AZ-801 Study Guide

Configuring Windows Server Hybrid Advanced Services

267 study sessions ☕ Support
⚠️ Retiring on 2026-09-30 — Replacement: AZ-802
Associate Azure ⚠️ Retiring
📅 Generate a Study Plan
Warning: This exam is retiring on 2026-09-30. Replacement: AZ-802

Exam Quick Facts

DetailValue
Exam CodeAZ-801
TitleConfiguring Windows Server Hybrid Advanced Services
LevelAssociate
Pass Score700 / 1000
Duration100 minutes
Questions~40-60
Cost$165 USD (varies by region)
SchedulingPearson VUE
Skills UpdatedOctober 6, 2025
Retires2026-09-30

Study Resources

ResourceLink
Official Exam PageMicrosoft Learn — AZ-801
Official Study GuideMicrosoft Study Guide
Free Practice AssessmentStart Practice Assessment
Exam SandboxTry the exam interface

Skills at a Glance

Skill AreaWeight
Secure Windows Server on-premises and hybrid infrastructures25-30%
Implement and manage Windows Server high availability15-20%
Implement disaster recovery10-15%
Migrate servers and workloads20-25%
Monitor and troubleshoot Windows Server environments15-20%

Who is this exam for?

This is a Microsoft Azure certification exam. It tests your practical knowledge of Azure services and your ability to implement, manage, and design solutions on the Azure platform. This is an associate-level exam that expects hands-on experience. You should have practical knowledge of the technologies covered.

This exam is retiring on 2026-09-30. The replacement exam is AZ-802. If you’re planning to take this exam, schedule it before the retirement date.


Skills Measured

Secure Windows Server on-premises and hybrid infrastructures (25–30%)

This domain covers infrastructure design and implementation. You need to understand how to architect solutions using the right services and patterns.

Secure Windows Server operating system

  • Configure and manage Exploit Protection
  • Configure and manage Windows Defender Application Control
  • Configure and manage Windows Defender Credential Guard
  • Configure SmartScreen
  • Implement operating system security by using Group Policies
  • Manage Windows Server security baseline by using OSConfig
  • Implement Windows Local Administrator Password Solution (Windows LAPS)

Secure a hybrid Active Directory infrastructure

  • Configure password policies
  • Implement Microsoft Entra Password Protection for AD DS
  • Manage protected users
  • Manage account security on a Read-Only Domain controller (RODC)
  • Harden domain controllers
  • Configure authentication policy silos
  • Restrict access to domain controllers
  • Configure security options for user accounts
  • Configure security options for built-in administrative groups
  • Manage AD delegation
  • Implement and manage Microsoft Defender for Identity
  • Audit usage of and disable NTLM

Identify and remediate Windows Server security issues by using Azure services

  • Implement ingestion of Windows Server data into Microsoft Sentinel
  • Manage security for Windows Server by using Microsoft Defender for Cloud
  • Manage security for Windows Server by using Microsoft Defender for Servers

Secure Windows Server networking

  • Manage Windows Defender Firewall
  • Implement domain isolation
  • Implement connection security rules
  • Create and configure network security groups (NSGs) for Windows Server virtual machines on Azure

Secure Windows Server storage

  • Manage Windows BitLocker Drive Encryption
  • Enable storage encryption by using Azure Disk Encryption
  • Manage and recover encrypted volumes
  • Manage disk encryption keys for IaaS virtual machines

Implement and manage Windows Server high availability (15–20%)

This domain covers the skills needed to work with the topics described below. Study each objective carefully and use the linked resources to deepen your understanding.

Implement a Windows Server failover cluster

  • Implement a failover cluster on-premises, hybrid, or cloud-only
  • Create a Windows failover cluster, including workgroup clusters
  • Implement a stretch cluster across datacenters or Azure regions, including Storage Spaces Direct (S2D) campus clusters
  • Configure storage for failover clustering
  • Modify quorum options
  • Configure network adapters for failover clustering
  • Deploy host networking with Network ATC
  • Configure cluster workload options
  • Configure Scale-Out File servers
  • Configure an Azure witness
  • Configure a floating IP address for the cluster

Manage failover clustering

  • Implement cluster-aware updating
  • Recover a failed cluster node
  • Upgrade failover cluster nodes
  • Failover workloads between nodes
  • Install Windows updates on cluster nodes
  • Manage failover clusters using Windows Admin Center

Implement and manage Storage Spaces Direct

  • Upgrade an S2D node
  • Implement networking for S2D
  • Configure S2D

Implement disaster recovery (10–15%)

This domain covers business continuity, backup, and disaster recovery. You need to understand how to design solutions that keep services running when things go wrong.

