- 260 Actual Exam Questions
- Compatible with all Devices
- Printable Format
- No Download Limits
- 90 Days Free Updates
Get All Administering Windows Server Hybrid Core Infrastructure Exam Questions with Validated Answers
| Vendor: | Microsoft |
|---|---|
| Exam Code: | AZ-800 |
| Exam Name: | Administering Windows Server Hybrid Core Infrastructure |
| Exam Questions: | 260 |
| Last Updated: | August 22, 2026 |
| Related Certifications: | Windows Server Hybrid Administrator Associate |
| Exam Tags: | Cloud Certifications, Microsoft Azure Certifications, Infrastructure Certifications Intermediate Windows Server AdministratorsAzure Administrators |
Looking for a hassle-free way to pass the Microsoft Administering Windows Server Hybrid Core Infrastructure exam? DumpsProvider provides the most reliable Dumps Questions and Answers, designed by Microsoft certified experts to help you succeed in record time. Available in both PDF and Online Practice Test formats, our study materials cover every major exam topic, making it possible for you to pass potentially within just one day!
DumpsProvider is a leading provider of high-quality exam dumps, trusted by professionals worldwide. Our Microsoft AZ-800 exam questions give you the knowledge and confidence needed to succeed on the first attempt.
Train with our Microsoft AZ-800 exam practice tests, which simulate the actual exam environment. This real-test experience helps you get familiar with the format and timing of the exam, ensuring you're 100% prepared for exam day.
Your success is our commitment! That's why DumpsProvider offers a 100% money-back guarantee. If you don’t pass the Microsoft AZ-800 exam, we’ll refund your payment within 24 hours no questions asked.
Don’t waste time with unreliable exam prep resources. Get started with DumpsProvider’s Microsoft AZ-800 exam dumps today and achieve your certification effortlessly!
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your network contains an Active Directory Domain Services (AD DS) domain named contoso.com.
You need to identify which server is the PDC emulator for the domain.
Solution: From Active Directory Domains and Trusts, you right-click Active Directory Domains and Trusts in the console tree, and then select Operations Master.
Does this meet the goal?
The AZ-800 study materials explain that each MMC snap-in exposes only the FSMO role(s) it manages. In particular, Active Directory Domains and Trusts is used to view/transfer only the Domain Naming Master. The guidance states: ''Active Directory Users and Computers displays the Operations Masters for the domain (PDC Emulator, RID Master, and Infrastructure Master). Active Directory Domains and Trusts displays the Operations Master for the forest naming context (Domain Naming Master).'' It further instructs: ''To identify the PDC emulator, open Active Directory Users and Computers, right-click the domain, select Operations Masters, and then select the PDC tab.'' Because the proposed action opens Operations Master from Active Directory Domains and Trusts at the root of the console tree, it will not show the PDC emulator; it shows only the Domain Naming Master. Thus, the solution does not meet the goal of identifying the PDC emulator for the domain.
You need to ensure that VM3 meets the technical requirements.
What should you install first?
To meet the requirement that VM3 be configured for per-folder quotas, the Windows Server file services module directs you to install File Server Resource Manager (FSRM). The course content explains: ''FSRM provides quota management, file screening, and storage reporting. Quotas can be applied to volumes and to specific folders, enabling administrators to control the space consumed.'' None of the other features listed deliver folder-level quota capability: Enhanced Storage and Windows Standards-Based Storage Management relate to storage management/SMI-S, and iSNS Server concerns iSCSI discovery services. Therefore, the first step is to install FSRM on VM3; after installation, you can create per-folder quota templates and assignments to enforce the desired limits.
You have an Azure virtual machine named VM1 that runs Windows Server.
You have an Azure subscription that has Microsoft Defender for Cloud enabled.
You need to ensure that you can use the Azure Policy guest configuration feature to manage VM1.
What should you do?
The Administering Windows Server Hybrid Core Infrastructure materials covering Microsoft Defender for Cloud and Azure Policy guest configuration explain that guest configuration policies use a guest configuration extension and a managed identity on the VM to retrieve policy artifacts and report compliance. The text emphasizes: ''When using Azure Policy guest configuration (audit or deployIfNotExists/modify), the virtual machine must have a managed identity enabled. The platform uses the VM's managed identity to securely access content and to send compliance data.'' It further clarifies that installing DSC or Custom Script extensions is not required to enable the Azure Policy guest configuration feature; the policy assignment deploys the needed guest configuration extension automatically when the VM has an identity. A system-assigned managed identity is the simplest least-privilege option because its lifecycle is tied to the VM and it requires no separate credential management. Hence, enabling a system-assigned managed identity on VM1 fulfills the prerequisite for Azure Policy guest configuration to manage the server.
Your network contains an on -premises Active Directory Domain Services (AD DS) domain named contoso.com The domain contains the objects shown in the following table.

You plan to sync contoso.com with an Azure Active Directory (Azure AD) tenant by using Azure AD Connect You need to ensure that all the objects can be used in Conditional Access policies What should you do?
To ensure that all objects, specifically Computer1, can be used in Conditional Access (CA) policies, the environment must support device-based identity in the cloud. In a hybrid scenario, while user objects and security groups (like Group1 and Group2) can be synchronized through standard Azure AD Connect (Microsoft Entra Connect) synchronization cycles, computer objects require specific configuration to become 'identifiable' by Conditional Access.
According to the official study guides for the AZ-800 exam, simply syncing a computer object does not make it a 'Hybrid Azure AD joined' device. To enable Computer1 to be used as a target or a condition (e.g., 'Require Hybrid Azure AD joined device') in a CA policy, you must run the Azure AD Connect wizard and select the Configure Hybrid Azure AD join task. This process configures a Service Connection Point (SCP) in your on-premises Active Directory, which allows Windows 10/11 devices like Computer1 to discover the Azure AD tenant and complete the registration process.
Furthermore, while group scopes (Universal vs. Domain Local) are often discussed in sync scenarios, Azure AD Connect by default synchronizes security groups regardless of their scope if they are within the synchronized Organizational Units (OUs). Therefore, the critical step to satisfy the requirement for 'all objects'---especially the computer account---is enabling the Hybrid Join feature to establish a cloud-side device identity. This provides the necessary 'device signal' that Conditional Access evaluates to grant or deny access.
Your on-premises network contains an Active Directory domain named contoso.com. You have an Azure AD tenant. You plan to sync contoso.com with the Azure AD tenant by using Azure AD Connect cloud sync. You need to create an account that will be used by Azure AD Connect cloud sync. Which type of account should you create?
In the AZ-800/''Administering Windows Server Hybrid Core Infrastructure'' content, Azure AD Connect cloud sync uses a lightweight provisioning agent that reads from on-premises AD DS. The agent runs under a Group Managed Service Account (gMSA) so it can securely obtain and rotate credentials automatically. The implementation guidance states that during agent installation you provide domain admin credentials once so the installer can create and delegate a gMSA for the agent; alternatively, you can pre-create the gMSA and assign it. The documentation emphasizes that cloud sync does not rely on user or computer accounts with static passwords; instead it ''deploys a gMSA for the agent service to ensure secure, automatic password management and least-privilege directory access.'' System-assigned managed identities apply to Azure resources only (not on-prem AD DS), and InetOrgPerson is an object class for users, not a service identity. A regular user account would introduce password management and rotation issues and is not the recommended nor required identity type for the cloud sync agent. Therefore, to satisfy Azure AD Connect cloud sync prerequisites, you create and use a gMSA.
Security & Privacy
Satisfied Customers
Committed Service
Money Back Guranteed