AZ-801 retired on September 30, 2026, so there is no reason to prepare for it as a new exam appointment in October 2026. However, its final blueprint remains a useful way to structure advanced Windows Server hybrid skills or to review legacy material before transitioning to AZ-802. The sequence below follows dependency order rather than implying that AZ-801 is still available.
Phase one: secure the Windows Server operating system
Start with Exploit Protection, WDAC, Credential Guard, SmartScreen, Group Policy security, OSConfig baselines and Windows LAPS. Build or use a lab where you can distinguish prevention, credential protection and local-admin password management.
Security fundamentals should be stable before clustering or migration introduces more systems.
Phase two: harden Active Directory and privileged access
Study password policy, Entra Password Protection, Protected Users, RODC security, domain-controller hardening, authentication policy silos, delegation, Defender for Identity and NTLM reduction.
Create one privileged-access map that shows where credential theft could affect servers, clusters, backup and migration tooling.
Phase three: add server network and storage protection
Practice Windows Defender Firewall, domain isolation, connection-security rules, Azure NSGs, BitLocker, Azure Disk Encryption and key recovery. Keep network and storage controls attached to clear business requirements.
Then verify that monitoring can reveal relevant security state.
Phase four: build failover clustering before DR
Create or diagram a failover cluster, quorum, networking, storage, Azure witness and workload failover. Add S2D and cluster-aware updating once basic cluster state makes sense.
This phase teaches local service continuity before you move into site-level disaster recovery.
Phase five: practice backup and restore
Use a Recovery Services vault or training lab to understand file/VM backup, policy, snapshots and restore paths. Include encrypted VM recovery and verify that required keys or permissions are actually available.
A backup is valuable only when restoration is tested.
Phase six: add Site Recovery and Hyper-V Replica
Model network mappings, replication policy, recovery plans and failover. Compare Site Recovery with Hyper-V Replica by topology and operational model.
Practice a tabletop where the primary site fails and the business must recover dependencies in sequence.
Phase seven: study migration as a controlled change
Review Storage Migration Service, Azure Migrate, workload-specific moves and in-place upgrade. For each, define source inventory, compatibility, cutover, rollback and validation.
A migration plan should preserve identity, security and business continuity rather than only move bytes.
Phase eight: modernize Windows Server 2025 and AD
Practice choosing among upgrade, migration and forest restructure. Review AD Migration Tool concepts, Group Policy/object migration and functional-level changes.
Use a disposable lab because identity migrations can have wide blast radius if practiced on real enterprise directories.
Phase nine: build monitoring and troubleshooting routines
Use Performance Monitor, event logs, Windows Admin Center, System Insights, Azure Monitor data collection rules and VM Insights. Establish a healthy baseline, then create one harmless connectivity, DNS or performance fault.
Evidence-first troubleshooting is more durable than memorizing repair commands.
Finish by transitioning the study map to AZ-802
Review which AZ-801 topics remain directly useful—security, monitoring, migration and hybrid administration—and then compare them against the live AZ-802 guide. Do not assume old domain weights or scope carry over unchanged.
Keep one reference environment through the legacy review: two domain controllers, a file server, Hyper-V hosts, one clustered workload, a branch/site, Azure subscription and a few Azure-connected servers. This lets security, HA, DR, migration and monitoring reinforce one another instead of becoming separate labs.
During OS hardening, record the baseline before and after policy changes. Test service functionality so you learn when a hardening control creates application compatibility issues. Security baselines are safer when rollout and exceptions are measured rather than applied blindly.
During LAPS practice, verify password rotation and access control around the secret. Local-admin password management only reduces credential reuse if ordinary users and automation cannot read every password.
During AD hardening, create one legacy-authentication inventory. Identify which services still require NTLM or weak delegation patterns, then plan staged remediation. A direct “disable everything” approach can break old applications and does not model professional hybrid administration.
During Defender for Identity study, map alerts back to directory activity and privilege. The goal is to understand which identity behaviors can indicate reconnaissance, credential theft or lateral movement and how those signals influence incident response.
During failover-cluster practice, cause a safe node loss and observe quorum, resource ownership and client behavior. Then simulate a communication split conceptually and explain how witness/quorum decisions prevent both sides from serving the same clustered resource incorrectly.
During S2D study, separate capacity from resiliency. Disk/node layout, storage pool health and network performance all affect the cluster. A large amount of raw storage does not guarantee usable fault-tolerant capacity.
During backup practice, test granular file recovery and full VM recovery separately. Record recovery time and whether application consistency matters. Backup design should match what the business actually needs to recover.
