
AZ-802 Exam Overview
The AZ-802 Administering Windows Server exam evaluates the skills required to
deploy, implement, manage, secure, monitor, and troubleshoot Windows Server
environments across on-premises, cloud, and hybrid infrastructures. Microsoft
identifies Active Directory Domain Services (AD DS), Windows Admin Center,
PowerShell, Azure Arc, Azure Monitor, Azure Update Manager, Hyper-V, and
Microsoft Defender for Cloud among the technologies relevant to the exam.
AZ-802 is designed for Windows Server administrators who work with identity,
security, compute, networking, storage, monitoring, and hybrid administration.
AZ-802 Topics Covered
According to Microsoft's current study guide, AZ-802 covers these major areas:
Deploy and manage AD DS 2025%
Domain controllers
Read-Only Domain Controllers (RODC)
FSMO roles
AD DS sites and replication
Domain and forest trusts
Users, groups, and service accounts
Group Policy
Manage Windows Server instances and hybrid workloads 1015%
Windows Admin Center
PowerShell remoting
SSH and Remote Desktop
Azure Arc-enabled servers
Azure Update Manager
Azure Automation runbooks
Manage virtual machines 1015%
Hyper-V
VM memory and checkpoints
Virtual switches
NIC teaming
Hyper-V Replica
GPU partitioning
Azure VMs
Availability sets and zones
Azure Bastion
Implement on-premises and hybrid networking 1015%
DNS and AD DS integration
DNS zones and records
DNS forwarding
Hybrid DNS
Network configuration
Manage storage and file services 1520%
Disks and volumes
Storage Spaces
Storage Spaces Direct
Storage Replica
Data Deduplication
SMB Direct
Storage QoS
NTFS and ReFS
iSCSI
BitLocker
Secure Windows Server infrastructure 1015%
Windows Firewall
Credential Guard
Application Control
Exploit protection
Security baselines
Windows LAPS
Defender for Servers
AD DS security
Password policies
Domain controller hardening
Monitor and troubleshoot Windows Server 1520%
Performance Monitor
Event Logs
Data Collector Sets
System Insights
Azure Monitor
VM Insights
Windows Update troubleshooting
DNS and connectivity troubleshooting
Storage and encryption troubleshooting
AD replication
Kerberos and authentication
Secure channel and trust issues
AZ-802 Exam Overview
What Students Search on Google, ChatGPT, Copilot, DeepSeek, Gemini, Reddit,
Facebook and YouTube
Students preparing for AZ-802 commonly search for questions and resources such
as:
What is the AZ-802 Administering Windows Server exam?
How do I prepare for AZ-802?
What topics are covered in AZ-802?
What is the current AZ-802 exam syllabus?
Where can I find AZ-802 practice questions?
What are the most important AZ-802 topics?
How difficult is the AZ-802 exam?
How many questions are on the AZ-802 exam?
What score is required to pass AZ-802?
What is the best way to study for AZ-802?
Are AZ-802 practice tests useful?
Where can I find AZ-802 mock exams?
What AD DS topics are tested on AZ-802?
What Hyper-V questions should I study for AZ-802?
What Azure Arc topics are included in AZ-802?
How do I practice Windows Server troubleshooting for AZ-802?
What PowerShell skills are required for AZ-802?
What DNS and networking topics should I know?
What storage technologies should I study for AZ-802?
What Windows Server security topics are tested?
What are the latest AZ-802 exam questions?
How can I test my AZ-802 knowledge before the exam?
What should I study first for AZ-802?
Are AZ-802 exam dumps legitimate?
How can I use practice questions without relying on memorization?
Short Google Snippet Content
AZ-802 Administering Windows Server preparation covering AD DS, hybrid Windows
Server, Hyper-V, Azure Arc, networking, storage, security, monitoring, and
troubleshooting. Practice with updated AZ-802 questions and realistic exam preparation resources.
