Index

A

access-denied assistance, 247

Active Directory Domains and Trusts, 6

Active Directory Federation Services, 74

Active Directory Recycle Bin, 1213

Active Directory Sites and Services, 6

Active Directory Users and Computers, 5

Delegation of Control Wizard, 5

tasks, 5

View Advanced Features function, 5

Active Directory-integrated zones, 186187

AD DS (Active Directory Domain Services), 1, 9. See also Azure AD; domain(s)

backup, 10

database optimization, 2021

DNS integration, 186, 188, 192

Active Directory-integrated zones, 186187

alias (CNAME) records, 191

conditional forwarders, 193

forwarders, 192193

GlobalNames zones, 189190

host records, 190

MX (mail exchanger) records, 191

pointer records, 191

resource records, 190, 194195

reverse lookup zones, 188189

scavenging, 192

secondary zones, 188

stub zones, 193

unknown records, 191

zone aging, 191192

zone delegation, 190

domain(s), 1617

authentication and, 18

controllers, 12, 67

forests and, 1920

functional levels, 19

trees and, 18

DSRM (Directory Services Restore Mode), 78

forests, 16

Group Policy, 83. See also AGPM (Advanced Group Policy Management); Group Policy

Administrative template, 9293

caching, 91

fixing GPO problems, 8586

forced update, 9192

GPO backup, 8485

GPO management, 8385, 86

implementing, 95

import and copy GPOs, 85

loopback processing, 9091

preferences, 9394

security filtering, 8990

WMI filters, 90

groups, 47

integration with other AD instances, 71

metadata cleanup, 21

multi-domain forests, 1718

partitions, 41

password(s)

