab, you’ll achieve the knowledge and skills to:
Lab 7 Troubleshoot Group Policy infrastructure
By completing this lesson, you’ll achieve the knowledge and skills to:
Lesson 4 Troubleshoot the application of GPOs
By completing this lab, you’ll achieve the knowledge and skills to:
Lab 6 Implement a Group Policy infrastructure
By completing this lesson, you’ll achieve the knowledge and skills to:
Lesson 3 Group Policy scope and processing
By completing this lesson, you’ll achieve the knowledge and skills to:
Lesson 2 Implement and administer Group Policy
By completing this lesson, you’ll achieve the knowledge and skills to:
Module 5 Implement Group Policy
For organizations operating in an on-premises AD DS environment, Group Policy offers centralized management of both user and computer settings. This enables administrators to configure, enforce, and maintain their organization’s on-premises configuration. GPOs are linked to container objects such as sites, domains, and OUs. Users and computers placed in those containers inherit the applicable container’s settings. However, GPOs can be blocked, unlinked, or enforced to override the default application behavior. GPOs can also be filtered based on security-group membership and Windows Management Instrumentation (WMI) filters. When settings don’t apply as you expect, it’s important that you know how to investigate and resolve the issues.
Lesson 1 What is Group Policy?
By completing this module, you’ll achieve the knowledge and skills to:
By completing this lab, you’ll achieve the knowledge and skills to:
Lab 5 Implement AD DS sites and replication
By completing this lesson, you’ll achieve the knowledge and skills to:
Lesson 3 Configure and monitor AD DS replication
By completing this lesson, you’ll achieve the knowledge and skills to:
Lesson 2 Configure AD DS sites
By completing this lesson, you’ll achieve the knowledge and skills to:
Module 4 Implement and administer AD DS sites and replication
In this module, you’ll learn about the technical details of AD DS replication and how you can leverage that knowledge to optimize the design and implementation of AD DS environments that consist of multiple geographically distributed DCs.
Lesson 1 Overview of AD DS replication
By completing this module, you’ll achieve the knowledge and skills to:
By completing this lab, you’ll achieve the knowledge and skills to:
Lab 4 Domain and trust management in AD DS
By completing this lesson, you’ll achieve the knowledge and skills to:
Lesson 3 Configure AD DS trusts
By completing this lesson, you’ll achieve the knowledge and skills to:
Lesson 2 Deploy a distributed AD DS environment
By completing this lesson, you’ll achieve the knowledge and skills to:
Module 3 Advanced AD DS infrastructure management
This module describes key technologies that serve as the building blocks of more advanced AD DS environments and provides guidance about implementing and managing such environments.
Lesson 1 Overview of advanced AD DS deployments
By completing this module, you’ll achieve the knowledge and skills to:
By completing this lab, you’ll achieve the knowledge and skills to:
Lab 3 Administer Active Directory
By completing this lesson, you’ll achieve the knowledge and skills to:
Lesson 5 Implement and manage OUs
By completing this lesson, you’ll achieve the knowledge and skills to:
By completing this lab, you’ll achieve the knowledge and skills to manage objects in AD DS.
Lesson 4 Administer AD DS by using PowerShell
Lab 2 Manage AD DS objects
By completing this lesson, you’ll achieve the knowledge and skills to:
Lesson 3 Manage computer objects in AD DS
By completing this lesson, you’ll achieve the knowledge and skills to:
Lesson 2 Manage groups in AD DS
By completing this lesson, you’ll achieve the knowledge and skills to:
Module 2 Manage directory objects
Active Directory, at its heart, is a hierarchical database. Unlike a traditional database, however, you can create many different types of records within Active Directory. These records are referred to as objects, which you can create to represent almost anything in your network, from users and groups to printers, shared folders, and computers.
Each object can have many different properties, referred to as attributes. For example, the user object type has attributes in which you can store the user’s sign-in name, and street and email addresses.
Not only does Active Directory allow you to store information about objects, but it also enables you to manage those objects. After you create objects, you can use AD DS to manage and control these objects, which you can group together in containers to easily apply policies to them.
Active Directory is a powerful tool to centrally manage your network. Large organizations might want to distribute management to different teams of administrators. Active Directory enables this by allowing a domain administrator to provide lower-level administrators access to specific objects and containers.
Lesson 1 Manage user accounts
By completing this module, you’ll achieve the knowledge and skills to:
By completing this lab, you’ll achieve the knowledge and skills to:
Lab 1 Deploy and administer AD DS
By completing this lesson, you’ll achieve the knowledge and skills to:
Lesson 4 Azure AD overview
By completing this lesson, you’ll achieve the knowledge and skills to:
Lesson 3 Deploy AD DS DCs
By completing this lesson, you’ll achieve the knowledge and skills to:
Lesson 2 AD DS DCs
By completing this lesson, you’ll achieve the knowledge and skills to:
Course Details
Course Duration:Â 5 Days
Module 1 Deploy Active Directory services
Active Directory Domain Services (AD DS) is the cornerstone of on-premises networks for many organizations worldwide. AD DS delivers authentication and authorization by using domain controllers (DCs) for on-premises apps and services. In this module, you’ll learn how to configure DCs to suit your specific organizational needs, and integrate AD DS with Microsoft Azure Active Directory (Azure AD) to provide single sign-on (SSO) for users that access both on-premises and cloud-based apps.
Lesson 1 Components of AD DS
At Course Completion
By completing this course, you’ll achieve the knowledge and skills to:
At Course Completion
By completing this course, you’ll achieve the knowledge and skills to:
By completing this course, you’ll achieve the knowledge and skills to: