Courses Job Ready Program Fresher Trainings AI For Class 7 to 12 Corporate Training Placements Tutorials
Free Learning Resources

IT Tutorials & Interview Prep

Free guides, interview Q&As, and job responsibility breakdowns — curated by industry veterans to help you crack MNC interviews

247+
Tutorial Articles
17
Topic Categories
100%
Free to Read
← Back to Windows Administration

Windows Desktop Administration

Windows Administration Last Updated: Sep 30, 2026

1. Introduction to Windows Desktop Administration

1.1 What is Windows Desktop Administration?

Windows Desktop Administration refers to the set of tasks, tools, and practices used to install, configure, secure, monitor, and maintain Windows-based desktop and laptop computers within an organization or home environment. It covers everything from creating user accounts and installing software to managing updates, permissions, and hardware devices, ensuring that every Windows machine runs smoothly, securely, and in line with organizational policies. Without proper desktop administration, computers become inconsistent, insecure, and difficult to support at scale.

Easy Hinglish Explanation:

Desktop Administration ka matlab hai Windows computers ko set up karna, unhe manage karna aur unka khayal rakhna — jaise naya user account banana, software install karna, updates dena, aur system ko secure rakhna. Ek IT admin puri company ke computers ko is tarah handle karta hai jaise ek caretaker apne ghar ke saare rooms ka khayal rakhta hai.

Day-to-Day Example:

When a new employee joins a company and IT sets up their laptop with a login account, installs Office and antivirus, and connects it to the office Wi-Fi, that entire process is Windows Desktop Administration in action.

 

1.2 Why do we need Windows Desktop Administration?

Windows Desktop Administration is essential because a computer straight out of the box is not secure, not configured for organisational needs, and not connected to shared resources like printers, servers, or the internet safely. Proper administration ensures every machine follows the same security baseline, users get only the access they need, software stays updated against vulnerabilities, and problems can be diagnosed and fixed quickly. Without it, organisations would face frequent breakdowns, security breaches, and wasted productivity every time something went wrong.

  • Provides a consistent, secure, and ready-to-use environment for every employee.
  • Manages hardware and software resources efficiently across many machines.
  • Allows multiple users to share the same computer or network safely.
  • Provides security and protection against unauthorised access and malware.
  • Handles updates, backups, and hardware/software failures gracefully.

Day-to-Day Example:

Imagine an office with 200 laptops and no IT team — every employee would have to install their own antivirus, manage their own updates, and fix their own printer issues, leading to total chaos. Windows Desktop Administration is like a dedicated caretaker who keeps all 200 machines healthy, secure, and working the same way, so employees only need to focus on their own work.

 

1.3 How does Windows Desktop Administration work?

Desktop administration works by combining local configuration tools on each machine with centralized management systems that push settings, software, and policies to many computers at once. When an admin needs to make a change — say, installing an application or resetting a password — the request typically flows through a defined process involving authentication, permission checks, and execution, very similar to how any IT service request is handled.

  • Step 1: A request or need is identified (e.g., 'install this software' or 'unlock this account').
  • Step 2: The admin logs in with an administrator/domain-admin account that has the required rights.
  • Step 3: The action is performed using a tool — Control Panel, Settings, PowerShell, Group Policy, or a management console.
  • Step 4: Windows validates permissions and applies the change to the system or user profile.
  • Step 5: The change takes effect immediately or after a restart/policy refresh, and the result is verified.

 

1.4 When is Windows Desktop Administration performed?

Windows Desktop Administration is not a one-time activity — it is an ongoing responsibility performed from the moment a computer is first unboxed and imaged, throughout its entire working life, until it is finally retired. Daily tasks include monitoring, patching, and helpdesk support, while periodic tasks include audits, upgrades, and policy reviews.

Day-to-Day Example:

The moment a new laptop is issued to an employee, admin work begins with imaging and account setup, continues every month with Windows Updates and security patches, and only ends when the laptop is wiped and retired years later.

 

1.5 Where is Windows Desktop Administration used?

Windows Desktop Administration is practiced anywhere Windows computers are deployed and need to be kept secure and functional, from a single home PC to thousands of machines spread across multiple office locations.

  • Corporate offices — employee desktops and laptops managed centrally by IT.
  • Schools & colleges — computer labs shared by many students.
  • Banks & government departments — highly secured, policy-driven desktop environments.
  • Hospitals — desktops running patient-record and diagnostic software.
  • Cybercafes & shared kiosks — locked-down, restricted-access machines.
  • Remote/work-from-home setups — laptops managed remotely via VPN or cloud tools.