managing, 7475

policy items, 75

replication, 2425

settings permissions, 76

replication, 41

conflict resolution, 43

KCC (Knowledge Consistency Checker), 42

managing and monitoring, 44

multi-master, 42

RODC, 4344

store and forward, 42

triggering, 44

security, 45

site(s), 3537

creating, 3738

link bridges, 40

links, 3940

subnets, 38

snapshots, 22

tombstone lifetime, 1012

trust(s), 29, 30

direction, 3031

external, 32

forest, 3132

name suffix routing, 35

netdom.exe and, 34

realm, 33

shortcut, 32

SID filtering, 3435

transitivity, 30

ADAC (Active Directory Administrative Center), 3

Powershell and, 3

search functionality, 34

Add-Clusternode cmdlet, 257

Add-Computer cmdlet, 52

Add-DhcpServer4Filter cmdlet, 209

Add-DHCPServer4Scope cmdlet, 205

Add-DHCPServer6Scope cmdlet, 205

Add-DhcpServerv4SuperScope cmdlet, 206

Add-DNSPrimaryZone cmdlet, 189

Add-DnsServerConditionalForwarderZone cmdlet, 193

Add-DNSServerDirectoryPartition cmdlet, 187

Add-DnsServerPrimaryZone cmdlet, 187

Add-DNSServerQueryResolutionPolicy cmdlet, 199

Add-DNSServerSecondaryZone cmdlet, 188

Add-DnsServerStubZone cmdlet, 193

Add-DnsServerZoneDelegation cmdlet, 190

ADDomainMode cmdlet, 19

Add-VMAssignableDevice cmdlet, 134

administration tools, Windows Server, 100

jump servers, 101

PAWs (Privileged Access Workstations), 100101

remote access and, 100

Remote Desktop, 101102

WAC (Windows Admin Center), 102105

AGPM (Advanced Group Policy Management), 8889

alias (CNAME) records, 191

ARM (Azure Resource Manager), templates, 53

assessment, Windows update compliance, 119

authentication

intra-forest, 18

NPS and, 223

pass-through, 74

on-premises environments and, 73

VPN, 213214

authoritative restore, 1315

Azure AD, 1, 2. See also domain controllers

Application Proxy, 229230

Connect Health, 72

deleted items, restoring, 15

Active Directory Recycle Bin, 1213

AD DS (Active Directory Domain Services), 10

authoritative restore, 1315

non-authoritative restore, 15

integration with other AD instances, 71

managing, 23

using Active Directory Domains and Trusts, 6

using AD sites and Services, 6

using AD Users and Computers, 5

using ADAC (Active Directory Administrative Center), 34

Password Protection, 82

Azure AD Connect, 5455

cloud sync, 67

installing, 5863

requirements, 5657

deployment account, 5758

SQL Server, 57

synchronization, 6567

Azure AD DS

deploying, 6870

domain join, 70

integration with other AD instances, 71

managing, 68

Azure App Service Hybrid Connections, 230231

Azure Arc, 114

connecting to Windows Server instances, 115116

deployment, 115116

functionality, 114115

Azure Automation

Hybrid Runbook Worker, 123124

runbooks, 123

State Configuration, 124

Azure Bastion, connecting to IaaS VMs, 178

Azure DNS, integrating with Windows Servers DNS, 193194

Azure ExpressRoute, 228229

Azure Extended Network, 219220

Azure File Sync, 233

cloud endpoints, creating, 235

cloud tiering, 237

migrating DFS to, 234239

monitoring, 234238

server endpoints, creating, 236

server registration, 235236

storage sync service, deploying, 234

sync groups, creating, 234235

Azure Monitor, 120

agent, 121

Azure File Sync and, 234238

data collection, 120

installing, 121

Log Analytics workspace, 120

Azure Network Adapter, 219

Azure Policy guest configuration, 116117

Azure Relay, 227228

Azure Serial Console, connecting to IaaS VMs, 179

Azure Virtual WAN, 229

B

backup and restore, 1012

Active Directory Recycle Bin, 1213

AD DS (Active Directory Domain Services), 10

authoritative restore, 1315

checkpoints and, 137

GPOs, 8485

non-authoritative restore, 15

bandwidth management, Hyper-V, 155

basic disks, 252

BranchCache, 247248

C

checkpoints, 136137, 153

cloning, virtual domain controllers, 16

cloud endpoints, creating, 235

Cloud Shell, 122

cloud sync, 67

cloud tiering, 237

cmdlets, 3

Add-Clusternode, 257

Add-Computer, 52

Add-DhcpServer4Filter, 209

Add-DHCPServer4Scope, 205

Add-DHCPServer6Scope, 205

Add-DhcpServerv4SuperScope, 206

Add-DNSPrimaryZone, 189

Add-DnsServerConditionalForwarderZone, 193

Add-DNSServerDirectoryPartition, 187

Add-DnsServerPrimaryZone, 187

