About the Exam

This intermediate Microsoft exam leads to the Windows Server Administrator Associate certification and replaces AZ-800 and AZ-801, which retire on September 30, 2026. Aimed at administrators of on-premises and hybrid Windows Server, it covers AD DS, hybrid workloads, virtual machines, networking, storage and file services, security, and monitoring and troubleshooting. Passing demonstrates Windows Server administration skills with Windows Admin Center, PowerShell and Azure Arc.

Exam Topics

  • Deploy and manage AD DS20–25%
  • Manage Windows Server instances and workloads in a hybrid environment10–15%
  • Manage virtual machines10–15%
  • Implement and manage an on-premises and hybrid networking infrastructure10–15%
  • Manage storage and file services15–20%
  • Secure Windows Server infrastructure10–15%
  • Monitor and troubleshoot Windows Server environments15–20%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated September 2, 2026 at 6:42 PM

Topic filter
Retired questions
Question sort
Questions per page

QuestionQ1

Deploy and manage AD DS

Your network contains an Active Directory Domain Services (AD DS) domain with two domain controllers named DC1 and DC2.

Active Directory Recycle Bin is disabled.

An organizational unit (OU) named Finance and its child objects were deleted from DC1, and the deletion replicated to DC2. DC1 has a system state backup from before the deletion, while changes to other AD DS objects were made after the backup.

You need to recover only the Finance OU and its child objects. The solution must ensure that the recovered objects replicate to DC2 and that unrelated AD DS changes are preserved.

What should you configure?

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Deploy and manage AD DS

Your network contains the Active Directory Domain Services (AD DS) forests shown in the following table.

Question Image

You need to configure trust relationships as shown in the following table.

Question Image

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Yes or No
StatementsYesNo
After both trusts are configured, contoso.com users can access the resources in adatum.com.
A single two-way forest trust between contoso.com and fabrikam.com satisfies the Contoso-Fabrikam access requirement.
A one-way external trust in which research.fabrikam.com trusts adatum.com satisfies the Adatum-Fabrikam access requirements.
Explanation

A forest trust is a transitive trust between the root domains of two forests that, once established, automatically extends to every domain within both forests, so a single two-way forest trust between contoso.com and fabrikam.com allows users in any of contoso.com, europe.contoso.com, and asia.contoso.com to authenticate to (and be authorized for) resources in fabrikam.com or research.fabrikam.com, and vice versa — fully satisfying a requirement that users from any domain in either forest reach authorized resources in any domain of the other forest. Trust relationships do not chain across separate, independently-configured trust boundaries: a forest trust between contoso.com and fabrikam.com and a separate external trust between research.fabrikam.com and adatum.com are two unrelated, non-transitive relationships, so no trust path exists directly between the contoso.com and adatum.com forests. For the narrower requirement that only adatum.com users need access to research.fabrikam.com specifically, a one-way external trust is the correct minimally-scoped tool: external trusts are non-transitive and must be created with the resource domain trusting the account domain, so configuring research.fabrikam.com to trust adatum.com lets adatum.com's users be authorized for resources in research.fabrikam.com without granting access to the rest of either forest.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Deploy and manage AD DS

Your network includes an Active Directory Domain Services (AD DS) domain.

A Group Policy Object (GPO) named Security Baseline is linked to the domain, and its link is configured as Enforced.

A GPO named Kiosk Baseline is linked to an organizational unit (OU) named Kiosks.

Client computers in the Kiosks OU receive Group Policy settings from the Security Baseline GPO.

You need to ensure that computers in Kiosks receive settings from the Kiosk Baseline GPO. Security Baseline must continue to apply to other client computers in the domain.

What should you do?

Explanation

An enforced domain-level GPO cannot be overridden by GPOs linked to lower-level OUs. Clearing Enforced from the Security Baseline link restores normal Group Policy precedence, under which the GPO linked directly to the Kiosks OU is processed later and can override conflicting domain settings for those computers. The Security Baseline GPO remains linked to the domain and therefore still applies to other domain client computers.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Deploy and manage AD DS

Your network contains an Active Directory Domain Services (AD DS) domain called contoso.com.