During Site Recovery study, create a recovery plan with dependency order and network mapping. Then perform a test failover if the lab permits it. Test failover should avoid disrupting production and should prove DNS, authentication and application dependencies.
During Storage Migration Service, practice inventory before cutover. Identify files, shares, permissions and source identity. Then validate clients after cutover rather than assuming a completed migration job means users can access everything.
During Azure Migrate study, compare assessment output with actual target design. CPU/memory utilization, disk performance, network dependency and supported target can influence right-sizing and migration strategy.
During IIS modernization, take one application and decide whether it should remain on a Windows VM, move to Web Apps or run in a container. Base the decision on dependency and operating model rather than modernization for its own sake.
During Windows Server 2025 migration, include rollback and coexistence. Domain/forest or infrastructure upgrades can be staged, while workload migrations may require parallel operation. Plan how clients and administrators know which system is authoritative during transition.
During monitoring, define a healthy baseline before inducing faults. Collect CPU, memory, disk, network, event, replication and Azure telemetry. Baselines make troubleshooting a comparison rather than guesswork.
During AD recovery, practice in a fully disposable directory. Restore a deleted object and review DSRM/SYSVOL recovery procedures. Directory recovery has high blast radius, so conceptual accuracy and tested runbooks matter more than casual experimentation.
Finish by reading the active AZ-802 guide end to end and mapping your practiced skills to the current sections. That transition exercise is more useful in October 2026 than taking another retired AZ-801 mock exam.
Add one combined identity-and-recovery exercise: assume a domain controller and backup administrator credential are compromised during the same incident. Decide how emergency access, offline/isolated recovery credentials and clean administrative workstations preserve the ability to restore services. This makes the security-to-DR dependency obvious.
Add one cluster-maintenance scenario where a node must be patched while the business service remains available. Plan drain/failover, maintenance, return-to-cluster and validation. The exercise shows why availability is an operational process, not only a cluster object.
Add one migration readiness checklist covering inventory, compatibility, dependencies, backup, network, identity, DNS, security baseline, maintenance window, validation and rollback. Use the same checklist for file, IIS and VM migration so differences in workload requirements become visible.
Add one monitoring escalation exercise. Define thresholds for CPU, disk, replication or backup failure, then identify who receives the alert and what runbook follows. Collecting Azure Monitor or Windows events without operational ownership does not improve reliability.
Add one final comparison between “recover” and “migrate.” Recovery restores a known service after failure; migration intentionally changes the platform or location. The tools, validation and rollback logic overlap, but the business objectives differ. Keeping that distinction clear helps modern administrators choose the right change plan.
Add one security-to-monitoring verification after every major lab. When LAPS, firewall, backup, clustering or migration changes state, identify which Windows event, Azure signal, cluster status or application test proves the intended result. This habit turns configuration into evidence and makes later troubleshooting faster because you already know what healthy operation should look like.
Finally, preserve the retired blueprint as a historical skills checklist rather than an exam calendar. Date the notes, mark AZ-801 retired on September 30, 2026, and keep a separate AZ-802 sheet for current certification objectives. That separation prevents useful Windows Server knowledge from being confused with outdated registration or weighting information.
Add a hybrid-security monitoring phase after AD hardening. Send representative Windows security events into the cloud security/monitoring stack or study the flow through a training lab. Identify which events support identity investigation, server posture or incident response and who owns follow-up. Collection without an operational process is only telemetry, not a security capability.
Add one storage-encryption recovery exercise before the DR phase. Protect a disposable volume, record the recovery material and confirm an authorized recovery path. Then ask how a disaster-recovery administrator obtains the key when the normal identity system is unavailable. This links confidentiality controls with continuity.
During cluster study, include both service availability and administrative availability. A clustered application might keep serving while the normal management host is offline. Define how administrators reach, monitor and repair the cluster during degraded operation so high availability is not dependent on one management workstation.
During migration planning, establish a measurable success baseline: application response, file/share access, authentication, performance and monitoring. After cutover, compare the target with that baseline before declaring success. This prevents teams from accepting a migration merely because the service starts.
After each legacy objective group, map the skill to current Windows Server operations rather than to an exam score. This changes the purpose of the study session: you are preserving hardening, resiliency, recovery and migration competence while separately following AZ-802 for certification. That separation is the most sensible study strategy after retirement.
The AZ-801 advanced-hybrid-services material can still deepen your Windows knowledge, but current certification preparation should be anchored to Microsoft’s active exam path.