Add-DNSServerQueryResolutionPolicy, 199

Add-DNSServerSecondaryZone, 188

Add-DnsServerStubZone, 193

Add-DnsServerZoneDelegation, 190

ADDomainMode, 19

Add-VMAssignableDevice, 134

checkpoint-related, 136137

DNSServerCache, 197

Enable-PSRemoting, 106107, 129

Enter-PSSession, 107, 129, 130

Get-ADTrust, 34

Get-Command-Module <modulename>, 106

Get-NetAdapter, 131

Get-PSSessionConfigurationFile, 113

Get-SRPartnership, 260

Get-StoragePool, 254

getting help with, 106

GPO management, 84

Install-ADDSForest, 9

Install-ADServiceAccount, 49

Invoke-Command, 108

Move-ADDirectoryServer, 40

New-ADDCCloneConfig, 16

New-ADReplicationSiteLink, 40

New-ADReplicationSubnet, 38

New-AzADServicePrincipal, 115116

New-NetNAT, 131

New-StorageQosPolicy, 262

New-VMSwitch, 131

Register-PSSessionConfiguration, 113

Set-ADComputer, 50

Set-ADForestMode, 20

Set-ADObject, 9

Set-DhcpServerv4DnsSetting, 207

Set-PhysicalDisk, 254

Set-SRPartnership, 260

Test-SRTopology, 259

Uninstall-ADDSDomainController, 21

commands

Docker, 160

docker load, 166

docker rmi, 166

docker run, 167, 169

docker save, 166

docker tag, 166

get-credential, 107

netdom trust, 34

compliance, Windows update, 119

computer accounts, 47

conditional forwarders, 193

conflict resolution, 43

connection request policies, 220

creating, 224

default, 223224

Realm and RADIUS attributes, 223

consoles, 23

Active Directory Domains and Trusts, 6

Active Directory Sites and Services, 6

Active Directory Users and Computers, 5

Delegation of Control Wizard, 5

tasks, 5

View Advanced Features function, 5

ADAC (Active Directory Administrative Center), 3

Powershell and, 3

search functionality, 34

constrained delegation, 108

container(s), 158. See also Docker

host, 159

Hyper-V isolation, 160

image dependency, 159

images, 158159

creating, 171172

managing, 166

updating, 165166

Windows Server, 163164

instance, 159, 167168

modifying, 168

networking, 168169

Layer 2 Bridge mode, 171

NAT, 169170

transparent mode, 170

process isolation, 160

registries, 159, 163

sandbox, 159

Windows, service accounts, 164165

continuous delivery, IaaS VMs and, 176

copying, VMs, 153

core scheduler, Hyper-V, 135136

CPU groups, 135

creating

Azure File Sync endpoints, 236

cloud endpoints, 235

connection request policies, 224

container images

from a container, 171

using Dockerfiles, 171172

container instance, 167168

GPOs, 8687

network policies, 225227

shared folders, 240

site links, 3940

sites, 3738

sync groups, 234235

CSVs (Cluster Shared Volumes), 143

D

DANE (DNS-based Authentication of Named Entities), 198

data disks, 174

DDA (Discrete Device Assignment), 133134

decommissioning RODCs, 2627

deduplication, 152, 260261

defragmentation, Active Directory database, 2021

delegation, 108

Delegation of Control Wizard, Active Directory Users and Computers, 5

deployment

Azure Arc, 115116

domain controller, 67

global catalog servers, 910

Server Core, 89

virtualized, 9

IPAM, 200

Windows updates, 118119

detached clusters, 143144

DFS (Distributed File System), 248

namespace, 249250

replication, 234239, 250

groups, 250251

replicated folders and targets, 250

schedules, 251

DHCP (Dynamic Host Configuration Protocol)

failover, 209

filtering, 208209

name protection, 207

policies, 208

relay, 207208

scopes, 204206

multicast, 206

split, 207

super, 206

server options, 205206

server role, deploying, 203204

differencing disks, 149

DirectAccess, 216

NLS (Network Location Server), 218219

server, 217218

topologies, 216217

Directory Services Restore Mode, authoritative restore, 1415

disks. See also storage

basic, 252

dynamic, 252

partitions, 252

thin-provisioned, 254255

DNS (Domain Name System), 186, 188, 192. See also IPAM

cache locking, 197

conditional forwarders, 193

DANE (DNS-based Authentication of Named Entities), 198

forwarders, 192193

netmask ordering, 197

policies, 199

records

alias (CNAME), 191

host, 190

MX (mail exchanger), 191

pointer, 191

resource, 190, 194195

unknown, 191

recursion, 197

response rate limiting, 198

scavenging, 192

socket pool, 196

spoofing, 196

Windows Server, event logs, 196

zone(s)

