certslothcertsloth
← AZ-802 overview

Windows Server Administrator Associate / STUDY TOOLS

AZ-802 quick review

AZ-800 and AZ-801 retired on 30 September 2026. AZ-802 is the replacement exam; this is not a combined legacy two-exam checklist.

Memory hook: Directory, guest, network, storage: diagnose each layer.

Reviewed 10 October 2026. Read this once, then answer the last-pass checks without looking.

Scope/version: AZ-800 and AZ-801 retired on 30 September 2026. AZ-802 is the replacement exam; this is not a combined legacy two-exam checklist.

Must remember by domain

Domain Rapid revision
AD DS DNS/SRV records locate DCs; sites/subnets guide locality; replication shares directory changes. Schema Master and Domain Naming Master are forest roles; RID Master, PDC Emulator and Infrastructure Master are per-domain roles. Transfer for planned work; seize only under safe recovery rules. RODC password replication policy limits cached credentials.
Directory administration Use AGDLP within suitable domain designs: accounts → global groups → domain-local groups → permissions; universal groups help appropriate multi-domain nesting. Trust authentication does not grant resource access. gMSAs automate supported service passwords. GPO normally processes local → site → domain → OU; filtering, enforcement and inheritance alter the result.
Hybrid management Windows Admin Center is a management gateway; PowerShell remoting provides remote commands; JEA narrows allowed administration. Double-hop requires an appropriate constrained authentication design. Arc registers non-Azure machines for supported extensions/configuration; Update Manager schedules updates; runbooks automate work.
Virtual machines External vSwitch reaches a physical network; internal connects host/guests; private connects guests only. PowerShell Direct uses the host path for supported guests. Standard checkpoints capture state; production checkpoints use supported data-consistency mechanisms. Replica is asynchronous DR; clustering addresses host availability. Azure VM disks/zones/scale sets need their own design.
Networking AD-integrated zones replicate through AD. Forwarders resolve general misses; conditional forwarders target namespaces. DNSSEC validates signed responses, not encryption. DHCP scope/options, exclusions, reservations and failover solve different needs; relay crosses routed broadcast boundaries.
Files/storage Effective network file access needs share and NTFS rights. DFS Namespace locates; DFS Replication copies. File Sync caches/synchronizes supported file data with Azure Files. FSRM quotas/screens/classification are not ACLs. SMB over QUIC secures supported remote SMB; SMB Direct uses RDMA. Storage Spaces, S2D and Storage Replica are distinct pooling/cluster/replication tools.
Security Credential Guard protects supported credential material; LAPS rotates local admin credentials; BitLocker encrypts volumes. Secure recovery keys separately. Baselines/OSConfig, application control, Firewall, Defender and protected-user/AD delegation controls require effective-policy validation. Fine-grained password policy targets users/global security groups, not OUs directly.
Monitoring/recovery PerfMon measures counters; events explain failures; DCR/AMA routes guest telemetry. Diagnose AD with DNS, time, secure channel, dcdiag and repadmin. Recycle Bin restores eligible deleted objects; DSRM/system-state and SYSVOL recovery handle deeper failures. A checkpoint is not an independent backup.

Troubleshooting sequence

For domain sign-in: IP/DNS → time → DC discovery → authentication/secure channel → replication → policy/resource permissions. For slow files: client path → share/NTFS permissions → storage latency → locks/sync/recall → network. Gather evidence before resetting trust or seizing roles.

Last-pass self-check

1. Which FSMO role is associated with domain time/password-change coordination?

The PDC Emulator; the forest-root PDC typically anchors the domain time hierarchy.

2. A trusts B: what does that establish?

B identities can be authenticated for access toward A, subject to trust configuration and A resource authorization.

3. Does DFS Namespace replicate files?

No. DFS Replication or another data replication mechanism handles copying.

4. Can DNSSEC hide a DNS query?

No. It provides validation of signed data, not confidentiality.

5. Which check shows actually applied GPO settings?

gpresult/Resultant Set of Policy, including filtering and inheritance effects.

Sources

Every topic at a glance

Open any topic to revisit its essential facts, decisions and exam traps. Use the full topic for active recall and supporting references.

01 · Active Directory and Group Policy

Memory hook: DNS locates; replication shares; policy configures.

Must remember

  • AD DS stores domain identities and directory configuration. Deploy domain controllers with reliable DNS, time and replication; an Azure VM domain controller still requires correct guest-level directory design.
  • RODCs suit locations where physical security is limited; password replication policy controls which credentials may be cached. Do not treat every account as safe to cache on a branch RODC.
  • FSMO roles handle specific single-master operations. Transfer roles during planned changes; seize only when the old holder cannot return safely under the required recovery process.
  • Forest roles: Schema Master coordinates schema updates; Domain Naming Master coordinates domain naming changes. Domain roles: RID Master allocates relative-ID pools; PDC Emulator supports time/password and legacy coordination functions; Infrastructure Master maintains relevant cross-domain references. Do not memorize all five as forest-wide roles. Placement/recovery depends on the actual topology and supported guidance.
  • Sites/subnets guide replication and client locality. Trust direction controls who can be authenticated across domains/forests; authentication through a trust does not automatically grant resource permissions.
  • Choose group scope and nesting according to domain/forest access needs. Managed/group managed service accounts reduce manual service-password handling where supported; service permissions still require least privilege.
  • Group Policy normally processes local, site, domain and OU settings with inheritance, filtering and enforcement affecting results. Preferences configure settings but are not always equivalent to enforced policy; use Resultant Set of Policy/gpresult to inspect actual application.

