Book Image

Configuring Windows Server Hybrid Advanced Services Exam Ref AZ-801

By : Chris Gill
Book Image

Configuring Windows Server Hybrid Advanced Services Exam Ref AZ-801

By: Chris Gill

Overview of this book

Configuring Windows Server Hybrid Advanced Services Exam Ref AZ-801 helps you master various cloud and data center management concepts in detail, helping you grow your expertise in configuring and managing Windows Server in on-premises, hybrid, and cloud-based workloads. Throughout the book, you'll cover all the topics needed to pass the AZ-801 exam and use the skills you acquire to advance in your career. With this book, you’ll learn how to secure your on-premises Windows Server resources and Azure IaaS workloads. First, you’ll explore the potential vulnerabilities of your resources and learn how to fix or mitigate them. Next, you'll implement high availability Windows Server virtual machine workloads with Hyper-V Replica, Windows Server Failover Clustering, and Windows File Server. You’ll implement disaster recovery and server migration of Windows Server in on-premises and hybrid environments. You’ll also learn how to monitor and troubleshoot Windows Server environments. By the end of this book, you'll have gained the knowledge and skills required to ace the AZ-801 exam, and you'll have a handy, on-the-job desktop reference guide.
Table of Contents (31 chapters)
1
Part 1: Exam Overview and the Current State of On-Premises, Hybrid, and Cloud Workflows
3
Part 2: Secure Windows Server On-Premises and Hybrid Infrastructures
9
Part 3: Implement and Manage Windows Server High Availability
13
Part 4: Implement Disaster Recovery
17
Part 5: Migrate Servers and Workloads
23
Part 6: Monitor and Troubleshoot Windows Server Environments

Enabling storage encryption by using ADE

When it comes to Azure VMs running as IaaS in Microsoft Azure, storage-level protection is ultimately provided in the form of encryption on the VM disk files, and can be handled through ADE using BitLocker Drive Encryption for Windows systems and DM-Crypt for Linux-based systems. ADE can automatically encrypt the OS disk, any data disks, and the temporary disks and will support both managed and unmanaged disks.

A few scenarios where you can utilize ADE are as follows:

  • Enabling encryption on existing Azure VMs that are already in Azure
  • Enabling encryption on new Azure VMs that were created from Azure Marketplace pre-created images
  • Enabling encryption on new Azure VMs that were established from a customer-encrypted virtual hard drive file using existing encryption keys

In addition, there are key requirements that need to be met for ADE regarding other OSes, networking, memory, VM generation, Group Policy, and encryption...