Active Directory-integrated, 186187

aging, 191192

delegation, 190

GlobalNames, 189190

reverse lookup, 188189

secondary, 188

stub, 193

DNSSEC (Domain Name System Security Extensions), 194195

DNSServerCache cmdlet, 197

Docker, 160

commands, 160

daemon.json file, 161163

installing, 160161

docker load command, 166

docker rmi command, 166

docker run command, 167, 169

docker save command, 166

docker tag command, 166

Dockerfiles, 171172

domain controllers, 12

deploying, 67

domain names and, 67

FMSO roles, 2627

domain naming master, 27

infrastructure master, 28

PDC emulator, 28

RID master, 28

schema master, 27

seizing, 29

global catalog servers, 910

installing, from media, 8

KCC (Knowledge Consistency Checker), 42

moving, 40

physical security, 24

read-only, 24

decommissioning, 2627

local administrators, 26

password replication, 2425

replication, 4344

Server Core deployment, 89

USNs (update sequence numbers), 43

virtual, 9, 16, 23

domain local groups, 48

domain(s), 1617

computer accounts and, 47

forests, 1718, 1920

functional levels, 19

joining, 70

trees, 17, 18

trust(s), 30

direction, 3031

external, 32

forest, 3132

name suffix routing, 35

netdom.exe and, 34

realm, 33

shortcut, 32

SID filtering, 3435

transitivity, 29

DSC (Desired State Configuration), 124

dynamic

disks, 252

memory, 131, 132

quorum, 142

Dynamic Virtual Machine Queue, 156

E

editing, GPOs, 87

Enable-PSRemoting cmdlet, 106107, 129

encryption

IaaS VMs, 175

NPS and, 224225

endpoints

Azure File Sync, creating, 236

cloud, 235

JEA, 109, 112113

Enhanced Session Mode, 130

Enter-PSSession cmdlet, 107, 129, 130

ESAE (Enhanced Security Administrative Environment), forests, 20

event logs, DNS, 196

exporting, VMs, 153

extensions

Azure VM, 117118

Extended Network, 220

WAC (Windows Admin Center), 104

external switches, 157

external trusts, 32

F

failover

clustering, 140

Active Directory detached clusters, 143144

cluster networking, 142143

cluster node weight, 142

cluster quorum, 141

Cluster Shared Volumes, 143

dynamic quorum, 142

Force Quorum Resiliency, 143

guest clusters, 145147

host cluster storage, 140

preferred owner and failover settings, 144

VM drain on shutdown, 144145

VM Network Health Detection, 144

DHCP, 209

replica, 139140

fan-out administration, 107

FAT/FAT32, 265

file classification, 245246

file screen(s), 241

file groups and, 241242

templates, 243

filesystems

FAT/FAT32, 265

NTFS, 263264

ReFS, 264265

fine-grained password policies, 7677

FMSO roles, 2627

domain naming master, 27

infrastructure master, 28

PDC emulator, 28

RID master, 28

seizing, 29

forests, 16, 1920

authentication and, 18

ESAE (Enhanced Security Administrative Environment), 20

multi-domain, 1718

trusts and, 3132

forwarders, 192193

FSRM (File Server Resource Manager)

access-denied assistance, 247

file classification, 245246

file management tasks, 246

quotas, 243244

storage reports, 244245

G

gateway server, 103

Generation 2 VMs, 128129

Get-ADTrust cmdlet, 34

Get-Command-Module <modulename> cmdlet, 106

get-credential command, 107

Get-NetAdapter cmdlet, 131

Get-PSSessionConfigurationFile cmdlet, 113

Get-SRPartnership cmdlet, 260

Get-StoragePool cmdlet, 254

global catalog servers, 910

global groups, 48

GlobalNames zones, 189190

GMSAs (group managed service accounts), 48, 4950, 164165

GPMC (Group Policy Management Console), 8385

Group Policy, 83, 95, 247. See also AGPM (Advanced Group Policy Management)