AZ-802 Brain Dumps Exam + Online / Offline and Android Testing Engine 4500+ other exams included
$50 - $25 (you save $25)
Buy Now
New Topic: Topic 1, Case Study 1: Contoso, Ltd.
Overview
This is a case study. Case studies are not timed separately. You can use as much
exam time as you
would like to complete each case. However, there may be additional case studies
and sections on
this exam. You must manage your time to ensure that you are able to complete all
questions included
on this exam in the time provided.
To answer the questions included in a case study, you will need to reference
information that is
provided in the case study. Case studies might contain exhibits and other
resources that provide
more information about the scenario that is described in the case study. Each
question is
independent of the other questions in this case study.
AD DS Environment: The network contains an on-premises Active Directory Domain
Services (AD DS)
forest named contoso.com. The forest contains two domains named contoso.com and
canada.contoso.com. The forest contains the domain controllers shown in the
exhibit below. All the
domain controllers are global catalog servers.
Domain controllers
Server Infrastructure: The network contains the servers shown in the exhibit
below. A server named
Server4 runs Windows Server and is in a workgroup. Windows Firewall on Server4
uses the private
profile. Server2 hosts three virtual machines named VM1, VM2, and VM3. VM3 is a
file server that
stores data in the volumes shown in the exhibit below.
Servers
VM3 volumes
Group Policies: The contoso.com domain has the Group Policy Objects (GPOs) shown
in the exhibit below.
GPOs
Existing Identities: The forest contains the users shown in the exhibit below.
The forest also contains the groups shown
in the exhibit below.
Users
Groups
Current Problems: When an administrator signs in to the console of VM2 by using
Virtual Machine
Connection, and then disconnects from the session without signing out, another
administrator can
connect to the console session as the currently signed-in user.
Requirements: Contoso identifies the following technical requirements:
- Change the replication schedule for all site links to 30 minutes.
- Promote Server1 to a domain controller in canada.contoso.com.
- Install and authorize Server3 as a DHCP server.
- Ensure that User1 can manage the membership of all the groups in Contoso\OU3.
- Ensure that you can manage Server4 from Server1 by using PowerShell remoting.
- Ensure that you can run virtual machines on VM1.
- Force users to provide credentials when they connect to VM2.
- On VM3, ensure that Data Deduplication on all eligible volumes is possible.
QUESTION 1
You need to meet the technical requirements for Server1. Which users can
currently perform the required task?
A. Admin1 only
B. Admin3 only
C. Admin1 and Admin3 only
D. Admin1, Admin2, and Admin3
Answer: C
Explanation:
Promoting a member server to a domain controller in a specific domain requires
membership in
either the Enterprise Admins group (forest-wide rights) or the Domain Admins
group of that target
domain. Server1 is a member server in canada.contoso.com, and the requirement is
to promote it to
a domain controller in that same domain. Admin1 belongs to Contoso\Enterprise
Admins, which has
full administrative rights across every domain in the forest, including the
right to install AD DS and
promote a server anywhere in the forest, so Admin1 qualifies. Admin3 belongs to
Canada\Domain
Admins, the Domain Admins group of canada.contoso.com itself, which grants full
administrative
control, including domain controller promotion, within that domain, so Admin3
also qualifies.
Admin2, by contrast, is a member of Contoso\Domain Admins, the Domain Admins
group of the
contoso.com domain; Domain Admins rights are scoped to their own domain and do
not extend into
a child domain such as canada.contoso.com, so Admin2 cannot promote Server1.
User1 has only
standard Domain Users membership and holds no administrative rights anywhere.
Therefore, only
Admin1 and Admin3 currently have sufficient rights, making option C correct.
QUESTION 2
You need to meet the technical requirements for the site links. Which users can
perform the required task?
A. Admin1 only
B. Admin1 and Admin3 only
C. Admin1 and Admin2 only
D. Admin3 only
E. Admin1, Admin2, and Admin3
Answer: C
Explanation:
Site, subnet, and site-link objects are stored in the Configuration partition,
which replicates to every
domain controller in the forest but is administratively owned by the forest root
domain. By default,
only members of Enterprise Admins and members of the Domain Admins group of the
forest root
domain (contoso.com in this forest) have permissions to modify objects in the
Configuration
container, including editing a site link's replication schedule. Admin1 is a
member of
Contoso\Enterprise Admins and therefore has forest-wide rights over the
Configuration partition.
