Microsoft Windows Server Hybrid Administrator Associate AZ-801 — Study Guide
Practice as you learn. Every concept maps to real exam questions with verified answers in the Microsoft exam hub, or drill the full exam with timed practice on ExamRoll.io.
This guide covers each AZ-801 domain in depth. Pick a domain to go deep, or work through them in order.
The domains
- Windows Server Security and Hardening — Enable Credential Guard via Group Policy: Computer Configuration > Administrative Templates > System > Device Guard > Turn On Virtualization Based
- Microsoft Defender for Cloud and Endpoint Security — Defender for Servers provides layered protections via two plans: - Plan 1 (approximately $5/server/month, regional variations apply) focuses on
- Microsoft Sentinel and Security Monitoring — Syslog via AMA collects from Linux servers and network devices that speak Syslog. Install AMA on Linux hosts (or a dedicated Linux collector) and
- Active Directory Domain Services Security — The Protected Users security group hardens high‑value accounts by removing legacy and risky authentication behaviors. Members: - Cannot use NTLM,
- Azure Arc and Hybrid Server Management — - Scripted interactive onboarding is the fastest way to start. From the Azure portal, generate the “Add servers” script and run it locally. The
- Encryption, Certificates and PKI — Recovery key governance is mandatory. In AD DS environments, escrow recovery information to computer objects (msFVE-RecoveryInformation) via Group
- Windows Server Update and Patch Management — Approval rules operationalize rings. Automatic approval rules can approve Security Updates (and optionally Critical Updates) immediately for a
- Hyper-V, Virtualization and Storage — Fabric and tenant roles are deliberately separated. Fabric administrators manage hosts, clusters, storage, and networking but are prevented from
- Disaster Recovery and Business Continuity — Hyper-V protection - Replication policy: Defines RPO threshold, recovery point retention, and app-consistent snapshot cadence. For example, set the
- Identity and Access Management for Hybrid Environments — Password writeback extends self-service password reset (SSPR) and password change in the cloud back to on-premises AD. It requires Microsoft Entra ID
Ready to practice?
- Browse every question with verified answers → — free, with explanations.
- Start timed practice tests on ExamRoll.io → — the full question bank, in 20+ languages.
Pass the whole exam — not just this question
You found this answer. Get every verified question and explanation in one place, and save hours of prep. Free to start.
Pass your exam →