 

1.6 Who performs and uses Windows Desktop Administration?

Windows Desktop Administration involves two broad groups. End users (employees, students, and staff) use the administered computer every day, usually without needing to know how it is configured behind the scenes. On the other side, Desktop Support Engineers, System Administrators, and IT Helpdesk teams are responsible for setting up, securing, monitoring, and troubleshooting these machines, often using centralized tools like Active Directory and Group Policy to manage hundreds of computers at once.

Easy Hinglish Explanation:

Do tarah ke log hote hain — ek jo computer ko sirf use karte hain (employees, students), aur doosre jo unn computers ko set up aur maintain karte hain (IT admin, desktop support engineer, helpdesk team).

Fig 1.1 — Layered View of Windows Desktop Administration

 

2. Functions of Windows Desktop Administration

Windows Desktop Administration covers several core functions, each targeting a specific part of the computer's operation. Together these functions make sure that every machine is usable, secure, and aligned with organizational needs.

2.1 User Account Management

This function covers creating, modifying, disabling, and deleting user accounts, assigning the right permission level (standard or administrator), resetting forgotten passwords, and organizing users into groups so that access to files and resources can be controlled easily.

Day-to-Day Example:

When a new intern joins and IT creates a limited 'Standard User' account for them (instead of full Admin rights), that is user account management in action, keeping the intern productive without risking system settings.

 

2.2 Software & Application Management

This involves installing, updating, licensing, and uninstalling software across desktops, often using centralized deployment tools so that hundreds of machines can receive the same application without an admin visiting each one physically.

 

2.3 Hardware & Device Management

The admin ensures printers, scanners, external drives, monitors, and other peripherals are correctly installed with proper drivers, and monitors hardware health (disk space, RAM usage, battery health) to prevent failures before they disrupt work.

Easy Hinglish Explanation:

Jab bhi ek naya printer office mein lagaya jaata hai aur usse sab computers se connect kiya jaata hai, ye Hardware & Device Management ka hi kaam hai.

 

2.4 Security & Patch Management

This function protects desktops from malware, unauthorized access, and known vulnerabilities by enforcing antivirus protection, firewall rules, encryption (like BitLocker), and by regularly deploying Windows Updates and security patches across all machines.

 

2.5 Group Policy & Configuration Management

Using Group Policy Objects (GPOs) in an Active Directory environment, admins can push consistent settings — password rules, desktop wallpaper restrictions, drive mappings, USB restrictions — to thousands of computers at once, instead of configuring each one manually.

 

2.6 Backup, Recovery & Troubleshooting

This covers scheduling regular backups of important data, configuring System Restore points, and diagnosing/fixing issues like slow performance, failed updates, or corrupted user profiles when things go wrong.

Day-to-Day Example:

When an employee's laptop suddenly stops booting properly and IT restores it using a recovery point or reimages it from a backup, this is Backup, Recovery & Troubleshooting at work.

 

3. Important Concepts & Technical Terms

This section covers the key terminology every student must understand clearly before performing real desktop administration tasks. Each term is explained in detail with a simple example so the concept sticks.

Active Directory (AD)

Active Directory is Microsoft's centralized directory service that stores information about users, computers, and groups on a network, and allows administrators to manage authentication, permissions, and policies for an entire organization from one place.

Easy Hinglish Explanation:

Active Directory ek bada database hai jisme company ke saare users aur computers ki entry hoti hai — isi ki madad se admin sabko ek jagah se control karta hai.

Day-to-Day Example:

Just as a school maintains one central register of all students and teachers instead of separate lists per classroom, a company uses Active Directory as one central record of all its users and computers.

 

Domain vs Workgroup

A Domain is a centrally managed network where all computers are controlled by a server running Active Directory, while a Workgroup is a small peer-to-peer setup where each computer manages its own users and settings independently, typically used at home or in very small offices.

Easy Hinglish Explanation:

Domain mein ek central server sab kuch control karta hai, jabki Workgroup mein har computer apna khud ka boss hota hai—koi central control nahi hota.

 

Group Policy Object (GPO)

A Group Policy Object is a collection of settings that an administrator creates and links to a domain, site, or organizational unit, which then automatically applies configurations — like password complexity rules or restricted Control Panel access — to many computers and users at once.

 

Easy Hinglish Explanation:

GPO ek 'rule-book' ki tarah hai jo admin banata hai aur jise saare computers ya users par ek sath laagu kar diya jaata hai, bina har machine par manually jaakar setting change kiye.

