MCSA

AZ-802: Administering Windows Server

Overview of AZ-802 Consolidated Exam: AZ-802 replaces the older two-exam combination of AZ-800 and AZ-801, which retire on September 30, 2026.
Target Audience: System administrators and infrastructure engineers managing workloads in on-premises, cloud, or hybrid setups.
Prerequisites: No formal prerequisites are required, though foundational cloud knowledge like AZ-900 is helpful

Skills at a glance

Deploy and manage AD DS (20–25%)
Manage Windows Server instances and workloads in a hybrid environment (10–15%)
Manage virtual machines (10–15%)
Implement and manage an on-premises and hybrid networking infrastructure (10–15%)
Manage storage and file services (15–20%)
Secure Windows Server infrastructure (10–15%)
Monitor and troubleshoot Windows Server environments (15–20%)

Deploy and manage AD DS (20–25%)

Deploy and manage AD DS domain controllers

  • Deploy and manage domain controllers locally
  • Deploy and manage domain controllers in Azure
  • Deploy Read-Only Domain Controllers (RODCs)
  • Manage account security on an RODC
  • Manage and troubleshoot Flexible Single-Master Operations (FSMO) roles

Configure and manage multi-site, multi-domain, and multi-forest environments

  • Configure domain and forest trust relationships
  • Configure and manage AD DS sites
  • Configure and manage AD DS replication

Create and manage AD DS security principals

  • Create and manage AD DS users and groups
  • Manage users and groups in multi-domain or multi-forest environments
  • Select and manage service accounts

Manage Windows Server by using domain-based Group Policies

  • Implement Group Policy
  • Implement Group Policy preferences

 

Manage Windows Server instances and workloads in a hybrid environment (10–15%)

Configure remote management for Windows Server instances in a hybrid environment

  • Deploy and manage Windows Admin Center on-premises and in the Azure portal
  • Configure remote management by using PowerShell, including double-hop and Just Enough Administration (JEA)
  • Configure and manage remote Secure Shell (SSH)
  • Configure and manage remote desktop access

Manage Windows Server instances and workloads by using Azure services in a hybrid environment

  • Implement Azure Arc–enabled Windows Server instances
  • Implement device configuration by using Azure Arc
  • Deploy Azure services with virtual machine (VM) extensions on non–Azure machines
  • Manage updates by using Azure Update Manager
  • Create and run Azure Automation runbooks
Manage VMs (10–15%)

Manage Hyper-V and guest VM

  • Enable Enhanced Session Mode
  • Manage VMs remotely by using PowerShell, PowerShell Direct, and SSH Direct for Linux guests
  • Enable nested virtualization
  • Configure VM memory settings
  • Configure integration services
  • Configure device assignment
  • Configure GPU partitioning
  • Manage VM checkpoints
  • Implement high availability for Hyper-V VMs
  • Manage Hyper-V virtual hard disks
  • Configure Hyper-V network adapter
  • Configure network interface card (NIC) teaming on the Hyper-V host and VM
  • Configure Hyper-V Virtual Switch
  • Configure Hyper-V Replica

Manage Windows Server VMs in Azure

  • Manage storage for Windows Server VMs in Azure
  • Manage capacity, including resizing and VM scale sets
  • Manage availability sets and zones
  • Manage just-in-time (JIT) VM access and Azure Bastion
  • Manage Azure Virtual Machines network configuration

Implement and manage an on-premises and hybrid networking infrastructure (10–15%)

Implement on-premises and hybrid name resolution

  • Integrate domain name system (DNS) with AD DS
  • Create and manage DNS zones and records
  • Configure DNS forwarding and conditional forwarding
  • Configure DNS name resolution in a hybrid environment
  • Implement DNS policies
  • Implement DNS security extensions (DNSSEC)

Manage IP addressing in on-premises and hybrid scenarios

  • Implement and configure the Dynamic Host Configuration Protocol (DHCP) server role
  • Troubleshoot IP addressing in hybrid environments
  • Create and manage DHCP scopes
  • Create IP reservations
  • Implement high availability for DHCP
Manage storage and file services (15–20%)

Configure and manage Azure Files

  • Create and manage Azure file shares
  • Manage permissions for Azure file shares
  • Configure and manage Azure File Sync
  • Monitor Azure File Sync
  • Migrate Distributed File System (DFS) to Azure File Sync
  • Migrate from file shares to Azure Files

Configure and manage Windows Server file shares

  • Configure access to Windows Server file shares
  • Configure File Server Resource Manager (FSRM)
  • Implement and configure DFS
  • Configure Server Message Block (SMB) over QUIC
  • Configure SMB settings and management

Configure Windows Server storage

  • Configure disks and volumes
  • Configure and manage Storage Spaces
  • Implement and manage Storage Spaces Direct
  • Configure and manage Storage Replica
  • Configure Data Deduplication
  • Configure SMB direct (SMB over Remote Direct Memory Access [RDMA])
  • Configure Storage QoS
  • Select and configure file systems, including NTFS and ReFS
  • Configure and manage iSCSI
  • Manage BitLocker Drive Encryption
  • Manage and recover encrypted volumes.
Secure Windows Server infrastructure (10–15%)

Secure Windows Server operating system

  • Configure and manage exploit protection
  • Configure and manage Application Control for Windows
  • Configure and manage Credential Guard
  • Configure Microsoft Defender SmartScreen
  • Implement operating system security by using Group Policies
  • Manage Windows Server security baseline by using OSConfig
  • Implement Windows Local Administrator Password Solution
  • Configure and manage Defender for Servers
  • Manage Windows Firewall, including connection security rules

Secure AD DS

  • Configure password policies
  • Implement Microsoft Entra Password Protection for AD DS
  • Manage protected users
  • Harden domain controllers
  • Restrict access to domain controllers
  • Configure security options for user accounts
  • Configure security options for built-in administrative groups
  • Manage AD delegation
  • Manage authentication protocols and methods for AD DS
Monitor and troubleshoot Windows Server environments (15–20%)

Monitor by using Windows Server tools and Azure services

  • Monitor by using Performance Monitor
  • Create and configure data collector sets
  • Monitor servers and configure alerts by using Windows Admin Center
  • Analyze by using the System Insights feature of Windows Server
  • Manage event logs
  • Configure data collection rules for Azure Monitor
  • Create alerts
  • Monitor Azure Virtual Machines performance by using VM Insights

Troubleshoot Windows Server issues

  • Troubleshoot connectivity issues
  • Troubleshoot name resolution
  • Troubleshoot Windows Update
  • Troubleshoot Time service
  • Troubleshoot performance issues
  • Troubleshoot VM and Azure Arc extension issues
  • Troubleshoot disk encryption issues
  • Troubleshoot storage issues

Troubleshoot Active Directory

  • Restore objects from AD Recycle Bin
  • Recover AD database by using Directory Services Restore Mode
  • Recover SYSVOL
  • Troubleshoot AD replication
  • Troubleshoot on-premises AD
  • Troubleshoot Kerberos and authentication issues
  • Troubleshoot secure channel and computer account trust issues