Trening govori o konfiguraciji naprednih usluga Windows Servera koristeći lokalne (engl. on-premises), hibridne i tehnologije u oblaku (eng. cloud). Na ovom tečaju IT profesionalci će naučiti kako iskoristiti hibridne mogućnosti Azurea, kako premjestiti radna opterećenja virtualnog i fizičkog poslužitelja na Azure IaaS i kako osigurati Azure VM-ove koji koriste Windows Server.
IT profesionalci će tijekom treninga usvojiti vještine i znanja vezane uz visoku dostupnost (engl. high availability), rješavanje problema (engl. troubleshooting) i oporavak od katastrofe (engl. disaster recovery). Tečaj naglašava administrativne alate i tehnologije uključujući Windows Admin Center, PowerShell, Azure Arc, Azure Automation Update Management, Microsoft Defender for Identity, Azure Security Center, Azure Migrate i Azure Monitor.
Što ćete naučiti
- Pojačati sigurnosnu konfiguraciju okruženja operacijskog sustava Windows Server.
- Poboljšati hibridnu sigurnost koristeći Azure Security Center, Azure Sentinel i Windows Update Management.
- Primijeniti sigurnosne značajke za zaštitu kritičnih resursa.
- Implementirati rješenja visoke dostupnosti i oporavka od katastrofe.
- Implementirati usluge oporavka u hibridnim scenarijima.
- Planirati i implementirati hibridnu i cloud migraciju, backup i oporavak.
- Nadogradnje i migracije povezane s AD DS-om i prostrom za pohranu.
- Upravljati i nadgledati hibridne scenarije koristeći WAC, Azure Arc, Azure Automation i Azure Monitor.
- Implementirati monitoring servisa i performansi i primijeniti rješavanja problema (engl. troubleshooting).
Kome je namijenjeno
Server administratorima koji imaju iskustva u radu s Windows Serverom i žele proširiti mogućnosti svojih lokalnih (engl. on-premises) okruženja kombiniranjem lokalnih i hibridnih tehnologija. Server administratorima koji već implementiraju i upravljaju lokalnim osnovnim tehnologijama, koji žele osigurati i zaštititi svoje okoline, migrirati virtualna i fizička radna opterećenja na Azure IaaS, omogućiti visoko dostupno, potpuno redundantno okruženje i obavljati nadzor i rješavanje problema.
Preduvjeti
- Iskustvo upravljanja Windows Serverom u lokalnim (engl. on-premises) okruženjima, uključujući AD DS, DNS, DFS, Hyper-V te sustava pohrane podataka.
- Iskustvo u radu s alatima za upravljanje servisima poput AD DS, DNS, DFS, Hyper-V.
- Osnovno poznavanje Microsoftovih tehnologija za pohranu, umrežavanje i virtualizaciju.
- Iskustvo u radu sa i razumijevanje osnovnih tehnologija umrežavanja kao što su IP adresiranje, name resolution i DHCP.
- Razumijevanje i iskustvo u radu s Microsoft Hyper-V-om i osnovnim konceptima virtualizacije.
- Svijest o sigurnosnim najboljim praksama.
- Osnovno razumijevanje sigurnosnih tehnologija (vatrozidovi, enkripcija, višefaktorska autentifikacija, SIEM/SOAR).
- Osnovno znanje o lokalnoj servisima kao što su Failover Clustering i Storage Spaces.
- Osnovno iskustvo s implementcijom i upravljanjem IaaS uslugama u Microsoft Azureu.
- Osnovno poznavanje Azure Active Directorya.
- Iskustvo praktičnog rada sa Windows klijentskim operativnim sustavima kao što su Windows 10 ili Windows 11.
- Osnovno iskustvo sa Windows PowerShellom.
- Razumijevanje koncepata koji se odnose na tehnologije Windows Servera kao što su visoka dostupnost i oporavak od katastrofe, automatizacija, monitoring i rješavanje problema.
