Microsoft · AZ-802
Validates the ability to deploy, manage, and troubleshoot Windows Server in on-premises and hybrid Azure environments. Covers identity, security, networking, storage, high availability, disaster recovery, and monitoring for Windows Server workloads.
Practice Questions
600
≈ 12 practice exams
Duration
120 minutes
Passing Score
700/1000
Difficulty
AssociateLast Updated
Aug 2026
This AZ-802 practice exam follows the July 2026 version of Microsoft's official study guide. Deploy and manage AD DS is the heaviest domain at 20 to 25 percent of the marks, with storage and file services and monitoring and troubleshooting at 15 to 20 percent each, so those three areas alone decide roughly half of your score. The remaining four domains, hybrid workload management, virtual machines, networking, and securing Windows Server infrastructure, carry 10 to 15 percent each, and the question bank mirrors that weighting.
AZ-802 replaces the AZ-800 and AZ-801 pair, which retire on September 30, 2026; after that date this single exam is the only path to the Windows Server Administrator Associate credential. You get 120 minutes through Pearson VUE, at a test center or online proctored, and you need a scaled 700 on a 1000-point scale to pass. Expect scenario questions that reach across domains: hybrid identity with Microsoft Entra Connect Sync, Azure Arc-enabled servers, Hyper-V and Azure VM management, Azure File Sync, and Active Directory recovery all appear in applied contexts rather than as isolated definitions.
Microsoft has not yet released an official practice assessment for AZ-802, which makes independent question practice the main way to pressure-test your readiness before booking. Start with the 30 free questions to benchmark yourself, then work through the full 600-question bank until your accuracy holds steady across all seven domains, especially AD DS, storage, and troubleshooting, where most of the marks sit.
The Microsoft Certified: Windows Server Hybrid Administrator Associate, earned by passing exam AZ-802, validates a professional's ability to deploy, manage, and troubleshoot Windows Server workloads across both on-premises and hybrid Azure environments. AZ-802 consolidates the content previously covered by two separate exams—AZ-800 (Administering Windows Server Hybrid Core Infrastructure) and AZ-801 (Configuring Windows Server Hybrid Advanced Services)—into a single associate-level credential, with AZ-800 and AZ-801 retiring on September 30, 2026. The exam entered beta in June 2026 and covers a broad range of hybrid infrastructure topics including Active Directory Domain Services (AD DS), hybrid identity with Microsoft Entra ID, Hyper-V virtualization, containerization, storage management, and hybrid networking.
Candidates are assessed on their ability to use core administrative toolsets such as Windows Admin Center, PowerShell, Azure Arc, Azure Policy, Azure Monitor, Azure Update Manager, Microsoft Defender for Identity, and Microsoft Defender for Cloud. The certification also covers high availability and disaster recovery strategies, server and workload migration to Azure, and end-to-end monitoring and troubleshooting of Windows Server environments. It is a role-based credential that reflects the real-world skills required of hybrid infrastructure administrators who bridge traditional on-premises Windows Server management with cloud-native Azure services.
This certification is designed for IT professionals who administer Windows Server as a workload in hybrid environments—both on-premises and in Azure. Relevant job roles include system administrators, infrastructure engineers, identity and access administrators, network engineers, security engineers, support engineers, and technology managers who are responsible for Windows Server operations at their organizations. Candidates typically collaborate with architects and cloud engineers on hybrid deployments.
Ideal candidates will have several years of hands-on experience with Windows Server operating systems and should be comfortable working across on-premises Active Directory, Azure IaaS virtual machines, and hybrid connectivity scenarios. Those who previously held the Windows Server Hybrid Administrator Associate certification via AZ-800 and AZ-801 can maintain their credential through the standard annual renewal assessment rather than sitting the full AZ-802 exam.
Microsoft does not enforce formal prerequisites for AZ-802, but candidates are strongly recommended to have several years of practical experience administering Windows Server in enterprise environments before attempting the exam. Foundational knowledge of Active Directory Domain Services, Group Policy, DNS, DHCP, and Windows Server networking is essential, as these topics form a significant portion of the exam content.
