Choose your language
Deploying and Managing Active Directory in Hybrid Environments Course
More than 2 million students worldwide

Deploying and Managing Active Directory in Hybrid Environments Course

4.7

Master every layer of Active Directory — from on-premises domain design to cloud-connected hybrid identity. This course equips IT professionals with the hands-on skills to deploy, secure, and manage AD in real-world enterprise environments. Whether you're extending your infrastructure to Microsoft Entra ID or hardening your domain against modern threats, you'll finish ready to deliver.

Dedika for businesses

What you will learn:

  • Configure and manage Active Directory domain controllers, FSMO roles, and replication topology.

  • Deploy Microsoft Entra Connect to establish hybrid identity with password hash sync and Seamless SSO.

  • Design and enforce Group Policy Objects to meet security compliance and desktop management requirements.

  • Implement AD security hardening techniques, including Credential Guard, LAPS, and tiered administration models.

  • Run domain controllers on cloud IaaS infrastructure and connect on-premises AD to cloud workloads.

  • Develop backup strategies and execute domain controller and forest recovery procedures in lab environments.

How you study in practice Deploying and Managing Active Directory in Hybrid Environments Course

How you practise Deploying and Managing Active Directory in Hybrid Environments Course

For companies looking to train their team

With Dedika for businesses, the course includes exercises and examples tailored to your own business and the specific needs of your company.

Click here

Course content

8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Active Directory Fundamentals and Architecture

  • Lesson 1 • Domain Controllers and FSMO Roles

    Details DC responsibilities and the five FSMO roles. Students identify which role handles each operation and plan role placement.

  • Lesson 2 • Directory Services and Identity Concepts

    Covers LDAP, X.500 standards, and the role of directory services in enterprise identity. Provides the conceptual baseline for all subsequent AD topics.

  • Lesson 3 • AD Logical and Physical Components

    Explains domains, trees, forests, OUs, sites, and site links. Students map logical design to physical network topology.

  • Lesson 4 • AD Replication Fundamentals

    Teaches intra-site and inter-site replication, KCC, and replication topology. Students troubleshoot basic replication failures using built-in tools.

  • Lesson 5 • AD Schema and Global Catalog

    Examines schema structure, attribute definitions, and global catalog partial attribute sets. Students extend the schema safely in a lab environment.

Chapter 2See details

Deploying On-Premises Active Directory

  • Lesson 1 • Planning the AD Domain Design

    Covers namespace planning, single vs. multi-domain models, and forest design criteria. Students produce a domain design document before any deployment.

  • Lesson 2 • Sites, Subnets, and Replication Topology

    Configures AD sites, subnets, and site link objects to control replication traffic. Students optimise replication schedules for WAN-connected branch offices.

  • Lesson 3 • DNS Integration with Active Directory

    Explains AD-integrated DNS zones, SRV records, and dynamic updates. Students configure DNS to support DC locator and replication.

  • Lesson 4 • Functional Levels and Feature Enablement

    Covers domain and forest functional levels and the features each unlocks. Students raise functional levels and validate compatibility before proceeding.

  • Lesson 5 • Installing and Promoting Domain Controllers

    Walks through DC installation via Server Manager and PowerShell. Students promote the first DC and add replica DCs to an existing domain.

Chapter 3See details

User, Group, and Computer Object Management

  • Lesson 1 • Computer Account Management

    Manages computer accounts, pre-staging, and secure channel maintenance. Students join machines to the domain and reset broken secure channels.

  • Lesson 2 • Delegation of Administrative Control

    Uses the Delegation of Control Wizard and custom ACLs to assign granular permissions. Students delegate password reset and OU management without granting Domain Admin rights.

  • Lesson 3 • Automating Object Management with PowerShell

    Leverages the ActiveDirectory module for scripted provisioning and reporting. Students build reusable scripts for onboarding and offboarding workflows.

  • Lesson 4 • Group Types, Scopes, and Nesting

    Explains security vs. distribution groups and domain local, global, and universal scopes. Students apply the AGDLP nesting strategy.

  • Lesson 5 • User Account Creation and Configuration

    Covers attribute population, UPN suffixes, and account options. Students create accounts manually and via PowerShell bulk import.

Chapter 4See details

Group Policy Design and Management

  • Lesson 1 • Creating and Linking GPOs

    Covers GPO creation, linking to OUs, and WMI filter targeting. Students link GPOs to the correct scope and verify application with gpresult.

  • Lesson 2 • Configuring Security and Compliance Settings

    Applies password policies, account lockout, audit policies, and security options. Students implement a security baseline aligned with industry hardening guidance.

  • Lesson 3 • Group Policy Architecture and Processing

    Explains GPO structure, LSDOU processing order, and inheritance. Students predict effective policy by tracing the processing chain.

  • Lesson 4 • Software and Desktop Management via GPO

    Deploys software packages, drive maps, and desktop restrictions through GPO. Students configure folder redirection and preference items for managed desktops.

