Choose your language
Active Directory Administration Training
More than 2 million learners worldwide

Active Directory Administration Training

4.3

Master every layer of Active Directory administration, from domain controller deployment and Group Policy design to security hardening and hybrid cloud integration. This training gives IT professionals the hands-on skills to build, manage, and protect enterprise AD environments with confidence. If you support Windows infrastructure, this is the course that closes your skill gaps.

Dedika for businesses

What you will learn:

You will learn how to design and deploy Active Directory forests, domains, and sites from the ground up. The course covers user, group, and computer account management, including bulk automation with PowerShell. You will configure and troubleshoot Group Policy Objects, manage AD replication across multi-site environments, and implement advanced security controls. Backup, recovery, and disaster planning procedures are covered in full detail. You will also extend on-premises AD into hybrid environments using Azure AD Connect and Active Directory Federation Services.

How you study in practice Active Directory Administration Training

How you practise Active Directory Administration Training

For companies looking to train their teams

With Dedika for Businesses, the course includes exercises and examples tailored to your own business and the specific needs of your company.

Click here

Course content

8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Active Directory Fundamentals and Architecture

  • Lesson 1 • AD Data Store and Schema

    Describes the NTDS.DIT database, schema partitions, and attribute definitions. Provides the technical grounding needed for advanced administration tasks.

  • Lesson 2 • Physical Structure and Site Topology

    Explains how sites, subnets, and site links reflect physical IT network infrastructure. Connects physical design to replication efficiency.

  • Lesson 3 • Logical Structure of Active Directory

    Covers forests, trees, domains, and organizational units as the logical building blocks of AD. Students map business requirements to logical AD design.

  • Lesson 4 • Kerberos and NTLM Authentication Basics

    Introduces the two primary authentication protocols used by AD. Understanding these protocols is prerequisite knowledge for security and troubleshooting chapters.

  • Lesson 5 • Directory Services and AD Overview

    Introduces directory services as centralised identity stores and positions AD within that context. Establishes vocabulary used throughout the course.

Chapter 2See details

Installing and Configuring Domain Controllers

  • Lesson 1 • Promoting a New Domain Controller

    Walks through the AD DS role installation and dcpromo-equivalent wizard steps. Students perform GUI and PowerShell-based promotions.

  • Lesson 2 • Domain Controller Demotion and Decommission

    Covers safe demotion procedures and metadata cleanup for failed DCs. Proper decommission prevents lingering objects and replication errors.

  • Lesson 3 • Prerequisites and Planning

    Covers hardware, OS, DNS, and IT network requirements before promotion. Proper planning prevents post-deployment reconfiguration.

  • Lesson 4 • Adding DCs to Existing Domains

    Explains how to add redundant domain controllers to an existing domain. Redundancy ensures availability and load distribution.

  • Lesson 5 • Operations Master Roles (FSMO)

    Identifies the five FSMO roles, their functions, and placement best practices. Misplaced FSMO roles cause authentication and replication failures.

Chapter 3See details

Managing Users, Groups, and Computers

  • Lesson 1 • User Account Management

    Covers creating, modifying, disabling, and deleting user accounts via GUI and PowerShell. Consistent account management reduces security gaps.

  • Lesson 2 • Automating Object Management with PowerShell

    Introduces the ActiveDirectory PowerShell module for scripted object management. Automation reduces errors and accelerates repetitive administrative tasks.

  • Lesson 3 • Group Types and Scopes

    Explains security vs. distribution groups and domain local, global, and universal scopes. Correct group design is foundational to permission management.

  • Lesson 4 • Organizational Unit Design and Delegation

    Teaches OU hierarchy design aligned to administrative and policy needs. Delegation of control reduces reliance on Domain Admin privileges.

  • Lesson 5 • Computer Account Management

    Addresses computer account creation, domain join, and lifecycle policies. Managed computer accounts enable policy application and authentication.

Chapter 4See details

Group Policy Objects: Design and Deployment

  • Lesson 1 • Creating and Linking GPOs

    Covers GPO creation, linking to sites, domains, and OUs, and link order. Correct linking ensures policies reach intended targets.

  • Lesson 2 • Configuring Security and Desktop Policies

    Applies GPO settings for password policies, software restriction, and desktop lockdown. These settings form the baseline security configuration for domain clients.

  • Lesson 3 • Group Policy Architecture

    Explains GPO structure, SYSVOL storage, and the client-side extension model. Understanding architecture is required before creating effective policies.

  • Lesson 4 • Troubleshooting Group Policy

    Uses gpresult, RSOP, and event logs to diagnose policy failures. Systematic troubleshooting restores policy compliance quickly.

  • Lesson 5 • Policy Processing and Inheritance

    Details LSDOU processing order, inheritance blocking, and enforcement flags. Mastery prevents unintended policy application across the hierarchy.

