Microsoft · Practice Exam · Associate · Updated for 2026

AZ-801: Configuring Windows Server Hybrid Advanced Services Practice Exam

Cover every domain on Microsoft’s current AZ-801 outline — securing Windows Server, high availability and failover clustering, disaster recovery, server migration, and monitoring and troubleshooting — with scenario-based questions, source-linked explanations to Microsoft Learn, and full timed simulation in Exam mode.

Start 24-hour free trial →

⚠ AZ-801 retires September 30, 2026 — successor is AZ-802

Microsoft has announced that AZ-801 (and its pair exam AZ-800) will retire on September 30, 2026 (5:00 PM CST). The successor is AZ-802. Because the Windows Server Hybrid Administrator Associate certification requires passing both AZ-800 and AZ-801, you must complete both before the retirement date to earn the current credential.

If you can pass both exams before September 30, the certification stays valid for a year and renews through the usual free online assessment. If your realistic completion date is later, plan around the successor path instead. Always confirm the latest status on Microsoft’s certification page.

780+
Practice questions
5
Objective domains
2
Study modes
24h
Free trial

AZ-801 exam at a glance

Vendor
Microsoft
Exam code
AZ-801
Exam name
Configuring Windows Server Hybrid Advanced Services
Certification
Microsoft Certified: Windows Server Hybrid Administrator Associate (requires AZ-800 + AZ-801)
Level
Associate (role-based)
Status
Retires September 30, 2026 — successor is AZ-802
Blueprint
Skills Measured outline as of October 6, 2025 (five domains); verify current edition before publish
Format
40–60 questions; multiple choice, multiple response, drag-and-drop, case studies, occasional labs
Duration
Approximately 100 minutes seat time
Passing score
700 of 1000 (scaled)
Delivery
Pearson VUE test center or online proctored (OnVUE)
Prerequisites
None enforced, but AZ-801 is the second of two exams — AZ-800 is required alongside it for the certification. Microsoft expects several years of Windows Server experience.
Cost (USD)
$165 USD (regional pricing varies)
Validity
1 year; renew free via an online assessment on Microsoft Learn

Sources: Microsoft — Windows Server Hybrid Administrator Associate certification · AZ-801 Study Guide (Skills measured as of October 6, 2025; retirement notice). Verify current details with Microsoft before scheduling.

About the AZ-801 Configuring Windows Server Hybrid Advanced Services exam

AZ-801 is the advanced half of Microsoft’s Windows Server Hybrid Administrator track. It validates that you can secure Windows Server on-premises and in hybrid setups, build and manage failover clusters and Storage Spaces Direct, implement disaster recovery with Azure Site Recovery and Hyper-V Replica, migrate servers and workloads to Azure, and monitor and troubleshoot the whole estate. Questions are scenario-driven and lean on real configuration judgment across Windows Admin Center, PowerShell, Azure Arc, and Azure Monitor.

Two things to plan around. First, AZ-801 alone does not earn a certification — it is the second of two exams, and you must also pass AZ-800 for the Windows Server Hybrid Administrator Associate credential. Second, both exams retire September 30, 2026 (successor: AZ-802), so if you want the current credential, complete both before that date. The current outline (October 2025) also shifted two weights: high availability rose to 15–20% and monitoring eased to 15–20%.

Every PowerKram practice question maps to one of the five current domains and links to the specific Microsoft Learn page it was derived from, so your weak spots become a reading list rather than a guess. For broader context on the administration skills AZ-801 tests, see our platform administrators guide in the Learning Hub.

AZ-801 exam domains and weights (October 2025 outline)

Five domains, led by security. The ranges are Microsoft’s; actual exam composition varies within the bands. Plan your study time roughly in proportion to these weights.

Secure Windows Server on-premises and hybrid infrastructures

OS security (Exploit Protection, App Control for Business/WDAC, Credential Guard, SmartScreen, OSConfig baselines, Windows LAPS); hybrid AD hardening (Entra Password Protection for AD DS, protected users, RODC, authentication policy silos, Defender for Identity, disabling NTLM); Azure-based remediation (Sentinel ingestion, Defender for Cloud/Servers); network security; and storage encryption (BitLocker, Azure Disk Encryption).

25–30%Heaviest domain
Migrate servers and workloads

On-premises storage migration with Storage Migration Service; server migration with Azure Migrate (VM and physical); migrating older Windows Server workloads (IIS, Hyper-V hosts, RDS, DHCP, print); IIS migration to Azure Web Apps or containers; and migrating an on-premises AD forest to Windows Server 2025.

