Memory hook: Directory, guest, network, storage: diagnose each layer.
Reviewed 10 October 2026. Read this once, then answer the last-pass checks without looking.
Scope/version: AZ-800 and AZ-801 retired on 30 September 2026. AZ-802 is the replacement exam; this is not a combined legacy two-exam checklist.
Must remember by domain
| Domain | Rapid revision |
|---|---|
| AD DS | DNS/SRV records locate DCs; sites/subnets guide locality; replication shares directory changes. Schema Master and Domain Naming Master are forest roles; RID Master, PDC Emulator and Infrastructure Master are per-domain roles. Transfer for planned work; seize only under safe recovery rules. RODC password replication policy limits cached credentials. |
| Directory administration | Use AGDLP within suitable domain designs: accounts → global groups → domain-local groups → permissions; universal groups help appropriate multi-domain nesting. Trust authentication does not grant resource access. gMSAs automate supported service passwords. GPO normally processes local → site → domain → OU; filtering, enforcement and inheritance alter the result. |
| Hybrid management | Windows Admin Center is a management gateway; PowerShell remoting provides remote commands; JEA narrows allowed administration. Double-hop requires an appropriate constrained authentication design. Arc registers non-Azure machines for supported extensions/configuration; Update Manager schedules updates; runbooks automate work. |
| Virtual machines | External vSwitch reaches a physical network; internal connects host/guests; private connects guests only. PowerShell Direct uses the host path for supported guests. Standard checkpoints capture state; production checkpoints use supported data-consistency mechanisms. Replica is asynchronous DR; clustering addresses host availability. Azure VM disks/zones/scale sets need their own design. |
| Networking | AD-integrated zones replicate through AD. Forwarders resolve general misses; conditional forwarders target namespaces. DNSSEC validates signed responses, not encryption. DHCP scope/options, exclusions, reservations and failover solve different needs; relay crosses routed broadcast boundaries. |
| Files/storage | Effective network file access needs share and NTFS rights. DFS Namespace locates; DFS Replication copies. File Sync caches/synchronizes supported file data with Azure Files. FSRM quotas/screens/classification are not ACLs. SMB over QUIC secures supported remote SMB; SMB Direct uses RDMA. Storage Spaces, S2D and Storage Replica are distinct pooling/cluster/replication tools. |
| Security | Credential Guard protects supported credential material; LAPS rotates local admin credentials; BitLocker encrypts volumes. Secure recovery keys separately. Baselines/OSConfig, application control, Firewall, Defender and protected-user/AD delegation controls require effective-policy validation. Fine-grained password policy targets users/global security groups, not OUs directly. |
| Monitoring/recovery | PerfMon measures counters; events explain failures; DCR/AMA routes guest telemetry. Diagnose AD with DNS, time, secure channel, dcdiag and repadmin. Recycle Bin restores eligible deleted objects; DSRM/system-state and SYSVOL recovery handle deeper failures. A checkpoint is not an independent backup. |
Troubleshooting sequence
For domain sign-in: IP/DNS → time → DC discovery → authentication/secure channel → replication → policy/resource permissions. For slow files: client path → share/NTFS permissions → storage latency → locks/sync/recall → network. Gather evidence before resetting trust or seizing roles.
Last-pass self-check
1. Which FSMO role is associated with domain time/password-change coordination?
The PDC Emulator; the forest-root PDC typically anchors the domain time hierarchy.
2. A trusts B: what does that establish?
B identities can be authenticated for access toward A, subject to trust configuration and A resource authorization.
3. Does DFS Namespace replicate files?
No. DFS Replication or another data replication mechanism handles copying.
4. Can DNSSEC hide a DNS query?
No. It provides validation of signed data, not confidentiality.
5. Which check shows actually applied GPO settings?
gpresult/Resultant Set of Policy, including filtering and inheritance effects.
Sources
- Official exam scope and version
- FSMO role scope and responsibilities
- Product documentation
- Product documentation
- Product documentation
- Product documentation
- Product documentation
- Product documentation
- Product documentation
Every topic at a glance
Open any topic to revisit its essential facts, decisions and exam traps. Use the full topic for active recall and supporting references.
01 · Active Directory and Group Policy
Memory hook: DNS locates; replication shares; policy configures.
Must remember
- AD DS stores domain identities and directory configuration. Deploy domain controllers with reliable DNS, time and replication; an Azure VM domain controller still requires correct guest-level directory design.
- RODCs suit locations where physical security is limited; password replication policy controls which credentials may be cached. Do not treat every account as safe to cache on a branch RODC.
- FSMO roles handle specific single-master operations. Transfer roles during planned changes; seize only when the old holder cannot return safely under the required recovery process.