Administrative template, 9293

caching, 91

DNSSEC and, 195

forced update, 9192

GPOs

backing up, 8485

creating, 8687

editing, 87

import and copy, 85

linking, 87

managing, 8385, 86

troubleshooting, 8586

loopback processing, 9091

Modeling Wizard, 87

policy enforcement and blocking, 8889

preferences, 9394

Results, 88

security filtering, 8990

WMI filters, 88, 90

groups, 47

domain local, 48

global, 48

universal, 47

guest clusters, 145

shared virtual hard disk, 146

storage, 145146

VHD Sets, 147

H

high availability

DHCP, 209

Hyper-V failover clusters, 140

Active Directory detached clusters, 143144

cluster networking, 142143

cluster node weight, 142

cluster quorum, 141

Cluster Shared Volumes, 143

dynamic quorum, 142

Force Quorum Resiliency, 143

host cluster storage, 140

preferred owner and failover settings, 144

VM drain on shutdown, 144145

VM Network Health Detection, 144

Hyper-V guest clusters, 145

shared virtual hard disk, 146

storage, 145146

VHD Sets, 147

Hyper-V live migration, 147148

Hyper-V Replica, 137138

Broker, 139140

configuring replica servers, 138

configuring VM replicas, 138139

replica failover, 139140

host records, 190

HVC.exe, VM management, 130

hybrid workloads, Azure Automation and, 123124

Hyper-V, 127, 128

checkpoints, 136137

CPU groups, 135

Enhanced Session Mode, 130

failover clusters, 140

Active Directory detached clusters, 143144

cluster networking, 142143

cluster node weight, 142

cluster quorum, 141

Cluster Shared Volumes, 143

dynamic quorum, 142

Force Quorum Resiliency, 143

host cluster storage, 140

preferred owner and failover settings, 144

VM drain on shutdown, 144145

VM Network Health Detection, 144

guest clusters, 145

shared virtual hard disk, 146

storage, 145146

VHD Sets, 147

integration services, 133

isolation, 160

live migration, 147148

nested virtualization, 130131

dynamic memory, 131

networking, 131

network adapter

network isolation, 155

NIC teaming, 156

VM MAC address and, 154155

optimizing network performance, 155

bandwidth management, 155

Dynamic Virtual Machine Queue, 156

SR-IOV, 155156

Replica, 137138

Broker, 139140

configuring replica servers, 138

configuring VM replicas, 138139

failover, 139140

scheduling types, 135136

smart paging, 132133

storage optimization

deduplication, 152

storage migration, 152153

storage tiering, 152

virtual hard disks

differencing disks, 149

dynamically expanding disks, 149

fixed-size disks, 149

formats, 148

modifying, 150

pass-through disks, 150151

Storage QoS, 151

Virtual Fibre Channel adapters, 151

virtual switches, 156

external, 157

internal, 157

private, 157

I

IaaS VMs, 173

configuring continuous delivery, 176

connecting

with Azure AD account, 176177

JIT access, 178

with Remote PowerShell, 177178

using Azure Bastion, 178

using Azure Serial Console, 179

using Windows Admin Center, 178

data disks, 174

encryption, 175

images, 174

IP addressing, 180181

managing, 122123

NSGs and, 181

RBAC roles, 173174

resizing, 175176

shared disks, 174

snapshots, 175

virtual networks, 179180, 181

identities, hybrid, 54

IKEv2, 214215

importing, VMs, 153

inactive accounts, 82

infrastructure master, 28

Install-ADDSForest cmdlet, 9

Install-ADServiceAccount cmdlet, 49

installing

Azure AD Connect, 5863

Azure Monitor, 121

BranchCache, 247

Docker, 160161

domain controllers, 8

WAC (Windows Admin Center), 103104

integration services, 133

internal switches, 157

intra-forest authentication, 18

Invoke-Command cmdlet, 108

IP addressing

IaaS VMs and, 180181

reservations, 208

troubleshooting, 204

IPAM, 200

administration, 201202

deployment, 200

IP address

space management, 202

tracking, 202203

server discovery, 201

IPsec, 215

J

JEA (Just Enough Administration), 109

endpoints, 112113

role-capability files, 110111

session-configuration files, 111112

JIT (Just-in-Time) VM access, 178

joining

domains, 70

Windows Server to an Active Directory instance, 5253

jump servers, 101

K

KCC (Knowledge Consistency Checker), 42

Kerberos

delegation, 50, 108

policies, 5152

SPNs (service principal names), 52

L

L2TP, 215

LAN routing, 215

Layer 2 Bridge networks, 171

linking GPOs, 87

Linux

integration services, 133

VMs (virtual machines), HVC.exe and, 130

live migration, 147148

local administrators, RODC, 26

Local Service (NT AUTHORITYLocalService) account, 48

Local System (NT AUTHORITYSYSTEM) account, 48

lockout policies, 79, 81

Log Analytics, integrating with Windows Servers, 120121

M

MAC address, VM, 153154

managing. See also administration tools

AD DS passwords, 7475

Azure AD, 23

using Active Directory Domains and Trusts, 6

using AD sites and Services, 6

using AD Users and Computers, 5

using ADAC (Active Directory Administrative Center), 34

container images, 166

GMSAs (group managed service accounts), 49

IaaS VMs, 122123

VMs

using HVC.exe, 130

using PowerShell Direct, 130

using PowerShell remoting, 129

Windows Server instances, 113116

Windows updates, 119

memory

dynamic, 132

nested virtualization and, 131

smart paging and, 132133

Startup, 132133

Microsoft Defender for Cloud, integrating with Windows Servers, 121122

Microsoft Exchange Server, 2

modifying

containers, 168

virtual hard disks, 150

modules, PowerShell, 106

monitoring

Azure File Sync, 234238

replication, 44

Move-ADDirectoryServer cmdlet, 40

moving, domain controllers, 40

multi-domain forests, 1718

multi-master replication, 42

MX (mail exchanger) records, 191

N

name suffix routing, 35

NAT (network address translation), 169170, 216

nested resiliency, 256

nested virtualization, 130131

dynamic memory, 131

networking, 131

netdom trust command, 34

netdom.exe, 34

network adapters, Hyper-V

network isolation, 155

NIC teaming, 156

VM MAC address and, 153154

Network Service (NT AUTHORITYNetworkService) account, 49

networking, containers, 168169

Layer 2 Bridge mode, 171

NAT, 169170

transparent mode, 170

New-ADDCCloneConfig cmdlet, 16

New-ADReplicationSiteLink cmdlet, 40

New-ADReplicationSubnet cmdlet, 38

New-AzADServicePrincipal cmdlet, 115116

New-NetNAT cmdlet, 131

New-StorageQosPolicy cmdlet, 262

New-VMSwitch cmdlet, 131

NIC teaming, 156

NLS (Network Location Server), 218219

non-authoritative restore, 15

non-Azure machines, deploying Azure services on, 117118

nonexpiring passwords, 8081

NPS (Network Policy Server), 211, 220, 221. See also RADIUS servers

authentication, 223

connection request forwarding, 222

connection request policies, 220

default, 223224

Realm and RADIUS attributes, 223

encryption, 224225

IP filters, 224

IP settings, 225

network policies, creating, 225227

policy conditions, 221222

templates, 227

NSGs (network security groups), IaaS VMs and, 181

ntdsutil.exe, 21

metadata cleanup, 21

snapshots, 22

NTFS, 263264

O-P

one-to-many remoting, 107

one-way trust, 6

partitions, 41, 252

pass-through

authentication, 74

disks, 150151

password(s)

