AZ-802 hybrid management explained

Updated September 29, 2026

Manage Windows Server instances and workloads in a hybrid environment is worth 10–15% of AZ-802. It has two halves: remote management of individual servers with Windows Admin Center, PowerShell, SSH and Remote Desktop, and management at scale through Azure with Azure Arc, machine configuration, VM extensions, Azure Update Manager and Azure Automation. Most questions ask which tool fits a requirement, or why a remote command fails.

Remote management

Windows Admin Center

Windows Admin Center is a browser-based management tool for servers, clusters and Hyper-V hosts. It runs in two ways:

DeploymentManagesAccess
On-premises gatewayServers the gateway can reachBrowser to the gateway
In the Azure portalAzure VMs and Arc-enabled serversAzure portal, controlled by Azure RBAC

The Azure portal version needs no gateway server of your own. Access is granted with the Windows Admin Center Administrator Login role, and the connection runs over the Arc agent or the VM’s network. It suits servers you already manage in Azure; the on-premises gateway suits environments without Azure.

PowerShell remoting

PowerShell remoting runs over WinRM (HTTP 5985, HTTPS 5986) or SSH. Two topics come up repeatedly.

The second hop. Your credentials reach the first server but are not passed on to a second one, so a command on SRV1 that touches a share on SRV2 fails with access denied.

SolutionSecurityNotes
Resource-based Kerberos constrained delegationGoodSet on the target’s computer object; no credentials stored on the first hop
Kerberos constrained delegationGoodConfigured on the first server; needs domain admin rights
CredSSPWeakerDelegates your reusable credentials to the first server
Pass credentials explicitly inside the sessionAcceptableWorks, but you handle credentials in scripts

Just Enough Administration. JEA gives users a remote endpoint where they can run only the commands you allow, as a temporary virtual account with admin rights. You write a role capability file (.psrc) listing visible cmdlets, functions and parameters, a session configuration file (.pssc) mapping groups to roles, and register it with Register-PSSessionConfiguration. Users connect with Enter-PSSession -ConfigurationName.

SSH and Remote Desktop

OpenSSH Server is an optional feature on Windows Server; PowerShell can use it as a remoting transport, which is how you remote between Windows and Linux. Remote Desktop needs the setting enabled, the firewall rule allowed and the user in Remote Desktop Users. Network Level Authentication requires the user to authenticate before a session is created.

Management through Azure

Azure Arc

Azure Arc projects a non-Azure server into Azure as a resource. You install the Connected Machine agent (azcmagent) and connect it interactively for a single server, or with a service principal for many servers at once. The server then appears in a resource group and can use Azure Policy, RBAC, tags, extensions and monitoring like an Azure VM.

  • Machine configuration (formerly guest configuration) audits or applies settings inside the OS through Azure Policy assignments.
  • VM extensions install software on Arc-enabled servers: the Azure Monitor Agent, Defender for Servers components, Custom Script Extension and others.
  • The agent needs outbound HTTPS to Azure. A proxy or private endpoint can carry it.

Azure Update Manager

Update Manager assesses and installs updates for Azure VMs and Arc-enabled servers from one place. Periodic assessment checks for missing updates every 24 hours. Maintenance configurations define scheduled patching windows and which classifications to install. You can also run a one-off update from the portal. It needs no Log Analytics workspace and no Automation account, unlike the older Update Management solution it replaces.

Azure Automation

Runbooks are PowerShell or Python scripts that run in Azure on a schedule, from a webhook or from an alert. To reach on-premises resources, a runbook runs on a Hybrid Runbook Worker, installed as an extension on a Windows or Linux machine. Runbooks authenticate to Azure with the Automation account’s managed identity.

Sample questions

Question 1. Help desk staff must be able to restart the print spooler on file servers remotely, and nothing else. They must not be members of the local Administrators group. What should you implement?

  • A. Remote Desktop access with the Remote Desktop Users group
  • B. Windows Admin Center with gateway user access
  • C. A JEA endpoint with a role capability that allows restarting only the Spooler service
  • D. CredSSP authentication for the help desk group
Show answer

Answer: C

Just Enough Administration provides a constrained remoting endpoint where users run only the listed cmdlets, such as Restart-Service limited to the Spooler service, under a temporary virtual account with the needed rights. Remote Desktop and Windows Admin Center give broad access. CredSSP is a delegation method, not an access control.

Want more questions like this? Full AZ-802 practice tests →

Question 2. You must onboard 400 on-premises servers to Azure Arc with a script, without anyone signing in interactively on each server. What should the script use to authenticate the Connected Machine agent?

  • A. A system-assigned managed identity on each server
  • B. A service principal with the Azure Connected Machine Onboarding role
  • C. A global administrator account
  • D. The Log Analytics workspace ID and key
Show answer

Answer: B

At-scale onboarding uses a service principal with the Azure Connected Machine Onboarding role, passed to azcmagent connect. A managed identity only exists once the server is connected. A user account needs interactive sign-in, and a Log Analytics workspace key is for agents that send data, not for Arc onboarding.

Want more questions like this? Full AZ-802 practice tests →

Question 3. Arc-enabled servers and Azure VMs must install critical and security updates every second Tuesday at 22:00, and you want to see missing updates across all of them daily. What should you configure?

  • A. Azure Update Manager with periodic assessment and a maintenance configuration
  • B. Machine configuration assignments through Azure Policy
  • C. An Azure Automation runbook scheduled on a Hybrid Runbook Worker
  • D. A WSUS server with automatic approval rules
Show answer

Answer: A

Azure Update Manager covers both Azure VMs and Arc-enabled servers: periodic assessment checks for missing updates every 24 hours, and a maintenance configuration schedules the installation window and classifications. Machine configuration audits settings rather than installing updates. A runbook could script updates but is not the managed solution. WSUS alone does not give the Azure view.

Want more questions like this? Full AZ-802 practice tests →

What to practise

Arc-enable one lab server with a service principal, assign a built-in machine configuration policy, deploy the Azure Monitor Agent as an extension, and schedule its updates in Update Manager. Then open it in Windows Admin Center in the Azure portal. On-premises, reproduce the second-hop failure and fix it with resource-based constrained delegation, and build a JEA endpoint that exposes a single cmdlet.