It is amazing that i passed the AZ-800 exam easily. I just followed the AZ-800 exam dump and studied for about one week. Thank you guys!
Questions deserve immediate answers. Whether you are comparing AZ-800 materials, setting up the software, or planning your Microsoft Administering Windows Server Hybrid Core Infrastructure timeline in 2026, the TestkingPass support team responds at once — before and after purchase.
| Certification Vendor: | Microsoft |
|---|---|
| Exam Name: | Administering Windows Server Hybrid Core Infrastructure |
| Exam Number: | AZ-800 |
| Related Certifications: | Microsoft Certified: Windows Server Hybrid Administrator Associate |
| Exam Duration: | 120 minutes |
| Exam Format: | Multiple-select, Case studies, Multiple-choice, Drag-and-drop |
| Passing Score: | 700 (on a scale of 1-1000) |
| Exam Price: | $165 USD |
| Certificate Validity Period: | 1 year |
| Real Exam Qty: | 40-60 |
| Available Languages: | Chinese (Traditional), Japanese, French, Portuguese (Brazil), Chinese (Simplified), Spanish, German, Italian, Korean, English |
| Sample Questions: | ![]() |
| Exam Way: | Online (proctored) or at a Pearson VUE testing center |
| Pre Condition: | Candidates should have extensive experience working with Windows Server operating systems, including experience with on-premises, hybrid, and cloud Windows Server administration. No specific prerequisite certification is required. |
| Official Syllabus URL: | https://learn.microsoft.com/en-us/credentials/certifications/exams/az-800/ |
| Section | Weight | Objectives |
|---|---|---|
| Manage storage and file services | 15-20% | - Configure and manage Windows Server file shares
|
| Implement and manage an on-premises and hybrid networking infrastructure | 15-20% | - Implement on-premises and hybrid name resolution
|
| Manage virtual machines and containers | 15-20% | - Create and manage containers
|
| Manage Windows Servers and workloads in a hybrid environment | 10-15% | - Configure and manage PowerShell Remoting
|
| Deploy and manage Active Directory Domain Services (AD DS) in on-premises and cloud environments | 30-35% | - Manage Windows Server by using Group Policies
|
By treating quality as a system, not a slogan. Our experts specialize in Microsoft technology and constantly upgrade the AZ-800 bank, with expert-verified answers across the Microsoft Administering Windows Server Hybrid Core Infrastructure objectives. You can download a free trial before paying, pay securely by credit card on our trusted payment platform, and rely on 365 days of free updates afterward — every revision is emailed to you automatically. Questions at any point get immediate answers from our support team.
The Microsoft Administering Windows Server Hybrid Core Infrastructure blueprint centers on these domains:
The full official outline lists further domains, and our bank covers them all.
According to current exam information, the AZ-800 exam presents 40-60 questions within a 120 minutes-minute limit. Timed practice sessions are the simplest way to make that constraint feel familiar before the real day.
Upon successful payment, our system automatically sends the product to your mailbox — typically within about a minute — and a download link appears immediately. If nothing arrives within two hours, check your spam folder and contact support. Install on unlimited devices, and enjoy 365 days of free updates: you receive an email with the updated AZ-800 materials whenever a revision is released, followed by a 50% renewal discount at the end of the period.
Microsoft publishes the following prerequisites for the Microsoft Administering Windows Server Hybrid Core Infrastructure: Candidates should have extensive experience working with Windows Server operating systems, including experience with on-premises, hybrid, and cloud Windows Server administration. No specific prerequisite certification is required..
Always confirm the latest requirements on the official certification page.
At present, passing the AZ-800 exam requires a score of 700 (on a scale of 1-1000), and registration costs $165 USD. Both are Microsoft's figures and subject to change — verify them on the official site when booking.