DSRM (Directory Services Restore Mode), 78

lockout settings, 79

managing, 7475

nonexpiring, 8081

policies, 75, 76, 7879

protection, 82

replication, 2425

settings permissions, 76

synchronization, 7374

PAWs (Privileged Access Workstations), 100101

PDC emulator, 28

permissions, 201202

NTFS, 263264

password, 76

Windows update deployment, 119

physical security, domain controllers and, 24

pointer records, 191

policy(ies). See also Group Policy

BranchCache, 247248

conditions, 221222

connection request, 220

creating, 224

default, 223224

Realm and RADIUS attributes, 223

DHCP, 208

DNS, 199

Kerberos, 5152

lockout, 79, 81

network, creating, 225227

password, 75, 76, 7879

PowerShell

cmdlets, 3

Add-Clusternode, 257

Add-Computer, 52

Add-DhcpServer4Filter, 209

Add-DHCPServer4Scope, 205

Add-DHCPServer6Scope, 205

Add-DhcpServerv4SuperScope, 206

Add-DNSPrimaryZone, 189

Add-DnsServerConditionalForwarderZone, 193

Add-DNSServerDirectoryPartition, 187

Add-DnsServerPrimaryZone, 187

Add-DNSServerQueryResolutionPolicy, 199

Add-DNSServerSecondaryZone, 188

Add-DnsServerStubZone, 193

Add-DnsServerZoneDelegation, 190

ADDomainMode, 19

Add-VMAssignableDevice, 134

checkpoint-related, 136137

DNSServerCache, 197

Enable-PSRemoting, 106107, 129

Enter-PSSession, 107, 129, 130

Get-ADTrust, 34

Get-Command-Module <modulename>, 106

Get-NetAdapter, 131

Get-PSSessionConfigurationFile, 113

Get-SRPartnership, 260

Get-StoragePool, 254

getting help with, 106

GPO management, 84

Install-ADDSForest, 9

Install-ADServiceAccount, 49

Invoke-Command, 108

Move-ADDirectoryServer, 40

New-ADDCCloneConfig, 16

New-ADReplicationSiteLink, 40

New-ADReplicationSubnet, 38

New-AzADServicePrincipal, 115116

New-NetNAT, 131

New-StorageQosPolicy, 262

New-VMSwitch, 131

Register-PSSessionConfiguration, 113

Set-ADComputer, 50

Set-ADForestMode, 20

Set-ADObject, 9

Set-DhcpServerv4DnsSetting, 207

Set-PhysicalDisk, 254

Set-SRPartnership, 260

Test-SRTopology, 259

Uninstall-ADDSDomainController, 21

Direct, VM management, 130

Gallery, 106

GMSA management, 49

JEA (Just Enough Administration), 109

endpoints, 112113

role-capability files, 110111

session-configuration files, 111112

modules, 106

remoting, 106108

IaaS VMs and, 177178

VM management, 129

WAC (Windows Admin Center) and, 104105

PPTP (Point-to-Point Tunneling Protocol), 215

private switches, 157

Process Automation, 123

process isolation, 160

protocols, VPN, 214

IKEv2, 214215

L2TP/IPsec, 215

PPTP, 215

SSTP, 215

PSOs (Password Settings Object), 7778

Q-R

quotas, FSRM (File Server Resource Manager), 243244

RADIUS servers, 211

accounting, 212213

clients, 211212

proxies, 211

RBAC (remote-based access control), 109, 173174

realm trusts, 33

ReFS (Resilient File System), 264265

Register-PSSessionConfiguration cmdlet, 113

registration, Azure File Sync server, 235236

Remote Access role service, 210

Remote Desktop, 2, 101102, 130

RemoteFX, 134

repadmin tool, 44

replication

AD DS, 41

KCC (Knowledge Consistency Checker), 42

multi-master, 42

conflict resolution, 43

DFS, 250

groups, 250251

replicated folders and targets, 250

schedules, 251

managing and monitoring, 44

RODC, 4344

triggering, 44

reservations, 208

resiliency

nested, 256

storage space, 253

Storage Spaces Direct, 256257

resizing, IaaS VMs, 175176

resource

groups, 134135

records, 190, 194195

restoring. See backup and restore

Resultant Set of Policy tool, 92

RID (Relative ID) master, 28

RODCs (read-only domain controllers), 24, 187

decommissioning, 2627

