[Jan 10, 2026] Pass Windows Server AZ-800 Exam With 310 Questions
Ultimate Guide to Prepare Free Microsoft AZ-800 Exam Questions and Answer
The AZ-800 exam measures the skills and knowledge required to administer and manage Windows Server hybrid core infrastructure. This includes managing virtual machines, storage, networking, and security in a hybrid environment that includes both on-premises and cloud-based resources.
AZ-800 Exam Details
Diving deep into the details of the exam, you will be given 40-60 questions of different types and will need to complete them within 100 or 120 minutes. The exam duration depends on whether labs are included in the exam or not. If they are included, the duration is, of course, longer. You will need to score at least 700 points to pass the test. Also, do not forget to pay a registration fee, which is $165 now.
NEW QUESTION # 80
Your network contains an on -premises Active Directory Domain Services (AD DS) domain named contoso.com The domain contains the objects shown in the following table.
You plan to sync contoso.com with an Azure Active Directory (Azure AD) tenant by using Azure AD Connect You need to ensure that all the objects can be used in Conditional Access policies What should you do?
- A. Select the Configure Hybrid Azure AD join option.
- B. Change the scope of Group2 to Universal
- C. Change the scope o' Group1 and Group2 to Global
- D. Clear the Configure device writeback option.
Answer: A
Explanation:
Hybrid Azure AD join needs to be configured to enable Computer1 to be used in Conditional Access Policies.
Synchronized users, universal groups and domain local groups can be used in Conditional Access Policies.
NEW QUESTION # 81
Hotspot Question
You have a Windows Server 2022 container host named Host1 that has the Subsystem for Linux installed and the container images shown in the following table.
You need to deploy the images to Host1. The solution must maximize the isolation of the containers.
Which images can you run by using process isolation, and which images can you run by using Hyper-V isolation? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
https://learn.microsoft.com/en-us/virtualization/windowscontainers/deploy-containers/version- compatibility?tabs=windows-server-202
NEW QUESTION # 82
Which of the following tools helps the users in identifying and remediating the object synchronization errors or issues like malformed or duplicate proxyAddresses and userPrincipalName in the Active directory?
- A. Dsdiag.exe tool
- B. ADModify.NET tool
- C. Microsoft 365 IdFix tool
- D. Repadmin.exe tool
Answer: C
Explanation:
The Microsoft 365 IdFix tool allows the users to identify and remediate the common object synchronization errors including general like malformed or duplicate proxyAddresses and userPrincipalName in Active Directory. You can choose the Organizational units that you expect IdFix to check, and the common errors can be fixed within the tool itself.
Reference:
https://docs.microsoft.com/en-us/learn/modules/implement-hybrid-identity-windows-server/04- prepare-premises-active-directory-synchronization
NEW QUESTION # 83
You have a server named Server1 that has Windows Admin Center installed. The certificate used by Windows Admin Center was obtained from a certification authority (CA).
The certificate expires.
You need to replace the certificate.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
Explanation
Graphical user interface, text, application Description automatically generated with medium confidence
Reference:
https://www.starwindsoftware.com/blog/change-the-windows-admin-center-certificate
NEW QUESTION # 84
You have a Windows Server container host named Server1 that has a single disk.
On Server1, you plan to start the containers shown in the following table.
Which isolation mode can you use for each container? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:

Reference:
https://docs.microsoft.com/en-us/virtualization/windowscontainers/manage-containers/hyperv-container
NEW QUESTION # 85
Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com. The domain contains the users shown in the following table.
The domain has the Group Policy Objects (GPOs) shown in the following table.
The GPOs are configured to map a drive named H as shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
NEW QUESTION # 86
You need to implement the planned change for Data1.
Which actions should you perform in sequence? To answer, drag the appropriate actions to the correct order.
Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
NEW QUESTION # 87
Which groups can you add lo Group3 and Groups? To answer, select the appropriate options in the answer are
a. NOTE Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 88
Case Study 2 - Contoso, Ltd
Overview
Contoso, Ltd. is a company that has a main office in Seattle and two branch offices in Los Angeles and Montreal.
