Welcome to ONLC Training Centers

MOC On-Demand: 10969-Active Directory Services with Windows Server Course Outline

 (5 days)
Version 2012
Special Note to New Hampshire Residents
This course has not yet been approved by the New Hampshire Department of Education. Please contact us for an update on when the class will be available in New Hampshire.

*** Note: This is an On-Demand Self Study Class, 5-days of content, 90-days unlimited access, $995 ***
You can take this class at any time; there are no set dates. It covers the same content as the 5-day instructor-led class of the same name. The cost for this MOC On-Demand class is $995. (Applicable State and Local taxes may be added for On-Demand purchases, depending on your location.) Microsoft Enterprise customers paying with Software Assurance Vouchers, see SATV Payment note below.

MOC On-Demand Learner Profiles
MOC On-Demand is a self-study training solution that was designed for two types of learners. First, MOC On-Demand is a great fit for experienced IT professionals who don't need a traditional 5-day class to upgrade their existing skills. They can pick and choose topics to make the most effective use of their time. Second, MOC On-Demand is perfect for highly-motivated individuals who are new to a technology and need to space their learning over a period of weeks or months. These learners can take their time and repeat sections as needed until they master the new concepts.

About MOC On-Demand
Our MOC On-Demand classes are self-study courses with 30 to 40 hours of content. They include hours of videos, hands-on labs using the actual software, and knowledge checks and were created by Microsoft to mirror the content found in the traditional live instructor-led version of this course. Those features are all part of the standard MOC On-Demand training. But don't settle for the standard MOC On-Demand class! Check out the "ONLC Extras" that you get when purchasing this course from us.

ONLC Extras
ONLC Training Centers bundles in valuable extras with our MOC On-Demand Courses. These items are not available from other training companies.
Courseware After the Course. Get the digital courseware that is used in the live, instructor-led version of this class. While the MOC On-Demand access goes away after 90 days, you will have access to the "extra" digital courseware for an unlimited period of time.
24/7 Online Support. You will be able to chat online with a content matter expert while you are taking your MOC On-Demand class. And, with your permission, the expert can even take over your computer to provide with assistance with your labs.

Optional Add-Ons
These add-ons are available exclusively by ONLC Training Centers and are offered to you at an additional cost.
Certification Pak, $150. Interested in obtaining certification? Get a Transcender practice exam and a Microsoft exam voucher at this reduced price.
ILT Listener, $250. Want to listen in and follow along with a live Instructor-Led Training (ILT) class? We offer this option for individuals on a limited budget who have time during the day to hear a live class in progress. ILT Listeners have access to their online support chat expert during the class but they do not have direct access to the live instructor.
ILT Participant, $ Varies. You've purchased MOC On-Demand, have gone through the training and decided that you still want a live class. Just pay difference between MOC On-Demand course and and the Instructor-Led Training (ILT) class and you can have a seat in our live class. Get both self-study and live, instructor-led training for the retail price of the instructor-led class alone!

Paying with Software Assurance Training Vouchers (SATV)
For Microsoft Enterprise customers paying with Software Assurance Vouchers, the cost of this class is 5 vouchers--this includes access to the self-study materials, the student workbook, 24/7 access to an online expert, and a corresponding exam voucher, if applicable, upon request.

Do You Still Prefer a Live, Instructor-led Class?
Already know MOC On-Demand is not right for you? We also offer this same course content in a live, instructor-led format. For more details, click on the link below:
10969 Instructor-led


This self-study class (equivalent to our 5-day instructor-led course) provides hands-on instruction and practice administering Active Directory technologies in Windows Server 2012 and Windows Server 2012 R2 in this 5-day Microsoft Official Course. You will learn the skills you need to better manage and protect data access and information, simplify deployment and management of your identity infrastructure, and provide more secure access to data from virtually anywhere. You will learn how to configure some of the key features in Active Directory such as Active Directory Domain Services, Group Policy, Dynamic Access Control, Work Folders, Workplace Join, Certificate Services, Rights Management Services and Federation Services, as well as integrating your on premise environment with cloud based technologies such as Windows Azure Active Directory. As part of the learning experience, you will perform hands-on exercises in a virtual lab environment. NOTE: This course is based on Windows Server 2012 and Windows Server 2012 R2. This course is designed for experienced IT professionals who support medium to large enterprises and have fundamental knowledge and experience administering Active Directory.

