Windows Server Advanced Administration

3 days (24 hours total)
Focus: advanced AD, security, automation, cluster/HA, PKI, hybrid integration.



Day 1 – Advanced Active Directory & Security

1. AD Replication Deep Dive

Multi-site replication, site links, bridgeheads, troubleshooting lingering objects, USN rollback behavior.

2. Advanced FSMO & Domain Recovery

FSMO seizure, metadata cleanup, authoritative restores, tombstone lifecycle, DC isolation testing.

3. AD Tiered Administration Model

Admin tiering, privileged access workstations, role separation, secure delegation, ESAE principles.

4. Group Policy Advanced

Loopback, AGPM, GPO versioning, advanced filtering, GPO processing analysis, Sysvol migration (DFSR).

5. PKI & Enterprise CA Advanced

AIA/CRL design, OCSP responders, HSM integration basics, cross-forest PKI trust, certificate lifecycle controls.


Day 2 – Networking, Security & Automation

6. DNS Advanced

Conditional forwarders, stub zones, DNSSEC high-level, secure dynamic updates, AD-integrated DNS health.

7. DHCP Advanced

Failover clustering, MAC filtering, superscopes, option inheritance, rogue server detection.

8. Windows Firewall + IPsec

Connection security rules, IPSec negotiation modes, certificate auth, securing server-to-server channels.

9. Windows Server Hardening

CIS templates, secure baselines, LAPS (Legacy + LAPS v2), credential guard, secure bootchain analysis.

10. PowerShell Automation & DSC

Advanced scripting structure, remoting at scale, Just Enough Administration, DSC configurations, partial configs.


Day 3 – Failover, HA, Hybrid & Operations

11. Failover Clustering Advanced

Cluster networking, CSV internals, cluster-aware updating, resource fencing, Stretch cluster fundamentals.

12. Hyper-V Advanced

Nested virtualization, SR-IOV, NUMA tuning, shielded VMs, storage live migration behavior.

13. Storage & SMB Advanced

SMB Direct (RDMA), multi-channel, SOFS, ReFS behavior, S2D conceptual overview.

14. Hybrid Integration (Azure AD + Entra)

Seamless SSO, PTA vs AAD Connect, device writeback, hybrid join, conditional access workflows.

15. Monitoring, Auditing & Forensics

Event forwarding, advanced audit policy, Sysmon, AD change tracking, core incident response flow.