- Forest roles: Schema Master coordinates schema updates; Domain Naming Master coordinates domain naming changes. Domain roles: RID Master allocates relative-ID pools; PDC Emulator supports time/password and legacy coordination functions; Infrastructure Master maintains relevant cross-domain references. Do not memorize all five as forest-wide roles. Placement/recovery depends on the actual topology and supported guidance.
- Sites/subnets guide replication and client locality. Trust direction controls who can be authenticated across domains/forests; authentication through a trust does not automatically grant resource permissions.
- Choose group scope and nesting according to domain/forest access needs. Managed/group managed service accounts reduce manual service-password handling where supported; service permissions still require least privilege.
- Group Policy normally processes local, site, domain and OU settings with inheritance, filtering and enforcement affecting results. Preferences configure settings but are not always equivalent to enforced policy; use Resultant Set of Policy/gpresult to inspect actual application.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| A branch has weak physical security | Evaluate an RODC with a restrictive password replication policy. |
| One user receives unexpected settings | Inspect applied GPOs, OU placement, filtering and inheritance. |
Traps
- A trust is an authentication path, not blanket authorization.
- Seizing an FSMO role is not the routine first step for a temporary network outage.
02 · Remote and hybrid administration
Memory hook: Connect safely; delegate narrowly; manage centrally.
Must remember
- Windows Admin Center provides a management gateway for supported Windows Server tasks. Secure the gateway and delegated access rather than exposing unrestricted management endpoints.
- PowerShell remoting uses authenticated remote sessions; the double-hop problem occurs when a remote session must authenticate to another resource. Choose a supported constrained delegation/credential approach rather than broadly forwarding administrator credentials.
- Just Enough Administration (JEA) limits available administrative commands and capabilities. SSH and RDP provide different remote access paths; secure both identity and network reachability.
- Azure Arc registers non-Azure servers for supported Azure management capabilities. It does not move the server into Azure or make all network access private automatically.
- Arc extensions and machine configuration support inventory/configuration tasks; Azure Update Manager schedules assessment and updates. Automation runbooks execute controlled workflows with appropriate identities.
- Check agent/extension health, outbound connectivity, permissions and resource scope. Infrastructure registration without healthy agents does not prove policy or update actions reached the guest.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Help desk needs only a few administrative commands | A JEA endpoint with scoped access. |
| Manage on-premises servers through Azure services | Azure Arc with supported agents, extensions and network paths. |
Traps
- Arc onboarding does not migrate the workload.
- Solving double-hop by giving every operator unrestricted credentials creates unnecessary exposure.
03 · Hyper-V and Azure virtual machines
Memory hook: Guest, host and platform are separate layers.
Must remember
- Hyper-V virtual switches can be external, internal or private. VM NIC settings, host adapters and supported teaming affect different traffic paths; verify management connectivity before changing host networking.
- Configure memory, virtual disks, integration services and device assignment to match the workload. GPU partitioning and discrete device assignment have different hardware/support requirements.
- PowerShell Direct manages supported Windows guests through the host without ordinary guest network connectivity; SSH Direct serves supported Linux scenarios. Enhanced Session Mode improves supported interactive access.
- Checkpoints preserve VM state for supported purposes; production and standard checkpoints differ. They do not replace independent backups. Hyper-V Replica supplies asynchronous replication, while failover clustering addresses host-level availability.
- Nested virtualization requires supported host/VM settings and capacity. Additional virtualization layers can affect performance and network design.
- Azure VMs need appropriate disks, NICs, availability sets/zones, resizing and scale-set design. Bastion/JIT secure management entry; the Windows guest still needs patching, identity, backup and monitoring.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Manage a Windows guest with broken networking from its host | PowerShell Direct when prerequisites are met. |
| Protect against Hyper-V host failure | A supported failover-cluster design, with storage and quorum requirements. |
Traps
- A checkpoint stored with the VM is not an independent disaster-recovery backup.
- Placing a VM in a zone does not create another running copy in a second zone.
04 · DNS, DHCP and hybrid addressing
Memory hook: Name to address; address to network.
Must remember
- AD-integrated DNS stores supported zones in the directory and replicates through AD. Forward lookup maps names to addresses; reverse lookup maps addresses to names; SRV records help clients locate directory services.
- Forwarders send unresolved queries to another resolver; conditional forwarders target specific namespaces. Hybrid Azure/on-premises DNS needs deliberate paths in both directions and must avoid loops.
- DNS policies control supported responses/handling by criteria. DNSSEC validates signed DNS data; it does not encrypt DNS traffic or solve every name-resolution problem.
- DHCP scopes define address pools and options; exclusions reserve addresses outside allocation; reservations bind a specific client to an address. Relay is required when broadcasts cannot reach the server across routed networks.
- Configure DHCP failover/high availability using supported modes and partner behavior. Exhausted scopes, wrong options, stale leases and duplicate addresses require different remedies.