20–25%
Implement and manage Windows Server high availability

Failover clusters (on-premises, hybrid, cloud-only, stretch clusters, S2D campus clusters, quorum and Azure witness, Network ATC, floating IP, Scale-Out File Server); cluster management (cluster-aware updating, node recovery/upgrade, failover); and Storage Spaces Direct.

15–20%Weight increased
Monitor and troubleshoot Windows Server environments

Monitoring with Windows Server tools and Azure (Performance Monitor, Data Collector Sets, Windows Admin Center, System Insights, Azure Monitor data collection rules, VM Insights); troubleshooting connectivity, name resolution, updates, boot/performance, Azure Arc extensions, disk encryption, and storage; and troubleshooting Active Directory (recycle bin, DSRM, SYSVOL, replication, hybrid auth/sync).

15–20%Weight reduced
Implement disaster recovery

Backup and recovery (Azure Recovery Services vault, Azure Backup Server, VM backup and instant recovery); disaster recovery with Azure Site Recovery (network mapping, on-premises and Azure VM protection, recovery plans, replication policies); and protecting VMs with Hyper-V Replica.

10–15%

Source: Microsoft AZ-801 Study Guide — skills measured as of October 6, 2025. Relative to older outlines, high availability rose to 15–20% and monitoring/troubleshooting eased to 15–20%.

Who AZ-801 is for

AZ-801 is aimed at experienced Windows Server administrators taking the advanced half of the hybrid track — Microsoft expects several years of Windows Server experience and the AZ-800 foundation:

  • Windows Server administrators and engineers securing, clustering, and troubleshooting server estates on-premises and in Azure.
  • Hybrid cloud administrators integrating Windows Server with Azure Arc, Azure Monitor, Azure Backup, and Azure Site Recovery.
  • Infrastructure migration specialists moving servers, file shares, IIS workloads, and AD forests to current versions and to Azure.
  • Datacenter and platform teams responsible for high availability, disaster recovery, and business continuity for Windows workloads.

Because AZ-801 is the second exam in the pair, most candidates pass AZ-800 Windows Server Hybrid Administrator first, and many pair the track with AZ-104 for broader Azure administration. For the roles this certification carries genuine resume value in — including salary ranges and progression paths — see our IT administrator career paths in the Career Hub.

What this AZ-801 practice exam delivers

Learn mode

Get the correct answer, the reasoning, and a direct link to the exact Microsoft Learn page each question was derived from — immediately after each question. Best for the high-availability and disaster-recovery domains, where multi-step clustering and ASR configurations are the main testing pattern.

Exam mode

Scenario-based questions on a timer that mirrors the real 100-minute AZ-801 format, including case studies. Build the pacing for the configuration-heavy scenarios the exam is known for.

Source-linked explanations

Every answer cites the exact Microsoft Learn page (learn.microsoft.com/windows-server, /azure/site-recovery…) it was built from — so you can verify and dig deeper into the documentation, not just memorize.

Score by AZ-801 domain

Results break down by the five current domains — Secure, Migrate, High availability, Monitor, and Disaster recovery — so practice tells you exactly which area to revisit.

Sample AZ-801 practice questions

Ten free questions across the five current AZ-801 domains, with full explanations and source links to the Microsoft Learn pages each is derived from. The complete bank is available with the 24-hour trial.

Question 1 · Secure Windows Server on-premises and hybrid infrastructures (25–30%)

A company needs to protect credentials on domain controllers from pass-the-hash and credential-theft attacks. Which security feature should be enabled?

  1. BitLocker Drive Encryption on all drives
  2. NTFS Encrypting File System applied to the NTDS.dit file
  3. Windows Defender Credential Guard
  4. Windows Firewall with default rules
Show answer & explanation

Correct: C — Windows Defender Credential Guard. Credential Guard uses virtualization-based security to isolate LSASS secrets, preventing pass-the-hash and credential dumping.

Why not the others: BitLocker (A) protects at-rest disk data but not runtime in-memory credentials; EFS on NTDS.dit (B) encrypts the file at rest but not credentials loaded into memory; Windows Firewall (D) controls network traffic, not credential storage.

Source: Microsoft Learn — Windows Defender Credential Guard → Further reading: PowerKram — Windows Server hardening →
Question 2 · Secure Windows Server on-premises and hybrid infrastructures (25–30%)

An administrator must apply and continuously enforce a consistent security baseline (services, policies, and hardening settings) across many Windows Server 2025 machines, both on-premises and in Azure, with minimal manual GPO work. Which approach fits best?

