AZ-800 — Frequently Asked Questions

Community-vetted answers to 10 common questions about this exam.

By default, members of the Administrators group have the right to establish a PowerShell remoting session. This is controlled by the 'Allow users to connect remotely by using Remote Desktop Services' user right and membership in the local Administrators group, which is granted access via the default security descriptor for the WinRM service.

On a member server (a server joined to a domain but not a Domain Controller), you cannot configure domain-wide password policies. Instead, you manage local account policies using the Local Security Policy (secpol.msc) or Group Policy Objects (GPOs) linked to the OU containing the member server. Fine-Grained Password Policies (FGPP) apply to domain users but are configured on the Domain Controller, not the member server itself.

In Microsoft Entra Domain Services, the AAD DC Administrators group is the privileged group that has the permissions to manage GPOs. Members of this group can create, edit, and link GPOs within the managed domain, similar to how Domain Admins function in a traditional on-premises Active Directory.

The first step is to install and configure the Log Analytics agent (Microsoft Monitoring Agent) or the Azure Monitor Agent (AMA) on the on-premises servers. Without the agent installed and connected to a Log Analytics workspace, Azure Monitor cannot collect data from the on-premises environment.

You must check for Fine-Grained Password Policies (FGPP). If a Password Settings Object (PSO) is linked directly to User1 or a group User1 belongs to, that PSO's settings override the default domain policy. If no PSO applies, the minimum password length defined in the Default Domain Policy applies.

Any server running the DFS Namespaces role service can host a namespace, but folder targets can be located on any server that shares a folder (SMB share). However, for replication and high availability, the targets are typically Windows Servers (Domain Controllers or Member Servers) that are part of the domain and have the DFS Replication role installed.

Access is restricted using Role-Based Access Control (RBAC) and Local User Groups. You should configure the 'Access' settings within Windows Admin Center to specify which users or groups (e.g., 'Windows Admin Center Administrators') are allowed to log in. Additionally, using Constrained Delegation or Just Enough Administration (JEA) helps limit what administrators can do once connected.

The Azure Connected Machine agent must be installed directly on the on-premises physical server or virtual machine (whether it is hosted on-premises, in another cloud like AWS/GCP, or in a virtualized environment like VMware/Hyper-V) that you intend to manage via Azure Arc.

The most secure method is to use CredSSP (Credential Security Support Provider) or Kerberos Constrained Delegation. CredSSP allows the client to delegate credentials to the second hop, but it carries a risk of credential theft if the intermediate server is compromised. Constrained Delegation is generally preferred for better security, allowing specific services to act on behalf of a user to a specific service on another server.

Drive D: is typically reserved for the Temporary Resource Disk. To assign D: to a persistent data disk, you must first change the drive letter of the temporary disk to something else (like T: or Z:) using Disk Management or diskpart. Once D: is free, you can assign it to your mounted persistent data disk. Note: This is generally not recommended as the temporary disk is optimized for pagefile and scratch space.

← Back to Microsoft AZ-800 Exam Questions & Knowledge Points Guide