The next is a listing of Lively Listing Area Companies modules on Microsoft Be taught sorted from introductory to superior. Is there an Lively Listing subject that is not listed right here that you simply’d wish to see coated? (AD CS modules are coming)
URL: https://study.microsoft.com/en-us/coaching/modules/introduction-to-ad-ds/
Evaluation: BEGINNER
This module establishes the important AD DS vocabulary and psychological mannequin. It introduces listing providers, customers, teams, computer systems, forests, domains, websites, area controllers, and organizational items, then reveals how listing objects and their properties are managed. It ought to come first as a result of almost each later module assumes familiarity with these constructions and their relationships.
2. Handle customers and teams
URL: https://study.microsoft.com/en-us/coaching/modules/manage-users-groups/
Evaluation: BEGINNER
This module offers an accessible first have a look at id administration by evaluating AD DS with Microsoft Entra ID, explaining safety and distribution teams, tracing the area sign-in and authentication course of, and introducing consumer and group administration. It follows the final AD DS overview so learners can join on a regular basis id duties to the listing constructions launched within the first module.
3. Create and handle Lively Listing objects
URL: https://study.microsoft.com/en-us/coaching/modules/create-manage-active-directory-objects/
Evaluation: INTERMEDIATE
This module turns the foundational ideas into routine administrative expertise. It covers customers, teams, computer systems, organizational items, object properties, object creation and configuration, bulk user-account administration, and primary area controller upkeep. The module is the pure bridge from understanding AD DS to working it.
4. Handle Lively Listing Area Companies utilizing PowerShell cmdlets
URL: https://study.microsoft.com/en-us/coaching/modules/manage-active-directory-domain-services-use-powershell-cmdlets/
Evaluation: INTERMEDIATE
This module applies PowerShell to the object-management duties discovered beforehand. It introduces cmdlets for creating and sustaining customers, teams, group memberships, computer systems, organizational items, and different listing objects, giving learners a repeatable and scalable various to graphical administration. Prior PowerShell familiarity is predicted.
5. Deploy and handle Lively Listing Area Companies area controllers
URL: https://study.microsoft.com/en-us/coaching/modules/deploy-manage-active-directory-domain-services-domain-controllers/
Evaluation: INTERMEDIATE
This module strikes from listing objects to the servers that host the listing. It opinions forests and domains, explains area controller topology, covers area controller deployment and motion between websites, and introduces operations grasp roles. It offers the deployment context wanted earlier than learning area controller upkeep and position placement in larger depth.
6. Handle AD DS area controllers and FSMO roles
URL: https://study.microsoft.com/en-us/coaching/modules/manage-active-directory-domain-services-flexible-single-master-operation-roles/
Evaluation: INTERMEDIATE
This module deepens area controller administration by way of deployment, upkeep, backup and restoration concerns, international catalog placement, Versatile Single Grasp Operations (FSMO) position placement and administration, and an introduction to schema administration. It builds on the previous deployment module and prepares learners for later structure, restoration, and design matters.
URL: https://study.microsoft.com/en-us/coaching/modules/implement-group-policy-objects/
Evaluation: INTERMEDIATE
This module introduces domain-based Group Coverage Objects (GPOs), together with scope, inheritance, creation, configuration, storage, administrative templates, and the Central Retailer. It ought to precede the opposite Group Coverage modules as a result of it explains each the logical processing mannequin and the underlying storage elements on which later coverage and troubleshooting work relies upon.
8. Create and configure Group Coverage Objects in Lively Listing
URL: https://study.microsoft.com/en-us/coaching/modules/create-configure-group-policy-objects-active-directory/
Evaluation: INTERMEDIATE
This module reinforces GPO definition, scope, inheritance, and domain-based configuration, then extends these expertise into area password coverage and fine-grained password coverage. Though some content material overlaps the previous module, its identity-policy focus makes it a helpful second step after learners perceive GPO storage, templates, and normal processing.
URL: https://study.microsoft.com/en-us/coaching/modules/manage-security-active-directory/
Evaluation: INTERMEDIATE
This module addresses sensible listing hardening by way of consumer rights, entry restrictions, delegated permissions, the Protected Customers group, Home windows Defender Credential Guard, NTLM blocking, and identification of problematic accounts. It connects id administration and Group Coverage data to least-privilege operations and fashionable credential safety.
