70-742 Overview
70-742 is one of the exams that makes up the MCSA: Windows Server 2016 Microsoft Certified Solutions Associate certification from Microsoft. I am creating a course for this certification at CBT Nuggets beginning on 3/13/2017.
This exam focuses on the identity functionality in Windows Server 2016. It covers the installation and configuration of Active Directory Domain Services (AD DS), in addition to Group Policy implementation for non-Nano Server environments. It also covers functionality such as Active Directory Certificate Services (AD CS), Active Directory Federations Services (AD FS), and Web Application proxy implementations.
70-742 Complete Outline
This is one really long outline – so be sure to click the Read More button below if you are interested in the entire thing!
Install and configure Active Directory Domain Services (AD DS) (20–25%)
- Install and configure domain controllers
- Install a new forest
- Add or remove a domain controller from a domain
- Upgrade a domain controller
- Install AD DS on a Server Core installation
- Install a domain controller from Install from Media (IFM)
- Resolve DNS SRV record registration issues
- Configure a global catalog server
- Transfer and seize operations master roles
- Install and configure a read-only domain controller (RODC)
- Configure domain controller cloning
- Create and manage Active Directory users and computers
- Automate the creation of Active Directory accounts
- Create, copy, configure, and delete users and computers
- Configure templates
- Perform bulk Active Directory operations
- Configure user rights
- Implement offline domain join
- Manage inactive and disabled accounts
- Automate unlocking of disabled accounts using Windows PowerShell
- Automate password resets using Windows PowerShell
- Create and manage Active Directory groups and organizational units (OUs)
- Configure group nesting
- Convert groups, including security, distribution, universal, domain local, and domain global
- Manage group membership using Group Policy
- Enumerate group membership
- Automate group membership management using Windows PowerShell
- Delegate the creation and management of Active Directory groups and OUs
- Manage default Active Directory containers
- Create, copy, configure, and delete groups and OUs
Manage and maintain AD DS (15–20%)
- Configure service authentication and account policies
- Create and configure Service Accounts
- Create and configure Group Managed Service Accounts (gMSAs)
- Configure Kerberos Constrained Delegation (KCD)
- Manage Service Principal Names (SPNs)
- Configure virtual accounts
- Configure domain and local user password policy settings
- Configure and apply Password Settings Objects (PSOs)
- Delegate password settings management
- Configure account lockout policy settings
- Configure Kerberos policy settings within Group Policy
- Maintain Active Directory
- Back up Active Directory and SYSVOL
- Manage Active Directory offline
- Perform offline defragmentation of an Active Directory database
- Clean up metadata
- Configure Active Directory snapshots
- Perform object- and container-level recovery
- Perform Active Directory restore
- Configure and restore objects by using the Active Directory Recycle Bin
- Configure replication to Read-Only Domain Controllers (RODCs)
- Configure Password Replication Policy (PRP) for RODC
- Monitor and manage replication
- Upgrade SYSVOL replication to Distributed File System Replication (DFSR)
- Configure Active Directory in a complex enterprise environment
- Configure a multi-domain and multi-forest Active Directory infrastructure
- Deploy Windows Server 2016 domain controllers within a pre-existing Active Directory environment
- Upgrade existing domains and forests
- Configure domain and forest functional levels
- Configure multiple user principal name (UPN) suffixes
- Configure external, forest, shortcut, and realm trusts
- Configure trust authentication
- Configure SID filtering
- Configure name suffix routing
- Configure sites and subnets
- Create and configure site links
- Manage site coverage
- Manage registration of SRV records
- Move domain controllers between sites
Create and manage Group Policy (25–30%)
- Create and manage Group Policy Objects (GPOs)
- Configure a central store
- Manage starter GPOs
- Configure GPO links
- Configure multiple local Group Policies
- Back up, import, copy, and restore GPOs
- Create and configure a migration table
- Reset default GPOs
- Delegate Group Policy management
- Detect health issues using the Group Policy Infrastructure Status dashboard
- Configure Group Policy processing
- Configure processing order and precedence
- Configure blocking of inheritance
- Configure enforced policies
- Configure security filtering and Windows Management Instrumentation (WMI) filtering
- Configure loopback processing
- Configure and manage slow-link processing and Group Policy caching
- Configure client-side extension (CSE) behaviour
- Force a Group Policy update
- Configure Group Policy settings
- Configure software installation
- Configure folder redirection
- Configure scripts
- Configure administrative templates
- Import security templates
- Import a custom administrative template file
- Configure property filters for administrative templates
- Configure Group Policy preferences
- Configure printer preferences
- Define network drive mappings
- Configure power options
- Configure custom registry settings
- Configure Control Panel settings
- Configure Internet Explorer settings
- Configure file and folder deployment
- Configure shortcut deployment
- Configure item-level targeting
Implement Active Directory Certificate Services (AD CS) (10–15%)
- Install and configure AD CS
- Install Active Directory Integrated Enterprise Certificate Authority (CA)
- Install offline root and subordinate CAs
- Install standalone CAs
- Configure Certificate Revocation List (CRL) distribution points
- Install and configure Online Responder
- Implement administrative role separation
- Configure CA backup and recovery
- Manage certificates
- Manage certificate templates
- Implement and manage certificate deployment, validation, and revocation
- Manage certificate renewal
- Manage certificate enrollment and renewal for computers and users using Group Policies
- Configure and manage key archival and recovery
Implement identity federation and access solutions (15–20%)
- Install and configure Active Directory Federation Services (AD FS)
- Upgrade and migrate previous AD FS workloads to Windows Server 2016
- Implement claims-based authentication, including Relying Party Trusts
- Configure authentication policies
- Configure multi-factor authentication
- Implement and configure device registration
- Integrate AD FS with Microsoft Passport
- Configure for use with Microsoft Azure and Office 365
- Configure AD FS to enable authentication of users stored in LDAP directories
- Implement Web Application Proxy (WAP)
- Install and configure WAP
- Implement WAP in pass-through mode
- Implement WAP as AD FS proxy
- Integrate WAP with AD FS
- Configure AD FS requirements
- Publish web apps via WAP
- Publish Remote Desktop Gateway applications
- Configure HTTP to HTTPS redirects
- Configure internal and external Fully Qualified Domain Names (FQDNs)
- Install and configure Active Directory Rights Management Services (AD RMS)
- Install a licensor certificate AD RMS server
- Manage AD RMS Service Connection Point (SCP)
- Manage AD RMS templates
- Configure Exclusion Policies
- Back up and restore AD RMS