Admin2 is a member of Contoso\Domain Admins; because contoso.com is the forest
root domain,
this group also carries default rights over the Configuration and Schema
partitions. Admin3,
however, is a member of Canada\Domain Admins, the Domain Admins group of the
canada.contoso.com child domain, which has no inherent rights over the
Configuration partition.
Consequently, to change the replication schedule on all site links to 30
minutes, only Admin1 and
Admin2 currently have the necessary permissions, making option C the correct
answer.
QUESTION 3
HOTSPOT
You need to meet the technical requirements for VM1. Which cmdlet should you run
first? To answer,
select the appropriate options in the answer are a. NOTE: Each correct selection
is worth one point.
Answer:
Set-VMProcessor -VMName VM1 -ExposeVirtualizationExtensions $true
The requirement is to run virtual machines on VM1 itself, which means enabling
nested
virtualization so that VM1 (a guest VM hosted on Server2) can install Hyper-V
and host its own virtual
machines. Nested virtualization on Hyper-V requires the parent VM's virtual
processor to expose the
host's hardware virtualization extensions (Intel VT-x or AMD-V) through to the
guest. This is done
with the Set-VMProcessor cmdlet using the -ExposeVirtualizationExtensions
parameter set to $true,
run against VM1 from the Hyper-V host (Server2): Set-VMProcessor -VMName VM1 -
ExposeVirtualizationExtensions $true. VM1 must be turned off before this setting
can be applied, and
after it is applied, VM1 needs the Hyper-V role installed inside the guest
before it can run its own
VMs. Set-VM, Set-VMBios, Set-VMHost, and Set-VMFirmware do not control
virtualization extension
exposure: Set-VM manages general VM configuration such as memory and name, Set-VMHost
configures host-wide settings, and Set-VMFirmware/Set-VMBios control boot and
firmware settings
for generation 2 and generation 1 VMs respectively. Only Set-VMProcessor with -
ExposeVirtualizationExtensions satisfies the stated requirement, making it the
correct first step.
QUESTION 4
You need to meet the technical requirements for VM3. On which volume can you
enable Data Deduplication?
A. D and E only
B. C, D, E, and F
C. D only
D. C and D only
E. D, E, and F only
Answer: C
Explanation:
Data Deduplication is a Windows Server file-and-storage feature that can only be
enabled on NTFSformatted
data volumes; it cannot be enabled on the operating system (boot/system) volume,
and it
does not support ReFS or FAT/exFAT volumes at all. VM3's volumes are C (NTFS,
the operating system
volume), D (NTFS, a data volume), E (ReFS), and F (exFAT). Volume C is excluded
because
Deduplication is never supported on the volume that hosts the operating system,
even though its file
system is NTFS. Volume E is excluded because Data Deduplication has no ReFS
support in generalpurpose
deployments; ReFS uses its own separate storage-efficiency mechanisms such as
block
cloning, not the Deduplication feature. Volume F is excluded because exFAT is a
lightweight file
system with no support for Windows Server roles or features such as
Deduplication, which depends
on NTFS-specific metadata structures. That leaves volume D as the only NTFS data
volume that is
neither the boot volume nor formatted with an unsupported file system, so it is
the only volume on
which Data Deduplication can currently be enabled, making option C correct.
QUESTION 5
You need to meet the technical requirements for User1. The solution must use the
principle of least privilege. What should you do?