Existing Environment
AD DS Environment
The network contains an on premises Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains two domains named contoso.com and canada.contoso.com.
The forest contains the domain controllers shown in the following table.
All the domain controllers are global catalog servers.
Server infrastructure
The network contains the servers shown in the following table.
A server named Server4 runs Windows Server and is in a workgroup. Windows Firewall on Server4 uses the private profile.
Server2 hosts three virtual machines named VM1, VM2, and VM3.
VM3 is a file server that stores data in the volumes shown in the following table.
Group Policies
The contoso.com domain has the Group Policies Objects (GPOs) shown in the following table.
Existing Identities
The forest contains the users shown in the following table.
The forest contains the groups shown in the following table.
Current Problems
When an administrator signs in to the console of VM2 by using Virtual Machine Connection, and then disconnects from the session without signing out, another administrator can connect to the console session as the currently signed in user.
Requirements
Technical Requirements
Contoso identifies the following technical requirements:
Change the replication schedule for all site links to 30 minutes.
Promote Server1 to a domain controller in canada.contoso.com.
Install and authorize Server3 as a DHCP server.
Ensure that User1 can manage the membership of all the groups in Contoso\OU3.
Ensure that you can manage Server4 from Server1 by using PowerShell remoting.
Ensure that you can run virtual machines on VM1.
Force users to provide credentials when they connect to VM2.
On VM3, ensure that Data Deduplication on all volumes is possible.
Question
Hotspot Question
You need to meet the technical requirements for VM1.
Which cmdlet should you run first? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
https://docs.microsoft.com/en-us/virtualization/hyper-v-on-windows/user-guide/nested- virtualization
NEW QUESTION # 89
You have a server named Server1 that runs Windows Server and has the Hyper V server role installed. Server1 hosts a virtual machine named VM1.
Server1 has an NVMe storage device. The device is currently assigned to VM1 by using Discrete Device Assignment.
You need to make the device available to Server1.
Which four actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
1 - From Server1, stop VM1.
2 - From Server1, run the Remove-VMAssignableDevice cmdlet.
3 - From Server1, run the Mount-VMHostassignableDevice cmdlet.
4 - From Server1, enable the device by using Device Manager.
Reference:
https://docs.microsoft.com/en-us/windows-server/virtualization/hyper-v/deploy/deploying-storage-devices-using-dda
NEW QUESTION # 90
Your on-premises network contains an Active Directory Domain Services (AD DS) domain. The domain contains the servers shown in the following table.
The domain controllers do NOT have internet connectivity.
You plan to implement Azure AD Password Protection for the domain.
You need to deploy Azure AD Password Protection agents. The solution must meet the following requirements:
* All Azure AD Password Protection policies must be enforced.
* Agent updates must be applied automatically.
* Administrative effort must be minimized.
What should you do? To answer select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
NEW QUESTION # 91
Task 1
You need to ensure that DC2 is the schema master for contoso.com.
Answer:
Explanation:
See the solution of this Task below.
Explanation:
Step-by-Step Guide: Seizing/Transferring the Schema Master Role to DC2
# Step 1: Log in to DC2
* Use an account that is a member of the Schema Admins, Enterprise Admins, and Domain Admins groups.
# Step 2: Register the Schema Snap-in
The Schema snap-in is not loaded by default.
* Open Command Prompt as Administrator.
* Type the following command to register the schema management DLL:
powershell
Copy
regsvr32 schmmgmt.dll
# Step 3: Open MMC (Microsoft Management Console)
* Press Windows + R, type mmc, and hit Enter.
* In MMC, go to File > Add/Remove Snap-in.
* Select Active Directory Schema, then click Add > OK.
# Step 4: Connect to DC2
* In the Active Directory Schema console, right-click Active Directory Schema and select Change Active Directory Domain Controller.
* In the dialog box, select DC2 and click OK.
* This will connect the console to DC2.
# Step 5: Transfer the Schema Master Role
* Right-click Active Directory Schema again and select Operations Master.
* In the Change Schema Master dialog box, confirm that DC2 is shown as the target.
* Click the Change button to transfer the Schema Master role to DC2.
