
Deploying and Managing Active Directory in Hybrid Environments Course
Master every layer of Active Directory — from on-premises domain design to cloud-connected hybrid identity. This course equips IT professionals with the hands-on skills to deploy, secure, and manage AD in real-world enterprise environments. Whether you're extending your infrastructure to Microsoft Entra ID or hardening your domain against modern threats, you'll finish ready to deliver.
What you will learn:
Configure and manage Active Directory domain controllers, FSMO roles, and replication topology.
Deploy Microsoft Entra Connect to establish hybrid identity with password hash sync and Seamless SSO.
Design and enforce Group Policy Objects to meet security compliance and desktop management requirements.
Implement AD security hardening techniques, including Credential Guard, LAPS, and tiered administration models.
Run domain controllers on cloud IaaS infrastructure and connect on-premises AD to cloud workloads.
Develop backup strategies and execute domain controller and forest recovery procedures in lab environments.
How you study in a practical way Deploying and Managing Active Directory in Hybrid Environments Course
How you practice Deploying and Managing Active Directory in Hybrid Environments Course
For companies who want to train their team
With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.
Course content
8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsActive Directory Fundamentals and Architecture
Active Directory Fundamentals and Architecture
Lesson 1 • Domain Controllers and FSMO Roles
Details DC responsibilities and the five FSMO roles. Students identify which role handles each operation and plan role placement.
Lesson 2 • Directory Services and Identity Concepts
Covers LDAP, X.500 standards, and the role of directory services in enterprise identity. Provides the conceptual baseline for all subsequent AD topics.
Lesson 3 • AD Logical and Physical Components
Explains domains, trees, forests, OUs, sites, and site links. Students map logical design to physical network topology.
Lesson 4 • AD Replication Fundamentals
Teaches intra-site and inter-site replication, KCC, and replication topology. Students troubleshoot basic replication failures using built-in tools.
Lesson 5 • AD Schema and Global Catalog
Examines schema structure, attribute definitions, and global catalog partial attribute sets. Students extend the schema safely in a lab environment.
Chapter 2HideHide detailsSee detailsDeploying On-Premises Active Directory
Deploying On-Premises Active Directory
Lesson 1 • Planning the AD Domain Design
Covers namespace planning, single vs. multi-domain models, and forest design criteria. Students produce a domain design document before any deployment.
Lesson 2 • Sites, Subnets, and Replication Topology
Configures AD sites, subnets, and site link objects to control replication traffic. Students optimize replication schedules for WAN-connected branch offices.
Lesson 3 • DNS Integration with Active Directory
Explains AD-integrated DNS zones, SRV records, and dynamic updates. Students configure DNS to support DC locator and replication.
Lesson 4 • Functional Levels and Feature Enablement
Covers domain and forest functional levels and the features each unlocks. Students raise functional levels and validate compatibility before proceeding.
Lesson 5 • Installing and Promoting Domain Controllers
Walks through DC installation via Server Manager and PowerShell. Students promote the first DC and add replica DCs to an existing domain.
Chapter 3HideHide detailsSee detailsUser, Group, and Computer Object Management
User, Group, and Computer Object Management
Lesson 1 • Computer Account Management
Manages computer accounts, pre-staging, and secure channel maintenance. Students join machines to the domain and reset broken secure channels.
Lesson 2 • Delegation of Administrative Control
Uses the Delegation of Control Wizard and custom ACLs to assign granular permissions. Students delegate password reset and OU management without granting Domain Admin rights.
Lesson 3 • Automating Object Management with PowerShell
Leverages the ActiveDirectory module for scripted provisioning and reporting. Students build reusable scripts for onboarding and offboarding workflows.
Lesson 4 • Group Types, Scopes, and Nesting
Explains security vs. distribution groups and domain local, global, and universal scopes. Students apply the AGDLP nesting strategy.
Lesson 5 • User Account Creation and Configuration
Covers attribute population, UPN suffixes, and account options. Students create accounts manually and via PowerShell bulk import.
Chapter 4HideHide detailsSee detailsGroup Policy Design and Management
Group Policy Design and Management
Lesson 1 • Creating and Linking GPOs
Covers GPO creation, linking to OUs, and WMI filter targeting. Students link GPOs to the correct scope and verify application with gpresult.
Lesson 2 • Configuring Security and Compliance Settings
Applies password policies, account lockout, audit policies, and security options. Students implement a security baseline aligned with industry hardening guidance.
Lesson 3 • Group Policy Architecture and Processing
Explains GPO structure, LSDOU processing order, and inheritance. Students predict effective policy by tracing the processing chain.
Lesson 4 • Software and Desktop Management via GPO
Deploys software packages, drive maps, and desktop restrictions through GPO. Students configure folder redirection and preference items for managed desktops.
Lesson 5 • Troubleshooting Group Policy Issues
