Monitor and troubleshoot Windows Server environments

At a glance

This learning path covers how to monitor and troubleshoot Windows Server environments. You learn how to use Performance Monitor, Event Viewer, and auditing tools to track server health and compliance, and extend monitoring into Azure with Azure Monitor and VM Insights. You also troubleshoot on-premises and hybrid networking issues including DHCP, DNS, and routing, manage server updates with WSUS and Azure Update Management, and troubleshoot Active Directory including replication failures, Group Policy processing, and hybrid authentication.

This learning path helps you prepare for Exam AZ-802: Administering Windows Server.

Prerequisites

  • Experience administering Windows Server operating systems
  • Familiarity with Active Directory Domain Services (AD DS) and core networking technologies
  • Basic knowledge of PowerShell and Azure monitoring services

Modules in this learning path

This module covers how to monitor Windows Server performance and plan for capacity. You learn how to use Performance Monitor for real-time and historical analysis with built-in and custom counters, use Resource Monitor for process-level CPU, disk, network, and memory tracking, establish performance baselines and implement trend analysis, create custom data collector sets with performance counters and event traces, monitor DNS, DHCP, and Hyper-V infrastructure using Resource Metering, and use Windows Admin Center and System Insights for performance monitoring and capacity forecasting.

This module covers how to manage and monitor event logs in Windows Server. You learn how to use Event Viewer to review application, security, system, and role-specific logs, review events across multiple servers using Windows Admin Center and Server Manager, create custom views that filter events by time, level, event ID, user, and computer across multiple logs, and configure event subscriptions using collector-initiated and source-initiated modes with WinRM for centralized event collection.

This module covers how to implement auditing and diagnostics in Windows Server for compliance and security. You learn how to configure the nine basic audit policy categories including account logon, object access, and privilege use, implement advanced auditing with granular policy settings for precise event tracking, use User Access Logging (UAL) to quantify unique client requests for installed server roles, and enable Setup and Boot Event Collection to monitor startup, driver loading, and system readiness events.

This module covers how to monitor Windows Server IaaS virtual machines and hybrid instances using Azure Monitor. You learn how to enable Azure Monitor for VMs with Log Analytics workspaces and the Dependency Agent for service maps, monitor VM performance, health, and dependencies through the Azure portal, configure Azure Monitor in hybrid scenarios to extend monitoring to on-premises servers using the Log Analytics agent, collect monitoring data from Windows computers in hybrid environments, and integrate Azure Monitor with Microsoft Operations Manager for organizations using existing System Center investments.

Learn how to monitor your Azure VMs by using Azure Monitor to collect and analyze VM host and client metrics and logs.

This module covers how to troubleshoot on-premises and hybrid networking issues in Windows Server. You learn how to diagnose DHCP problems including server authorization, scope availability, and relay agent configuration, troubleshoot DNS issues including zone data accuracy and AD DS replication, apply a structured IP troubleshooting methodology to isolate connectivity problems, understand routing tables and traffic delivery between networks and subnets, use Packet Monitor to intercept and analyze network packets at multiple stack levels, and use Azure Network Watcher to diagnose and log metrics for virtual networks and IaaS resources.

This module covers how to troubleshoot Windows Server virtual machines hosted in Azure. You learn how to diagnose provisioning failures and allocation errors, use boot diagnostics with screenshots and serial logs to identify startup problems, check VM Agent status and extension provisioning state using PowerShell, troubleshoot RDP and SSH connectivity via the Azure portal and test connection tools, monitor VM performance using Performance Monitor, Windows Admin Center, and System Insights, and understand Azure storage tiers and managed vs. unmanaged disk approaches.

This module covers how to manage updates for Windows Server using WSUS and Azure Automation Update Management. You learn how to deploy WSUS in various topologies including single server, server hierarchies, and disconnected environments, follow the four-phase update management process (assess, identify, evaluate and plan, deploy), configure computer groups and approval rules for staged update deployments, and extend update management to cloud and hybrid environments using Azure Automation Update Management with the Log Analytics agent.

This module covers how to troubleshoot Active Directory Domain Services (AD DS) and hybrid authentication issues. You learn how to recover deleted objects using tombstone reanimation with Ldp.exe or Active Directory Recycle Bin, manage and recover the AD DS database (Ntds.dit) using NtdsUtil, perform authoritative restore of SYSVOL for Group Policy recovery, troubleshoot AD DS replication across domain, configuration, schema, and application partitions, and diagnose hybrid authentication issues with Microsoft Entra Connect including directory synchronization, password hash sync, and pass-through authentication.