local administrators, 26

password replication, 2425

replication, 4344

role-capability files, 110111

RSO (replicate-single-object) operation, 4344

runbooks, 123

S

sandbox, 159

scavenging, 192

scheduling, Hyper-V, 135136

schema master, 27

search functionality, ADAC (Active Directory Administrative Center), 34

secondary zones, 188

second-hop remoting, 108

security

DNS (Domain Name System), 196

cache locking, 197

DANE (DNS-based Authentication of Named Entities), 198

netmask ordering, 197

policies, 199

recursion, 197

response rate limiting, 198

socket pool, 196

DNSSEC (Domain Name System Security Extensions), 194195

Group Policy and, 8990

physical, domain controllers, 24

seizing FMSO roles, 29

Server Core deployment, 89

service accounts, 48, 164165

session-configuration files, 111112

Set-ADComputer cmdlet, 50

Set-ADForestMode cmdlet, 20

Set-ADObject cmdlet, 9

Set-DhcpServerv4DnsSetting cmdlet, 207

Set-PhysicalDisk cmdlet, 254

SetSPN utility, 52

Set-SRPartnership cmdlet, 260

shared disks, 174

shared folders, 239241. See also BranchCache

shortcut trusts, 32

SID filtering, 3435

site(s), 3537, 3940

creating, 3738

link bridges, 40

subnets, creating, 38

site-to-site VPN, 228

smart paging, 132133

SMB Direct, 261262

SMTP (Simple Mail Transfer Protocol), reverse lookup zones and, 189

snapshots, 22, 175

SPNs (service principal names), 52

spoofing, 196

SR-IOV (Single-Root I/O Virtualization), 155156

SSTP (Secure Socket Tunneling Protocol), 214215

State Configuration, 124

storage

disks

basic, 252

dynamic, 252

partitions, 252

thin-provisioned, 254255

guest cluster, 145146

Hyper-V

deduplication, 152

tiering, 152

migration, 152153

pools, 253

reports, 244245

space, 253

resiliency, 253

tiering, 254

trim, 255

Storage QoS, 151, 262263

Storage Replica, 257258

requirements, 259260

supported configurations, 258259

Storage Spaces Direct, 255

cluster nodes, 257

deployment options, 256

nested resiliency, 256

properties, 255256

resiliency types, 256257

store and forward replication, 42

stub zones, 193

subnets, 38

synchronization, password, 7374

T

tasks, Active Directory Users and Computers, 5

templates

Administrative, 9293

ARM (Azure Resource Manager), 53

file screen, 243

NPS, 227

quota, 244

Test-SRTopology cmdlet, 259

thin provisioning, 254255

tombstone lifetime, 1012

tombstone reanimation, 15

tools. See also PowerShell

Azure AD Connect, 5455

deployment account requirements, 5758

Health, 72

installing, 5863

requirements, 5657

SQL Server requirements, 57

synchronization, 6567

Cloud Shell, 122

repadmin, 44

Resultant Set of Policy, 92

SetSPN, 52

Validate-DCB, 143

Windows Server administration, 100

jump servers, 101

PAWs (Privileged Access Workstations), 100101

remote access and, 100

Remote Desktop, 101102

WAC (Windows Admin Center), 102105

topologies, DirectAccess, 216217

transitivity, trust, 30

transparent networks, 170

triggering, replication, 44

trim, 255

troubleshooting

GPOs, 8586

IP address issues, 204

Trust Anchor, 195

trust(s), 6, 29, 30

direction, 3031

external, 32

forest, 3132

name suffix routing, 35

netdom.exe and, 34

realm, 33

shortcut, 32

SID filtering, 3435

transitivity, 30

two-way trust, 6

U

UGMC (universal group membership caching), 10

Uninstall-ADDSDomainController cmdlet, 21

universal groups, 47

unknown records, 191

updates, Windows, 118

compliance, 119

deploying, 118119

managing permissions, 119

UPN (user principal name) suffixes, 6365

user accounts, 4546. See also password(s)