Audience Profile
This course is intended for Information Technology (IT) professionals who have Active Directory Domain Services (AD DS) experience and are looking for a single course that will further develop knowledge and skills using Access and Information Protection technologies in Windows Server 2012 and Windows Server 2012 R2. This would typically include:
AD DS administrators who are looking to further develop skills in the latest Access and Information Protection technologies with Windows Server 2012 and Windows Server 2012 R2.
System or Infrastructure administrators with general AD DS experience and knowledge who are looking to build upon that core knowledge and cross-train into advanced Active Directory technologies in Windows Server 2012 and Windows Server 2012 R2
IT Professionals who have taken the 10967A: Fundamentals of a Windows Server Infrastructure course and are looking to build upon that Active Directory knowledge.

Before attending this course, students must have:
Experience working with AD DS.
Experience working in a Windows Server infrastructure enterprise environment.
Experience working with and troubleshooting core networking infrastructure technologies such as name resolution, IP Addressing, Domain Name System (DNS) and Dynamic Host Configuration Protocol (DHCP).
Experience with Hyper-V and Server Virtualization concepts.
An awareness and understanding of general security best practices.
Experience working hands on with Windows Client operating systems such as Windows Vista, Windows 7 or Windows 8.

At Course Completion
After completing this course, students will be able to:
Understand available solutions for identity management and be able to address scenarios with appropriate solutions.
Deploy and administer AD DS in Windows Server 2012.
Secure AD DS deployment.
Monitor, troubleshoot and establish business continuity for AD DS services.
Implement AD DS sites, configure and manage replication
Implement and manage GPOs.
Manage user settings with GPOs.
Secure and provision data access using technologies such as Dynamic Access Control, Work Folders and Workplace Join
Implement certification authority (CA) hierarchy with AD CS and how to manage CAs.
Implement certificates.
Implement and manage AD RMS.
Implement and administer AD FS.
Implement Windows Azure Active Directory.
Implement and administer Active Directory Lightweight Directory Services (AD LDS).

Course Outline

Module 1: Overview of Access and Information Protection
This module explains Access and Information Protection (AIP) solutions from the business perspective and maps business problems to technical solutions.
Introduction to Access and Information Protection Solutions in Business
Overview of AIP Solutions in Windows Server 2012
Overview of Forefront Identity Manager 2010 R2
Lab : Choosing an Appropriate Access and Information Protection Management Solution
Analyze the Lab Scenario and Identify Business Requirements
Propose a Solution

Module 2: Advanced Deployment and Administration of AD DS
This module explains how to deploy AD DS remotely and describes the virtualization safeguards, cloning abilities and extending AD DS to the cloud.
Deploying AD DS
Deploying and Cloning Virtual Domain Controllers
Deploying Domain Controllers in Windows Azure
Administering AD DS
Lab : Deploying and Administering AD DS
Deploying AD DS
Deploying Domain Controller by Performing Domain Controller Cloning
Administering AD DS

Module 3: Securing Active Directory Domain Services
This module describes the threats to domain controllers and what methods can be used to secure the AD DS and its domain controllers.
Securing Domain Controllers
Implementing Password and Lockout Policies
Audit Authentication
Lab : Securing Active Directory Domain Services
Implementing Security Policies for Accounts and Passwords and Administrative Groups
Deploying and Configuring a RODC

Module 4: Monitoring, Managing, and Recovering AD DS
This module explains how to use tools that help monitor performance in real time, and how to record performance over time to spot potential problems by observing performance trends. This module also explains how to optimize and protect your directory service and related identity and access solutions so that if a service does fail, you can restart it as quickly as possible.
Monitoring AD DS
Managing the AD DS Database
AD DS Backup and Recovery Options for AD°DS and Other Identity and Access Solutions
Lab : Monitoring AD DS
Monitoring AD DS with Performance Monitor
Lab : Recovering Objects in AD DS
Backing up and Restoring AD DS
Recovering Objects in AD DS

Module 5: Implementing and Administering AD DS Sites and Replication
This module explains how AD DS replicates information between domain controllers within a single site and throughout multiple sites. This module also explains how to create multiple sites and how to monitor replication to help optimize AD DS replication and authentication traffic.
Overview of AD DS Replication
Configuring AD DS Sites
Configuring and Monitoring AD DS Replication
Lab : Implementing AD DS Sites and Replication
Creating Subnets and Sites
Deploying an Additional Domain Controller
Configuring AD DS Replication
Troubleshooting AD DS Replication

