This is an example of a simple banner

Training: Administer Active Directory Domain Services (AZ-1008)

Ref. AZ-1008
Duration:
1
 jour
Exam:
Non certifiant
Level:
Intermédiaire

Administer Active Directory Domain Services Training (AZ-1008)

The Active Directory AZ-1008 training teaches you to administer Active Directory Domain Services in hybrid environments combining on-premises infrastructure and Microsoft cloud services. In one intensive day, you master deploying domain controllers, managing users and groups, configuring Group Policy Objects (GPOs), integrating with Microsoft Entra ID, and securing privileged accounts. This practical course addresses the needs of system administrators managing Windows identity infrastructure.

Delivered by MCT certified trainers at ITTA in Geneva and Lausanne or via virtual classroom, this training includes hands-on labs on Microsoft cloud environments. You configure domain controllers, create organizational structures, deploy GPOs, set up Microsoft Entra Connect synchronization, and implement privileged access security. These skills are essential for IT teams in Switzerland that maintain Active Directory as the backbone of their identity infrastructure.

Participant Profiles

  • System and network administrators
  • IT support technicians
  • Infrastructure engineers
  • Identity management consultants

Objectives

  • Deploy and manage Active Directory domain controllers
  • Configure AD objects: users, groups and organizational units
  • Implement Group Policy Objects (GPO) for centralized administration
  • Integrate AD DS with Microsoft Entra ID for hybrid environments
  • Secure privileged accounts and configure administration delegation
  • Manage AD replication and Active Directory sites

Prerequisites

  • Master Windows Server administration
  • Understand networking and authentication concepts
  • Know the basics of Active Directory

Course Content

Module 1 : Deploy and Manage Active Directory Domain Services Domain Controllers

  • Define Active Directory Domain Services
  • Define Active Directory Domain Services forests and domains
  • Deploy Active Directory Domain Services domain controllers
  • Migrate a domain controller to a new site
  • Manage Active Directory Domain Services operations masters

Module 2 : Create and Manage Active Directory Objects

  • Define users, groups, and computers
  • Define organizational units
  • Manage objects and their properties in Active Directory
  • Create objects in Active Directory
  • Configure objects in Active Directory
  • Perform bulk management tasks for user accounts
  • Maintain Active Directory Domain Services domain controllers

Module 3 : Create and Configure Group Policy Objects in Active Directory

  • Define Group Policy Objects
  • Implement Group Policy Object scope and inheritance
  • Define domain-based Group Policy Objects
  • Create and configure a domain-based Group Policy Object
  • Configure a domain password policy
  • Configure and apply a fine-grained password policy

Module 4 : Manage Security in Active Directory

  • Configure user account rights
  • Configure user account rights to restrict access
  • Delegate permissions in Active Directory
  • Protect user accounts with the Protected Users group
  • Describe Windows Defender Credential Guard
  • Block Windows NTLM authentication
  • Locate problematic accounts

Module 5 : Guided Project – Administer Active Directory Domain Services

  • Create and deploy domains
  • Configure group policy objects
  • Manage password policies
  • Configure security settings

Documentation

  • Access to Microsoft Learn, Microsoft’s online learning platform, offering interactive resources and educational content to deepen your knowledge and develop your technical skills.

Lab / Exercises

  • Ce cours vous donne un accès exclusif au laboratoire officiel Microsoft, vous permettant de mettre en pratique vos compétences dans un environnement professionnel.

Complementary Courses

Eligible Funding

ITTA is a partner of a continuing education fund dedicated to temporary workers. This fund can subsidize your training, provided that you are subject to the “Service Provision” collective labor agreement (CCT) and meet certain conditions, including having worked at least 88 hours in the past 12 months.

Additional Information

Active Directory Training: Administer AD DS in Modern Hybrid Environments

Active Directory Domain Services (AD DS) remains the cornerstone of identity and access management in most enterprise environments. Despite the rise of cloud identity services, the vast majority of Swiss organizations maintain on-premises Active Directory as the authoritative source for user identities, computer accounts, and security policies. The hybrid integration with Microsoft Entra ID adds a cloud dimension that administrators must master.

The AZ-1008 training, “Administer Active Directory Domain Services,” provides practical skills to deploy, configure, and manage AD DS in modern hybrid environments. In one intensive day delivered by MCT certified trainers at ITTA in Geneva or Lausanne, you work through hands-on labs covering domain controller deployment, object management, Group Policy, hybrid integration, and security. This training is essential for system administrators responsible for Windows identity infrastructure in Switzerland.

Domain Controllers and Active Directory Architecture

Domain controllers are the servers that host the AD DS database and provide authentication and authorization services. The AZ-1008 training covers deploying domain controllers using Server Manager and PowerShell, configuring sites and subnets for optimal replication, and managing FSMO (Flexible Single Master Operations) roles. You learn to plan a domain controller topology that ensures high availability and fault tolerance.

Active Directory architecture encompasses forests, domains, trees, and trust relationships. The training covers designing organizational unit (OU) structures that reflect your organization’s administrative model, configuring trust relationships between domains or forests, and managing the AD DS schema. These architectural decisions have long-term implications for security and manageability.

