Courses Job Ready Program Fresher Trainings AI For Class 7 to 12 Corporate Training Placements Tutorials
Free Learning Resources

IT Tutorials & Interview Prep

Free guides, interview Q&As, and job responsibility breakdowns — curated by industry veterans to help you crack MNC interviews

247+
Tutorial Articles
17
Topic Categories
100%
Free to Read
← Back to Windows Administration

Windows Server & Active Directory Fundamentals

Windows Administration Last Updated: Sep 28, 2026

1. Introduction to Windows Server & Active Directory Fundamentals

1.1 What is Windows Server & Active Directory?

Windows Server is Microsoft's operating system built to run on servers instead of everyday desktops, providing the core infrastructure services — file sharing, authentication, networking, and application hosting — that an entire organization relies on. Active Directory (AD) is the identity and directory service that runs on top of Windows Server, storing information about every user, computer, and group in the organization so that logins, permissions, and policies can be managed centrally from one place instead of machine by machine.

Easy Hinglish Explanation:

Windows Server ek special operating system hai jo computers ko nahi, balki poori company ke network ko chalata hai — jaise ek control room jo sabko service deta hai. Active Directory us control room ka ‘register’ hai jisme company ke saare users aur computers ki entry hoti hai.

Day-to-Day Example:

When an employee types their username and password on any office computer and it logs them in correctly with access to their email and shared folders, that login is being verified by a Windows Server running Active Directory in the background.

1.2 Why do we need Windows Server & Active Directory?

A group of ordinary desktop computers, left on their own, cannot share one central login system, enforce the same security rules, or let an admin manage hundreds of machines from a single console. Windows Server and Active Directory solve this by giving an organization one authoritative place to create accounts, enforce password and security policies, and control exactly who can access what, across every computer in the network.

  • Provides one central identity store so a user logs in once and accesses everything they're allowed to.
  • Lets administrators enforce consistent security policies across thousands of computers at once.
  • Makes shared resources — files, printers, applications — available to the right people only.
  • Reduces the time needed to add, remove, or reconfigure user access as staff join or leave.
  • Provides a foundation for backup, monitoring, and disaster recovery at an organizational scale.

Day-to-Day Example:

Imagine a university with 5,000 student accounts and no central system — every lab computer would need its own separate login list, and revoking a graduated student's access would mean visiting every single machine. Active Directory lets the IT team disable that one account centrally, and access disappears everywhere at once.

1.3 How does Windows Server & Active Directory work?

Windows Server runs the Active Directory Domain Services (AD DS) role on a machine called a Domain Controller (DC), which holds the directory database of users, computers, and groups. When any computer or user needs to log in or access a resource, the request is checked against this central database rather than against information stored locally.

  • Step 1: A user turns on a domain-joined computer and enters their username and password.
  • Step 2: The request is sent to the nearest Domain Controller for verification.
  • Step 3: Active Directory checks the credentials and issues a security ticket (via Kerberos) confirming the user's identity.
  • Step 4: The system checks Group Policy and group memberships to work out what the user is allowed to do.
  • Step 5: Access is granted, the user's desktop and permissions load, and the session is logged for auditing.

1.4 When is Windows Server & Active Directory used?

Windows Server and Active Directory are set up once, during the initial build of an organization's network, and then remain in continuous operation for the organization's entire lifetime — verifying logins every second of every working day, while periodic tasks like patching, replication checks, and policy reviews happen on a regular schedule.

Day-to-Day Example:

The moment a company installs its first server and promotes it to a Domain Controller, Active Directory starts working immediately, verifying every single login from that day onward, right up until the server is eventually decommissioned years later.

1.5 Where is Windows Server & Active Directory used?

  • Corporate offices — centrally managing thousands of employee logins and shared resources.
  • Educational institutions — controlling access to labs, staff systems, and student portals.
  • Banks & government departments — enforcing strict, auditable security policies.
  • Hospitals — protecting access to patient-record and diagnostic systems.
  • Data centers — hosting file servers, web servers, and application servers for the business.
  • Hybrid/cloud environments — extending on-premises AD to the cloud via Azure AD Connect.

1.6 Who works with Windows Server & Active Directory?

Two broad groups interact with this environment. End users (employees, students, staff) simply log in and use the resources every day without needing to know how the directory is structured behind the scenes. System Administrators, Server Administrators, and Infrastructure/IT teams are responsible for installing server roles, configuring Active Directory, managing Group Policy, and keeping domain controllers healthy and secure.

Easy Hinglish Explanation:

Do tarah ke log hote hain — ek jo sirf apna login use karte hain (employees, students), aur doosre jo poora server aur Active Directory setup manage karte hain (system admin, server admin, IT infrastructure team).

Fig 1.1 — Layered View of Windows Server & Active Directory Administration

2. Functions of Windows Server & Active Directory Administration

Windows Server and Active Directory administration covers several core functions, each responsible for a specific part of keeping the organization's infrastructure running, secure, and accessible.

