
Active Directory administration training
Master every layer of Active Directory administration, from domain controller deployment and Group Policy design to security hardening and hybrid cloud integration. This training gives IT professionals the hands-on skills to build, manage, and protect enterprise AD environments with confidence. If you support Windows infrastructure, this is the course that closes your skill gaps.
What you will learn:
You will learn how to design and deploy Active Directory forests, domains, and sites from the ground up. The course covers user, group, and computer account management, including bulk automation with PowerShell. You will configure and troubleshoot Group Policy Objects, manage AD replication across multi-site environments, and implement advanced security controls. Backup, recovery, and disaster planning procedures are covered in full detail. You will also extend on-premises AD into hybrid environments using Azure AD Connect and Active Directory Federation Services.
How you study in practice Active Directory administration training
How you practise Active Directory administration training
For companies looking to train their teams
With Dedika for businesses, the course includes exercises and examples tailored to your company and its specific needs.
Course content
8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsActive Directory Fundamentals and Architecture
Active Directory Fundamentals and Architecture
Lesson 1 • AD Data Store and Schema
Describes the NTDS.DIT database, schema partitions, and attribute definitions. Provides the technical grounding needed for advanced administration tasks.
Lesson 2 • Physical Structure and Site Topology
Explains how sites, subnets, and site links reflect physical network infrastructure. Connects physical design to replication efficiency.
Lesson 3 • Logical Structure of Active Directory
Covers forests, trees, domains, and organisational units as the logical building blocks of AD. Students map business requirements to logical AD design.
Lesson 4 • Kerberos and NTLM Authentication Basics
Introduces the two primary authentication protocols used by AD. Understanding these protocols is prerequisite knowledge for security and troubleshooting chapters.
Lesson 5 • Directory Services and AD Overview
Introduces directory services as centralised identity stores and positions AD within that context. Establishes vocabulary used throughout the course.
Chapter 2HideHide detailsSee detailsInstalling and Configuring Domain Controllers
Installing and Configuring Domain Controllers
Lesson 1 • Promoting a New Domain Controller
Walks through the AD DS role installation and dcpromo-equivalent wizard steps. Students perform GUI and PowerShell-based promotions.
Lesson 2 • Domain Controller Demotion and Decommission
Covers safe demotion procedures and metadata cleanup for failed DCs. Proper decommission prevents lingering objects and replication errors.
Lesson 3 • Prerequisites and Planning
Covers hardware, OS, DNS, and network requirements before promotion. Proper planning prevents post-deployment reconfiguration.
Lesson 4 • Adding DCs to Existing Domains
Explains how to add redundant domain controllers to an existing domain. Redundancy ensures availability and load distribution.
Lesson 5 • Operations Master Roles (FSMO)
Identifies the five FSMO roles, their functions, and placement best practices. Misplaced FSMO roles cause authentication and replication failures.
Chapter 3HideHide detailsSee detailsManaging Users, Groups, and Computers
Managing Users, Groups, and Computers
Lesson 1 • User Account Management
Covers creating, modifying, disabling, and deleting user accounts via GUI and PowerShell. Consistent account management reduces security gaps.
Lesson 2 • Automating Object Management with PowerShell
Introduces the ActiveDirectory PowerShell module for scripted object management. Automation reduces errors and accelerates repetitive administrative tasks.
Lesson 3 • Group Types and Scopes
Explains security vs. distribution groups and domain local, global, and universal scopes. Correct group design is foundational to permission management.
Lesson 4 • Organisational Unit Design and Delegation
Teaches OU hierarchy design aligned to administrative and policy needs. Delegation of control reduces reliance on Domain Admin privileges.
Lesson 5 • Computer Account Management
Addresses computer account creation, domain join, and lifecycle policies. Managed computer accounts enable policy application and authentication.
Chapter 4HideHide detailsSee detailsGroup Policy Objects: Design and Deployment
Group Policy Objects: Design and Deployment
Lesson 1 • Creating and Linking GPOs
Covers GPO creation, linking to sites, domains, and OUs, and link order. Correct linking ensures policies reach intended targets.
Lesson 2 • Configuring Security and Desktop Policies
Applies GPO settings for password policies, software restriction, and desktop lockdown. These settings form the baseline security configuration for domain clients.
Lesson 3 • Group Policy Architecture
Explains GPO structure, SYSVOL storage, and the client-side extension model. Understanding architecture is required before creating effective policies.
Lesson 4 • Troubleshooting Group Policy
Uses gpresult, RSOP, and event logs to diagnose policy failures. Systematic troubleshooting restores policy compliance quickly.
Lesson 5 • Policy Processing and Inheritance
Details LSDOU processing order, inheritance blocking, and enforcement flags. Mastery prevents unintended policy application across the hierarchy.
Chapter 5HideHide detailsSee detailsActive Directory Replication and Sites