The domain includes a user named User1 and two global security groups, Group1 and Group2. User1 belongs to both groups.

A Group Policy Object (GPO) named GPO1 is linked to the domain. GPO1 includes the following User Configuration preference items.

Question Image

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Yes or No
StatementsYesNo
If User1 signs in from 10.20.5.20, drive S will be mapped.
If User1 is removed from Group1, after sign in, the user will NOT have drive S in File Explorer.
If User1 signs in to a client computer that does NOT have C:\Program Files\SalesApp\SalesApp.exe, the SalesApp shortcut is created once and is never recreated.
Explanation

Group Policy Preferences item-level targeting evaluates every configured condition with the specified AND/OR logic, applying the preference only when the whole expression is true. The Drive Maps preference targets Group1 AND the IP address range 10.10.0.0 through 10.10.255.255, so both conditions must hold at once; a client signing in from 10.20.5.20 falls outside that range, so the AND expression is false and the drive is not mapped regardless of group membership. Because that preference item has 'Remove this item when it is no longer applied' enabled, its behavior is action-based: once a previously-matching user stops meeting the targeting criteria — for instance, after being removed from Group1 — the Group Policy client-side extension removes the mapping it had previously created the next time policy processes, leaving the user without drive S. The Shortcuts preference targets Group2 OR the presence of the local file C:\Program Files\SalesApp\SalesApp.exe, so membership in Group2 alone satisfies the targeting even when the local executable is absent, and the item applies. Because that preference item has 'Apply once and do not reapply' enabled, the client-side extension creates the shortcut the first time targeting matches and then never reprocesses that item again for the user on any later Group Policy refresh, so the shortcut is created exactly once and is never subsequently recreated, modified, or removed.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Deploy and manage AD DS

Overview

Contoso, Ltd. has a main office in Seattle and two branch offices in Los Angeles and Montreal.

Existing Environment

AD DS Environment

The network includes an on-premises Active Directory Domain Services (AD DS) forest named contoso.com. The forest includes two domains: contoso.com and canada.contoso.com.

The forest includes the domain controllers shown in the following table.

Question Image

All domain controllers are global catalog servers.

Server Infrastructure

The network includes the servers shown in the following table.

Question Image

Server4 runs Windows Server and belongs to a workgroup. Windows Defender Firewall on Server4 uses the private profile.

Server2 hosts three virtual machines named VM1, VM2, and VM3.

VM3 is a file server that stores data in the volumes shown in the following table.

Question Image

Group Policies

The contoso.com domain contains the Group Policy Objects (GPOs) shown in the following table.

Question Image

Existing Identities

The forest includes the users shown in the following table.

Question Image

The forest includes the groups shown in the following table.

Question Image

Current Problems

When an administrator signs in to the VM2 console by using Virtual Machine Connection and disconnects without signing out, another administrator can connect to that console session as the currently signed-in user.

Requirements

Technical Requirements

Contoso identifies the following technical requirements:

  • Change the replication schedule for all site links to 30 minutes.
  • Promote Server1 to a domain controller in canada.contoso.com.
  • Install and authorize Server3 as a DHCP server.
  • Ensure that User1 can manage membership of all groups in Contoso\OU3.
  • Ensure that Server4 can be managed from Server1 by using PowerShell remoting.
  • Ensure that virtual machines can run on VM1.
  • Require users to provide credentials when they connect to VM2.
  • On VM3, enable Data Deduplication on every volume that supports the feature.

You need to meet the technical requirements for Server1.

Which users can currently perform the required tasks?

Explanation

Promoting Server1 as an additional domain controller in canada.contoso.com requires administrative permission in that domain or equivalent forest-level rights. Managing the workgroup Server4 through PowerShell remoting requires administrative rights to configure and use the required remoting settings. Admin1 and Admin3 have the necessary permissions for these Server1 requirements; Admin2 does not. Microsoft documents that installing another domain controller in an existing domain requires Domain Admin credentials, and that changing TrustedHosts/remoting configuration requires local administrator permissions.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home