2.1 Server Roles & Role Management

This function covers installing and configuring specific server roles — such as AD DS, DNS, DHCP, File and Storage Services, or Web Server (IIS) — using Server Manager or PowerShell, and deciding which roles run on which physical or virtual servers for performance and resilience.

Day-to-Day Example:

When an IT team sets up one server to hand out IP addresses (DHCP) and a separate server to store shared department files, that division of responsibility is Server Roles & Role Management in action.

2.2 Active Directory Domain Services (AD DS) Management

This involves creating and organizing domains, Organizational Units (OUs), users, computers, and groups, and keeping the directory database consistent through replication across multiple domain controllers.

2.3 DNS & DHCP Management

Active Directory depends completely on DNS to let computers find domain controllers, so administrators configure and maintain DNS zones and records, while DHCP automatically assigns IP addresses and network settings to client computers as they join the network.

Easy Hinglish Explanation:

DNS ek 'phone book' ki tarah hai jo naam se server dhoondta hai, aur DHCP naye computers ko automatically ek IP address de deta hai — dono AD ke sahi kaam karne ke liye zaroori hain.

2.4 Group Policy Management

Using Group Policy Objects (GPOs), admins push consistent settings — password complexity, desktop restrictions, drive mappings, software deployment — to thousands of computers and users at once, instead of configuring each one manually.

2.5 Backup, Replication & Disaster Recovery

This covers scheduling regular backups of the Active Directory database and critical server data, monitoring replication health between domain controllers across sites, and planning recovery procedures in case a server or an entire site fails.

Day-to-Day Example:

When a company keeps a second Domain Controller in a different building specifically so that logins keep working even if the main office loses power, that redundancy is Backup, Replication & Disaster Recovery planning at work.

2.6 Security, Auditing & Compliance

This function protects the server environment through role-based access, firewall configuration, encryption, and regular patching, while also enabling audit logging so that login attempts, permission changes, and administrative actions can be reviewed for compliance.

3. Important Concepts & Technical Terms

This section covers the key terminology every student must understand clearly before performing real Windows Server and Active Directory administration tasks. Each term is explained with a simple example so the concept sticks.

Domain Controller (DC)

A Domain Controller is a Windows Server that has the Active Directory Domain Services role installed and holds a copy of the directory database, handling authentication and authorization requests for the entire domain.

 

Easy Hinglish Explanation:

Domain Controller ek server hai jiske paas company ke saare users aur computers ka data hota hai — yehi decide karta hai ki kaun login kar sakta hai aur kise kya access milega.

Day-to-Day Example:

Just as a school's main office keeps the master attendance register that every classroom teacher checks against, a Domain Controller keeps the master record every computer checks against before granting access.

Forest, Tree, Domain & Organizational Unit (OU)

A Domain is the basic administrative boundary in Active Directory; related domains sharing a common naming structure form a Tree, and one or more trees sharing the same schema and configuration form a Forest, which is the top-level security boundary. An Organizational Unit is a container inside a domain used to group users, computers, and groups for easier management and GPO application.

Easy Hinglish Explanation:

Forest sabse bada container hai, uske andar Trees aur Domains hote hain, aur har Domain ke andar OUs hoti hain jisme users aur computers ko groups mein organize kiya jaata hai — jaise ek company ke andar alag-alag departments.

FSMO Roles

Flexible Single Master Operation (FSMO) roles are five special responsibilities — Schema Master, Domain Naming Master, RID Master, PDC Emulator, and Infrastructure Master — that are held by specific domain controllers to prevent conflicting changes across the directory.

Easy Hinglish Explanation:

FSMO roles kuch special zimmedariyan hain jo sirf ek particular Domain Controller ko di jaati hain, taaki important changes (jaise naya domain add karna) sirf ek jagah se controlled tarike se ho.

Active Directory Replication

Replication is the automatic process by which changes made on one domain controller — a new user, a password reset, a policy update — are copied to every other domain controller in the domain, keeping the directory consistent everywhere.

Easy Hinglish Explanation:

Replication ka matlab hai ki agar ek Domain Controller par koi change hota hai, to woh change apne aap doosre saare Domain Controllers tak pahunch jaata hai.

Day-to-Day Example:

Just as updating one branch's records in a bank automatically syncs across all branches overnight, a change on one domain controller replicates out to every other domain controller in the domain.

Schema

The Schema is the blueprint of Active Directory — it defines every type of object (user, computer, group) and every attribute (name, email, phone number) that the directory is allowed to store.

Easy Hinglish Explanation:

Schema ek blueprint hai jo batata hai ki Active Directory mein kis tarah ka data store ho sakta hai — jaise ek form ka structure jo decide karta hai kaunse fields bhare jaa sakte hain.

Trust Relationship

A Trust is a configured relationship between two domains or forests that allows users in one domain to be authenticated and granted access to resources in the other, without needing a separate account in each.

