Planning and installing Windows Server 2025
- Standard, Datacenter and Datacenter: Azure Edition editions, Server Core and Server with Desktop Experience installation options
- Installing from media and unattended installation with an answer file, direct upgrade from Windows Server 2012 R2
- Activation with KMS and automatic VM activation, overview of pay-as-you-go licensing via Azure Arc
- Initial configuration with SConfig and settings: name, network, domain join, updates
Managing servers
- Server Manager, Remote Server Administration Tools (RSAT) and Windows Admin Center
- Windows PowerShell and PowerShell remoting, Windows Terminal and WinGet
- Enabling the OpenSSH server (installed by default) and controlling access via the «OpenSSH Users» group
- Installing roles, features and Features on Demand
Setting up Active Directory Domain Services
- Installing domain controllers, new forest with the Windows Server 2025 functional level
- Managing users, groups, computer accounts and organizational units, delegating administration
- Managing AD DS with Active Directory Administrative Center and PowerShell, automating bulk changes
- Using group managed service accounts (gMSA) for services
Group Policy
- Creating, linking and filtering Group Policy Objects; processing, inheritance and troubleshooting
- Central store for administrative templates
- Distributing security settings and password policies via Group Policy
- Managing local administrator passwords with Windows LAPS
Network services
- Configuring IPv4 and IPv6, checking connections and troubleshooting with PowerShell
- DNS servers: Active Directory-integrated zones, records, forwarders, verifying name resolution
- DHCP servers: authorisation, scopes, options and reservations
Storage and file services
- Managing disks and volumes, NTFS and ReFS, Storage Spaces
- File servers: SMB shares, share and NTFS permissions, shadow copies
- SMB security in Windows Server 2025: signing required by default for outbound connections, more restrictive firewall rules for shares
- Overview of iSCSI target servers and data deduplication
Securing servers
- Microsoft Defender Antivirus and Windows Defender Firewall with Advanced Security
- Credential Guard, active by default on suitable hardware
- Applying a security baseline with OSConfig, BitLocker drive encryption
Hyper-V fundamentals
- Installing the Hyper-V role, creating virtual switches
- Creating Generation 2 virtual machines, using checkpoints
Updates, monitoring and backup
- Controlling Windows Update, overview of Windows Server Update Services (no longer being developed further) and Azure Update Manager
- Event Viewer, Performance Monitor, Resource Monitor and Task Manager
- Windows Server Backup: volumes, system state and bare-metal recovery