AZ-802 cheat sheet
Last-minute reference for AZ-802. AD DS is the largest area; storage has the most objectives; troubleshooting ties everything together.
Exam facts
| Duration | 120 minutes |
| Passing score | 700 / 1000 |
| Price | Set per country or region; shown at booking |
| Languages | English |
| Renewal | Free, every 12 months |
Skill areas
| Area | Weight |
|---|---|
| Deploy and manage AD DS | 20–25% |
| Manage storage and file services | 15–20% |
| Monitor and troubleshoot Windows Server environments | 15–20% |
| Manage Windows Server instances and workloads in a hybrid environment | 10–15% |
| Manage virtual machines | 10–15% |
| Implement and manage an on-premises and hybrid networking infrastructure | 10–15% |
| Secure Windows Server infrastructure | 10–15% |
Requirement to answer
| Requirement | Answer |
|---|---|
| Branch DC that stores only some passwords | RODC + Password Replication Policy |
| New objects fail, RID pool exhausted | RID master |
| Time source for the forest | PDC emulator of the forest root |
| Access to only some servers in another forest | Forest trust + selective authentication |
| One service account on several servers | gMSA (needs KDS root key) |
| User settings based on the computer | Loopback processing |
| Remote command reaches a second server | Resource-based Kerberos constrained delegation |
| Users may run only certain cmdlets | JEA |
| Manage non-Azure servers from Azure | Azure Arc |
| Scheduled patching across Azure and Arc | Azure Update Manager |
| Hyper-V inside a VM | Nested virtualization |
| Whole GPU for one VM / shared GPU | DDA / GPU partitioning |
| Test a replica without interruption | Hyper-V Replica test failover |
| Time-limited RDP to Azure VMs | Just-in-time VM access |
| On-premises resolves Azure private zone | Private Resolver inbound endpoint + conditional forwarder |
| Different answers per client subnet | DNS policy with zone scope |
| Backup DHCP server that waits | DHCP failover, hot standby |
| Small local disk, large file share | Azure File Sync + cloud tiering |
| File shares over the internet without VPN | SMB over QUIC |
| Block file types on a share | FSRM active file screen |
| Zero-loss volume replication | Storage Replica, synchronous |
| Unique local admin passwords | Windows LAPS |
| Baseline that fixes its own drift | OSConfig |
| Different password rules for a group | Fine-grained password policy |
| No NTLM, no caching for admins | Protected Users |
| Restore deleted user with memberships | AD Recycle Bin |
| Trust relationship failed | Test-ComputerSecureChannel -Repair |
| Forecast disk capacity locally | System Insights |
Numbers worth knowing
| Kerberos clock skew | 5 minutes |
| Default intersite replication interval | 180 minutes; minimum 15 |
| Hyper-V Replica frequencies | 30 seconds, 5 minutes, 15 minutes |
| Protected Users TGT lifetime | 4 hours |
| SMB over QUIC | UDP 443, TLS 1.3 |
| Azure platform DNS resolver | 168.63.129.16 |
Traps
- Seized FSMO holders must never return to the network.
- Denied beats Allowed in the RODC Password Replication Policy.
- Planned failover needs the primary VM off; test failover does not.
- Deduplication cannot run on system or boot volumes; ReFS cannot be a boot volume.
- The Recycle Bin cannot be disabled and does not cover objects deleted before it was enabled.
- Only the forest root PDC emulator should sync with an external time source.
- Credential Guard is not a replacement for Protected Users; one protects the machine, the other the account.
- DHCP servers must be authorised in AD before they lease.
Night-before checklist
- Name the seven areas and which three are largest
- The five FSMO roles, their scope and symptoms, cold
- Authoritative versus non-authoritative, for both AD and SYSVOL
- Check ID and proctoring rules; see exam day
Take the 20-question practice test and check your weakest area.