  1. Manually configure each server’s settings and document them in a runbook
  2. Manage the Windows Server security baseline by using OSConfig
  3. Apply a single legacy Group Policy Object and rely on periodic manual audits
  4. Enable Windows Defender Antivirus real-time protection on each server
Show answer & explanation

Correct: B — manage the baseline with OSConfig. OSConfig applies and continuously enforces Windows Server security baselines at scale across on-premises and Azure machines, correcting drift automatically — the current outline calls this out explicitly.

Why not the others: manual per-server config (A) does not scale and drifts; a single legacy GPO with manual audits (C) does not continuously enforce or easily reach Azure machines; antivirus (D) detects malware but does not apply a hardening baseline.

Source: Microsoft Learn — Windows Server security baselines →
Question 3 · Secure Windows Server on-premises and hybrid infrastructures (25–30%)

Windows Server VMs must be patched within 72 hours of a security-update release, and updates must be staged before production. Which update-management solution should be used?

  1. Manually download patches from the Microsoft Update Catalog and install them each month
  2. Azure Update Manager with scheduled maintenance windows and pre/post deployment scripts
  3. Allow Windows Update to download and install patches automatically without any controls
  4. Disable all automatic update mechanisms to prevent unexpected reboots during business hours
Show answer & explanation

Correct: B — Azure Update Manager. Update Manager schedules patches with configurable maintenance windows, supports staging through pre/post scripts, and tracks compliance across hybrid environments.

Why not the others: uncontrolled automatic updates (C) lack staging verification; manual monthly patching (A) cannot reliably meet the 72-hour requirement at scale; disabling updates (D) leaves servers exposed to known vulnerabilities.

Source: Microsoft Learn — Azure Update Manager →
Question 4 · Secure Windows Server on-premises and hybrid infrastructures (25–30%)

A government agency needs to restrict application execution on servers to a pre-approved allow-list only. Which Windows Server feature should be configured?

  1. Software Restriction Policies using legacy hash-based rules from Local Security Policy
  2. App Control for Business (WDAC) with code-integrity policies enforcing the allow-list
  3. User Account Control prompts requiring elevation confirmation for admin operations
  4. Windows Defender Antivirus with real-time scanning and cloud-delivered protection
Show answer & explanation

Correct: B — App Control for Business (WDAC). App Control for Business (the current name for Windows Defender Application Control) enforces code-integrity policies that allow only approved applications to execute, with kernel-level control.

Why not the others: antivirus (D) detects known malware but does not prevent execution of unknown, non-listed apps; Software Restriction Policies (A) are deprecated and lack kernel enforcement; UAC (C) controls privilege elevation, not which applications can run.

Source: Microsoft Learn — App Control for Business →
Question 5 · Implement and manage Windows Server high availability (15–20%)

A critical SQL Server instance on Windows Server needs automatic failover to a standby node within 30 seconds if the primary fails. Which HA solution should be implemented?

  1. Network Load Balancing distributing SQL Server client connections across multiple nodes
  2. Windows Server Failover Clustering with a SQL Server Failover Cluster Instance
  3. Hyper-V Replica providing asynchronous VM replication with manual failover initiation
  4. Scheduled database backups running every 30 seconds to a secondary storage location
Show answer & explanation

Correct: B — WSFC with a SQL Server FCI. Failover clustering with an FCI provides automatic failover with near-instant failure detection and role transfer to the standby node.

Why not the others: 30-second backups (D) cannot provide automatic failover or meet the RPO; NLB (A) distributes stateless traffic and cannot handle stateful SQL failover; Hyper-V Replica (C) requires manual failover and has RPO greater than zero.

Source: Microsoft Learn — Failover Clustering overview → Further reading: PowerKram — high availability & clustering →
Question 6 · Implement and manage Windows Server high availability (15–20%)

A two-node hospital cluster risks split-brain during a network partition — both nodes may believe the other is down. Which cluster component prevents split-brain?

  1. A Cloud Witness quorum resource hosted in Azure providing a third arbitration vote
  2. An additional network interface card added to each node for redundant communication
  3. A higher-frequency heartbeat network with shorter timeout intervals between nodes
  4. DNS round-robin load balancing distributing client connections between the two nodes
Show answer & explanation

Correct: A — a Cloud Witness quorum resource. A Cloud Witness provides an Azure-hosted quorum vote that determines which partition retains cluster ownership during a network split, preventing split-brain.

