Deploy and manage AD DS
- Deploy and manage domain controllers on-premises and in Azure, read-only domain controllers (RODCs) and their account security
- Manage FSMO roles and troubleshoot issues with them
- Multi-site, multi-domain and multi-forest environments: trusts, AD DS sites and replication
- Manage users, groups and service accounts, including across multiple domains and forests
- Control Windows Server with Group Policy and Group Policy Preferences
Manage Windows Server and workloads in hybrid environments
- Deploy and use Windows Admin Center on-premises and in the Azure portal
- Remote management with PowerShell including double-hop and Just Enough Administration (JEA), SSH and Remote Desktop
- Connect servers with Azure Arc, device configuration via Azure Arc and VM extensions on non-Azure machines
- Manage updates with Azure Update Manager, create and run Azure Automation runbooks
Manage virtual machines
- Hyper-V: enhanced session mode, remote management with PowerShell Direct and SSH Direct, nested virtualisation
- Configure memory, integration services, device assignment and GPU partitioning
- Manage checkpoints, virtual hard disks, network adapters, NIC teaming and virtual switches
- Set up high availability and Hyper-V Replica
- Windows Server VMs in Azure: storage, capacity and scale sets, availability sets and zones, just-in-time access, Azure Bastion and network configuration
On-premises and hybrid network infrastructure
- Integrate DNS with AD DS, zones and records, forwarders and conditional forwarders
- Name resolution in hybrid environments, DNS policies and DNSSEC
- DHCP server role, scopes, reservations and high availability
- Troubleshoot IP addressing issues in hybrid environments
Storage and file services
- Azure Files: file shares and permissions, set up and monitor Azure File Sync, migration from DFS and file shares
- Windows Server file shares, File Server Resource Manager (FSRM), DFS, SMB over QUIC and SMB settings
- Disks and volumes, Storage Spaces, Storage Spaces Direct and Storage Replica
- Data deduplication, SMB Direct, Storage QoS, NTFS and ReFS, and iSCSI
- Manage BitLocker drive encryption and recover encrypted volumes
Secure Windows Server infrastructure
- Harden the operating system: exploit protection, Application Control for Windows, Credential Guard and Microsoft Defender SmartScreen
- Security via Group Policy, security baseline with OSConfig and Windows LAPS
- Defender for Servers and Windows Firewall including connection security rules
- Secure AD DS: password policies, Microsoft Entra Password Protection, protected users, hardening and access restriction for domain controllers
- Delegation, security options for accounts and administrative groups, authentication protocols and methods
Monitor Windows Server environments and troubleshoot
- Monitoring with Performance Monitor, data collector sets, Windows Admin Center, System Insights and event logs
- Data collection rules and alerts in Azure Monitor, VM Insights
- Troubleshoot connectivity, name resolution, Windows Update, time service, performance, VM and Azure Arc extensions, disk encryption and storage
- Recover Active Directory: AD Recycle Bin, Directory Services Restore Mode and SYSVOL
- Analyse replication, Kerberos, authentication, secure channel and computer account trusts