Clear terms, honored consistently. If you fail the corresponding exam within 60 days of purchase, send a scanned copy of your enrollment slip and your official Score Report PDF within two days of the exam date; verified claims are refunded in full within seven days. Exclusions: exams taken within three days of purchase, candidate names that differ from the payer, and free or expired products. You may instead request a free exchange for two products of equal value.
SIMULATION
You need to create a Group Policy Object (GPO) named GPO1 that only applies to a group named MemberServers.
To complete this task, sign in the required computer or computers.
Correct Answer:
Step 1: Open Group Policy Management by navigating to the Start menu > Windows Administrative Tools, then select Group Policy Management.
Step 2: Right-click Group Policy Objects, then select New to create a new GPO.
Step 3: Enter a name [here GPO1] for the new GPO that you can identify what it is for easily, then click OK.
Step 4: Select the GPO from Group Policy Objects list, then in the Security Filtering section, Add and Remove users, groups, and computers that the GPO should apply to. [Here add group MemberServers] Step 5: Close the GPO Editor when you are done.
Now, the GPO is created.
Reference:
https://support.globalsign.com/aeg/aeg-how-create-and-link-gpo-active-directory
You have an on-premises network that is connected to an Azure virtual network by using a Site- to-Site VPN. Each network contains a subnet that has the same IP address space. The on- premises subnet contains a virtual machine.
You plan to migrate the virtual machine to the Azure subnet.
You need to migrate the on premises virtual machine to Azure without modifying the IP address.
The solution must minim administrative effort.
What should you implement before you perform the migration?
Correct Answer: C 🗳️
Explanation: Only visible for TestkingPass members. You can sign-up / login (it's free).
Hotspot Question
Your network contains two Active Directory Domain Services (AD DS) forests named contoso.com and adatum.com. A two-way external trust exists between contoso.com and adatum.com. The forests contain the servers shown in the following table.
You need to ensure that users from contoso.com can access only shared resources hosted on SRV1. The solution must meet the following requirements:
- Ensure that users from adatum.com can access the resources hosted in
contoso.com.
- Prevent the contoso.com users from accessing any other resources in
adatum.com.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Correct Answer:

Explanation:
Box 1: DC1
Modify the trust on:
Prevent the contoso.com users from accessing any other resources in adatum.com.
To prevent users in domain contoso.com from accessing resources in domain adatum.com you must break the existing two-way external trust by removing the outgoing trust from domain contoso.com using the Active Directory Domains and Trusts snap-in on a domain controller that hosts all FSMO roles in domain contoso.com, this is DC1. This will cut the connection from contoso.com's perspective, while the two-way trust still allows users in fabrik adatum.com to access resources in contoso.com.
Box 2: File shares on SRV1
Modify the permissions for the:
Prevent the contoso.com users from accessing any other resources in adatum.com.
Configure both share and NTFS permissions on the specific file server resource in domain adatum.com to grant access to users from domain contoso.com while denying access to all others. This can be achieved by creating a group in domain contoso.com that contains the users, and then adding that group to a local group on the domain adatum.com server, which is then granted permissions to the file share.
Reference:
https://learn.microsoft.com/en-us/entra/identity/domain-services/concepts-forest-trust
https://learn.microsoft.com/sv-se/azure/storage/files/storage-files-identity-multiple-forests
Case Study 2 - Contoso, Ltd
Overview
Contoso, Ltd. is a company that has a main office in Seattle and two branch offices in Los Angeles and Montreal.
Existing Environment
AD DS Environment
The network contains an on premises Active Directory Domain Services (AD DS) forest named contoso.com. The forest contains two domains named contoso.com and canada.contoso.com.
The forest contains the domain controllers shown in the following table.
All the domain controllers are global catalog servers.
Server infrastructure
The network contains the servers shown in the following table.
A server named Server4 runs Windows Server and is in a workgroup. Windows Firewall on Server4 uses the private profile.
Server2 hosts three virtual machines named VM1, VM2, and VM3.
VM3 is a file server that stores data in the volumes shown in the following table.