* Click Yes when prompted to confirm the transfer.
# Step 6: Verify the Transfer
* In the same dialog box, ensure that DC2 is now listed as the Schema Master.
* Optionally, run the following command in PowerShell to verify:
netdom query fsmo
The Schema Master should now be DC2.
NEW QUESTION # 92
SIMULATION
Task 4
You need to run a container that uses the mcrmicrosoft.com/windows/servercofe/iis image on SRV1. Port 80 on the container must be published to port 5001 on SRV1 and the container must run in the background
Answer:
Explanation:
See the solution of this Task below
Explanation:
To run a container on SRV1 using the mcrmicrosoft.com/windows/servercofe/iis image, publish port 80 on the container to port 5001 on SRV1, and ensure it runs in the background, you can follow these steps:
Step 1: Pull the IIS Image First, pull the correct IIS image from the Microsoft Container Registry:
docker pull mcr.microsoft.com/windows/servercore/iis
Step 2: Run the Container Next, run the container with the required port mapping and ensure it runs in the background using the -d flag:
docker run -d -p 5001:80 --name iis_container mcr.microsoft.com/windows/servercore/iis This command will start a container named iis_container using the IIS image, map port 80 inside the container to port 5001 on SRV1, and run the container in detached mode.
Step 3: Verify the Container is Running To verify that the container is running and the port is published, use the following command:
docker ps
This will list all running containers and show the port mappings.
Step 4: Access the IIS Server You can now access the IIS server running in the container by navigating to http://<SRV1_IP>:5001 in a web browser, where <SRV1_IP> is the IP address of SRV1.
Note: Ensure that Docker is installed on SRV1 and that the port 5001 is open on the firewall to allow incoming connections1.
By following these steps, you should be able to run the IIS container on SRV1 with the specified port mapping and have it running in the background. Please replace mcrmicrosoft.com/windows/servercofe/iis with the correct image name mcr.microsoft.com/windows/servercore/iis as shown in the commands above.
NEW QUESTION # 93
While creating a zone on a DNS server, it is essential to identify whether it is a primary zone or a secondary zone. Which of the following statements is false about a primary or a secondary zone?
- A. You can't manage resource records in a secondary zone.
- B. It is possible to create, delete or edit resource records in a primary zone.
- C. A secondary zone is a read-only copy of a primary zone.
- D. A secondary zone allows creating resource records but you can't delete records in the secondary zone.
Answer: D
Explanation:
While creating a zone on a DNS server, you need to identify whether it is a primary zone or a secondary zone. If you want to create, delete or edit the resource records, you need to use the primary zone. As a secondary zone is a read-only copy of a primary zone, resource records can't be managed in a secondary zone.
NEW QUESTION # 94
You are an administrator and you need to create and manage AD DS Partitions. You have to use a command-line tool to perform the required tasks. Which of the following tools can help you?
- A. NtdsUtil.exe
- B. Repadmin.exe
- C. Diskpart
- D. Dcdiag.exe
Answer: A
Explanation:
AD DS partitions can be created and managed by using the NtdsUtil.exe command-line tool. This tool also allows the users to perform various other AD DS related management tasks, such as:
Cleaning up domain-controller metadata after its unrecoverable failure.
NTDS database maintenance, which includes creating snapshots, relocating, files, database and offline defragmentation.
Resetting the password utilized to sign in to the DSRM (Directory Services Restore Mode).
Reference:
https://www.oreilly.com/library/view/active-directory-5th/9781449361211/ch04.html
NEW QUESTION # 95
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You are planning the deployment of DNS to a new network.
You have three internal DNS servers as shown in the following table.
The contoso.local zone contains zone delegations for east.contoso.local and west.contoso.local. All the DNS servers use root hints.
You need to ensure that all the DNS servers can resolve the names of all the internal namespaces and internet hosts.
Solution: On Server2, you create a conditional forwarder for contoso.local and west.contoso.local. On Server3, you create a conditional forwarder for contoso.local and east.contoso.local.
Does this meet the goal?
- A. Yes
- B. No
Answer: A
NEW QUESTION # 96
You have four testing devices that are configured with static IP addresses as shown in the following table.