User, Group and GPO Management

Managing user accounts, groups, and organizational units is the daily work of Active Directory administrators. The training covers creating and managing these objects using Active Directory Administrative Center, PowerShell, and bulk operations. You learn to implement naming conventions, configure account policies (password, lockout), and delegate administrative permissions at the OU level.

Group Policy Objects (GPOs) enable centralized configuration management across thousands of computers and users. The AZ-1008 training covers creating GPOs, linking them to sites, domains, and OUs, configuring security settings, software deployment, folder redirection, and logon scripts. You learn to use Group Policy Management Console (GPMC) to troubleshoot policy application with RSoP and GPResult.

Hybrid Integration with Microsoft Entra ID

Most Swiss organizations operate in hybrid mode, maintaining on-premises Active Directory while using Microsoft 365 and Azure services. The AZ-1008 training covers configuring Microsoft Entra Connect (formerly Azure AD Connect) to synchronize identities between AD DS and Entra ID. You learn to configure password hash synchronization, pass-through authentication, and filtering rules to control which objects are synchronized.

The hybrid integration enables single sign-on (SSO) for users accessing both on-premises resources and cloud services. The training covers troubleshooting synchronization issues, managing hybrid identity lifecycle, and understanding the implications of different authentication methods for security and user experience.

Security and Privileged Access Management

Securing Active Directory is critical because a compromised AD environment gives attackers access to the entire organization. The AZ-1008 training covers implementing tiered administration models, configuring Protected Users group membership, enabling advanced audit policies, and securing LDAP communications. You learn to identify and remediate common AD security weaknesses.

Privileged access management includes configuring delegation of administration to limit permissions to the minimum required, implementing Administrative Tier model separation, and using Group Managed Service Accounts (gMSA) for service accounts. These security practices are particularly important for Swiss companies in regulated industries that must demonstrate access control compliance.

Career Opportunities and Practical Applications

Active Directory administration skills remain in high demand in Switzerland. Despite cloud adoption, AD DS continues to be the foundation of most enterprise identity infrastructures, and skilled administrators are needed for maintenance, security hardening, and hybrid integration. The AZ-1008 training is an excellent entry point for the AZ-800 and AZ-801 certifications.

At ITTA, a Microsoft Learning Partner in Switzerland, this training is delivered by MCT certified trainers with hands-on labs on official Microsoft cloud environments. Sessions are available in-person in Geneva and Lausanne or via virtual classroom.

FAQ

What are the prerequisites for the AZ-1008 training?

Basic Windows Server familiarity and understanding of networking concepts (DNS, DHCP) are recommended. No certification is required.

Is Active Directory still relevant with Microsoft Entra ID?

Yes. Most organizations maintain on-premises AD DS alongside Microsoft Entra ID in a hybrid configuration. The skills learned in this training are essential for managing this hybrid identity infrastructure.

Does this training cover Microsoft Entra Domain Services?

The training focuses on on-premises AD DS and hybrid integration with Entra ID. Microsoft Entra Domain Services (managed AD in Azure) is mentioned but covered in more detail in Azure-focused trainings.

Is the training available as a virtual classroom?

Yes. ITTA offers this training in-person in Geneva and Lausanne as well as via virtual classroom with the same content and the same Microsoft cloud labs.

Prix de l'inscription
CHF 850.-
Inclus dans ce cours
  • Training provided by a certified trainer
  • 180 days of access to Official Microsoft Labs
  • Official documentation in digital format
  • Official Microsoft achievement badge
Mois actuel

mer08juil09:00mer17:00VirtuelVirtual Etiquettes de sessionAZ-1008

mer08juil09:00mer17:00Lausanne, Av. Mon-Repos 24, 1005 Lausanne Etiquettes de sessionAZ-1008

mer12Aoû09:00mer17:00VirtuelVirtual Etiquettes de sessionAZ-1008

mer12Aoû09:00mer17:00Genève, Route des Jeunes 35, 1227 Genève Etiquettes de sessionAZ-1008

mer16Sep09:00mer17:00VirtuelVirtual Etiquettes de sessionAZ-1008

mer16Sep09:00mer17:00Lausanne, Av. Mon-Repos 24, 1005 Lausanne Etiquettes de sessionAZ-1008

mer21Oct09:00mer17:00VirtuelVirtual Etiquettes de sessionAZ-1008

mer21Oct09:00mer17:00Genève, Route des Jeunes 35, 1227 Genève Etiquettes de sessionAZ-1008

mer25Nov09:00mer17:00VirtuelVirtual Etiquettes de sessionAZ-1008

mer25Nov09:00mer17:00Lausanne, Av. Mon-Repos 24, 1005 Lausanne Etiquettes de sessionAZ-1008

mer30Déc09:00mer17:00VirtuelVirtual Etiquettes de sessionAZ-1008

mer30Déc09:00mer17:00Genève, Route des Jeunes 35, 1227 Genève Etiquettes de sessionAZ-1008

Contact

ITTA
Route des jeunes 35
1227 Carouge, Suisse

Opening hours

Monday to Friday
8:30 AM to 6:00 PM
Tel. 058 307 73 00

Contact-us

ITTA
Route des jeunes 35
1227 Carouge, Suisse

Make a request

Contact

ITTA
Route des jeunes 35
1227 Carouge, Suisse

Opening hours

Monday to Friday, from 8:30 am to 06:00 pm.

Contact us

Your request