Chapter 5See details

Active Directory Replication and Sites

  • Lesson 1 • Knowledge Consistency Checker (KCC)

    Describes how the KCC automatically builds replication topology. Understanding KCC behaviour helps administrators tune or override topology when needed.

  • Lesson 2 • Monitoring Replication Health

    Uses repadmin, dcdiag, and event logs to assess replication status. Proactive monitoring catches latency and failures before they affect users.

  • Lesson 3 • Intrasite and Intersite Replication

    Compares replication within a site to replication across site links. Site topology directly controls replication frequency and bandwidth consumption.

  • Lesson 4 • Resolving Replication Failures

    Addresses USN rollback, lingering objects, and replication quarantine scenarios. Resolving these issues restores directory consistency across the environment.

  • Lesson 5 • Replication Fundamentals

    Explains the multi-master replication model, update sequence numbers, and change notification. These concepts underpin all replication monitoring and troubleshooting.

Chapter 6See details

Active Directory Security Administration

  • Lesson 1 • AD Tiered Access and Just-Enough Administration

    Implements JEA endpoints and role-based delegation to minimise standing privileges. Least-privilege administration reduces the blast radius of compromised accounts.

  • Lesson 2 • Auditing and Security Event Logging

    Configures advanced audit policies to capture authentication, object access, and privilege use. Audit logs are essential for incident detection and forensic investigation.

  • Lesson 3 • Privileged Access and Tiered Administration

    Introduces the tiered administration model to limit lateral movement of privileged credentials. Proper tier separation is the primary defence against credential theft attacks.

  • Lesson 4 • Protecting AD Against Common Attacks

    Covers defences against pass-the-hash, Kerberoasting, and DCSync attacks. Mitigations are applied through configuration, not third-party tools.

  • Lesson 5 • Fine-Grained Password Policies

    Configures Password Settings Objects to apply different password policies to specific groups. This replaces the single domain-wide password policy limitation.

Chapter 7See details

Active Directory Backup, Recovery, and Maintenance

  • Lesson 1 • Recycle Bin and Object Recovery

    Enables and uses the AD Recycle Bin to restore deleted objects without downtime. The Recycle Bin is the fastest recovery path for accidental deletion.

  • Lesson 2 • Disaster Recovery Planning for AD

    Builds a documented AD disaster recovery plan covering RTO, RPO, and test procedures. A tested DR plan ensures predictable recovery during real incidents.

  • Lesson 3 • Database Maintenance with ntdsutil

    Uses ntdsutil to compact, move, and integrity-check the NTDS.DIT database. Regular maintenance prevents database corruption and reclaims disk space.

  • Lesson 4 • AD Backup Strategies

    Covers Windows Server Backup, bare-metal backup, and backup frequency requirements for AD. A tested backup strategy is the foundation of any recovery plan.

  • Lesson 5 • Authoritative and Non-Authoritative Restores

    Explains when to use each restore type and the steps to execute them safely. Choosing the wrong restore type can propagate deletion across the domain.

Chapter 8See details

Advanced AD Features and Hybrid Identity

  • Lesson 1 • Azure AD Connect and Hybrid Identity

    Installs and configures Azure AD Connect to synchronise on-premises identities to the cloud. Hybrid identity is the foundation for Microsoft 365 and cloud application access.

  • Lesson 2 • Azure AD and Entra ID Integration

    Explores Azure AD (Entra ID) features that complement on-premises AD, including Conditional Access and Identity Protection. Cloud-native controls extend security beyond the corporate perimeter.

  • Lesson 3 • Active Directory Certificate Services

    Deploys an enterprise CA to issue certificates for smart card logon, SSL, and code signing. An internal PKI reduces reliance on external certificate authorities.

  • Lesson 4 • Active Directory Federation Services

    Deploys AD FS to provide claims-based authentication for web applications. Federation enables SSO across organisational and cloud boundaries.

  • Lesson 5 • Active Directory Trusts

    Configures external, forest, shortcut, and realm trusts to enable cross-boundary authentication. Trust design directly affects security and user access across organisations.

Certification

Your valid completion certificate

This course is for you:

  • Helpdesk technician: ready to move into a sysadmin or infrastructure role.

  • Junior sysadmin: managing AD daily but lacking formal structured knowledge.

  • Network administrator: expanding responsibilities to include identity and directory services.

  • IT generalist at a small company: the sole person responsible for Windows infrastructure.

  • Career changer from development: transitioning into enterprise IT operations and administration.

  • Security analyst: needing deeper AD knowledge to assess and reduce identity-based risk.

What our students say

Your lessons are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to change platforms... I'm grateful for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the way videos are presented and transcribed, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos help a lot with learning.
André Felipe
André FelipePrompt Engineering Student

Top trainings

FAQs

Who is Dedika?

Is the certificate valid in Pakistan?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course