Group Policies
The contoso.com domain has the Group Policies Objects (GPOs) shown in the following table.
Existing Identities
The forest contains the users shown in the following table.
The forest contains the groups shown in the following table.
Current Problems
When an administrator signs in to the console of VM2 by using Virtual Machine Connection, and then disconnects from the session without signing out, another administrator can connect to the console session as the currently signed in user.
Requirements
Technical Requirements
Contoso identifies the following technical requirements:
* Change the replication schedule for all site links to 30 minutes.
* Promote Server1 to a domain controller in canada.contoso.com.
* Install and authorize Server3 as a DHCP server.
* Ensure that User1 can manage the membership of all the groups in Contoso\OU3.
* Ensure that you can manage Server4 from Server1 by using PowerShell remoting.
* Ensure that you can run virtual machines on VM1.
* Force users to provide credentials when they connect to VM2.
* On VM3, ensure that Data Deduplication on all volumes is possible.
Question
Hotspot Question
Which groups can you add to Group3 and Group5? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Correct Answer:

Explanation:
Group 3 = Group 1, 2 4 and 5 only. Domain-Local groups can contain members from the "forest".
Group 5 = Group 4 only. Global groups can only contain Users, Computers and Global groups from the "same" domain.
https://docs.microsoft.com/en-us/windows/security/identity-protection/access-control/active-directory-security-groups
Case Study 1 - Fabrikam, Inc
Overview
Fabrikam, Inc is a manufacturing company that has a main office in New York and a branch office in Seattle.
Existing Environment
On-premises Servers
The on-premises network contains servers that run Windows Server as shown in the following table.
DC1 hosts all the operation master roles.
WEB1 and WEB2 run an Internet Information Services (IIS) web app named Webapp1.
On-premises Network
The New York and Seattle offices are connected by using redundant WAN links.
The client computers in each office get IP addresses from their local DHCP server.
DHCP1 contains a scope named Scope1 that has addresses for the New York office, DHCP2 contains a scope named Scope2 that has addresses for the Seattle office.
Identity Infrastructure
The network contains a single on-premises Active Directory Domain Services (AD DS) domain named corp.falbrikam.com. Currently, all the service accounts use individual domain user accounts.
All domain controllers have the DNS Server role installed and host a copy of the Active Directory integrated DNS zone of corp.fabrikam.com.
The corp.fabrikam.com AD DS domain syncs with an Azure Active Directory (Azure AD) tenant.
Group Policy Objects (GPOs)
The corp.fabrikam.com domain contains the organizational units (OUs) and custom Group Policy Objects (GPOs) shown in the following table.
Requirements
Planned Changes
Fabrikam identifies the following planned changes:
* Create a single Azure subscription named Sub1 that will contain a single Azure virtual network named Vnet1.
* Replace the WAN links between the Seattle and New York offices by using Azure Virtual WAN and FxpressRoute. Both on premises offices will be connected to Vnet1 by using ExpressRoute.
* Create three Azure file shares named newyorkhiles, seattlefiles, and companyfiles.
* Create a domain controller named dc3.corp.fabrikam.com in Vnet1.
* Deploy an Azure Virtual Desktop host pool to Vnet1. The Azure Virtual Desktop session hosts will be hybrid Azure AD-joined.
* License all servers for Microsoft Defender for servers.
* Use Azure Policy to enforce configuration management policies on the servers in Azure and on- premises.
Networking Requirements
Fabrikam identifies the following networking requirements:
* Implement Virtual WAN and ensure that all the network traffic between the sites uses Virtual WAN. All communications must occur over ExpressRoute.
* If a DHCP server fails, ensure that the client computers can continue to receive their dynamic IP address and renew their existing lease.
* Ensure that the resources in Vnet1 can resolve the names of the on-premises servers in the corp.fabrikam.com domain.
Security Requirements
Fabrikam identifies the following security requirements:
* Apply GPO4 to the Azure Virtual Desktop session hosts. Ensure that Azure Virtual Desktop user sessions lock after being idle for 10 minutes. Users must be able to control the lockout time manually from their client computer.