Choose under exam pressure

Requirement Choice and reason
A branch has weak physical security Evaluate an RODC with a restrictive password replication policy.
One user receives unexpected settings Inspect applied GPOs, OU placement, filtering and inheritance.

Traps

  • A trust is an authentication path, not blanket authorization.
  • Seizing an FSMO role is not the routine first step for a temporary network outage.

Practise this topic

02 · Remote and hybrid administration

Memory hook: Connect safely; delegate narrowly; manage centrally.

Must remember

  • Windows Admin Center provides a management gateway for supported Windows Server tasks. Secure the gateway and delegated access rather than exposing unrestricted management endpoints.
  • PowerShell remoting uses authenticated remote sessions; the double-hop problem occurs when a remote session must authenticate to another resource. Choose a supported constrained delegation/credential approach rather than broadly forwarding administrator credentials.
  • Just Enough Administration (JEA) limits available administrative commands and capabilities. SSH and RDP provide different remote access paths; secure both identity and network reachability.
  • Azure Arc registers non-Azure servers for supported Azure management capabilities. It does not move the server into Azure or make all network access private automatically.
  • Arc extensions and machine configuration support inventory/configuration tasks; Azure Update Manager schedules assessment and updates. Automation runbooks execute controlled workflows with appropriate identities.
  • Check agent/extension health, outbound connectivity, permissions and resource scope. Infrastructure registration without healthy agents does not prove policy or update actions reached the guest.

Choose under exam pressure

Requirement Choice and reason
Help desk needs only a few administrative commands A JEA endpoint with scoped access.
Manage on-premises servers through Azure services Azure Arc with supported agents, extensions and network paths.

Traps

  • Arc onboarding does not migrate the workload.
  • Solving double-hop by giving every operator unrestricted credentials creates unnecessary exposure.

Practise this topic

03 · Hyper-V and Azure virtual machines

Memory hook: Guest, host and platform are separate layers.

Must remember

  • Hyper-V virtual switches can be external, internal or private. VM NIC settings, host adapters and supported teaming affect different traffic paths; verify management connectivity before changing host networking.
  • Configure memory, virtual disks, integration services and device assignment to match the workload. GPU partitioning and discrete device assignment have different hardware/support requirements.
  • PowerShell Direct manages supported Windows guests through the host without ordinary guest network connectivity; SSH Direct serves supported Linux scenarios. Enhanced Session Mode improves supported interactive access.
  • Checkpoints preserve VM state for supported purposes; production and standard checkpoints differ. They do not replace independent backups. Hyper-V Replica supplies asynchronous replication, while failover clustering addresses host-level availability.
  • Nested virtualization requires supported host/VM settings and capacity. Additional virtualization layers can affect performance and network design.
  • Azure VMs need appropriate disks, NICs, availability sets/zones, resizing and scale-set design. Bastion/JIT secure management entry; the Windows guest still needs patching, identity, backup and monitoring.

Choose under exam pressure

Requirement Choice and reason
Manage a Windows guest with broken networking from its host PowerShell Direct when prerequisites are met.
Protect against Hyper-V host failure A supported failover-cluster design, with storage and quorum requirements.

Traps

  • A checkpoint stored with the VM is not an independent disaster-recovery backup.
  • Placing a VM in a zone does not create another running copy in a second zone.

Practise this topic

04 · DNS, DHCP and hybrid addressing

Memory hook: Name to address; address to network.

Must remember

  • AD-integrated DNS stores supported zones in the directory and replicates through AD. Forward lookup maps names to addresses; reverse lookup maps addresses to names; SRV records help clients locate directory services.
  • Forwarders send unresolved queries to another resolver; conditional forwarders target specific namespaces. Hybrid Azure/on-premises DNS needs deliberate paths in both directions and must avoid loops.
  • DNS policies control supported responses/handling by criteria. DNSSEC validates signed DNS data; it does not encrypt DNS traffic or solve every name-resolution problem.
  • DHCP scopes define address pools and options; exclusions reserve addresses outside allocation; reservations bind a specific client to an address. Relay is required when broadcasts cannot reach the server across routed networks.
  • Configure DHCP failover/high availability using supported modes and partner behavior. Exhausted scopes, wrong options, stale leases and duplicate addresses require different remedies.
  • Troubleshoot client IP, mask, gateway, DNS servers, route and firewall in order. A successful ping to an IP does not establish that DNS, domain discovery or the required application port works.