Familiarity with Azure fundamentals—particularly Azure IaaS, Azure Arc, Microsoft Entra ID (formerly Azure Active Directory), and hybrid connectivity concepts—is also expected. Candidates without prior Azure exposure may benefit from first earning the Microsoft Azure Fundamentals (AZ-900) certification or completing relevant Microsoft Learn learning paths. Hands-on experience with tools such as Windows Admin Center, PowerShell remoting, and Hyper-V is strongly recommended, as many exam questions are scenario-based and require applied knowledge.
AZ-802 is an associate-level exam administered through Pearson VUE, available via online proctoring or at an authorized testing center. You have 120 minutes to complete the exam, which typically contains 40-60 questions. A passing score of 700 out of 1000 is required. The exam uses a scaled scoring model, meaning 700 does not equate directly to 70% correct answers. While AZ-802 is in beta, results are not scored immediately; scores are released after the beta data-collection period ends.
Question types include single-answer multiple choice, multiple-response, drag-and-drop, hotspot (active screen), and yes/no scenario-based questions. The exam is currently offered in English only, with localized versions typically released approximately eight weeks after the English version. Candidates whose preferred language is unavailable may request an additional 30 minutes. Microsoft recommends registering with a personal Microsoft account (MSA) rather than an organizational account to ensure exam records are permanently retained. A free exam sandbox is available at aka.ms/examdemo to familiarize candidates with the interface before exam day.
Earning the Windows Server Hybrid Administrator Associate credential positions professionals for roles such as Windows Server Administrator, Hybrid Cloud Administrator, Infrastructure Engineer, and Systems Engineer in organizations that maintain on-premises Windows Server environments alongside Azure workloads. These roles are consistently in demand across enterprise IT departments, government agencies, healthcare, and financial services. As organizations pursue hybrid cloud strategies rather than full cloud migration, Windows Server expertise with Azure integration skills remains highly valuable and difficult to automate away.
According to industry salary surveys, Windows Server administrators with hybrid cloud skills and Microsoft certifications typically earn between $85,000 and $130,000 annually in the United States, depending on experience, location, and scope of responsibility. Compared to cloud-only certifications such as AZ-104 (Azure Administrator), this certification differentiates candidates who can manage the full hybrid lifecycle—on-premises Active Directory, hybrid networking, and Azure IaaS—making it particularly valuable for mid-to-large enterprises where full datacenter retirement is not imminent. The credential renews annually via a free, unproctored online assessment on Microsoft Learn, keeping certified professionals current with platform updates.
5 sample questions with answers and explanations. The full bank has 600 questions, enough for 12 full-length practice exams.
Preview — answers shown1. Alpine Ski House has a single Windows Server 2022 DHCP server providing IP addresses to 800 client devices across the corporate network. The IT manager has identified the DHCP server as a critical single point of failure and requires a redundant solution that provides automatic failover without the complexity and cost of deploying a Windows Server Failover Cluster. Which solution should the administrator implement? (Select one!)
Explanation
DHCP Failover, introduced in Windows Server 2012, allows two DHCP servers to share a single scope and provide high availability without requiring a failover cluster. In hot standby mode, one server is active and handles all client requests while the partner remains passive, automatically taking over if the active server becomes unavailable. In load balance mode (an alternative configuration), both servers share client request processing simultaneously. Both modes coordinate through a failover relationship so that addresses are never double-assigned. DHCP scope splitting with an 80/20 distribution is a legacy technique that divides the address range between two servers, but it does not provide true failover — if the server holding 80% of the addresses fails, the majority of the address pool becomes unavailable and clients may be unable to renew leases. Promoting a DHCP server to a domain controller has no effect on DHCP database redundancy because AD DS replication does not replicate the DHCP lease database. Deploying multiple DHCP servers with identical scope configurations without DHCP Failover coordination causes address conflicts because both servers would independently issue overlapping addresses to different clients.
2. City Power & Light needs to synchronize their on-premises Active Directory Domain Services environment to Microsoft Entra ID to enable hybrid identity for cloud applications. Their environment consists of a single Active Directory forest with 12,000 user accounts spread across two child domains. The organization's IT policy mandates minimal on-premises infrastructure and requires that the synchronization configuration be managed from the cloud rather than from on-premises servers. Which identity synchronization solution best meets these requirements? (Select one!)