Day-to-Day Example:

Just as a school principal issues one circular that automatically applies to every classroom, an admin creates one GPO that automatically applies to every linked computer.

 

User Profile

A User Profile is the personalized collection of settings, files, desktop layout, and preferences that Windows loads whenever a specific user logs in, keeping each person's environment separate even on a shared computer.

Easy Hinglish Explanation:

User Profile matlab har user ka apna alag desktop, files aur settings — jaise ek hi computer par do log login karein to dono ko apna alag wallpaper aur files dikhengi.

 

Local Administrator vs Standard User Account

A Local Administrator account has full control over a specific computer, including the ability to install software, change system settings, and manage other accounts, whereas a Standard User account can only run programs and change personal settings, without the ability to alter critical system configuration.

Easy Hinglish Explanation:

Administrator account ke paas full power hoti hai (software install karna, settings change karna), jabki Standard User sirf apna kaam kar sakta hai, system settings nahi chhed sakta.

 

Remote Desktop Protocol (RDP)

Remote Desktop Protocol is a Microsoft protocol that allows a user or administrator to connect to and control another Windows computer over a network as if sitting in front of it, commonly used for remote troubleshooting and work-from-home access.

 

Easy Hinglish Explanation:

RDP se aap kisi doosre computer ko duur baithe hue bhi control kar sakte ho, bilkul waise jaise aap khud uske saamne baithe ho.

Day-to-Day Example:

Just as a doctor can examine a patient over a video call without being physically present, an IT admin can fix a colleague's computer over RDP without visiting their desk.

 

Windows Registry

The Windows Registry is a hierarchical database that stores low-level configuration settings for the operating system, installed applications, and hardware, and is edited carefully by administrators (using tools like Registry Editor) when troubleshooting deep system issues.

Easy Hinglish Explanation:

Registry Windows ka ek 'settings ka bada dabba' hai jisme sab kuch store hota hai — isse galat tarike se edit karna system ko kharab bhi kar sakta hai, isliye ise carefully use kiya jaata hai.

 

Task Scheduler

Task Scheduler is a Windows tool that allows administrators to automate the execution of scripts, backups, or maintenance tasks at specific times or triggered by specific events, without needing to run them manually every time.

Easy Hinglish Explanation:

Task Scheduler ek 'alarm clock' ki tarah kaam karta hai jo admin ke set kiye gaye time par khud-ba-khud koi task (jaise backup) chala deta hai.

Day-to-Day Example:

Just as setting a daily alarm ensures you wake up at the same time without remembering to do it manually, Task Scheduler ensures a backup job runs every night without an admin starting it by hand.

 

Windows Update / Patch Management

Windows Update is the built-in service that delivers security patches, bug fixes, and feature updates to a Windows computer, and Patch Management is the administrative practice of controlling when and how these updates are tested and rolled out across an organization's machines.

Easy Hinglish Explanation:

Windows Update naye security fixes aur improvements deta rehta hai, aur Patch Management ka matlab hai in updates ko sahi tarike se, bina kaam mein rukawat daale, sabhi computers par lagaana.

 

BitLocker

BitLocker is a Windows feature that encrypts an entire disk drive, ensuring that if a laptop is lost or stolen, the data on it remains unreadable to anyone without the correct recovery key or credentials.

Easy Hinglish Explanation:

BitLocker laptop ke poore disk ko lock/encrypt kar deta hai, taaki agar laptop chori ho jaaye to bhi koi uska data padh na sake bina sahi key ke.

Day-to-Day Example:

Just as a locked safe protects valuables even if someone steals the entire safe, BitLocker protects data even if the whole laptop is stolen.

 

System Restore

System Restore is a Windows recovery feature that lets an administrator or user revert the computer's system files and settings back to an earlier point in time, undoing problematic changes (like a bad driver installation) without affecting personal files.

Easy Hinglish Explanation:

System Restore computer ko purani, theek-thaak working state mein wapas le jaata hai, agar koi recent change (jaise driver install) system ko kharab kar de.

 

Imaging & Deployment

Imaging is the process of creating a standardized snapshot of a fully configured Windows installation (OS, drivers, and base applications), which is then deployed to multiple new computers so that every machine starts out identically configured, saving huge amounts of manual setup time.

Easy Hinglish Explanation:

Imaging matlab ek 'ready-made template' bana lena jisme OS aur zaroori software pehle se installed ho, aur usi template ko sabhi naye computers par copy kar dena.

