Active Directory and Hybrid Identity Administration on Windows Server
Active Directory still controls access to most enterprise systems, and it is a primary target in ransomware and credential attacks, now extended into the cloud through hybrid identity. This programme gives administrators the skills to design, run, secure and synchronise Active Directory on Windows Server with Microsoft Entra ID, and to automate routine work safely.
In many organisations Active Directory has grown for years without a clear design. Organisational units no longer reflect the business, group nesting is hard to follow, Group Policy objects conflict, service accounts have permanent administrator rights and old domain controllers remain in service. When the organisation adopts Microsoft 365 or other cloud services, this directory is synchronised to Microsoft Entra ID, and its weaknesses become cloud weaknesses. Attackers know this, and privileged credentials in Active Directory are a common route to a full network compromise.
This programme covers Active Directory from structure to security to the cloud. It moves through five stages: designing and deploying the directory, managing identities, groups and delegation, controlling configuration through Group Policy, connecting on-premises identity to Microsoft Entra ID, and securing, monitoring and recovering the environment. Participants learn why each practice matters as well as how to carry it out.
Built on recognised practice. The programme references current Microsoft documentation for Active Directory Domain Services on Windows Server 2025 and 2022, Microsoft Entra Connect Sync and Microsoft Entra Cloud Sync, the Microsoft enterprise access model for privileged access, Windows LAPS, and hardening guidance such as the CIS Benchmarks. Attack techniques are discussed with reference to the MITRE ATT&CK knowledge base.
What this changes in practice. How to structure organisational units and delegate administration; which synchronisation option and authentication method to choose for hybrid identity; how to separate and protect privileged accounts; how to replace shared service account passwords with managed accounts; which changes to automate with PowerShell; and how to prepare for the recovery of a compromised forest.
How it is delivered. Twenty hours across five sessions, built around one running case: an organisation with an ageing single-forest directory that is moving to Microsoft 365. Participants work in a lab environment to restructure the directory, apply policies, configure synchronisation, harden privileged access and script common tasks with PowerShell. AI assistants are used modestly to draft and review scripts, with attention to checking their output.
In-house option. For organisations, the programme can be tailored to your own directory design, Windows Server versions, cloud services and security policies, and can include a structured review of your current environment as part of the exercises.
Who Should Attend
Objectives
Course Outline
Competencies
Live Online
Related Topics
Poor quality in IT shows up late and costs most: defects found in production, services that miss their levels and projects delivered without meeting user needs. This programme gives IT practitioners a practical quality management approach covering software and service quality, testing, process improvement and measurement across the whole IT life cycle.
Many laboratories buy a LIMS and still run on spreadsheets, paper worksheets and manual transcription, because the system was configured before the workflows, data and controls were understood. This programme gives laboratory, quality and IT staff a practical method to define requirements, select, validate and run a LIMS that supports data integrity and ISO/IEC 17025 compliance.
To equip IT professionals with the skills to leverage AI technologies and Microsoft Copilot for automating IT tasks, enhancing support operations, managing systems, and improving decision-making through smart data analysis and scripting assistance.