Diagnoses GPO failures using gpresult, RSOP, and event logs. Students resolve common issues including blocked inheritance and replication lag.
Chapter 5HideHide detailsSee detailsActive Directory Security and Hardening
Active Directory Security and Hardening
Lesson 1 • Securing the AD Control Plane
Hardens DCs with SCM baselines, restricts RDP access, and enables Credential Guard. Students validate hardening with automated assessment tools.
Lesson 2 • AD Attack Surface and Threat Landscape
Identifies common AD attack vectors including pass-the-hash, Kerberoasting, and DCSync. Students map threats to AD components to prioritize hardening efforts.
Lesson 3 • Kerberos and Authentication Hardening
Configures Kerberos policies, disables weak encryption types, and enforces AES. Students harden service accounts against Kerberoasting.
Lesson 4 • Privileged Access and Tiered Administration
Implements the tiered administration model and Privileged Access Workstations. Students restrict admin account usage to appropriate tiers.
Lesson 5 • AD Auditing and Monitoring
Configures advanced audit policies and forwards events to a SIEM. Students define alert rules for high-risk AD events.
Chapter 6HideHide detailsSee detailsHybrid Identity with Microsoft Entra ID
Hybrid Identity with Microsoft Entra ID
Lesson 1 • Hybrid Identity Architecture Overview
Explains hybrid identity models: password hash sync, pass-through auth, and federation. Students select the appropriate model based on organizational requirements.
Lesson 2 • Single Sign-On and Seamless SSO
Enables Seamless SSO and configures browser settings for transparent authentication. Students test SSO from domain-joined and non-domain-joined devices.
Lesson 3 • Installing and Configuring Microsoft Entra Connect
Deploys Entra Connect, configures filtering, and maps attributes. Students perform an initial sync and validate object representation in Entra ID.
Lesson 4 • Managing Synchronization and Filtering
Configures scoping filters, attribute flow rules, and sync cycle management. Students resolve sync errors and force delta synchronization.
Lesson 5 • Hybrid Device Identity and Registration
Configures Hybrid Entra ID Join for domain-joined devices. Students register devices and verify device objects in both directories.
Chapter 7HideHide detailsSee detailsAD DS in Cloud and Hybrid Scenarios
AD DS in Cloud and Hybrid Scenarios
Lesson 1 • Connecting On-Premises AD to Cloud Networks
Establishes VPN or ExpressRoute connectivity and configures DNS forwarding. Students validate DC replication across the hybrid network boundary.
Lesson 2 • Extending GPO and Policy to Cloud Workloads
Applies GPO to cloud-hosted VMs joined to on-premises or managed domains. Students configure Intune co-management alongside GPO for hybrid endpoints.
Lesson 3 • Microsoft Entra Domain Services Overview
Explains Entra Domain Services as a managed AD DS offering and its limitations. Students identify use cases where Entra DS replaces IaaS DCs.
Lesson 4 • High Availability for Hybrid AD Deployments
Designs DC placement for resilience across on-premises and cloud sites. Students configure failover scenarios and test DC unavailability.
Lesson 5 • Running Domain Controllers on IaaS VMs
Covers DC placement on cloud VMs, disk configuration, and VM-specific best practices. Students deploy a replica DC in a cloud virtual network.
Chapter 8HideHide detailsSee detailsAD Backup, Recovery, and Disaster Planning
AD Backup, Recovery, and Disaster Planning
Lesson 1 • Domain Controller Recovery Procedures
Covers DC recovery from hardware failure, corruption, and accidental demotion. Students rebuild a failed DC and restore it to a functional state.
Lesson 2 • Authoritative and Non-Authoritative Restore
Explains the difference between authoritative and non-authoritative restores and when to use each. Students perform both restore types in a lab environment.
Lesson 3 • Restoring Deleted Objects and the AD Recycle Bin
Enables and uses the AD Recycle Bin to recover deleted objects. Students restore users, groups, and OUs with full attribute preservation.
Lesson 4 • AD Backup Strategies and Tools
Covers Windows Server Backup, third-party solutions, and backup frequency requirements. Students configure scheduled DC backups and verify backup integrity.
Lesson 5 • Forest Recovery Planning and Execution
Develops a forest recovery plan following Microsoft's documented procedure. Students execute a simulated forest recovery in a lab environment.
Your valid completion certificate
This course is for you:
Systems Administrator: ready to take ownership of enterprise identity infrastructure.
Help Desk Technician: aiming to move into a mid-level infrastructure or AD role.
Network Engineer: expanding their skill set to include directory services and identity.
IT Generalist: managing a small domain and needing structured, deeper AD knowledge.
Cloud Engineer: integrating on-premises AD with Microsoft Entra ID for hybrid setups.
Junior Security Analyst: focused on understanding AD attack surfaces and hardening controls.
What our students say
Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to change platforms... I thank you for everything you do, I've already recommended you to other people...

I like how the lessons are straight to the point and how I can switch chapters and skip content I don't need.

I like the content and the way videos are presented and transcribed, which speeds up the process!

The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.

Top trainings
FAQs
Who is Dedika?
Is the certificate valid in the Philippines?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course




