A. Add User1 to the Server Operators group in contoso.com.
B. Create a delegation on contoso.com.
C. Add User1 to the Account Operators group in contoso.com.
D. Create a delegation on OU3.
Answer: D
Explanation:
The requirement is narrow: User1 must be able to manage the membership of all
the groups located
in Contoso\OU3, and nothing more. The Delegation of Control Wizard, run against
OU3 specifically,
lets an administrator grant User1 exactly the built-in task "Modify the
membership of a group,"
which grants write access to the member attribute on group objects contained in
that OU only. This
satisfies the requirement while granting no rights outside OU3, which is the
definition of least
privilege. Creating the same delegation at the domain root (contoso.com) would
technically work
but grants far broader scope than needed, since it would apply to every
container in the domain, not
just OU3, violating least privilege. Adding User1 to Account Operators grants
domain-wide rights to
create, delete, and modify most user, group, and computer accounts throughout
the domain (with
some protections for built-in admin accounts), which is excessive for a task
limited to group
membership in one OU. Server Operators is unrelated to Active Directory object
management
altogether; it governs local administrative rights on domain controllers
themselves.
Therefore, delegating control on OU3 is the correct, minimally scoped solution.
QUESTION 6
HOTSPOT
Which groups can you add to Group3, and which groups can you add to Group5? To
answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Group3: Group1, Group2, Group4, and Group5 only. Group5: Group4 only.
Group nesting in AD DS is governed strictly by group scope, independent of
whether a group is
security- or distribution-type. A Domain Local group can contain user accounts,
Global groups from
any domain, and Universal groups from any domain, plus other Domain Local groups
from its own
domain only. Group3 is a Domain Local group in contoso.com, so it can accept
Group1 (Universal,
contoso.com), Group2 (Global, contoso.com), and Group4 and Group5 (both Global,
canada.contoso.com), since Global groups from any domain are valid Domain Local
members. It
cannot accept Group6, because Group6 is Domain Local in canada.contoso.com, a
different domain,
and Domain Local groups may only nest other Domain Local groups from their own
domain. That
gives Group3: Group1, Group2, Group4, and Group5 only. A Global group, by
contrast, can contain
only user accounts and other Global groups from the same domain. Group5 is
Global in
canada.contoso.com, so among the remaining groups only Group4 qualifies, since
it is also Global
and in the same domain; Group1 (Universal), Group2 (Global but a different
domain), and Group6
(Domain Local) are all excluded by scope rules. That gives Group5: Group4 only.
QUESTION 7
HOTSPOT
You need to meet the technical requirements for Server4. Which cmdlet should you
run on Server1,
and which cmdlet should you run on Server4? To answer, select the appropriate
options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Server1: Set-Item. Server4: Enable-PSRemoting.
The requirement is to manage Server4 from Server1 by using PowerShell remoting.
Server4 is a
workgroup computer, not a member of either AD DS domain, so the WinRM
authentication that
PowerShell remoting relies on cannot use Kerberos between Server1 and Server4;
it must fall back to
NTLM, which WinRM only permits toward hosts explicitly listed in the client's
TrustedHosts list. On
Server1, the correct action is therefore Set-Item, used as Set-Item
WSMan:\localhost\Client\TrustedHosts -Value "Server4" (with -Concatenate as
needed), which adds
Server4 to Server1's trusted hosts so an NTLM-based remoting session is
permitted. On Server4, the
target must first be configured to accept remote commands at all, which is done
with Enable-
PSRemoting; this cmdlet starts and configures the WinRM service, creates a
listener, and enables the
Windows Remote Management firewall rule for the current network profile,
matching Server4's
private firewall profile. Enable-ServerManagerStandardUserRemoting only grants a
nonadministrator
limited Server Manager access and does not establish remoting, and Start-Service
alone does not create or configure a WinRM listener or firewall exception.
Configuring Set-Item on
Server1 and Enable-PSRemoting on Server4 together satisfies the requirement.
Alternative Short Snippet
Prepare for the Microsoft AZ-802 Administering Windows Server exam with practice
questions covering AD DS, Hyper-V, Azure Arc, networking, storage, security,
monitoring, and troubleshooting.
Daniel Mwangi - Kenya: "The AZ-802 practice material helped me organize my
Windows Server study plan and identify topics I needed to review."