Day-to-Day Example:

Just as a bakery uses one master recipe to bake hundreds of identical cakes instead of designing each one from scratch, IT uses one master image to set up hundreds of identical laptops.

 

 

4. Domain Join Process — Step by Step

Joining a computer to a domain is one of the most common tasks in Windows Desktop Administration, connecting a standalone machine to the organization's centrally managed Active Directory environment. Understanding this process helps in troubleshooting connectivity and login issues on managed computers.

  • Step 1 — Power ON & Log in: The technician logs in to the new computer with a local administrator account.
  • Step 2 — Open System Properties: Navigate to Settings > System > About > Advanced system settings (or 'Domain or workgroup').
  • Step 3 — Choose 'Join a domain': The technician selects Domain instead of Workgroup and types the organization's domain name.
  • Step 4 — Provide Domain Admin Credentials: Windows asks for a domain administrator's username and password to authorize the join.
  • Step 5 — Active Directory Verifies: The domain controller checks the credentials and creates a new computer object for this machine in Active Directory.
  • Step 6 — Restart the Computer: A restart is required for the domain membership and related policies to take full effect.
  • Step 7 — Login with Domain Account: The user can now log in using their domain username and password, and Group Policies begin applying automatically.

Easy Hinglish Explanation:

Domain join karne ka matlab hai apne computer ko company ke central server (Active Directory) se jod dena, taaki company ka admin us computer ko duur se hi manage kar sake — login, policies, security sab kuch central control mein aa jaata hai.

Fig 4.1 — Step-by-step Domain Join Process

 

5. User Account and Its Life Cycle

A user account, once created, moves through a series of well-defined states over its working life, managed entirely by the administrator through Active Directory or local user management tools. Understanding these states is crucial for handling onboarding, temporary access issues, and offboarding correctly.

StateDescription
New / CreatedThe account is created by the admin with a username, initial password, and assigned permissions.
Active / EnabledThe account is fully usable — the user can log in and access resources according to their permissions.
LockedThe account is temporarily blocked, usually after too many failed login attempts, until unlocked by an admin or timeout.
DisabledThe admin has intentionally turned the account off (e.g., employee on long leave) without deleting it, so it can be re-enabled later.
Deleted / ArchivedThe account is permanently removed or archived when the user leaves the organization, and its resources are reclaimed or reassigned.

 

Day-to-Day Example:

Think of a library membership. 'New' is when you first register; 'Active' is when your card works normally; 'Locked' is when it's temporarily suspended for an unpaid fine; 'Disabled' is when you pause membership while traveling; and 'Deleted' is when you formally cancel your membership for good.

Fig 5.1 — User Account Life Cycle

 

6. Types of Windows Desktop Environments

Windows desktop environments are set up differently depending on the size of the organization, security needs, and whether devices are managed on-premises or through the cloud. Below is a look at the major types administrators work with.

Fig 6.1 — Major Types of Windows Desktop Environments

TypeDefinition & Use CaseSimple Example
WorkgroupA small peer-to-peer setup where each computer manages its own accounts independently; suited to homes and very small offices.A 3-computer home network
Domain (Active Directory)A centrally managed network where a server (domain controller) controls users, computers, and policies for the whole organization.A mid-to-large corporate office
Azure AD / Entra (Cloud-joined)Devices are registered and managed through Microsoft's cloud identity service instead of an on-premises server.A fully remote/cloud-first company
Hybrid JoinDevices are joined to both an on-premises Active Directory and Azure AD, allowing management through both systems.A company migrating gradually to the cloud
Standalone / Kiosk ModeA single-purpose, locked-down device restricted to running only one or a few approved applications.An airport check-in kiosk or library catalog PC

 

7. Important Difference / Comparison Tables

Comparison-based questions are very common in exams and interviews. These tables summarize the most important distinctions students must remember clearly.

7.1 Workgroup vs Domain

BasisWorkgroupDomain
ManagementDecentralized — each PC manages itself.Centralized — controlled by a domain controller.
Best suited forHomes and very small offices (under ~10 PCs).Medium to large organizations.
User AccountsCreated separately on every single computer.Created once in Active Directory, usable on any joined PC.
Security PolicySet individually per machine.Applied uniformly through Group Policy.
Administration EffortLow setup cost, but hard to manage at scale.Higher setup cost, but easy to manage at scale.