Why not the others: a faster heartbeat (C) detects failures sooner but cannot arbitrate which side survives; additional NICs (B) add redundancy but no quorum vote; DNS round-robin (D) distributes client traffic and has no role in quorum decisions.

Source: Microsoft Learn — cluster quorum & witness →
Question 7 · Migrate servers and workloads (20–25%)

A company migrates 50 physical Windows servers to Azure VMs and needs compatibility assessment and right-sized VM recommendations. Which Azure service should be used for the assessment?

  1. Azure Migrate with a server-discovery appliance and performance-based assessment for right-sizing
  2. A manual inventory spreadsheet documenting each server configuration, maintained by the team
  3. Azure Pricing Calculator estimating monthly cost from manually entered VM specifications
  4. Azure Advisor providing optimization recommendations for already-deployed Azure resources
Show answer & explanation

Correct: A — Azure Migrate. Azure Migrate discovers on-premises servers, collects performance data, assesses Azure readiness, and recommends right-sized VM SKUs based on actual utilization.

Why not the others: the Pricing Calculator (C) estimates cost but does not assess compatibility or performance; Advisor (D) optimizes existing Azure resources, not pre-migration servers; manual spreadsheets (B) lack automated analysis and trending.

Source: Microsoft Learn — Azure Migrate overview → Further reading: PowerKram — server migration roles →
Question 8 · Migrate servers and workloads (20–25%)

A company migrating file servers to Azure wants on-premises access to hot files while tiering cold data to the cloud. Which service should be deployed?

  1. A Robocopy script scheduled nightly to copy files from on-premises servers to Blob Storage
  2. DFS Replication configured to synchronize file shares to a Windows Server VM in Azure
  3. Azure File Sync with cloud tiering, automatically moving cold files to Azure Files
  4. Azure Data Box for a one-time bulk offline transfer of all file-server data to Azure
Show answer & explanation

Correct: C — Azure File Sync with cloud tiering. File Sync keeps frequently accessed files cached on-premises while cloud tiering automatically moves cold data to Azure Files, optimizing local storage.

Why not the others: Robocopy (A) is a one-directional copy without tiering or continuous sync; Data Box (D) is for bulk one-time offline transfer, not ongoing management; DFS Replication to an Azure VM (B) requires maintaining a full VM and lacks intelligent tiering.

Source: Microsoft Learn — Azure File Sync →
Question 9 · Implement disaster recovery (10–15%)

On-premises Hyper-V VMs need replication to Azure for DR with an RPO of 30 seconds and automated failover. Which Azure service should be used?

  1. Azure Site Recovery providing continuous Hyper-V-to-Azure replication with orchestrated failover
  2. Manual VHD file copy to Azure Blob Storage scheduled as a nightly batch transfer
  3. Azure Backup with daily application-consistent snapshots in a Recovery Services vault
  4. Azure File Sync replicating VM disk files from the on-premises host to Azure Files shares
Show answer & explanation

Correct: A — Azure Site Recovery. ASR provides continuous replication of Hyper-V VMs to Azure with RPO as low as 30 seconds and orchestrated failover via recovery plans.

Why not the others: Azure Backup snapshots (C) have daily RPO, far exceeding 30 seconds; manual VHD copy (B) is not continuous; File Sync (D) handles file-level sync, not full VM replication and failover.

Source: Microsoft Learn — Azure Site Recovery for Hyper-V → Further reading: PowerKram — disaster recovery planning →
Question 10 · Monitor and troubleshoot Windows Server environments (15–20%)

An administrator needs to collect performance counters and event logs from both on-premises and Azure Windows Servers into a central Azure workspace for alerting and analysis. Which approach should be used?

  1. Configure Azure Monitor data collection rules to gather counters and logs into a Log Analytics workspace
  2. Enable Performance Monitor locally on each server and review the logs individually per machine
  3. Export Windows Event Viewer logs to a file share and inspect them manually each week
  4. Rely on Windows Admin Center only, checking each server’s dashboard when an issue is reported
Show answer & explanation

Correct: A — Azure Monitor data collection rules into Log Analytics. Data collection rules gather performance counters and event logs from on-premises and Azure servers (via the Azure Monitor Agent and Azure Arc) into a central workspace for alerting and cross-server analysis.

Why not the others: local Performance Monitor (B) and manual Event Viewer exports (C) don’t centralize or alert across the estate; Windows Admin Center alone (D) is reactive and per-server, not a central alerting pipeline.