Active Directory Replication and Sites
Lesson 1 • Knowledge Consistency Checker (KCC)
Describes how the KCC automatically builds replication topology. Understanding KCC behaviour helps administrators tune or override topology when needed.
Lesson 2 • Monitoring Replication Health
Uses repadmin, dcdiag, and event logs to assess replication status. Proactive monitoring catches latency and failures before they affect users.
Lesson 3 • Intrasite and Intersite Replication
Compares replication within a site to replication across site links. Site topology directly controls replication frequency and bandwidth consumption.
Lesson 4 • Resolving Replication Failures
Addresses USN rollback, lingering objects, and replication quarantine scenarios. Resolving these issues restores directory consistency across the environment.
Lesson 5 • Replication Fundamentals
Explains the multi-master replication model, update sequence numbers, and change notification. These concepts underpin all replication monitoring and troubleshooting.
Chapter 6HideHide detailsSee detailsActive Directory Security Administration
Active Directory Security Administration
Lesson 1 • AD Tiered Access and Just-Enough Administration
Implements JEA endpoints and role-based delegation to minimise standing privileges. Least-privilege administration reduces the blast radius of compromised accounts.
Lesson 2 • Auditing and Security Event Logging
Configures advanced audit policies to capture authentication, object access, and privilege use. Audit logs are essential for incident detection and forensic investigation.
Lesson 3 • Privileged Access and Tiered Administration
Introduces the tiered administration model to limit lateral movement of privileged credentials. Proper tier separation is the primary defence against credential theft attacks.
Lesson 4 • Protecting AD Against Common Attacks
Covers defences against pass-the-hash, Kerberoasting, and DCSync attacks. Mitigations are applied through configuration, not third-party tools.
Lesson 5 • Fine-Grained Password Policies
Configures Password Settings Objects to apply different password policies to specific groups. This replaces the single domain-wide password policy limitation.
Chapter 7HideHide detailsSee detailsActive Directory Backup, Recovery, and Maintenance
Active Directory Backup, Recovery, and Maintenance
Lesson 1 • Recycle Bin and Object Recovery
Enables and uses the AD Recycle Bin to restore deleted objects without downtime. The Recycle Bin is the fastest recovery path for accidental deletions.
Lesson 2 • Disaster Recovery Planning for AD
Builds a documented AD disaster recovery plan covering RTO, RPO, and test procedures. A tested DR plan ensures predictable recovery during real incidents.
Lesson 3 • Database Maintenance with ntdsutil
Uses ntdsutil to compact, move, and integrity-check the NTDS.DIT database. Regular maintenance prevents database corruption and reclaims disk space.
Lesson 4 • AD Backup Strategies
Covers Windows Server Backup, bare-metal backup, and backup frequency requirements for AD. A tested backup strategy is the foundation of any recovery plan.
Lesson 5 • Authoritative and Non-Authoritative Restores
Explains when to use each restore type and the steps to execute them safely. Choosing the wrong restore type can propagate deletions across the domain.
Chapter 8HideHide detailsSee detailsAdvanced AD Features and Hybrid Identity
Advanced AD Features and Hybrid Identity
Lesson 1 • Azure AD Connect and Hybrid Identity
Installs and configures Azure AD Connect to synchronise on-premises identities to the cloud. Hybrid identity is the foundation for Microsoft 365 and cloud application access.
Lesson 2 • Azure AD and Entra ID Integration
Explores Azure AD (Entra ID) features that complement on-premises AD, including Conditional Access and Identity Protection. Cloud-native controls extend security beyond the corporate perimeter.
Lesson 3 • Active Directory Certificate Services
Deploys an enterprise CA to issue certificates for smart card logon, SSL, and code signing. An internal PKI reduces reliance on external certificate authorities.
Lesson 4 • Active Directory Federation Services
Deploys AD FS to provide claims-based authentication for web applications. Federation enables SSO across organisational and cloud boundaries.
Lesson 5 • Active Directory Trusts
Configures external, forest, shortcut, and realm trusts to enable cross-boundary authentication. Trust design directly affects security and user access across organisations.
Your valid completion certificate
This course is for you:
Helpdesk technician: ready to move into a sysadmin or infrastructure role.
Junior sysadmin: managing AD daily but lacking formal structured knowledge.
Network administrator: expanding responsibilities to include identity and directory services.
IT generalist at a small company: the sole person responsible for Windows infrastructure.
Career changer from development: transitioning into enterprise IT operations and administration.
Security analyst: needing deeper AD knowledge to assess and reduce identity-based risk.
What our students say
Your lessons are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of interest without needing to change platforms... I'm grateful for everything you do, I've already recommended you to other people...

I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.

I like the content and the way videos are presented and transcribed, which speeds up the process!

The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.

Top qualifications
FAQ
Who is Dedika?
Is the certificate valid in South Africa?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course




