 

7.2 Local Account vs Microsoft Account vs Domain Account

BasisLocal AccountMicrosoft AccountDomain Account
Where it's storedOn the single computer only.In Microsoft's online servers.In the organization's Active Directory.
Works on other PCs?No, unless manually recreated.Yes, on any PC after sign-in.Yes, on any PC joined to the domain.
Typical UserHome users, single-PC setups.Personal/home users wanting cloud sync.Employees in an organization.
Managed ByThe PC's own administrator.The individual user.The organization's IT/domain admin.

 

7.3 Administrator Account vs Standard User Account

BasisAdministrator AccountStandard User Account
System ChangesCan install software, change settings, manage other accounts.Cannot install most software or change system-wide settings.
Security RiskHigher — malware run under this account gets full access.Lower — limits the damage malware or mistakes can cause.
Typical UseIT admins, power users who need full control.Everyday employees, students, general use.
Recommended PracticeUse only when necessary, for admin tasks.Use as the default account for daily work.

 

7.4 Group Policy vs Local Security Policy

BasisGroup PolicyLocal Security Policy
ScopeApplies to many computers/users across a domain.Applies only to the single computer it's set on.
Managed FromA central domain controller (Active Directory).Directly on that one machine.
Use CaseEnforcing consistent rules across an organization.Configuring settings on a standalone or workgroup PC.
Requires Domain?Yes.No.

 

7.5 Windows 10 vs Windows 11 (Desktop Administration Features)

Windows 10 and Windows 11 share the same underlying administration model, but Windows 11 introduces refinements aimed at hybrid work, security, and cloud management that administrators should be aware of.

BasisWindows 10Windows 11
Minimum Hardware SecurityTPM recommended but not mandatory.TPM 2.0 and Secure Boot mandatory.
Management ToolsGroup Policy, Intune, SCCM/MECM.Same tools, with deeper Intune/cloud-management integration.
UI for AdminsClassic Control Panel plus Settings app.Settings app is primary; Control Panel largely legacy.
Update Channel OptionsStandard servicing channels.Similar channels, generally larger feature updates less often.
Support FocusWidely deployed, long legacy app compatibility.Newer devices, tighter security baseline by default.

 

Easy Hinglish Explanation:

Windows 10 aur Windows 11 dono ko admin karib-karib same tareeke se manage karte hain, lekin Windows 11 mein hardware security (TPM 2.0) mandatory hai aur cloud-based management (Intune) par zyada focus hai.

 

Day-to-Day Example:

An IT admin rolling out new laptops today must first check whether each machine has TPM 2.0 enabled before installing Windows 11, something that was optional back in the Windows 10 era.

8. Scenario-Based Questions (Practice)

These questions test your practical understanding of the concepts covered above. Try answering them yourself first, then check the given answer and reasoning.

Q1. An employee tries to log in but Windows shows 'This account has been locked out.' What is happening, and how should it be resolved?

Answer: The account has moved into the Locked state.

Why / Reason: Windows locks an account after a set number of consecutive failed login attempts as a security measure against password-guessing attacks. An administrator must unlock the account through Active Directory Users and Computers or Local Users and Groups, often after verifying the user's identity.

Q2. A newly joined employee's laptop is not receiving the company's password policy or wallpaper restrictions that every other computer has. What is most likely misconfigured?

Answer: The Group Policy Object (GPO) is not applying to this computer.

Why / Reason: GPOs apply based on domain, site, or organizational unit linkage. If the new computer's account object was placed in the wrong organizational unit, or the computer hasn't been restarted/refreshed policy (gpupdate), the relevant GPO settings will not take effect.

Q3. A company laptop is stolen from an employee's car, but IT is confident the data cannot be read by the thief. Which feature made this possible?

Answer: BitLocker Drive Encryption.

Why / Reason: Since the entire disk was encrypted with BitLocker, anyone without the correct recovery key or user credentials cannot read the data on the drive, even if they remove the hard disk and connect it to another computer.

Q4. An admin needs to install the same accounting software on 150 new desktops without visiting each one individually. What approach should they use?

Answer: Centralized software deployment through Group Policy Software Installation, SCCM/Intune, or a pre-built system image.

Why / Reason: Manually visiting 150 machines is impractical. Centralized deployment tools push the same application silently to many computers at once, saving enormous time and ensuring consistency.

Q5. A user's laptop suddenly stops starting normally after a driver update, but their personal files are still intact on the disk. What should be tried first?

Answer: System Restore, to roll the system back to a point before the driver update.