Choose under exam pressure

Requirement Choice and reason
Only a partner DNS namespace needs another resolver A conditional forwarder for that namespace.
Clients on another subnet receive no lease Check relay, routing, scope availability and server authorization/configuration.

Traps

  • DNSSEC provides authenticity/integrity, not confidentiality.
  • A DHCP reservation is not the same as manually configuring a static address outside DHCP.

Practise this topic

05 · Files, storage and replication

Memory hook: Namespace locates; permissions authorize; replication copies.

Must remember

  • SMB share permissions and NTFS permissions combine to determine effective access; inspect both. FSRM provides quotas, file screening and classification capabilities, not a replacement for file ACLs.
  • DFS Namespaces provides a logical path; DFS Replication copies supported file data. Azure File Sync caches/synchronizes supported Windows file-server data with Azure Files and can use cloud tiering.
  • Azure Files requires compatible identity/network access and share/filesystem permissions. Plan migration, file fidelity, recall behavior, backup and synchronization health rather than merely copying paths.
  • SMB over QUIC secures supported SMB access over QUIC; SMB Direct uses RDMA for supported high-performance paths. SMB encryption/signing and protocol settings address different risks and capabilities.
  • Storage Spaces pools disks; Storage Spaces Direct builds supported clustered storage; Storage Replica provides supported block-level replication. Plan disks, volumes, resiliency, fault domains, Storage QoS and iSCSI authentication/networking.
  • Choose NTFS/ReFS by workload and feature support. Deduplication reduces duplicate blocks for supported workloads; BitLocker encrypts volumes. Store recovery keys securely and test recovery independently of the protected machine.

Choose under exam pressure

Requirement Choice and reason
Users need one stable path across file servers DFS Namespace, with separate replication/availability design.
Keep local access to a large Azure-backed file dataset Azure File Sync with deliberate tiering and cache sizing.

Traps

  • DFS Namespace alone does not replicate file contents.
  • Replication can copy deletion or corruption and therefore does not replace backups.

Practise this topic

06 · Harden the OS and directory

Memory hook: Protect credentials; narrow privilege; verify enforcement.

Must remember

  • Apply supported security baselines through Group Policy or OSConfig and validate effective settings. Exploit protection, SmartScreen and application control address different execution risks.
  • Credential Guard isolates supported credential material; Windows LAPS manages local administrator passwords. Neither grants a reason to use domain administrator credentials for everyday tasks.
  • Defender for Servers and endpoint protection require supported onboarding and configuration. Windows Firewall and connection security/IPsec rules control host traffic and authentication requirements.
  • Secure AD with appropriate password policies, Entra Password Protection for AD DS, protected-user controls and restricted administrative delegation. Fine-grained password policies and ordinary GPO password settings have different scope semantics.
  • Harden domain controllers, limit interactive/remote access, protect privileged groups and use secure administrative workstations/processes. Audit changes to delegation and privileged membership.
  • Understand Kerberos versus NTLM and restrict legacy authentication through a tested migration. Authentication hardening can break dependencies; identify and remediate them before broad enforcement.

Choose under exam pressure

Requirement Choice and reason
Local administrator passwords are reused across servers Windows LAPS with controlled retrieval and rotation.
Only approved code should execute A tested application-control policy, staged before enforcement.

Traps

  • A baseline configured in policy is not proof it applied successfully.
  • Blanket denial of a legacy protocol without dependency discovery can cause an outage.

Practise this topic

07 · Monitor, diagnose and recover

Memory hook: Collect evidence before repairing state.

Must remember

  • Performance Monitor and data collector sets capture counters over time; Event Viewer/logs explain discrete failures; Windows Admin Center and System Insights provide supported management/analysis views.
  • Azure Monitor uses data collection rules and supported agents; VM Insights adds performance/dependency visibility. Configure actionable alerts with owners rather than collecting everything without a purpose.
  • For slow systems, correlate CPU, memory, disk latency, network, process and time. For updates/extensions, inspect agent health, prerequisites, connectivity, logs and reboot state.
  • AD issues often involve DNS, time, secure channels and replication. Use tools such as dcdiag and repadmin to gather evidence before resetting accounts or changing topology.
  • AD Recycle Bin restores supported deleted objects when enabled and retained. Directory Services Restore Mode and appropriate system-state recovery address deeper directory recovery; SYSVOL recovery has its own procedure.
  • Kerberos, computer-account trust, BitLocker and storage recovery need the correct keys/credentials and supported steps. Rehearse recovery in isolation and verify replication and application behavior afterward.

Choose under exam pressure

Requirement Choice and reason
One domain controller has stale objects Inspect replication, DNS, sites and time before assuming the data is lost.
A deleted user must be restored Evaluate AD Recycle Bin eligibility before more disruptive directory recovery.

Traps

  • Resetting multiple identities before gathering evidence can hide the root cause.
  • Restoring a directory database without considering replication can create further inconsistency.

Practise this topic

Search across every published topic.