Because AZ-801 retired at the end of September 2026, these labs should be treated as Windows Server hybrid skills practice rather than preparation for a live AZ-801 appointment. The value of the final AZ-801 blueprint is that it brings security, high availability, disaster recovery, migration and troubleshooting into one practical Windows Server environment.
Lab one: harden a disposable Windows Server
Apply a security baseline, configure LAPS, inspect Credential Guard/WDAC or supported equivalents, review firewall rules and record the before/after state. Use a test VM so policy mistakes do not affect production.
Document which control protects code execution, credentials, local administration and network access.
Lab two: build an AD security tabletop
Create a small lab domain or diagram and review Protected Users, delegation, password policies, authentication policy silos and domain-controller hardening. Add Defender for Identity conceptually or in a sandbox.
Introduce one legacy NTLM dependency and plan a measured reduction rather than disabling it blindly.
Lab three: implement a small failover cluster
Use nested virtualization or Microsoft training infrastructure where available. Configure cluster networking, quorum/witness and one workload, then fail the active node and verify service continuity.
Record whether the cluster remains healthy and how clients locate the workload after failover.
Lab four: explore Storage Spaces Direct
In a supported lab, create or study an S2D cluster, networking and capacity layout. Compare node maintenance or upgrade operations with ordinary standalone storage.
The goal is to understand fault domains and cluster storage behavior rather than build a production hyperconverged system at home.
Lab five: perform a backup and restore drill
Back up test data or a VM through Azure Backup/Recovery Services where practical, then restore to an alternate location or VM. Record credentials, vault permissions, encryption dependencies and actual recovery time.
Restoring successfully is the evidence that backup architecture works.
Lab six: model Site Recovery failover
Use a training lab or architecture exercise to configure replication, network mapping and recovery plan. Simulate primary-site failure and trace how DNS, networking, identity and application dependencies recover.
Do not stop when the replicated VM starts; validate the service path.
Lab seven: migrate a file server or workload
Use Storage Migration Service or an equivalent lab to inventory files/shares/security settings, transfer them, perform cutover and validate clients. Alternatively, use an Azure Migrate assessment for a test VM.
The Azure Migrate workflow is useful because assessment and dependency planning happen before cutover.
Lab eight: practice a Windows Server version migration
Move an IIS, DHCP or other test workload to a newer Windows Server VM, or create a detailed migration runbook. Capture compatibility, configuration, data, identity, DNS and rollback.
Use the exercise to compare side-by-side migration with in-place upgrade.
Lab nine: create a monitoring baseline and fault
Collect Performance Monitor data, review event logs and Azure Monitor/VM Insights where available. Then create one safe CPU, DNS, service-startup or extension problem and diagnose from evidence.
A troubleshooting note should record symptom, hypothesis, evidence, root cause, fix and validation.
Lab ten: reconcile legacy practice with today’s exam path
When the lab series is complete, compare the skills you practiced against the active AZ-802 objectives. Mark which knowledge still maps directly and which AZ-801-specific exam topics no longer define the current certification structure.
Add a Windows LAPS verification step to the hardening lab. Confirm that two managed servers no longer share the same local administrator password and that only approved administrators can retrieve the secret. This turns a configuration checkbox into evidence of reduced credential-reuse risk.
Add a Credential Guard or application-control compatibility exercise. Identify one legacy application or authentication workflow that could be affected, test it in the lab and document the exception process. Mature hardening balances attack reduction with service continuity.
Add a domain-controller security baseline review. Compare normal member-server policy with DC-specific requirements, restrict interactive/remote access and review delegation. Domain controllers are not ordinary servers because their compromise affects the entire identity plane.
Add a Sentinel/Defender data-flow diagram. Show which Windows logs or security events are collected, where they are analyzed and who responds. Hybrid monitoring is useful only when the organization can turn telemetry into action.
Add a cluster-quorum experiment or tabletop. Remove one node or witness and predict which partition can continue. Then compare the prediction with observed cluster state. This makes quorum a decision mechanism rather than a term memorized for the old exam.
Add a cluster-aware updating exercise in a lab. Patch one node at a time while workloads move, then confirm all nodes return healthy. High availability should allow maintenance without assuming zero operational impact.
Add a backup-policy comparison for short-term operational restore versus longer retention. Decide frequency, retention and vault protection based on a fictional RPO/RTO. Different business data should not automatically receive identical backup policy.
Add a Site Recovery test-failover runbook that does not commit production failover. Validate replicated VM boot, network mapping, identity and application health in an isolated test network. A non-disruptive exercise is the best way to find hidden dependencies.