Manage backup and recovery for Windows Server

  • Back up and restore files and folders to Azure Recovery Services Vault
  • Deploy and manage Azure Backup Server
  • Back up and recover using Azure Backup Server
  • Manage backups in Azure Recovery Services Vault
  • Create an Azure Recovery Services vault backup policy
  • Configure backup for Azure VM using the built-in backup agent
  • Recover a VM using instant recovery snapshots
  • Recover VMs to new Azure VMs
  • Restore a VM, including encrypted VMs

Implement disaster recovery by using Azure Site Recovery

  • Configure Azure Site Recovery network mapping
  • Configure Site Recovery for on-premises servers
  • Configure a recovery plan in Azure Site Recovery
  • Configure Site Recovery for Azure VMs
  • Implement VM replication to secondary datacenter or Azure region
  • Configure Azure Site Recovery replication policies

Protect virtual machines by using Hyper-V replicas

  • Configure Hyper-V hosts for replication
  • Manage Hyper-V replica servers
  • Configure VM replication
  • Perform a failover

Migrate servers and workloads (20–25%)

This domain covers workload management and implementation. You need to understand the specific workload requirements and how to configure solutions to meet them.

Migrate on-premises storage to on-premises servers or Azure

  • Transfer files, file shares, and security configurations by using Storage Migration Service (SMS)
  • Cut over to a new server by using Storage Migration Service (SMS)
  • Use Storage Migration Service to migrate to Azure VMs
  • Migrate to Azure file shares

Migrate on-premises servers by using Azure Migrate

  • Deploy and configure Azure Migrate appliance
  • Migrate VM workloads to Azure VMs
  • Migrate physical servers to Azure VMs

Migrate workloads from previous Windows Server versions to the most current version

  • Choose an appropriate migration method
  • Migrate IIS workloads and configurations
  • Migrate Hyper-V hosts
  • Migrate Remote Desktop Services (RDS) host servers
  • Migrate Dynamic Host Configuration Protocol (DHCP) servers
  • Migrate print servers
  • Migrate by using an in-place upgrade

Migrate IIS workloads to Azure

  • Assess IIS workloads by using Azure Migrate
  • Migrate IIS workloads to Azure Web Apps
  • Migrate IIS workloads to containers

Migrate an on-premises AD forest to Windows Server 2025

  • Choose an appropriate migration method
  • Implement a forest restructure
  • Migrate AD DS objects, including users, groups and Group Policies using AD Migration Tool
  • Migrate to a new Active Directory forest
  • Upgrade an existing forest, including setting functional levels

Monitor and troubleshoot Windows Server environments (15–20%)

This domain covers monitoring and maintenance. You need to know how to use monitoring tools, configure alerts, and implement backup and recovery solutions.

Monitor Windows Server by using Windows Server tools and Azure services

  • Monitor Windows Server by using Performance Monitor
  • Create and configure Data Collector Sets
  • Monitor servers and configure alerts by using Windows Admin Center
  • Analyze Windows Server system data by using System Insights
  • Manage event logs
  • Configure data collection rules for Azure Monitor
  • Create alerts
  • Monitor Azure VM performance by using VM Insights

Troubleshoot Windows Server issues

  • Troubleshoot connectivity
  • Troubleshoot name resolution
  • Troubleshoot Windows Update
  • Troubleshoot Time Service
  • Troubleshoot deployment failures
  • Troubleshoot booting failures
  • Troubleshoot performance issues
  • Troubleshoot VM and Azure Arc extension issues
  • Troubleshoot disk encryption issues
  • Troubleshoot storage

Troubleshoot Active Directory

  • Restore objects from AD recycle bin
  • Recover Active Directory database using Directory Services Restore mode
  • Recover system volume (SYSVOL)
  • Troubleshoot Active Directory replication
  • Troubleshoot hybrid authentication and synchronization issues
  • Troubleshoot on-premises Active Directory

What to Study Next

Based on this exam, here are related certifications to consider:


🧭 How does AZ-801 compare across AWS & Google Cloud?

See closest matches, skill overlap, and cost comparison with our Multi-Cloud Cert Compass.

Open Cert Compass →
💬