Nastavni plan
Pregledaj
- Module 1: Windows Server security This module discusses how to protect an Active Directory environment by securing user accounts to least privilege and placing them in the Protected Users group. The module covers how to limit authentication scope and remediate potentially insecure accounts. The module also describes how to harden the security configuration of a Windows Server operating system environment. In addition, the module discusses the use of Windows Server Update Services to deploy operating system updates to computers on the network. Finally, the module covers how to secure Windows Server DNS to help protect the network name resolution infrastructure. After completing this module, students will be able to:
- Diagnose and remediate potential security vulnerabilities in Windows Server resources
- Harden the security configuration of the Windows Server operating system environment
- Deploy operating system updates to computers on a network by using Windows Server Update Services
- Secure Windows Server DNS to help protect the network name resolution infrastructure
- Implement DNS policies
- Diagnose network security issues in Windows Server IaaS virtual machines
- Onboard Windows Server computers to Azure Security Cente
- Deploy and manage updates for Azure VMs by enabling Azure Automation Update Management
- Implement Adaptive application controls to protect Windows Server IaaS VMs
- Configure Azure Disk Encryption for Windows IaaS VMs
- Back up and recover encrypted data
- Monitor Windows Server Azure IaaS VMs for changes in files and the registry
- Implement highly available storage volumes by using Clustered Share Volumes
- Implement highly available Windows Server workloads using failover clustering
- Describe Hyper-V VMs load balancing
- Implement Hyper-V VMs live migration and Hyper-V VMs storage migration
- Describe Windows Server File Server high availablity options
- Implement scaling for virtual machine scale sets and load-balanced VMs
- Implement Azure Site Recovery
- Describe Hyper-V Replica, pre-requisites for its use, and its high-level architecture and components
- Describe Hyper-V Replica use cases and security considerations
- Configure Hyper-V Replica settings, health monitoring, and failover options
- Describe extended replication
- Replicate, failover, and failback virtual machines and physical servers with Azure Site Recovery
- Recover Windows Server IaaS virtual machines by using Azure Backup
- Use Azure Backup to help protect the data for on-premises servers and virtualized workloads
- Implement Recovery Vaults and Azure Backup policies
- Protect Azure VMs with Azure Site Recovery
- Run a disaster recovery drill to validate protection
- Failover and failback Azure virtual machines
- Compare upgrading an AD DS forest and migrating to a new AD DS forest
- Describe the Active Directory Migration Tool (ADMT)
- Identify the requirements and considerations for using Storage Migration Service
- Describe how to migrate a server with storage migration
- Use the Windows Server Migration Tools to migrate specific Windows Server roles
- Plan a migration strategy and choose the appropriate migration tools
- Perform server assessment and discovery using Azure Migrate
- Migrate Windows Server workloads to Azure VM workloads using Azure Migrate
- Explain how to migrate workloads using Windows Server Migration tool
- Migrate file servers by using the Storage Migration Service
- Discover and containerize ASP.NET applcations running on Windows
- Migrate a containerized application to Azure App Service
- Explain the fundamentals of server performance tuning
- Use built-in tools in Windows Server to monitor server performance
- Use Server Manager and Windows Admin Center to review event logs
- Implement custom views
- Configure an event subscription
- Audit Windows Server events
- Configure Windows Server to record diagnostic information
- Recover the AD DS database and objects in AD DS
- Troubleshoot AD DS replication
- Troubleshoot hybrid authentication issues
- Implement Azure Monitor for IaaS VMs in Azure and in on-premises environments
- Implement Azure Monitor for IaaS VMs in Azure and in on-premises environments
- View VM metrics in Azure Metrics Explorer
- Use monitoring data to diagnose problems
- Evaluate Azure Monitor Logs and configure Azure Monitor VM Insights
- Configure a Log Analytics workspace
- Troubleshoot on-premises connectivity and hybrid network connectivity
- Troubleshoot AD DS service failures or degraded performance
- Recover deleted security objects and the AD DS database
- Troubleshoot hybrid authentication issues
Za koji certifikat te priprema
Certifikacijski ispit: Exam AZ-801: Configuring Windows Server Hybrid Advanced Services