Explanation
Microsoft Entra Cloud Sync is the modern cloud-managed synchronization solution that uses lightweight provisioning agents installed on domain-joined servers. The agents themselves have a small on-premises footprint, and all synchronization configuration is performed from the Microsoft Entra admin center in the cloud rather than on the on-premises server. This directly satisfies both requirements: minimal on-premises infrastructure and cloud-managed configuration. Microsoft Entra Connect Sync — whether configured with Express Settings, Custom Settings, or with a staging server — requires a dedicated on-premises server running the full Connect application, and all configuration is managed locally on that server rather than from the cloud. Active Directory Federation Services is a federation and single sign-on technology that enables cross-organization authentication, not a directory synchronization tool, and it does not synchronize identities from on-premises AD DS to Microsoft Entra ID.
3. Litware Inc. operates three geographically separate Active Directory forests with no forest trusts between them, located in North America, Europe, and Asia-Pacific and managed by independent IT teams. Litware needs to synchronize all user accounts and groups from all three forests into a single Microsoft Entra tenant. The solution must minimize on-premises infrastructure footprint and long-term maintenance overhead in each region. Which synchronization solution should they deploy? (Select one!)
Explanation
Microsoft Entra Cloud Sync is purpose-built for scenarios involving multiple disconnected forests synchronizing to a single Microsoft Entra tenant. Each forest requires only a lightweight provisioning agent of less than 1 MB, and all synchronization configuration and logic is managed entirely in the cloud. This dramatically reduces the on-premises infrastructure burden compared to full Connect Sync deployments, and independent IT teams in each region only need to install and maintain a small agent rather than a full Windows Server application. A single Microsoft Entra Connect Sync server cannot directly reach three disconnected forests without forest trusts and complex customization, and a single server becomes a single point of failure for all synchronization. Deploying separate Connect Sync servers in each forest requires significant Windows Server infrastructure in each region, ongoing patching, and coordination across three independent teams, significantly increasing maintenance overhead. Microsoft Entra Domain Services provides a managed domain in Azure but does not replace on-premises forests or provide bidirectional synchronization for existing on-premises accounts, and users would still require management of their original forest credentials.
4. Fabrikam, Inc. has a main office in Chicago and 15 branch offices connected via WAN links. Branch office employees frequently download the same large engineering files from the main office file server, causing WAN saturation during peak hours. The IT team wants to deploy a native Windows Server caching solution where branch office client computers cache downloaded content locally after the first retrieval and serve subsequent requests to other branch users from that local cache, reducing repeated WAN downloads. No additional server hardware can be deployed at any branch office. Which BranchCache operating mode should be configured? (Select one!)
Explanation
Distributed Cache mode allows branch office Windows client computers to act as peers that cache previously downloaded content and serve it directly to other clients in the same branch subnet, eliminating repeated WAN downloads after the initial retrieval. No additional server hardware is required at branch offices because the Windows client machines themselves maintain and share the distributed cache. Hosted Cache mode also reduces WAN traffic through caching, but requires a dedicated Windows Server running the BranchCache Hosted Cache Server role at each branch office — this directly violates the no-additional-hardware constraint. DFS Replication proactively copies entire files between servers on a scheduled basis, requires server infrastructure at each branch, and does not provide on-demand peer caching based on actual client access patterns. Work Folders enables offline file synchronization for mobile users so they can access files when disconnected but does not implement a peer caching mechanism to prevent repeated WAN downloads of the same shared content.
5. Relecloud's DNS administrators need to enable clients in the relecloud.com forest to resolve host names in the margiestravels.com namespace. Margie's Travel operates a separate Active Directory forest with its own authoritative DNS servers at IP address 192.168.100.20. The requirement is to implement name resolution with minimum administrative overhead, without requiring zone transfer access to the margiestravels.com zone, and without hosting any copy of margiestravels.com zone data on the relecloud.com servers. Which DNS configuration should the administrator implement on the relecloud.com DNS servers? (Select one!)
