Active Directory for Administrators
Course Description
Overview
Active Directory (AD) is a directory service for Windows domain networks. Active Directory is used to organize users and computers within an organization.
This live training course (online or on-site) is aimed at system administrators who wish to use Microsoft Active Directory to manage data access and secure it.
By the end of this training, participants will be able to:
- configure and deploy the Active Directory service;
- create a domain and define access rights for users and devices;
- manage users and computers using Group Policies;
- control access to file servers;
- configure the certificate service and manage certificates;
- deploy and manage services such as encryption, certificates, and authentication.
Book the Training
- Format: Remote
- Language: PL
- Type: Open training (Groups and individuals can join)
- Date: 03-05.08.2026
- Duration: 3 days (21 hours)
- Trainer: Rafał Decyk
Net price per participant.
Course Format
- Interactive lessons with discussion
- Abundance of exercises and practical tasks
- Real deployments in a live-lab environment
Requirements
- Experience in system administration
- Knowledge of the Windows Server operating system
Target Audience
System Administrators.
Course Curriculum
1. Introduction
- Introduction to Active Directory Domain Services (AD DS)
- Course objectives and learning outcomes
- The role of Active Directory in an enterprise environment
- Overview of the laboratory environment
- Active Directory terminology and key concepts
2. Active Directory Functionality and Architecture Overview
- Active Directory architecture
- Logical structure vs. physical structure
- Domains, trees, and forests
- Organizational Units (OUs)
- Domain Controllers and the Global Catalog
- FSMO roles (Flexible Single Master Operations)
- Sites and subnets
- Integration with DNS in the context of Active Directory
- Active Directory partitions and database structure
3. Overview of Identity Management Solutions and Concepts
- Fundamental principles of Identity and Access Management (IAM)
- Difference between authentication and authorization
- Kerberos authentication
- NTLM authentication
- Single Sign-On (SSO)
- Role-Based Access Control (RBAC)
- Identity lifecycle management
- Hybrid identity concepts
4. Configuring Active Directory
- Planning an Active Directory deployment
- Installing Active Directory Domain Services (AD DS)
- Promoting a server to the role of Domain Controller
- Creating a new forest and domain
- Installing and configuring DNS service
- Verifying installation correctness
- Deployment best practices
5. Deploying Active Directory Domain Services
- Creating Organizational Units (OUs)
- Managing users, groups, and computers
- Managing user accounts
- Group scopes and group types
- Delegating administrative control
- Managing service accounts
- Adding computers to the domain
6. Configuring and Managing Replication
- Active Directory replication concepts
- Multimaster replication
- Replication topology
- Knowledge Consistency Checker (KCC)
- Replication schedule sets
- Troubleshooting replication issues
- Monitoring replication health
7. Deploying and Managing Group Policies
- Group Policy architecture
- Creating Group Policy Objects (GPOs)
- GPO linking and filtering
- Group Policy inheritance
- Loopback processing
- Administrative templates
- Deploying software using GPOs
- Folder redirection
- Security policies
- Password and account lockout policies
- Troubleshooting Group Policy issues
8. Deploying a Certificate Authority (CA) Hierarchy
- Introduction to Public Key Infrastructure (PKI)
- Certificate Services architecture
- Root CA and subordinate CA
- Installing Active Directory Certificate Services (AD CS)
- Designing the CA hierarchy
- Certificate templates
- Automatic enrollment
9. Managing Certificates
- Managing the certificate lifecycle
- Issuing certificates
- Renewing certificates
- Revoking certificates
- Certificate Revocation Lists (CRLs)
- Online Certificate Status Protocol (OCSP)
- Managing certificate templates
- Troubleshooting certificate issues
10. Deploying and Managing Active Directory Federation Services (AD FS)
- Introduction to federation services
- AD FS architecture
- Claims-based authentication
- Installing AD FS
- Configuring trust relationships
- Implementing Single Sign-On (SSO)
- Integration with external applications
- Monitoring and troubleshooting AD FS
11. Sharing Data Access
- Access control concepts
- NTFS permissions
- Share permissions
- Effective permissions
- Access-Based Enumeration
- Dynamic access control
- File classification infrastructure dependencies
- File access auditing
12. Securing Active Directory Domain Services
- Active Directory security best practices
- Administrative security model
- Tiered administration
- Privileged Access Management (PAM)
- Securing domain controllers
- Password policies
- Fine-Grained Password Policies
- Account lockout policies
- Auditing and monitoring
- Backup and recovery aspects
13. Deploying and Managing Rights Management Services (RMS)
- Introduction to Active Directory Rights Management Services
- RMS architecture
- Installing AD RMS
- Protecting confidential documents
- Information protection policies
- Integration with Microsoft Office
- Managing user access rights
14. Deploying Microsoft Entra ID (formerly Azure Active Directory)
- Introduction to Microsoft Entra ID
- Cloud identity concepts
- Hybrid identity architecture
- Microsoft Entra Connect
- Pass-through authentication
- Federation with AD FS
- Conditional access overview
- Identity synchronization
- Managing cloud identities
15. Integrating Active Directory with OpenLDAP
- LDAP fundamentals
- Active Directory LDAP protocol support
- OpenLDAP overview
- Identity synchronization methods
- Authentication integration
- Common interoperability scenarios
- Security implications
- Troubleshooting LDAP connectivity
16. Monitoring Active Directory
- Monitoring tools
- Event Viewer consoles
- Performance Monitor
- Active Directory Administrative Center
- PowerShell in the context of monitoring
- Monitoring replication
- System health checks
- Change auditing
- Performance optimization
17. Troubleshooting
- User login issues
- DNS problems
- Replication failures
- Troubleshooting Group Policy issues
- Authentication issues
- Certificate-related issues
- Domain controller health checks
- Diagnostic tools (dcdiag, repadmin, nltest, gpresult)
- Backup and recovery procedures
- Disaster recovery scenarios
18. Summary and Conclusions
- Review of key concepts
- Best practices in Active Directory administration
- Security recommendations
- Operational maintenance control
- Additional Microsoft resources and documentation
- Q&A
- Summary of practical exercises and labs

No budget? Obtain funding!
A program that allows you to easily and quickly obtain funds for individual participants' training.

Why Guaranteed Training?
- Execution guarantee — the training takes place regardless of the number of participants.
- Knowledge sharing and networking with professionals from various industries.
- Interactive, live sessions — not just theory, but also exercises and discussions.
- Flexible online format — you can join from anywhere.
Need Help?
Reach out to learn more about our team and the kinds of tailored solutions we can offer your organization.
Get in Touchwroclaw@nobleprog.pl or +48 (22) 103 3718