Sofia Martins - Portugal: "I found the AD DS and hybrid administration questions
useful for checking my understanding."
Liam O'Connor - Ireland: "The practice tests gave me a better idea of the areas
I needed to concentrate on before my exam."
Aarav Mehta - India: "The AZ-802 preparation material was easy to navigate and
covered several important Windows Server topics."
Emily Carter - Canada: "I used the questions alongside my Microsoft Learn study
and found them helpful for revision."
Yuki Tanaka - Japan: "The practice questions helped me review Hyper-V,
networking, and Windows Server administration."
Omar Haddad - Jordan: "The material gave me a convenient way to test my
knowledge before taking the exam."
Lucas Ferreira - Brazil: "I liked the combination of Windows Server, Azure, and
hybrid administration topics."
Nadia Petrova - Bulgaria: "The practice sessions helped me discover areas where
I needed additional study."
Thomas Schneider - Germany: "The AZ-802 questions were useful as part of my
overall certification preparation."
Amelia Williams - United Kingdom: "I used the practice material to review AD DS,
storage, security, and troubleshooting concepts."
Ravi Perera - Sri Lanka: "The testing format made it easier to measure my
progress during preparation."
Chloe Dubois - France: "The AZ-802 preparation resources helped me structure my
final revision."
Ethan Williams - Australia: "I found the Windows Server hybrid administration
questions useful for reinforcing what I studied."
Mateo Garcνa - Spain: "The practice questions provided a useful way to review
important AZ-802 concepts before the exam."
Most Asked FAQs
What is the AZ-802 exam?
AZ-802 is Microsoft's Administering Windows Server exam, covering deployment,
administration, security, networking, storage, monitoring, and troubleshooting.
What does AZ-802 test?
It tests Windows Server administration across on-premises, cloud, and hybrid
environments.
What are the main AZ-802 exam topics?
AD DS, hybrid Windows Server management, VMs, networking, storage, security,
monitoring, and troubleshooting.
Is Active Directory included in AZ-802?
Yes. AD DS deployment and management represents 2025% of the current skills
measured.
Is Hyper-V included in AZ-802?
Yes. VM management includes Hyper-V administration and Windows Server VMs in
Azure.
Is Azure Arc included in AZ-802?
Yes. Candidates should understand Azure Arc-enabled Windows Server instances and
related hybrid-management capabilities.
Is PowerShell important for AZ-802?
Yes. Microsoft specifically identifies PowerShell as an administration
technology relevant to the exam.
Does AZ-802 cover DNS?
Yes. DNS integration with AD DS, zones, records, forwarding, and hybrid name
resolution are included.
Does AZ-802 cover Windows Server storage?
Yes. Storage Spaces, Storage Spaces Direct, Storage Replica, NTFS, ReFS, iSCSI,
Data Deduplication, SMB Direct, and BitLocker are among the listed topics.
Does AZ-802 cover Windows Server security?
Yes. Security topics include Windows Firewall, Credential Guard, Application
Control, Windows LAPS, Defender for Servers, AD DS security, and
domain-controller hardening.
Does AZ-802 include troubleshooting questions?
Yes. The exam includes troubleshooting connectivity, DNS, Windows Update,
performance, storage, encryption, Azure Arc extensions, AD replication,
Kerberos, and authentication issues.
What is the AZ-802 passing score?
Microsoft states that a score of 700 or greater is required to pass.
Where can I find the official AZ-802 objectives?
Microsoft's AZ-802 study guide provides the current skills measured and detailed
objectives.
Should I use AZ-802 practice questions while studying?
Practice questions can be used to assess knowledge and identify weak areas, but
they should complement hands-on experience and official Microsoft learning
resources.
Are AZ-802 exam dumps enough to pass the exam?
Memorizing question-and-answer dumps is not a substitute for learning the
underlying Windows Server and hybrid administration skills. Candidates should
combine practice questions with Microsoft's objectives, documentation, and
hands-on experience.