- Troubleshoot client IP, mask, gateway, DNS servers, route and firewall in order. A successful ping to an IP does not establish that DNS, domain discovery or the required application port works.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Only a partner DNS namespace needs another resolver | A conditional forwarder for that namespace. |
| Clients on another subnet receive no lease | Check relay, routing, scope availability and server authorization/configuration. |
Traps
- DNSSEC provides authenticity/integrity, not confidentiality.
- A DHCP reservation is not the same as manually configuring a static address outside DHCP.
05 · Files, storage and replication
Memory hook: Namespace locates; permissions authorize; replication copies.
Must remember
- SMB share permissions and NTFS permissions combine to determine effective access; inspect both. FSRM provides quotas, file screening and classification capabilities, not a replacement for file ACLs.
- DFS Namespaces provides a logical path; DFS Replication copies supported file data. Azure File Sync caches/synchronizes supported Windows file-server data with Azure Files and can use cloud tiering.
- Azure Files requires compatible identity/network access and share/filesystem permissions. Plan migration, file fidelity, recall behavior, backup and synchronization health rather than merely copying paths.
- SMB over QUIC secures supported SMB access over QUIC; SMB Direct uses RDMA for supported high-performance paths. SMB encryption/signing and protocol settings address different risks and capabilities.
- Storage Spaces pools disks; Storage Spaces Direct builds supported clustered storage; Storage Replica provides supported block-level replication. Plan disks, volumes, resiliency, fault domains, Storage QoS and iSCSI authentication/networking.
- Choose NTFS/ReFS by workload and feature support. Deduplication reduces duplicate blocks for supported workloads; BitLocker encrypts volumes. Store recovery keys securely and test recovery independently of the protected machine.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Users need one stable path across file servers | DFS Namespace, with separate replication/availability design. |
| Keep local access to a large Azure-backed file dataset | Azure File Sync with deliberate tiering and cache sizing. |
Traps
- DFS Namespace alone does not replicate file contents.
- Replication can copy deletion or corruption and therefore does not replace backups.
06 · Harden the OS and directory
Memory hook: Protect credentials; narrow privilege; verify enforcement.
Must remember
- Apply supported security baselines through Group Policy or OSConfig and validate effective settings. Exploit protection, SmartScreen and application control address different execution risks.
- Credential Guard isolates supported credential material; Windows LAPS manages local administrator passwords. Neither grants a reason to use domain administrator credentials for everyday tasks.
- Defender for Servers and endpoint protection require supported onboarding and configuration. Windows Firewall and connection security/IPsec rules control host traffic and authentication requirements.
- Secure AD with appropriate password policies, Entra Password Protection for AD DS, protected-user controls and restricted administrative delegation. Fine-grained password policies and ordinary GPO password settings have different scope semantics.
- Harden domain controllers, limit interactive/remote access, protect privileged groups and use secure administrative workstations/processes. Audit changes to delegation and privileged membership.
- Understand Kerberos versus NTLM and restrict legacy authentication through a tested migration. Authentication hardening can break dependencies; identify and remediate them before broad enforcement.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Local administrator passwords are reused across servers | Windows LAPS with controlled retrieval and rotation. |
| Only approved code should execute | A tested application-control policy, staged before enforcement. |
Traps
- A baseline configured in policy is not proof it applied successfully.
- Blanket denial of a legacy protocol without dependency discovery can cause an outage.
07 · Monitor, diagnose and recover
Memory hook: Collect evidence before repairing state.
Must remember
- Performance Monitor and data collector sets capture counters over time; Event Viewer/logs explain discrete failures; Windows Admin Center and System Insights provide supported management/analysis views.
- Azure Monitor uses data collection rules and supported agents; VM Insights adds performance/dependency visibility. Configure actionable alerts with owners rather than collecting everything without a purpose.
- For slow systems, correlate CPU, memory, disk latency, network, process and time. For updates/extensions, inspect agent health, prerequisites, connectivity, logs and reboot state.
- AD issues often involve DNS, time, secure channels and replication. Use tools such as dcdiag and repadmin to gather evidence before resetting accounts or changing topology.
- AD Recycle Bin restores supported deleted objects when enabled and retained. Directory Services Restore Mode and appropriate system-state recovery address deeper directory recovery; SYSVOL recovery has its own procedure.
- Kerberos, computer-account trust, BitLocker and storage recovery need the correct keys/credentials and supported steps. Rehearse recovery in isolation and verify replication and application behavior afterward.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| One domain controller has stale objects | Inspect replication, DNS, sites and time before assuming the data is lost. |
| A deleted user must be restored | Evaluate AD Recycle Bin eligibility before more disruptive directory recovery. |
Traps
- Resetting multiple identities before gathering evidence can hide the root cause.
- Restoring a directory database without considering replication can create further inconsistency.