inactive, 82

locked-out, 81

lockout settings, 79

nonexpiring passwords, 8081

UPN (user principal name) suffixes, 6365

USNs (update sequence numbers), 43

V

Validate-DCB tool, 143

VHD Sets, 147

virtual accounts, 50

virtual domain controllers, 9, 16, 23

virtual hard disks

differencing disks, 149

dynamically expanding disks, 149

fixed-size disks, 149

formats, 148

modifying, 150

pass-through disks, 150151

Virtual Fibre Channel adapters, 151

virtual switches, 156

external, 157

internal, 157

private, 157

virtualization

Hyper-V, 127. See also Hyper-V

nested, 130131

dynamic memory, 131

networking, 131

VLAN tagging, 155

VMs (virtual machines). See also Hyper-V

checkpoints, 136137

configuring replicas, 138139

CPU groups, 135

DDA (Discrete Device Assignment), 133134

dynamic memory, 132

Enhanced Session Mode, 130

exporting, 153

extensions, 117118

Generation 2, 128129

high availability, Hyper-V Replica, 137140

IaaS, 173

configuring continuous delivery, 176

connections to, 176179

data disks, 174

encryption, 175

images, 174

IP addressing, 180181

managing, 122123

NSGs and, 181

RBAC roles, 173174

resizing, 175176

shared disks, 174

snapshots, 175

virtual networks, 179180, 181

importing, 153

integration services, 133

live migration, 147148

MAC address, 153154

managing

using HVC.exe, 130

using PowerShell Direct, 130

using PowerShell remoting, 129

nested virtualization, 130131

dynamic memory, 131

networking, 131

optimizing network performance, 155

bandwidth management, 155

Dynamic Virtual Machine Queue, 156

SR-IOV, 155156

resource groups, 134135

smart paging, 132133

VPN

authentication, 213214

Docker, 1

IaaS virtual networks and, 181

protocols, 214

IKEv2, 214215

L2TP/IPsec, 215

PPTP, 215

SSTP, 215

server configuration, 213

site-to-site, 228

W

WAC (Windows Admin Center), 102103

configuring a target machine, 105

extensions, 104

installing, 103104

managing Azure hybrid services, 105

showing PowerShell source code, 104105

Web Application Proxy, 227

Windows Admin Center, 2, 3, 178

Windows Server, 124

administration tools, 100

jump servers, 101

PAWs (Privileged Access Workstations), 100101

remote access and, 100

Remote Desktop, 101102

WAC (Windows Admin Center), 102105

Azure VM extensions, 117118

Backup, 10

checkpoints, 136

container(s)

images, 163164

service accounts, 164165

DHCP (Dynamic Host Configuration Protocol) server role, deploying, 203204

DNS, 196

cache locking, 197

DANE (DNS-based Authentication of Named Entities), 198

event logs, 196

netmask ordering, 197

policies, 199

recursion, 197

response rate limiting, 198

socket pool, 196

IaaS VMs, managing, 122123

integration

with Azure DNS private zones, 193194

with Log Analytics, 120121

with Microsoft Defender for Cloud, 121122

joining to an Active Directory instance, 5253

LAN routing, 215

managing, 113116

NPS, 220, 221

authentication, 223

connection request forwarding, 222

connection request policies, 220, 223224

encryption, 224225

IP settings, 225

network policies, creating, 225227

policy conditions, 221222

templates, 227

RemoteFX, 134

shared folders, 239241

updates, 118

compliance, 119

deploying, 118119

managing permissions, 119

X-Y-Z

zone(s)

Active Directory-integrated, 186187

aging, 191192

delegation, 190

GlobalNames, 189190

reverse lookup, 188189

secondary zones, 188

Trust Anchor, 195

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
13.58.119.195