AZ-802 AD DS explained

Updated September 29, 2026

Deploy and manage AD DS is the largest AZ-802 domain at 20–25%. It covers four areas: deploying domain controllers, running multi-site and multi-forest environments, managing users, groups and service accounts, and managing servers with Group Policy. The questions are practical. You need to know which FSMO role explains a symptom, which trust type fits two forests, and which service account type a given workload can use.

Domain controllers

On-premises and in Azure

Promoting a DC is the easy part. The exam cares about the decisions around it. A domain controller in an Azure VM should have a static private IP, store the AD database, logs and SYSVOL on a data disk with host caching set to None, and point its DNS settings at domain controllers rather than Azure’s resolver. Put Azure DCs in their own AD site, with the Azure address ranges as subnets, so clients there authenticate locally.

Read-only domain controllers

An RODC holds a read-only copy of the directory and caches only the passwords its Password Replication Policy allows.

SettingWhat it does
Allowed RODC Password Replication GroupAccounts whose passwords may be cached
Denied RODC Password Replication GroupAccounts never cached; takes precedence over Allowed
Prepopulate passwordsCaches allowed passwords before the first sign-in
Administrator role separationGives a branch user local admin rights on the RODC without domain rights

Domain Admins, Enterprise Admins and other privileged groups are denied by default. If an RODC is stolen, you reset the passwords of the accounts it had cached; the Accounts that have been cached list tells you which.

FSMO roles

RoleScopeSymptom when unavailable
Schema masterForestSchema extensions fail
Domain naming masterForestAdding or removing domains fails
RID masterDomainNew objects fail once a DC’s RID pool runs out
PDC emulatorDomainTime drift, password change delays, lockout processing issues
Infrastructure masterDomainCross-domain group memberships display stale names

Transfer a role while its holder is online; seize it only when the holder is gone for good, with Move-ADDirectoryServerOperationMasterRole -Force or ntdsutil. A DC whose role was seized must not come back online.

Sites, replication and trusts

Sites

Sites map the physical network. Each site has subnets; site links connect sites and carry a cost and a replication interval (180 minutes by default, 15 at minimum). Replication inside a site uses change notification and is near-immediate. Between sites it follows the site link schedule. A client whose IP address is not in any defined subnet may authenticate against a distant DC, which is a classic exam scenario.

Trusts

TrustBetweenTransitive
ForestTwo forest rootsYes, across both forests
ExternalA domain and a domain in another forestNo
ShortcutTwo domains in the same forestYes
RealmAD and a non-Windows Kerberos realmConfigurable

Selective authentication on a forest or external trust means users from the other side can reach only the computers where they are granted Allowed to authenticate. SID filtering is on by default for external and forest trusts and blocks SID history from the trusted side.

Security principals

Group scopes still matter in multi-domain forests: global groups collect users from their own domain, universal groups gather across the forest, and domain local groups hold permissions on resources. For service accounts:

TypeUse
Standalone managed service accountOne server
Group managed service account (gMSA)Several servers, such as a farm; needs a KDS root key
Delegated managed service account (dMSA)Windows Server 2025; replaces an existing service account

A gMSA needs a KDS root key in the forest first (Add-KdsRootKey), then New-ADServiceAccount, then Install-ADServiceAccount on each allowed host.

Group Policy

GPOs apply in the order local, site, domain, OU, with the last one applied winning. Enforced links override Block inheritance. Security filtering and WMI filters narrow who receives a GPO. Loopback processing applies user settings based on the computer, in Merge or Replace mode, which suits terminal servers. The central store in SYSVOL holds ADMX templates for the whole domain. Group Policy preferences set drive maps, registry values and local groups, can be targeted per item, and are not enforced like policies: users can change them unless you choose to apply once or remove when no longer applied.

Sample questions

Question 1. Users in a newly opened office authenticate against a domain controller in another country, even though a DC exists in their own office. The new office has its own AD site. What is the most likely cause?

  • A. The site link cost to the new site is too high
  • B. The office’s IP subnet is not associated with its AD site
  • C. The PDC emulator role is in the other country
  • D. The local DC is not a global catalog server
Show answer

Answer: B

Clients locate a DC through their site, which is determined by matching their IP address to a subnet object. If the new office’s subnet is not defined in AD or is linked to the wrong site, clients are treated as site-less and may use any DC. Site link cost affects replication routing between sites. The PDC emulator and the global catalog setting do not decide which DC a client picks.

Want more questions like this? Full AZ-802 practice tests →

Question 2. A web application runs on three IIS servers and needs one service account whose password is managed automatically. The forest has never used managed service accounts. What must you do first?

  • A. Create a standalone managed service account on each server
  • B. Create a fine-grained password policy for service accounts
  • C. Add the servers to the Protected Users group
  • D. Create a KDS root key
Show answer

Answer: D

A group managed service account can be used on several servers, and its password is generated by the Key Distribution Service. Before the first gMSA can be created, the forest needs a KDS root key. A standalone managed service account works on one server only. Fine-grained password policies and the Protected Users group do not create service accounts.

Want more questions like this? Full AZ-802 practice tests →

Question 3. Contoso and Fabrikam have separate forests. Contoso users must access only two file servers in Fabrikam, while all other Fabrikam computers must reject them. Which configuration meets the requirement?

  • A. A forest trust with selective authentication, granting Allowed to authenticate on the two servers
  • B. A forest trust with forest-wide authentication
  • C. A shortcut trust between the two forest root domains
  • D. A forest trust with SID filtering disabled
Show answer

Answer: A

A forest trust with selective authentication blocks authentication from the trusted forest by default; granting Allowed to authenticate on the two file servers’ computer objects opens access to just those. Forest-wide authentication allows access to every computer that grants permissions. A shortcut trust works within a forest. SID filtering controls SID history, not which computers can be reached.

Want more questions like this? Full AZ-802 practice tests →

What to practise

Build a two-site forest and walk through the domain in an afternoon: move the PDC emulator role and move it back, deploy an RODC and prepopulate one user, create a gMSA and run a scheduled task with it, set up a second forest with a selective trust, and link a GPO with loopback processing to a server OU. Then check replication with repadmin /replsummary. After that, most AD DS questions describe something you have already done.