Deploying and managing AD DS
- Deploy and manage domain controllers on-premises and in Azure, including read-only domain controllers (RODC) and account security
- Manage FSMO roles and troubleshoot issues
- Environments with multiple sites, domains and forests: trusts, AD DS sites and replication
- Manage users and groups, including across domains and forests; select and manage service accounts
- Manage Windows Server with domain-based Group Policy and Group Policy Preferences
Managing Windows Server in hybrid environments
- Deploy and manage Windows Admin Center on-premises and in the Azure portal
- Remote management with PowerShell, including double-hop and Just Enough Administration (JEA), via SSH and Remote Desktop
- Connect servers with Azure Arc, device configuration via Azure Arc, deploy Azure services via VM extensions on machines outside Azure
- Manage updates with Azure Update Manager, create and run runbooks in Azure Automation
Managing virtual machines
- Hyper-V: enhanced session mode, remote management with PowerShell, PowerShell Direct and SSH Direct for Linux guests, nested virtualisation
- VM settings: memory, integration services, device assignment, GPU partitioning, checkpoints and virtual hard disks
- Networking in Hyper-V: network adapters, NIC teaming on host and VM, virtual switches
- High availability for Hyper-V VMs and Hyper-V Replica
- Windows Server VMs in Azure: storage, resizing and VM scale sets, availability sets and zones, just-in-time VM access and Azure Bastion, network configuration
On-premises and hybrid network infrastructure
- Integrate DNS with AD DS, manage zones and records, forwarders and conditional forwarders
- Name resolution in hybrid environments, DNS policies and DNSSEC
- DHCP server role: scopes, reservations and high availability
- Troubleshoot IP addressing issues in hybrid environments
Managing storage and file services
- Azure Files: file shares and permissions, set up and monitor Azure File Sync, migrate DFS and file shares to Azure
- File shares on Windows Server: access, File Server Resource Manager (FSRM), DFS, SMB over QUIC and SMB settings
- Disks and volumes, Storage Spaces and Storage Spaces Direct, Storage Replica, data deduplication
- SMB Direct (SMB over RDMA), Storage QoS, NTFS and ReFS file systems, iSCSI
- Manage BitLocker drive encryption, recover encrypted volumes
Securing Windows Server infrastructure
- Harden the operating system: exploit protection, Application Control for Windows, Credential Guard, Microsoft Defender SmartScreen, security settings via Group Policy
- Manage the security baseline with OSConfig, deploy Windows LAPS, configure Defender for Servers, Windows Firewall including connection security rules
- Secure AD DS: password policies, Microsoft Entra Password Protection for AD DS, the «Protected Users» group
- Harden domain controllers and restrict access to them, security options for user accounts and built-in administrator groups, delegation in AD
- Manage authentication protocols and methods for AD DS
Monitoring and troubleshooting Windows Server environments
- Monitor with Performance Monitor and Data Collector Sets, Windows Admin Center with alerts, System Insights and event logs
- Azure Monitor: data collection rules, alerts, performance of Azure VMs with VM Insights
- Troubleshoot connectivity, name resolution, Windows Update, time service, performance, storage and disk encryption, as well as VM and Azure Arc extensions
- Restore Active Directory: objects from the AD Recycle Bin, the AD database in Directory Services Restore Mode (DSRM), SYSVOL
- Troubleshoot AD replication, Kerberos and authentication issues, as well as the secure channel and computer accounts