The test devices are turned on once a month.
You need to prevent Server1 from assigning the IP addresses allocated to the test devices to other devices when the test devices are offline. The solution must minimize administrative effort.
What should you do?
- A. Create a policy.
- B. Configure the Scope options.
- C. Create reservations.
- D. Create an exclusion range.
Answer: C
NEW QUESTION # 97
Your network contains an Active Directory Domain Services (AD DS) domain named adatum.com. The domain contains a file server named Server1 and three users named User1, User2, and User3.
Server1 contains a shared folder named Share1 that has the following configurations:
The share permissions for Share1 are configured as shown in the Share Permissions exhibit.
Share1 contains a file named File1.bxt. The share settings for File1.txt are configured as shown in the File Permissions exhibit.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
NEW QUESTION # 98
Your network contains an Active Directory Domain Services (AD DS) forest. The forest contains the servers shown in the following table.
On Server1, you create a DNS zone named Zone1.com as shown in the following exhibit.
To which DNS servers is Zone1.com replicated?
- A. Server2 and Server3 only
- B. Setver2 and Sen/er4 only
- C. Server2, Server3, Server4, and Server5
- D. Server2. Server3, and Server4 only
- E. Server2 only
Answer: D
NEW QUESTION # 99
Your network contains a DHCP server.
You plan to add a new subnet and deploy Windows Server to the subnet.
You need to use the server as a DHCP relay agent.
Which role should you install on the server?
- A. Remote Access
- B. Network Controller
- C. Network Policy and Access Services
- D. DHCP Server
Answer: A
NEW QUESTION # 100
Your network contains an Active Directory domain named contoso.com. The domain contains the computers shown in the following table.
On Server3, you create a Group Policy Object (GPO) named GP01 and link GPOI to contoso.com. GP01 includes a shortcut preference named Shortcut1 that has item-level targeting configured as shown in the following exhibit.
To which computer will Shortcut1 be applied?
- A. Server1, Server2, and Server3 only
- B. Computer1 and Server3 only
- C. Server2 and Server3 only
- D. Server3 only
Answer: D
NEW QUESTION # 101
You haw an Azure virtual machine named VM1 that runs Windows Server
You need to configure the management of VM1 to meet the following requirements:
* Require administrators to request access to VM1 before establishing a Remote Desktop connection.
* Limit access to VM1 from specific source IP addresses.
* Limit access to VMI to a specific management port
What should you configure?
- A. Azure Active Directory (Azure AD) Privileged identity Management (PIM)
- B. Azure Front Door
- C. a network security group (NSG)
- D. Microsoft Defender for Cloud
Answer: D
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/defender-fo
NEW QUESTION # 102
Hotspot Question
Your network contains the domains shown in the following exhibit.
You need to establish trust relationships as shown in the following exhibit.
Which type of trust can you use for Trust1 and Trust2? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 103
Your network contains an on -premises Active Directory Domain Services (AD DS) domain named contoso.
com The domain contains the objects shown in the following table.
You plan to sync contoso.com with an Azure Active Directory (Azure AD) tenant by using Azure AD Connect You need to ensure that all the objects can be used in Conditional Access policies What should you do?
- A. Select the Configure Hybrid Azure AD join option.
- B. Change the scope of Group2 to Universal
- C. Change the scope o' Group1 and Group2 to Global
- D. Clear the Configure device writeback option.
Answer: A
Explanation:
Hybrid Azure AD join needs to be configured to enable Computer1 to be used in Conditional Access Policies.
Synchronized users, universal groups and domain local groups can be used in Conditional Access Policies.
NEW QUESTION # 104
Your network contains an Active Directory domain named contoso.com. The domain contains group managed service accounts (gMSAs). You have a server named Server1 that runs Windows Server and is in a workgroup.
Server! hosts Windows containers.
You need to ensure that the Windows containers can authenticate to contoso.com.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
Explanation:
NEW QUESTION # 105
......
Pass AZ-800 Tests Engine pdf - All Free Dumps: https://passleader.examtorrent.com/AZ-800-prep4sure-dumps.html
