Administer Active Directory Domain Services

This learning path helps prepare you for the APL-1008 Administer Active Directory Domain Services modern credential. You'll learn how to create, deploy, and maintain an Active Directory Domain Services environment.

Prerequisites

Knowledge of and experience working with:

  • Windows Server.
  • Core networking technologies.

Modules in this learning path

This module introduces you to the topology of domain controllers within an Active Directory environment. It also starts you down the path of deploying, managing, and migrating a domain controller between servers.

This module covers how to create and manage the core objects in Active Directory Domain Services (AD DS). You learn how to create and configure user accounts, security groups, organizational units (OUs), and managed service accounts including group managed service accounts (gMSA). You also perform bulk management tasks such as moving accounts and forcing password resets, and maintain domain controller availability through multi-master replication, Active Directory Recycle Bin, and authoritative and nonauthoritative restore operations.

This module focuses on Group Policy objects, including using them to enforce a domain wide as well as fine-grained password policy.

This module covers how to manage security in an Active Directory Domain Services (AD DS) environment. You learn how to configure user account rights following the principle of least privilege, restrict privileged accounts from dangerous sign-in methods, delegate AD permissions to non-administrative users for tasks like password resets, add accounts to the Protected Users group to prevent credential caching and enforce Kerberos-only authentication, deploy Windows Defender Credential Guard to isolate credentials against Pass-the-Hash and Pass-the-Ticket attacks, block legacy NTLM authentication in favor of Kerberos, and find and remediate problematic accounts including inactive users and accounts with non-expiring passwords.

This guided project helps prepare you to manage Active Directory Domain services, including:

  • Creating and deploying domains.
  • Configuring group policy objects.
  • Establishing and enforcing passwords.
  • Maintaining security of Active Directory.

Note

This is a Guided Project module where you’ll complete an end-to-end project by following step-by-step instructions.