Advanced AD DS infrastructure
- Planning multiple domains and forests, setting up trusts
- Configuring and monitoring sites, site links and replication, adjusting replication priority
- Read-only domain controllers (RODC) for branch offices
- Windows Server 2025 functional level and optional 32k database pages, planning domain controller upgrades
- Backing up and restoring Active Directory, the Active Directory Recycle Bin
Securing identities and authentication
- Hardening Kerberos: retiring RC4, setting encryption types via Group Policy
- Identifying and reducing NTLM usage, blocking NTLM for SMB
- LDAP signing, channel binding and LDAP over TLS 1.3
- Delegated managed service accounts (dMSA) and group managed service accounts (gMSA)
- Protected Users, authentication policies and silos for privileged accounts
Public key infrastructure with AD CS
- Planning PKI: offline root certification authority and subordinate enterprise certification authorities
- Configuring certificate templates securely, autoenrollment
- Revocation with certificate revocation lists and the Online Responder, key archival and recovery
Advanced networking and remote access services
- DNS: conditional forwarders, DNS policies and DNSSEC
- DHCP failover and IP Address Management (IPAM)
- VPN with Routing and RAS via IKEv2 and SSTP (PPTP and L2TP disabled by default on new installations), Network Policy Server (NPS) as RADIUS
Advanced file and storage services
- DFS namespaces and DFS Replication
- File Server Resource Manager: quotas, file screening and classification
- SMB over QUIC in all editions with client access control, SMB encryption, alternative SMB ports
- Storage Replica with compression, Storage Migration Service for retiring old file servers
High availability with failover clustering
- Planning and validating clusters, quorum and witnesses (disk, file share, cloud)
- Highly available file servers and Scale-Out File Servers, Cluster-Aware Updating
- Storage Spaces Direct (Datacenter) with thin provisioning, stretch clusters across sites
- Network Load Balancing (NLB) is deprecated: assessing alternatives
Hybrid identity and management
- Connecting Active Directory to Microsoft Entra ID: comparing Microsoft Entra Connect Sync and Microsoft Entra Cloud Sync
- Connecting servers with Azure Arc setup, Windows Admin Center in Azure, Azure Update Manager and hotpatching
- Overview of disaster recovery with Azure Site Recovery