Add a Hyper-V Replica comparison to the same workload. Record management overhead, recovery orchestration and topology differences relative to Site Recovery. The exercise helps explain why multiple DR mechanisms existed in the final blueprint.
Add a Storage Migration Service cutover with client validation. Test mapped drives, permissions and service identity after the move. If the source name/IP is transferred, record how DNS and old-server shutdown are coordinated.
Add one Azure Migrate discovery exercise where the source workload depends on another server. Decide whether they must migrate together and how the target network preserves connectivity. Dependency awareness is often more important than VM conversion mechanics.
Add an in-place-upgrade versus side-by-side migration decision. Compare downtime, rollback, hardware/OS compatibility, application certification and cleanup. The fastest technical path is not always the safest modernization path.
Add a Performance Monitor baseline with a Data Collector Set for CPU, memory, disk and network. Create one safe resource bottleneck and identify which counter changes first. This makes old-school Windows diagnostics directly useful in modern hybrid environments.
Add an Azure Monitor data collection rule and alert in a sandbox if available. Compare centralized cloud monitoring with local event/performance evidence. The strongest troubleshooting workflow uses both rather than assuming one view has every detail.
Add an AD replication fault in a disposable domain by blocking or misconfiguring a safe dependency, then inspect replication/DNS/time evidence. Restore normal state before attempting recovery procedures. Directory troubleshooting should be methodical because random repairs can create wider inconsistency.
Finish the applied set with a migration-and-recovery handoff document. Another administrator should know source state, credentials, backup, target, cutover, rollback, monitoring and post-change validation. Even retired exam topics remain valuable when they improve real operational discipline.
Add a server-security exception lab. Apply a restrictive baseline to a test workload, observe one legitimate application failure and document a narrow exception rather than weakening the whole baseline. This practices the real-world balance between secure defaults and application compatibility.
Add a cluster-monitoring dashboard or worksheet that records node state, quorum, workload owner, storage health and recent maintenance. Then fail one component and confirm which signal changes first. High availability is easier to troubleshoot when healthy state is documented.
Add a recovery-time measurement to every backup or Site Recovery drill. Record the point of failure, start of recovery, service validation and any manual dependency. RTO discussions become meaningful only when actual or tested recovery timing exists.
Add a post-migration security review. A workload may arrive successfully in Azure but inherit overly broad NSGs, missing Defender coverage or outdated local accounts. Migration completion should include hardening and monitoring in the target environment rather than stopping when the VM boots.
Add a legacy-to-current mapping sheet after the labs. Put each practiced AZ-801 skill in one column and the corresponding AZ-802 area, current Microsoft Learn topic or operational runbook in another. This turns historical study effort into a current learning plan without pretending the retired exam remains active.
Add a final end-to-end resilience exercise: harden the server, verify privileged access, place the workload on a resilient cluster, protect it with backup, document DR, migrate or upgrade a component, and collect monitoring evidence throughout. The point is not to deploy every technology at maximum scale; it is to see how security, availability, recovery, change and observability depend on one another.
At the end, package the lab evidence as if handing the environment to another administrator: topology, identities, security baseline, cluster state, backup/restore procedure, migration record, monitoring baseline and rollback notes. This is durable operational practice even though AZ-801 itself is no longer a live Microsoft exam.
Add a hybrid identity recovery tabletop to the lab. Assume an on-premises domain controller fails while cloud-connected workloads still run. Identify which authentication paths continue, which administrative tasks fail and what recovery order restores directory, DNS and dependent services. The exercise demonstrates that hybrid identity can create both resilience and dependency.
Add a secure remote-management comparison. Manage one server through a protected administrative path and compare that with exposing RDP or WinRM broadly. Record firewall, identity and logging requirements. Remote administration is part of the attack surface and should be designed deliberately.
Add a cluster storage-capacity incident. Simulate or model a disk/node loss in an S2D environment and determine whether the remaining capacity/resiliency can sustain the workload. A cluster can remain online while running with reduced fault tolerance, so post-failure status matters as much as immediate availability.
Add a migration rollback drill. After moving a test service, introduce a validation failure and execute the rollback steps you documented. Measure what state changed during cutover and what data must be reconciled. A rollback plan that has never been rehearsed is only an assumption.
Add one final monitoring correlation exercise using Windows events, performance counters and Azure-side telemetry from the same failure. Compare what each source reveals. Local evidence can explain a service or OS problem while centralized monitoring provides fleet context and alert history.
This keeps the legacy AZ-801 study material useful without misleading candidates about exam availability.