AZ-802 Windows Server security explained

Updated September 29, 2026

Secure Windows Server infrastructure is worth 10–15% of AZ-802. It has two halves: hardening the operating system, and hardening Active Directory. The OS half covers exploit protection, App Control for Business, Credential Guard, SmartScreen, security baselines with OSConfig, Windows LAPS, Defender for Servers and Windows Firewall. The AD half covers password policies, Entra Password Protection, Protected Users, domain controller hardening, delegation and authentication protocols. Questions usually describe an attack or a compliance requirement and ask which control addresses it.

Securing the operating system

ControlProtects againstKey detail
Exploit protectionMemory exploits such as ROP or heap sprayingSystem-wide and per-app mitigations; export and import as XML
App Control for BusinessRunning unapproved codePolicies allow signed or listed code; start in audit mode
Credential GuardTheft of NTLM hashes and Kerberos tickets from LSASSUses virtualisation-based security; not recommended on domain controllers
SmartScreenMalicious downloads and sitesConfigured through Group Policy
Windows LAPSShared local administrator passwordsUnique, rotated passwords stored in AD DS or Microsoft Entra ID

OSConfig is the Windows Server 2025 way to apply and maintain security baselines. It is a PowerShell module: you apply a baseline scenario, such as the member server or domain controller baseline, with Set-OSConfigDesiredConfiguration, and OSConfig’s drift control puts settings back if something changes them. You can also apply it at scale through Azure Arc and machine configuration.

Windows LAPS is built into Windows Server. Before it can store passwords in AD, you extend the schema with Update-LapsADSchema and grant computers permission to write their own password with Set-LapsADComputerSelfPermission. Passwords can be encrypted in AD, and Get-LapsADPassword reads them back for authorised users.

Microsoft Defender for Servers is a plan within Defender for Cloud. Plan 1 adds Microsoft Defender for Endpoint. Plan 2 adds features such as just-in-time VM access, file integrity monitoring and agentless scanning. It covers Azure VMs and, through Azure Arc, on-premises servers.

Windows Firewall

Windows Firewall has three profiles, domain, private and public, and applies rules by profile. Connection security rules use IPsec to authenticate or encrypt traffic between computers:

Rule typeUse
IsolationRequire authentication between domain members
Authentication exemptionExclude computers such as DCs or DHCP servers
Server-to-serverProtect traffic between specific endpoints
TunnelIPsec between gateways

Securing AD DS

Passwords

The domain password policy applies to every user and is set in a GPO linked to the domain. Fine-grained password policies (password settings objects) apply different rules to users or global security groups; when several apply, the one with the lowest precedence number wins. Microsoft Entra Password Protection extends Microsoft’s banned password list and your custom list to on-premises AD: a proxy service fetches the policy from Entra ID, and a DC agent on every domain controller checks password changes. Start in audit mode, then enforce.

Privileged accounts

Members of Protected Users cannot authenticate with NTLM, cannot use DES or RC4 in Kerberos pre-authentication, cannot be delegated, do not cache credentials, and get a four-hour TGT lifetime. It is meant for administrators, not for service or computer accounts. Mark administrative accounts sensitive and cannot be delegated as well.

Domain controllers

  • Restrict interactive logon to DCs to the administrators who need it, through the Default Domain Controllers Policy user rights.
  • Run no other roles or software on DCs, and manage them from privileged access workstations.
  • Keep the membership of Enterprise Admins, Domain Admins and Schema Admins minimal. Schema Admins should normally be empty.
  • Use authentication policies and silos to limit where high-value accounts may sign in.

Delegation and authentication

The Delegation of Control Wizard grants rights on an OU, such as resetting passwords, without making anyone a domain admin. Review delegated permissions regularly; they accumulate. On authentication, the direction is Kerberos over NTLM: audit NTLM use, then restrict it; disable RC4 where possible; and use Kerberos armoring (FAST) to protect pre-authentication.

Sample questions

Question 1. Every member server uses the same local Administrator password, and an attacker who obtains it could move to all of them. You need a unique, automatically rotated password per server, stored in AD DS and readable only by the server team. What should you implement?

  • A. A Group Policy preference that sets the local Administrator password
  • B. Windows LAPS with passwords backed up to AD DS
  • C. Credential Guard on all member servers
  • D. A fine-grained password policy for the server team
Show answer

Answer: B

Windows LAPS generates a unique local administrator password for each computer, rotates it, stores it in AD DS or Entra ID, and lets you grant read access to a chosen group. Group Policy preferences can no longer set passwords securely. Credential Guard protects domain credentials in memory, and a fine-grained password policy applies to domain accounts, not local ones.

Want more questions like this? Full AZ-802 practice tests →

Question 2. Helpdesk accounts must use a 16-character minimum password, while all other users keep the domain policy of 12 characters. What should you create?

  • A. A GPO with a password policy linked to the helpdesk OU
  • B. Microsoft Entra Password Protection with a custom banned list
  • C. A fine-grained password policy applied to the helpdesk group
  • D. Add the helpdesk accounts to Protected Users
Show answer

Answer: C

A password settings object, the fine-grained password policy, applies different password rules to specific users or global security groups. A second password policy in a GPO linked to an OU does not affect domain accounts. Entra Password Protection bans weak passwords but does not set length per group. Protected Users does not change password length.

Want more questions like this? Full AZ-802 practice tests →

Question 3. You must stop domain administrator accounts from authenticating with NTLM and from having their credentials cached on servers they sign in to. Which change is simplest?

  • A. Add the domain administrator accounts to Protected Users
  • B. Enable Credential Guard on every domain controller
  • C. Configure selective authentication on the domain
  • D. Disable NTLM for the entire domain immediately
Show answer

Answer: A

Members of the Protected Users group cannot use NTLM, are not cached, cannot be delegated and receive short-lived Kerberos tickets. Credential Guard protects secrets on the machine but does not stop NTLM use by the account. Selective authentication applies to trusts. Disabling NTLM domain-wide at once would break applications that still need it.

Want more questions like this? Full AZ-802 practice tests →

What to practise

Apply the OSConfig member server baseline to a Windows Server 2025 lab VM and change a setting to watch drift control restore it. Deploy Windows LAPS with the schema update and read a password back. Create an App Control policy in audit mode and review the events. On the AD side, create a fine-grained password policy, add a test admin to Protected Users and try an NTLM sign-in, and install Entra Password Protection in audit mode if you have a tenant.