Module 6: Implementing Group Policy
This module describes Group Policy, how it works, and how best to implement it in your organization.
Introducing Group Policy
Implementing and Administering GPOs
Group Policy Scope and Group Policy Processing
Troubleshooting the Application of GPOs
Lab : Implementing and Troubleshooting a Group Policy Infrastructure
Creating and Configuring GPOs
Managing GPO Scope
Verifying GPO Application
Managing GPOs
Troubleshooting GPOs

Module 7: Managing User Settings with Group Policy
This module describes how to how to use GPO Administrative Templates, Folder Redirection, and Group Policy features to configure users’ computer settings.
Implementing Administrative Templates
Configuring Folder Redirection and Scripts
Configuring Group Policy Preferences
Lab : Managing User Desktops with Group Policy
Implementing Settings by Using Group Policy Preferences
Configuring Folder Redirection

Module 8: Implementing Secure Shared File Access
This module explains how to use Dynamic Access Control (DAC) and Work Folders and how to plan and implement these technologies.
Overview of DAC
Implementing DAC Components
Implementing DAC for Access Control
Implementing Access Denied Assistance
Implementing and Managing Work Folders
Implementing Workplace Join
Lab : Implementing Secure File Access
Preparing for DAC Deployment
Implementing DAC
Validating and Remediating DAC
Implementing Work Folders

Module 9: Deploying and Managing Active Directory Certificate Services
This module explain how to deploy and manage CAs.
Deploying CAs
Administering CAs
Troubleshooting, Maintaining, and Monitoring CAs
Lab : Deploying and Configuring a Two-Tier CA Hierarchy
Deploying an Offline Root CA
Deploying an Enterprise Subordinate CA

Module 10: Deploying and Managing Certificates
This module explains how to deploy and manage certificates, configure certificate templates and manage enrollment process. Also, this module describes certificate usage in business environments and about deployment and management of smart cards.
Deploying and Managing Certificate Templates
Managing Certificates Deployment, Revocation and Recovery
Using Certificates in a Business Environment
Implementing and Managing Smart Cards
Lab : Deploying and Using Certificates
Configuring Certificate Templates
Enrolling and Using Certificates
Configuring and Implementing Key Recovery

Module 11: Implementing and Administering Active Directory Rights Management Services
This module introduces Active Directory Rights Management Services (AD RMS). It also describes how to deploy AD RMS, how to configure content protection, and how to make AD RMS–protected documents available to external users.
Overview of AD RMS
Deploying and Managing an AD RMS Infrastructure
Configuring AD RMS Content Protection
Configuring External Access to AD RMS
Lab : Implementing AD RMS Infrastructure
Installing and Configure AD RMS
Configuring AD RMS Templates
Using ADRMS on Clients
Configuring AD RMS Monitoring and Reporting

Module 12: Implementing and Administering AD FS
This module explains AD FS, and then provides details on how to configure AD FS in both a single organization scenario and in a partner organization scenario. This module also describes the Web Application Proxy feature in Windows Server 2012 R2 that functions as an AD FS proxy and reverse proxy for web-based applications.
Overview of AD FS
Deploying AD FS
Implementing AD FS for a Single Organization
Deploying AD FS in a Business to Business Federation Scenario
Extending AD FS to External Clients
Lab : Implementing AD FS
Installing and Configuring AD FS
Configuring an Internal Application for AD FS
Configuring AD FS for a Federated Business Partner
Configuring a Web Application Proxy

Module 13: Implementing Windows Azure Active Directory
This module explains how to implement Windows Azure Active Directory.
Overview of Windows Azure Active Directory
Administering Windows Azure Active Directory
Lab : Implementing Azure AD
Planning to Implement Azure AD
Administering Azure AD

Module 14: Implementing and Administering AD LDS
This module explains how to deploy and configure AD LDS.
Overview of AD LDS
Deploying AD LDS
Configuring AD LDS Instances and Partitions
Configuring AD LDS Replication
Lab : Implementing and Administering AD LDS
Configuring AD LDS Instances and Partitions
Configuring AD LDS Replication
View outline in Word


Attend hands-on, instructor-led MOC On-Demand: 10969-Active Directory Services with Windows Server training classes at ONLC's more than 300 locations. Not near one of our locations? Attend these same live classes from your home/office PC via our Remote Classroom Instruction (RCI) technology.

For additional training options, check out our list of Active Directory Courses and select the one that's right for you.

Microsoft Gold Partner


Need a price quote?

Follow the link to our self-service price quote form to generate an email with a price quote.

Attend computer classes from ONLC Training Centers Request a copy via mail


Class Format
Class Policies
Student Reviews

Bookmark and Share

First Name

Last Name