Why / Reason: System Restore reverts system files, registry settings, and installed drivers to an earlier restore point, without touching personal documents, making it an ideal first fix for a problem introduced by a recent system-level change.

Q6. A small design studio with 5 computers wants simple file sharing between machines without buying a dedicated server. What kind of setup fits best?

Answer: A Workgroup.

Why / Reason: For a very small number of computers with no need for centralized policy control, a peer-to-peer Workgroup setup is simpler and cheaper than deploying and maintaining a full Active Directory domain.

Q7. An employee working from home needs IT to access their office desktop to fix a software issue, without physically being there. What technology enables this?

Answer: Remote Desktop Protocol (RDP).

Why / Reason: RDP allows an authorized user or administrator to connect to and control a remote Windows computer over the network exactly as if sitting in front of it, making remote troubleshooting possible.

Q8. A company wants every new laptop to arrive already configured with Windows, drivers, and the standard company software, without technicians repeating the setup by hand each time.

Answer: Imaging & Deployment using a standardized master image.

Why / Reason: By creating one properly configured master image and deploying it to every new machine, the company ensures identical, ready-to-use configurations while drastically cutting manual setup time.

 

9.1 Basic Interview Questions

1. What is Windows Desktop Administration?

It is the practice of installing, configuring, securing, and maintaining Windows desktop and laptop computers, covering user accounts, software, hardware, security, and policies.

2. What are the main functions of Windows Desktop Administration?

User account management, software/application management, hardware/device management, security and patch management, group policy/configuration management, and backup/recovery/troubleshooting.

3. What is the difference between a Workgroup and a Domain?

A Workgroup is a decentralized peer-to-peer setup where each PC manages itself, while a Domain is a centrally managed network controlled by a domain controller running Active Directory.

4. What is Active Directory?

Active Directory is Microsoft's centralized directory service that stores information about users, computers, and groups, allowing administrators to manage authentication and policies across an organization from one place.

5. What is a Group Policy Object (GPO)?

A GPO is a collection of configuration settings created by an admin and linked to a domain, site, or organizational unit, which automatically applies to all linked users or computers.

6. What is the difference between a Local Administrator and a Standard User account?

An Administrator account has full control to install software and change system settings, while a Standard User account can only run programs and change personal settings, without altering system-wide configuration.

7. What is BitLocker used for?

BitLocker encrypts an entire disk drive so that data remains unreadable to anyone without the correct recovery key or credentials, protecting data if a device is lost or stolen.

8. What is the purpose of Windows Update / Patch Management?

It delivers security patches, bug fixes, and feature updates to keep computers protected against known vulnerabilities, with patch management controlling how and when these are rolled out across an organization.

9. What are the different types of Windows desktop environments?

Workgroup, Domain (Active Directory), Azure AD/Entra (cloud-joined), Hybrid Join, and Standalone/Kiosk mode are the main types.

10. What is Imaging in the context of desktop deployment?

Imaging is the process of creating a standardized, pre-configured snapshot of a Windows installation that can be deployed to multiple new computers so every machine starts out identically configured.

9.2 Practical / Scenario-Based Interview Questions

1. A user's account keeps getting locked every morning. How would you investigate this?

I would check the Active Directory account lockout events to find the source of the failed login attempts — often a cached old password on a phone's email app or a mapped drive — and correct the credential at the source rather than only unlocking the account repeatedly.

2. You notice a Group Policy setting is not applying to a specific department's computers while it works everywhere else. What would you check?

I would verify the computer accounts are in the correct Organizational Unit that the GPO is linked to, check GPO security filtering and permissions, and run gpresult or gpupdate /force on an affected machine to confirm which policies are actually being applied.

3. How would you explain the difference between a Domain and a Workgroup to a small business owner with no technical background?

I'd explain that a Workgroup is like every employee keeping their own set of office keys and rules, while a Domain is like having one central office manager who issues keys and enforces the same rules for everyone, which makes managing many computers much easier as the business grows.

4. A department wants only IT staff to be able to install new software on office computers. How would you enforce this?

I would ensure regular employees use Standard User accounts instead of Administrator accounts, since Windows requires administrator rights to install most software, and then use Group Policy to further restrict software installation where needed.

5. A company is moving from fully on-premises Active Directory to a cloud-first setup. What Windows environment approach would you recommend during the transition?

I would recommend a Hybrid Join approach, keeping devices joined to the existing on-premises Active Directory while also registering them with Azure AD/Entra, allowing management through both systems during the gradual migration.