* Ensure that server administrators request approval before they can establish a Remote Desktop connection to an Azure virtual machine. If the request is approved, the connection must be established within two hours.
* Prevent user passwords from containing all or part of words that are based on the company name, such as Fab, f@br1kAm or fabr!|.
* Ensure that all instances of Webapp1 use the same service account. The password of the service account must change automatically every 30 days.
* Prevent domain controllers from directly contacting hosts on the internet.
File Sharing Requirements
You need to configure the synchronization of Azure files to meet the following requirements:
* Ensure that seattlefiles syncs to FS2.
* Ensure that newyorkfiles syncs to FS1.
* Ensure that companyfiles syncs to both FS1 and FS2.
Question
Hotspot Question
You need to configure network communication between the Seattle and New York offices. The solution must meet the networking requirements.
What should you configure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Correct Answer:

Explanation:
The network requirements state: "All communications must occur over ExpressRoute." That means you need to create the conditions for that kind of connection: an ExpressRoute gateway and an ExpressRoute circuit connection.
https://docs.microsoft.com/en-us/learn/modules/implement-hybrid-network-infrastructure/5-implement-azure-expressroute
Over 60420+ Satisfied Customers
It is amazing that i passed the AZ-800 exam easily. I just followed the AZ-800 exam dump and studied for about one week. Thank you guys!
Now you do not need to take tension. You can 100 % pass Administering Windows Server Hybrid Core Infrastructure very simply and easily with our AZ-800 dumps questions.
I cleared my AZ-800 exam a week back and now am trying to go for another certification. I will use only AZ-800 exam dumps for the future also as my experience with the AZ-800 exam preparation was positively and truly the best.
Valid sample exams for Microsoft certfied AZ-800 exam. Very helpful. Passed my exam with 98% marks. Thank you TestkingPass.
Glad to scribe a few words here just to guide professionals like me! I was a bit timid to opt for only questions and answers for an exam such as AZ-800. But it surprised me that they real TestkingPass AZ-800 dumps are really great!
Thank you for your efforts to help me. Your AZ-800 dump is 100% valid. Passed today. I will take next exam soon and will come back to buy the dump as well.
Hello.. I have just used the Simulator to get ready for the AZ-800 exam.. And I can tell you I HAVE JUST CLEARED THE MOST COMPLICATED AZ-800 EXAM - I AM SO HAPPYYYYYYY
Very detailed exam guide for AZ-800. Passed my exam with 91% marks. I studied with TestkingPass. Satisfied with their content. I suggest everyone refer to these before taking the original exam.
I didn’t have any issues using these AZ-800 exam questions! They are perfect and valid for me to pass the AZ-800 exam. Highly recommend!
All Good! AZ-800 practice dump is valid!
I used your updated AZ-800 study materials and passed my exam easily.
You finally released this Administering Windows Server Hybrid Core Infrastructure exam.
I prepared and passed the AZ-800 exam with these latest AZ-800 practice exam questions. This rehearsal is the best way to evaluate your preparation. I am sure you will pass your exam on the first attempt. Good luck!
I love this opportunity to use these AZ-800 exam questions and i passed with them by just one go. Cheers!
Very good! I like the soft version which can simulate the real exam. They will all buy your AZ-800 practice dumps!
TestkingPass Practice Exams are written to the highest standards of technical accuracy, using only certified subject matter experts and published authors for development - no all study materials.
We are committed to the process of vendor and third party approvals. We believe professionals and executives alike deserve the confidence of quality coverage these authorizations provide.
If you prepare for the exams using our TestkingPass testing engine, It is easy to succeed for all certifications in the first attempt. You don't have to deal with all dumps or any free torrent / rapidshare all stuff.
TestkingPass offers free demo of each product. You can check out the interface, question quality and usability of our practice exams before you decide to buy.