Source: Microsoft Learn — monitor VMs with Azure Monitor → Further reading: PowerKram — monitoring & troubleshooting roles →

Keep going: Learning & Career resources

AZ-801 sits at the intersection of two paths — hands-on Windows Server and hybrid administration, and broader infrastructure careers. Both PowerKram hubs back this exam (and the AZ-800 pair).

Related Microsoft Azure exams

Deep dive: AZ-801 format, scoring, the AZ-800 pairing, retirement, and what the current outline emphasizes

Exam format and scoring

AZ-801 delivers roughly 40–60 questions in about 100 minutes, in multiple choice, multiple response, drag-and-drop, and case-study formats, with occasional lab questions. It is scored on a 1000-point scale with 700 to pass. Expect configuration-judgment scenarios — a requirement gives you an RPO, an RTO, or a security constraint, and you pick the Windows Server or Azure feature that satisfies it. Read the administration guide →

The AZ-800 pairing and retirement

AZ-801 is the second of two exams for the Windows Server Hybrid Administrator Associate certification; AZ-800 (Administering Windows Server Hybrid Core Infrastructure) covers the core identity, networking, storage, and compute foundation, and AZ-801 covers the advanced security, HA, DR, migration, and monitoring layer on top. Both exams retire September 30, 2026, with AZ-802 as the successor, so complete both before that date to earn the current credential. Read the AZ-800 path →

What the current outline emphasizes

The October 2025 refresh raised high availability to 15–20% and eased monitoring to 15–20%, and added modern content: OSConfig security baselines, Windows LAPS, Microsoft Entra Password Protection for AD DS, Network ATC for cluster host networking, migrating an on-premises AD forest to Windows Server 2025, and IIS migration to Azure Web Apps or containers. If your study material predates late 2025, it likely misses these. Read the administrator skills path →

Realistic study path

AZ-801 rewards hands-on lab time. With AZ-800 behind you, work the official Microsoft Learn AZ-801 content, then build the canonical labs: a failover cluster with the right quorum and Azure witness, Storage Spaces Direct, an Azure Site Recovery replication and recovery plan, a Storage Migration Service cutover, and Azure Monitor data collection from a hybrid server. Drill scenario questions in PowerKram Learn mode by domain — starting with Secure and Migrate — and finish with full timed Exam-mode runs. Most candidates need 8–12 weeks after AZ-800. Read the clustering & DR guide →

Cost, renewal, and career outlook

The exam costs $165 USD (regional pricing varies), delivered through Pearson VUE at a test center or online with OnVUE. While active, the certification is valid for one year and renews through a free online assessment on Microsoft Learn. Windows Server and hybrid-infrastructure skills remain in steady demand across enterprises running on-premises and hybrid estates. For salary ranges and role-specific paths, see the Career Hub. Career Hub — IT Administrator →

Frequently asked questions

Is AZ-801 being retired?
Yes. Microsoft has announced AZ-801 (and its pair exam AZ-800) will retire on September 30, 2026, at 5:00 PM CST. The successor is AZ-802. Because the Windows Server Hybrid Administrator Associate certification requires both AZ-800 and AZ-801, you must complete both before the retirement date to earn the current credential; otherwise plan around the successor path.
Does AZ-801 earn a certification on its own?
No. AZ-801 is the second of two exams. You must also pass AZ-800 (Administering Windows Server Hybrid Core Infrastructure) to earn the Microsoft Certified: Windows Server Hybrid Administrator Associate. Most candidates take AZ-800 first, then AZ-801.
What are the AZ-801 exam domains and weights?
Per Microsoft’s October 2025 outline (five domains): Secure Windows Server on-premises and hybrid infrastructures (25–30%), Migrate servers and workloads (20–25%), Implement and manage Windows Server high availability (15–20%), Monitor and troubleshoot Windows Server environments (15–20%), and Implement disaster recovery (10–15%).
Did the AZ-801 blueprint change recently?
Yes. In the October 2025 refresh, high availability rose to 15–20% and monitoring/troubleshooting eased to 15–20%. The refresh also added OSConfig baselines, Windows LAPS, Entra Password Protection for AD DS, Network ATC, AD forest migration to Windows Server 2025, and IIS migration to Azure.
What is the AZ-801 passing score and cost?
700 of 1000 (scaled), with roughly 40–60 questions in about 100 minutes. The exam costs $165 USD (regional pricing varies). While active, the certification is valid for one year and renews via a free online assessment on Microsoft Learn.

Start your free 24-hour AZ-801 practice trial

Full access to 780+ questions, both study modes, source-linked explanations, and score-by-domain. No credit card required.

Start free trial →