  • Lesson 5 • Troubleshooting Group Policy Issues

    Diagnoses GPO failures using gpresult, RSOP, and event logs. Students resolve common issues including blocked inheritance and replication lag.

Chapter 5See details

Active Directory Security and Hardening

  • Lesson 1 • Securing the AD Control Plane

    Hardens DCs with SCM baselines, restricts RDP access, and enables Credential Guard. Students validate hardening with automated assessment tools.

  • Lesson 2 • AD Attack Surface and Threat Landscape

    Identifies common AD attack vectors including pass-the-hash, Kerberoasting, and DCSync. Students map threats to AD components to prioritise hardening efforts.

  • Lesson 3 • Kerberos and Authentication Hardening

    Configures Kerberos policies, disables weak encryption types, and enforces AES. Students harden service accounts against Kerberoasting.

  • Lesson 4 • Privileged Access and Tiered Administration

    Implements the tiered administration model and Privileged Access Workstations. Students restrict admin account usage to appropriate tiers.

  • Lesson 5 • AD Auditing and Monitoring

    Configures advanced audit policies and forwards events to a SIEM. Students define alert rules for high-risk AD events.

Chapter 6See details

Hybrid Identity with Microsoft Entra ID

  • Lesson 1 • Hybrid Identity Architecture Overview

    Explains hybrid identity models: password hash sync, pass-through auth, and federation. Students select the appropriate model based on organisational requirements.

  • Lesson 2 • Single Sign-On and Seamless SSO

    Enables Seamless SSO and configures browser settings for transparent authentication. Students test SSO from domain-joined and non-domain-joined devices.

  • Lesson 3 • Installing and Configuring Microsoft Entra Connect

    Deploys Entra Connect, configures filtering, and maps attributes. Students perform an initial sync and validate object representation in Entra ID.

  • Lesson 4 • Managing Synchronisation and Filtering

    Configures scoping filters, attribute flow rules, and sync cycle management. Students resolve sync errors and force delta synchronisation.

  • Lesson 5 • Hybrid Device Identity and Registration

    Configures Hybrid Entra ID Join for domain-joined devices. Students register devices and verify device objects in both directories.

Chapter 7See details

AD DS in Cloud and Hybrid Scenarios

  • Lesson 1 • Connecting On-Premises AD to Cloud Networks

    Establishes VPN or ExpressRoute connectivity and configures DNS forwarding. Students validate DC replication across the hybrid network boundary.

  • Lesson 2 • Extending GPO and Policy to Cloud Workloads

    Applies GPO to cloud-hosted VMs joined to on-premises or managed domains. Students configure Intune co-management alongside GPO for hybrid endpoints.

  • Lesson 3 • Microsoft Entra Domain Services Overview

    Explains Entra Domain Services as a managed AD DS offering and its limitations. Students identify use cases where Entra DS replaces IaaS DCs.

  • Lesson 4 • High Availability for Hybrid AD Deployments

    Designs DC placement for resilience across on-premises and cloud sites. Students configure failover scenarios and test DC unavailability.

  • Lesson 5 • Running Domain Controllers on IaaS VMs

    Covers DC placement on cloud VMs, disk configuration, and VM-specific best practices. Students deploy a replica DC in a cloud virtual network.

Chapter 8See details

AD Backup, Recovery, and Disaster Planning

  • Lesson 1 • Domain Controller Recovery Procedures

    Covers DC recovery from hardware failure, corruption, and accidental demotion. Students rebuild a failed DC and restore it to a functional state.

  • Lesson 2 • Authoritative and Non-Authoritative Restore

    Explains the difference between authoritative and non-authoritative restores and when to use each. Students perform both restore types in a lab environment.

  • Lesson 3 • Restoring Deleted Objects and the AD Recycle Bin

    Enables and uses the AD Recycle Bin to recover deleted objects. Students restore users, groups, and OUs with full attribute preservation.

  • Lesson 4 • AD Backup Strategies and Tools

    Covers Windows Server Backup, third-party solutions, and backup frequency requirements. Students configure scheduled DC backups and verify backup integrity.

  • Lesson 5 • Forest Recovery Planning and Execution

    Develops a forest recovery plan following Microsoft's documented procedure. Students execute a simulated forest recovery in a lab environment.

Certification

Your valid completion certificate

This course is for you:

  • Systems Administrator: ready to take ownership of enterprise identity infrastructure.

  • Help Desk Technician: aiming to move into a mid-level infrastructure or AD role.

  • Network Engineer: expanding their skill set to include directory services and identity.

  • IT Generalist: managing a small domain and needing structured, deeper AD knowledge.

  • Cloud Engineer: integrating on-premises AD with Microsoft Entra ID for hybrid setups.

  • Junior Security Analyst: focused on understanding AD attack surfaces and hardening controls.

What our students say

Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to change platforms... I thank you for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the way videos are presented and transcribed, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos help a lot with learning.
André Felipe
André FelipePrompt Engineering Student

Top trainings

FAQ

Who is Dedika?

Is the certificate valid in Nigeria?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course