10. Implement and handle Lively Listing Certificates Companies
URL: https://study.microsoft.com/en-us/coaching/modules/implement-manage-active-directory-certificate-services/
Evaluation: INTERMEDIATE
This module introduces public key infrastructure and Lively Listing Certificates Companies (AD CS), together with certification authority sorts, AD CS design and implementation, certificates enrollment, revocation, and belief. It belongs after core listing safety as a result of certificates prolong AD-based authentication and authorization right into a broader belief infrastructure.
11. Perceive Lively Listing Group Coverage safety settings
URL: https://study.microsoft.com/en-us/coaching/modules/understand-active-directory-security-policies/
Evaluation: ADVANCED
This module offers an in-depth therapy of safety coverage design and operation at scale. It covers password, lockout, and Kerberos account insurance policies; fine-grained password insurance policies; consumer rights; safety choices; auditing; secured teams, providers, registry keys, recordsdata, and logs; community and software insurance policies; and Home windows Server 2025 OSConfig baselines. Its assumptions about GPO processing, safety identifiers, entry tokens, ACLs, Kerberos, and NTLM make it the bridge from sensible GPO administration to protocol-level authentication hardening.
12. Lively Listing Area Companies authentication and Kerberos hardening
URL: https://study.microsoft.com/en-us/coaching/modules/active-directory-authentication-kerberos/
Evaluation: ADVANCED
This module examines Home windows authentication finish to finish, explaining how SSPI, Negotiate, NTLM, and Kerberos work together and tracing Kerberos from Ticket Granting Ticket issuance by way of service-ticket presentation and authorization. It covers analysis of Service Principal Title, delegation, Privilege Attribute Certificates, encryption-type, and NTLM fallback issues; staged migration from NTLM to Kerberos; RC4 auditing and remediation for Home windows Server 2025; and planning for PKINIT agility, Kerberos encryption coverage, SMB NTLM blocking, and password-change hardening. It caps the safety stage as a result of it requires learners to mix coverage, id, logging, and authentication-protocol data.
13. Perceive how Lively Listing Area Companies makes use of DNS
URL: https://study.microsoft.com/en-us/coaching/modules/understand-active-directory-domain-name-system/
Evaluation: ADVANCED
This module explains and diagnoses the DNS mechanisms on which AD DS relies upon. It traces service discovery and area controller location by way of SRV information, LDAP ping, website choice, and caching, and examines AD-integrated zones, software listing partitions, safe dynamic updates, registration, replication convergence, baselining, and failure restoration. This information is important earlier than designing or troubleshooting website topology and replication.
14. Lively Listing websites, topology, and replication
URL: https://study.microsoft.com/en-us/coaching/modules/active-directory-site-replication/
Evaluation: ADVANCED
This module develops an in depth mannequin of websites, subnets, website hyperlinks, prices, bridgeheads, connection objects, the Data Consistency Checker (KCC), and the Inter-Web site Topology Generator (ISTG). It additionally covers DC Locator habits, topology anti-patterns, replace sequence numbers, replication vectors, object metadata, replication failure analysis, and the Home windows Server 2025 replication precedence enhance. The module provides the replication basis wanted for the deeper storage and design modules that observe.
15. Perceive the Lively Listing Area Companies database and SYSVOL
URL: https://study.microsoft.com/en-us/coaching/modules/understand-active-directory-database/
Evaluation: ADVANCED
This module explains how a website controller shops and replicates listing information and SYSVOL by way of separate mechanisms. It distinguishes the logical listing from the native ESE database and listing partitions, traces transactional writes and logical AD DS replication, explains SYSVOL entry and DFS Replication, follows a GPO throughout its listing and file-system elements, and defines secure backup, restoration, virtualization, and model boundaries. It’s particularly helpful for diagnosing whether or not a failure lies in listing information, SYSVOL, replication, or shopper entry.
16. Perceive the Lively Listing Area Companies Schema
URL: https://study.microsoft.com/en-us/coaching/modules/understand-active-directory-schema/
Evaluation: ADVANCED
This module examines the forest-wide schema that defines listing object courses, attributes, syntax, inheritance, hyperlinks, identifiers, search habits, safety metadata, and international catalog content material. It covers secure inspection, schema variations, governance, extension design and deployment, indexing and replication results, entry management, and schema-related troubleshooting. The subject is superior as a result of schema adjustments are forest-wide, successfully everlasting, and demand disciplined testing and alter management.
