AZ-802 cheat sheet

Updated September 29, 2026

Last-minute reference for AZ-802. AD DS is the largest area; storage has the most objectives; troubleshooting ties everything together.

Exam facts

Duration120 minutes
Passing score700 / 1000
PriceSet per country or region; shown at booking
LanguagesEnglish
RenewalFree, every 12 months

Skill areas

AreaWeight
Deploy and manage AD DS20–25%
Manage storage and file services15–20%
Monitor and troubleshoot Windows Server environments15–20%
Manage Windows Server instances and workloads in a hybrid environment10–15%
Manage virtual machines10–15%
Implement and manage an on-premises and hybrid networking infrastructure10–15%
Secure Windows Server infrastructure10–15%

Requirement to answer

RequirementAnswer
Branch DC that stores only some passwordsRODC + Password Replication Policy
New objects fail, RID pool exhaustedRID master
Time source for the forestPDC emulator of the forest root
Access to only some servers in another forestForest trust + selective authentication
One service account on several serversgMSA (needs KDS root key)
User settings based on the computerLoopback processing
Remote command reaches a second serverResource-based Kerberos constrained delegation
Users may run only certain cmdletsJEA
Manage non-Azure servers from AzureAzure Arc
Scheduled patching across Azure and ArcAzure Update Manager
Hyper-V inside a VMNested virtualization
Whole GPU for one VM / shared GPUDDA / GPU partitioning
Test a replica without interruptionHyper-V Replica test failover
Time-limited RDP to Azure VMsJust-in-time VM access
On-premises resolves Azure private zonePrivate Resolver inbound endpoint + conditional forwarder
Different answers per client subnetDNS policy with zone scope
Backup DHCP server that waitsDHCP failover, hot standby
Small local disk, large file shareAzure File Sync + cloud tiering
File shares over the internet without VPNSMB over QUIC
Block file types on a shareFSRM active file screen
Zero-loss volume replicationStorage Replica, synchronous
Unique local admin passwordsWindows LAPS
Baseline that fixes its own driftOSConfig
Different password rules for a groupFine-grained password policy
No NTLM, no caching for adminsProtected Users
Restore deleted user with membershipsAD Recycle Bin
Trust relationship failedTest-ComputerSecureChannel -Repair
Forecast disk capacity locallySystem Insights

Numbers worth knowing

Kerberos clock skew5 minutes
Default intersite replication interval180 minutes; minimum 15
Hyper-V Replica frequencies30 seconds, 5 minutes, 15 minutes
Protected Users TGT lifetime4 hours
SMB over QUICUDP 443, TLS 1.3
Azure platform DNS resolver168.63.129.16

Traps

  • Seized FSMO holders must never return to the network.
  • Denied beats Allowed in the RODC Password Replication Policy.
  • Planned failover needs the primary VM off; test failover does not.
  • Deduplication cannot run on system or boot volumes; ReFS cannot be a boot volume.
  • The Recycle Bin cannot be disabled and does not cover objects deleted before it was enabled.
  • Only the forest root PDC emulator should sync with an external time source.
  • Credential Guard is not a replacement for Protected Users; one protects the machine, the other the account.
  • DHCP servers must be authorised in AD before they lease.

Night-before checklist

  • Name the seven areas and which three are largest
  • The five FSMO roles, their scope and symptoms, cold
  • Authoritative versus non-authoritative, for both AD and SYSVOL
  • Check ID and proctoring rules; see exam day

Take the 20-question practice test and check your weakest area.