Microsoft AZ-800 Exam Actual Questions
Administering Windows Server Hybrid Core Infrastructure (Page 3 )

Updated On: 13-Aug-2026
View Related Case Study

You need to meet the technical requirements for User1. The solution must use the principle of least privilege.
What should you do?

  1. Add User1 to the Server Operators group in contoso.com.
  2. Create a delegation on contoso.com.
  3. Add User1 to the Account Operators group in contoso.com.
  4. Create a delegation on OU3.

Answer(s): D


Reference:

https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/delegating-administration-of-account-ous-and-resource-ous



View Related Case Study

HOTSPOT (Drag and Drop is not supported)
Which groups can you add to Group3 and Group5? To answer, select the appropriate options in the answer area.
Note: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:


Reference:

https://docs.microsoft.com/en-us/windows/security/identity-protection/access-control/active-directory-security-groups



View Related Case Study

You need to meet the technical requirements for Server3.
Which users can perform the required tasks?

  1. Admin3 only
  2. Admin1 and Admin3 only
  3. Admin1 only
  4. Admin1, Admin2, and Admin3
  5. Admin1 and Admin2 only

Answer(s): C



Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com.
You need to identify which server is the PDC emulator for the domain.
Solution: From Active Directory Domains and Trusts, you right-click Active Directory Domains and Trusts in the console tree, and then select Operations Master.
Does this meet the goal?

  1. Yes
  2. No

Answer(s): B



Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com.
You need to identify which server is the PDC emulator for the domain.
Solution: From a command prompt, you run netdom.exe query fsmo.
Does this meet the goal?

  1. Yes
  2. No

Answer(s): A


Reference:

https://activedirectorypro.com/how-to-check-fsmo-roles/



You have an on premises Active Directory Domain Services (AD DS) domain that syncs with a Microsoft Entra tenant.
You plan to implement Microsoft Entra self-service password reset (SSPR).
You need to ensure that users that reset their passwords by using SSPR can use the new password resources in the AD DS domain.
What should you do?

  1. Deploy the Microsoft Entra Password Protection proxy service to the on premises network.
  2. Run the Microsoft Entra Connect wizard and select Password writeback.
  3. Grant the Change password permission for the domain to the Microsoft Entra Connect service account.
  4. Grant the impersonate a client after authentication user right to the Microsoft Entra Connect service account.

Answer(s): B


Reference:

https://docs.microsoft.com/en-us/azure/active-directory/authentication/tutorial-enable-sspr-writeback



You have a Microsoft Entra Domain Services domain named contoso.com.
You need to provide an administrator with the ability to manage Group Policy Objects (GPOs). The solution must use the principle of least privilege.
To which group should you add the administrator?

  1. AAD DC Administrators
  2. Domain Admins
  3. Schema Admins
  4. Enterprise Admins
  5. Group Policy Creator Owners

Answer(s): A

Explanation:

Microsoft Entra ID, Domain Services, Administer Group Policy in a Microsoft Entra Domain Services managed domain.
Settings for user and computer objects in Microsoft Entra Domain Services are often managed using Group Policy Objects (GPOs). Domain Services includes built-in GPOs for the AADDC Users and AADDC Computers containers. You can customize these built-in GPOs to configure Group Policy as needed for your environment. Members of the AAD DC Administrators group have Group Policy administration privileges in the Domain Services domain, and can also create custom GPOs and organizational units (OUs).


Reference:

https://learn.microsoft.com/en-us/entra/identity/domain-services/manage-group-policy



DRAG DROP (Drag and Drop is not supported)
You create a new Azure subscription.
You plan to deploy Microsoft Entra Domain Services (Azure AD DS) and Azure virtual machines.
You need to ensure that the virtual machines can join to Microsoft Entra Domain Services.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Select and Place:

  1. See Explanation section for answer.

Answer(s): A

Explanation:


Reference:

https://docs.microsoft.com/en-us/azure/active-directory-domain-services/tutorial-create-instance



Viewing page 3 of 39
Viewing questions 17 - 24 out of 302 questions


Post your Comments and Discuss Microsoft AZ-800 exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!