17. Design a single-domain Lively Listing forest
URL: https://study.microsoft.com/en-us/coaching/modules/design-single-domain-active-directory-forest/
Evaluation: ADVANCED
This module combines the previous operational data right into a resilient single-domain forest design. It covers sturdy DNS and UPN namespaces, AD-integrated DNS, websites, subnets, website hyperlinks, replication convergence and failure habits, and placement of area controllers, DNS servers, international catalogs, FSMO roles, and the authoritative time supply. Learners additionally validate designs towards goal proof and failure situations.
18. Design a multi-domain or multi-forest Lively Listing setting
URL: https://study.microsoft.com/en-us/coaching/modules/design-multi-domain-forest-trust/
Evaluation: ADVANCED
This module extends single-domain design to situations requiring safety isolation, authorized separation, administrative autonomy, mergers, or replication boundaries. It addresses area timber and partitions, namespace coexistence, delegation, GPO scope, schema governance, belief course and safety, cross-forest identify decision, international catalog and authentication paths, superior replication and capability, and read-only area controller department designs. It ought to observe single-domain design as a result of extra domains and forests introduce complexity that have to be justified.
URL: https://study.microsoft.com/en-us/coaching/modules/manage-advanced-features-of-ad-ds/
Evaluation: ADVANCED
This module brings collectively a number of specialised administration situations: creating belief relationships, implementing Enhanced Safety Administrative Surroundings (ESAE) forests, monitoring and troubleshooting replication, and creating customized AD DS partitions. These duties depend on a mature understanding of forest boundaries, trusts, safety, partitions, and replication, so they’re finest approached after each structure modules.
20. Deploy and handle Azure IaaS Lively Listing area controllers in Azure
URL: https://study.microsoft.com/en-us/coaching/modules/deploy-manage-azure-iaas-active-directory-domain-controllers-azure/
Evaluation: ADVANCED
This module applies established AD DS administration to Azure infrastructure. It compares listing and id service choices, prepares Azure digital networking for area controllers, deploys and configures AD DS on Azure digital machines, installs a duplicate area controller, and creates a brand new forest on an Azure digital community. The broad stipulations in on-premises AD DS, Azure IaaS, networking, resiliency, safety, PowerShell, automation, and monitoring make this superior within the proposed path.
21. Lively Listing Area Companies migration
URL: https://study.microsoft.com/en-us/coaching/modules/active-directory-domain-services-migration/
Evaluation: ADVANCED
This module evaluates the right way to transfer an current AD DS setting to Home windows Server 2025. It compares in-place forest improve with migration to a brand new forest, then outlines the method for every method. Though concise, migration is positioned late as a result of deciding on and executing a secure technique requires strong data of area controllers, operations roles, DNS, replication, safety, structure, restoration, and alter administration.
URL: https://study.microsoft.com/en-us/coaching/modules/troubleshoot-active-directory/
Evaluation: ADVANCED
This module offers broad restoration and troubleshooting protection for AD DS failures and degraded efficiency. It addresses restoring deleted objects with the AD Recycle Bin, recovering the AD DS database and SYSVOL, troubleshooting replication, and diagnosing hybrid authentication points. The potential affect of restoration operations and the necessity to correlate a number of listing subsystems make this a sophisticated operational module regardless of its comparatively compact scope.
23. Troubleshoot Lively Listing Area Companies replication
URL: https://study.microsoft.com/en-us/coaching/modules/troubleshoot-active-directory-replication/
Evaluation: ADVANCED
This module develops a disciplined course of for diagnosing replication failures with Repadmin, DCDiag, PowerShell, and occasion logs. It teaches learners to differentiate true failures from anticipated latency or transient topology states, isolate DNS, community, authentication, topology, and area controller well being dependencies, acknowledge data-consistency dangers, apply a focused correction or escalate safely, and confirm convergence and the unique enterprise symptom. This diagnostic self-discipline ought to precede superior restoration so learners can distinguish a correctable replication fault from a broader consistency failure that warrants restoration.
24. Superior Lively Listing again up and restoration
URL: https://study.microsoft.com/en-us/coaching/modules/active-directory-backup-recovery/
Evaluation: ADVANCED
This module treats AD DS backup and restoration as Tier 0 structure and incident response quite than a single restore operation. It covers backup design round restoration time and restoration level targets, topology, retention, and belief boundaries; evidence-based backup validation; collection of object, area controller, area, or forest restoration scope; restoration of objects, attributes, hierarchies, DNS, and SYSVOL; area and forest sequencing involving FSMO roles, RID state, international catalogs, and trusts; secure virtualized area controller restoration; and complete validation earlier than reconnection. It’s the last capstone as a result of secure restoration requires the learner to combine almost each previous subject whereas making high-impact choices below managed change and safety processes.