Explanation
A conditional forwarder for margiestravels.com instructs the relecloud.com DNS servers to forward all queries for that specific namespace to 192.168.100.20 without requesting a zone transfer, without storing any zone data locally, and without requiring any configuration changes on the Margie's Travel DNS infrastructure. Conditional forwarders are namespace-specific, so only margiestravels.com queries are affected; all other resolution continues normally. This is the standard DNS configuration for cross-forest name resolution in Windows Server environments. A secondary zone requires the relecloud.com DNS servers to perform full zone transfers from 192.168.100.20, meaning Margie's Travel must explicitly permit zone transfer access — this violates the stated requirement. A stub zone stores only SOA and NS records from the authoritative zone and must also retrieve those records from 192.168.100.20 via a restricted zone transfer, which still requires access to be granted. A global forwarder applies to all DNS queries the local servers cannot resolve, redirecting internet queries and all other namespaces to 192.168.100.20 — this would break resolution for all external names and is not limited to the margiestravels.com namespace.
Because AZ-802 sits under the same Candidate Agreement as every other Microsoft exam, getting caught with braindump material here does not just cost you AZ-802. Microsoft's policy allows revoking your entire certification history and banning you from future exams, and appeals have to reach Microsoft's certification security team within 14 days or they are not reviewed.
If you already hold other Microsoft credentials, that risk-to-reward math gets worse, not better. CertCompanion's AZ-802 bank has 600 practice questions, 30 free, covering hybrid identity, storage, and compute the way the real exam actually weights them.
AZ-802 (Administering Windows Server) is a single associate-level Microsoft exam that consolidates the retiring AZ-800 and AZ-801 pair. It entered beta in June 2026 and covers Windows Server administration across on-premises, hybrid, and Azure environments, from Active Directory and Hyper-V to Azure Arc and Azure File Sync.
Microsoft retires both exams on September 30, 2026. Until then, passing the pair still earns the certification; after that date, AZ-802 is the only available path.
If you have already passed one of the two older exams, finish the second before September 30, 2026 so the pair counts. If you are starting fresh, prepare for AZ-802 directly: the older exams retire soon and the consolidated exam gives you one blueprint to study instead of two.
You have 120 minutes and need a scaled score of 700 out of 1000 to pass. Microsoft associate exams typically contain 40 to 60 questions mixing multiple choice, drag-and-drop, hotspot, and scenario formats. While AZ-802 is in beta, scores are released after the beta period ends rather than immediately.
Seven domains: deploy and manage AD DS (20-25%), manage Windows Server instances and workloads in a hybrid environment (10-15%), manage virtual machines (10-15%), on-premises and hybrid networking (10-15%), storage and file services (15-20%), secure Windows Server infrastructure (10-15%), and monitor and troubleshoot Windows Server environments (15-20%).
USD $165 in the United States, with the price varying by country or region. Scheduling is through Pearson VUE, and if you fail you can retake after 24 hours, with longer waits between later attempts.
Not yet. Microsoft says the practice assessment usually arrives within about eight weeks of an exam leaving beta and becoming generally available, so independent practice questions are currently the main way to test yourself under exam-style conditions.
Passing AZ-802 earns the Microsoft Certified: Windows Server Administrator Associate credential, the successor title to Windows Server Hybrid Administrator Associate. Like other associate certifications it renews annually through a free online assessment on Microsoft Learn, and existing holders who certified via AZ-800 and AZ-801 keep their credential through that same renewal, without retaking the full exam.
Microsoft Certified: Power Platform Solution Architect Expert (PL-600)
PL-600 · 1080 questions
Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)
SC-900 · 230 questions
Microsoft Certified: Security Operations Analyst Associate (SC-200)
SC-200 · 599 questions
Microsoft 365 Certified: Administrator Expert (MS-102)
MS-102 · 965 questions
Microsoft 365 Certified: Copilot and Agent Administration Fundamentals (AB-900)
AB-900 · 700 questions
Microsoft 365 Certified: Fundamentals (MS-900)
MS-900 · 1201 questions
$17.99
One-time access to this exam