Microsoft AZ-801: A Hands-On Study Plan
AZ-801 retired on September 30, 2026, so candidates can no longer treat it as an active exam target. The knowledge it represented, however, has not disappeared. Securing Windows Server, designing high availability, recovering workloads, migrating servers, and monitoring hybrid environments remain core administration skills, and Microsoft certifications now include AZ-802 as the current exam that consolidates much of the Windows Server role.
The legacy AZ-801 exam measured advanced Windows Server hybrid services across security, high availability, disaster recovery, migration, and monitoring. A useful post-retirement study plan therefore should not attempt to memorize an obsolete blueprint. It should use those domains as hands-on practice areas and map them forward to the current administration model.
Microsoft now lists AZ-802 as the active Windows Server exam for the Windows Server Hybrid Administrator Associate certification. Anyone studying AZ-801 material in October 2026 should make that transition explicit so time is spent on durable skills rather than retired exam logistics.
Use at least two Windows Server instances, an Active Directory domain, a management workstation, and an Azure subscription if available. The goal is not to build a production-sized environment; it is to create enough moving parts to practice identity, networking, security, monitoring, and recovery together.
Document the baseline before changing anything. Record server roles, IP addressing, DNS, domain membership, administrator access, update state, and a simple application or file workload. This gives you a known-good reference when later labs deliberately break configuration.
The older AZ-801 hybrid administration can still organize the legacy domains, but every lab should be checked against the current AZ-802 role before being treated as certification preparation.
Hands-on security work should include privileged administration, Microsoft Defender integrations where available, firewall rules, secure remote access, update management, encryption decisions, auditing, and identity protection. The point is to understand how a server remains secure when it is managed across both on-premises and cloud services.
Add a service account and a privileged administrator, then review where credentials exist and how access is audited. Harden one management path and verify that the intended administrator can still operate the server. Security that blocks legitimate recovery work is not a complete design.
The current Windows Server Hybrid Administrator Associate path is the right certification context for these skills now that AZ-800 and AZ-801 have retired.
Azure Arc matters because many Windows Server estates will remain hybrid. Practice onboarding a non-Azure server where possible, reviewing the resource representation, applying management features, and understanding which capabilities depend on agents, extensions, policy, or connected services.
The conceptual shift is important: a server can remain physically or virtually outside Azure while participating in centralized inventory, governance, monitoring, security, and update workflows. Hybrid administration is increasingly about control-plane consistency rather than forcing every workload into one location.
The Azure Arc is useful background for understanding that control-plane model before building more advanced hybrid labs.
AZ-801 historically required knowledge of Windows Server high availability. Preserve that skill by building or simulating clustered workloads, failover behavior, redundant services, and recovery from a node or service failure. The objective is to distinguish high availability from backup and disaster recovery.
For every design, write down the failure it protects against. Two servers in the same failure domain may not protect against a site outage. A replicated service may still have a single authentication or network dependency. Availability only improves when the architecture removes a meaningful single point of failure.
Cloud-side patterns such as Azure availability sets and scale sets provide useful contrast when deciding whether resilience is being handled by Windows clustering, Azure infrastructure, or both.
Practice defining recovery time objective and recovery point objective before selecting backup, replication, or site-recovery mechanisms. The same workload may require rapid service recovery but tolerate some data loss, or require near-zero data loss while allowing a longer restoration window.
Run a restore rather than simply configuring backup. Recover a file, system state, or workload to a clean location and verify that application dependencies still work. A backup that has never been restored is an assumption, not a recovery capability.
The broader disaster-recovery discipline reinforces why technical restoration, business priority, communication, and validation all matter during a real failure.
Windows Server migration is not only copying a virtual machine or moving files. Candidates should identify identity dependencies, DNS, certificates, service accounts, storage, network paths, scheduled tasks, integrations, latency assumptions, and the operational window available for cutover.
Create a small migration plan for a file service or application server. Include pre-migration discovery, data synchronization, cutover steps, validation checks, and a rollback threshold. Then simulate one failed dependency and decide whether to fix forward or restore the prior state.
This is a durable administration skill because cloud migrations, hardware refreshes, consolidation, and modernization all require the same dependency awareness.
Collecting performance counters and event logs is not enough. Build monitoring around conditions that matter: service unavailable, disk pressure, authentication failure, replication problem, backup failure, update issue, or abnormal resource consumption. Every alert should have an owner and a plausible next action.
Use Azure Monitor or other tooling available in the lab to create a simple alert and follow it through notification and investigation. Compare the metric or log evidence with what the server reports locally so that you understand how centralized monitoring represents Windows state.
The practical Azure Monitor alert workflow is especially useful because current Windows Server administration increasingly depends on cloud-based visibility and automation.
GUI familiarity is useful, but repeatable administration requires scripting. Use PowerShell for inventory, service checks, role installation, firewall configuration, event queries, user or group tasks, and remote management. Start with commands you already know how to perform manually so that the automation has a clear expected result.
Add validation and error handling instead of building scripts that assume success. A script that changes ten servers should report which servers changed, which failed, and what state remains after the run. This is the difference between command automation and operational automation.
A practical starting point is Azure PowerShell, then expand toward Windows Server remoting and configuration tasks used in your own lab.
After completing a legacy-domain exercise, ask where the skill appears in the current role. AZ-802 covers AD DS, Windows Server instances and workloads, virtual machines, networking, storage, security, high availability and disaster recovery, migration, monitoring, and troubleshooting in a consolidated blueprint.
That mapping prevents candidates from spending time on an old objective simply because it appears in archived AZ-801 material. It also highlights gaps: AZ-802 contains administration areas that were formerly split across AZ-800 and AZ-801, so a candidate who studied only the advanced-services half of the old track may need to revisit core infrastructure.
Adjacent Azure credentials such as AZ-104 and AZ-305 can provide cloud administration and architecture context, but they do not replace the Windows Server depth expected in the current hybrid administrator role.
In week one, build the lab and focus on identity, secure administration, Arc onboarding, and repeatable PowerShell inventory. In week two, add networking, workload management, monitoring, and update operations. In week three, practice high availability, backup, disaster recovery, and migration. In week four, stop adding features and start breaking the environment deliberately.
Create failures such as DNS misconfiguration, a blocked management port, a broken trust relationship, a stopped service, a failed update, unreachable storage, a lost certificate, a monitoring gap, or an incomplete migration. Diagnose from symptoms, collect evidence, repair the smallest necessary layer, and document how you verified recovery.
That final week is the most valuable because it converts product knowledge into administration skill. AZ-801 itself is now historical, but the Azure architecture perspective and the current AZ-802 path both benefit from administrators who can reason about hybrid Windows Server failures instead of relying on memorized setup steps.
Because AZ-801 has retired, avoid buying new preparation time around memorizing its old percentages, scheduling rules, or question patterns. Use archived objectives only as a checklist of practical Windows Server capabilities, then make AZ-802 the authority for current certification scope. This distinction is especially important now because search results and older training courses can still present AZ-801 as if it were schedulable.
Keep evidence from every lab. Save configuration exports, PowerShell transcripts, screenshots of monitoring events, recovery notes, and short explanations of the failure you created and how you proved it was fixed. This turns study into a reusable operations portfolio and makes later revision faster because you are reviewing your own troubleshooting evidence rather than rereading generic instructions.
Also include one “no Azure portal” session each week. Perform as much diagnosis as possible from PowerShell, Windows Admin Center, server logs, command-line network tools, and the local operating system before using cloud dashboards. Hybrid administrators need to understand both sides of the management plane, and troubleshooting becomes much stronger when cloud tooling is an additional source of evidence rather than the only interface you know.