Easy Hinglish Explanation:

Trust ka matlab hai ki ek domain doosre domain ke users par bharosa karta hai aur unhe apne resources access karne deta hai, bina alag account banaye.

Day-to-Day Example:

Just as two partner colleges might accept each other's student ID cards for library access, two trusting domains accept each other's user credentials for resource access.

DNS in an Active Directory Environment

Domain Name System (DNS) translates human-readable names into IP addresses, and Active Directory uses it specifically to let client computers locate domain controllers and services by name rather than a fixed address.

Easy Hinglish Explanation:

DNS naam ko address mein badalta hai — AD environment mein isi ki madad se computer sahi Domain Controller ko dhoondh paata hai.

DHCP (Dynamic Host Configuration Protocol)

DHCP is a server role that automatically assigns IP addresses, subnet masks, and other network configuration to client devices as they connect to the network, removing the need to configure each device manually.

Easy Hinglish Explanation:

DHCP naye computers ko network join karte hi automatically ek IP address de deta hai, taaki manually configure na karna pade.

Sites and Subnets

An Active Directory Site represents a physical location (like an office or a data center) mapped to one or more IP subnets, allowing Active Directory to control replication traffic efficiently and direct users to the nearest domain controller.

Easy Hinglish Explanation:

Sites AD ko batate hain ki company ke alag-alag offices kahan hain, taaki users apne sabse nazdeeki Domain Controller se hi connect ho, na ki kisi door waale server se.

Global Catalog

The Global Catalog is a special, partial copy of directory information from every domain in a forest, stored on designated domain controllers, allowing fast searches across the entire forest without contacting every domain individually.

Easy Hinglish Explanation:

Global Catalog ek 'summary book' ki tarah hai jisme poore forest ki thodi-thodi jaankari hoti hai, taaki search fast ho sake.

Kerberos Authentication

Kerberos is the default authentication protocol used by Active Directory, which issues encrypted tickets to verified users so they can access multiple resources without repeatedly typing their password.

Easy Hinglish Explanation:

Kerberos ek security protocol hai jo login ke baad ek 'ticket' deta hai, taaki user baar-baar password na daale aur phir bhi secure rahe.

Day-to-Day Example:

Just as an amusement park wristband lets you re-enter rides all day without buying a new ticket each time, a Kerberos ticket lets a logged-in user access multiple resources without re-entering their password.

LDAP (Lightweight Directory Access Protocol)

LDAP is the standard protocol applications and administrators use to query and modify information stored in Active Directory, such as looking up a user's email address or group membership.

Easy Hinglish Explanation:

LDAP ek tarika hai jisse applications Active Directory se data maang sakti hain ya update kar sakti hain, jaise kisi user ki email dhoondhna.

Server Core vs Desktop Experience

Server Core is a minimal Windows Server installation without a graphical desktop, managed mainly through PowerShell or remote tools, while Desktop Experience installs the full graphical interface familiar from desktop Windows, at the cost of a larger footprint and more updates.

Easy Hinglish Explanation:

Server Core mein graphical screen nahi hoti, sirf command line se manage karte hain — halka aur zyada secure. Desktop Experience mein normal Windows jaisi screen hoti hai, jo use karne mein aasan hai lekin thoda bhaari.

Failover Clustering

Failover Clustering groups multiple servers together so that if one server fails, another server in the cluster automatically takes over its workload, minimizing downtime for critical services.

Easy Hinglish Explanation:

Failover Clustering matlab kai servers ek team ki tarah kaam karte hain — agar ek fail ho jaaye, doosra turant uska kaam sambhal leta hai, taaki service band na ho.

Day-to-Day Example:

Just as a relay race has a backup runner ready to take the baton if the lead runner trips, a failover cluster has a standby server ready to take over instantly if the active server goes down.

4. Domain Controller Promotion Process — Step by Step

Promoting a Windows Server to a Domain Controller is one of the most fundamental tasks in building an Active Directory environment, turning a standalone server into the authority for authentication and directory services. Understanding this process helps in troubleshooting installation and replication issues later.

  • Step 1 — Prepare the Server: Install Windows Server, assign it a static IP address, and point its DNS setting to an existing domain controller (or itself, for the first DC in a new forest).
  • Step 2 — Install the AD DS Role: Use Server Manager or PowerShell (Install-WindowsFeature AD-Domain-Services) to add the Active Directory Domain Services role.
  • Step 3 — Launch the Configuration Wizard: After the role installs, run the Active Directory Domain Services Configuration Wizard to begin promotion.
  • Step 4 — Choose the Deployment Type: Select whether to create a new forest, add a new domain to an existing forest, or add this server as an additional domain controller to an existing domain.
  • Step 5 — Set the DSRM Password: Provide a Directory Services Restore Mode (DSRM) password, used only for special recovery scenarios.
  • Step 6 — Review DNS, NetBIOS Name & Paths: Confirm DNS delegation options, the NetBIOS domain name, and the database, log, and SYSVOL folder locations, then let the wizard check prerequisites.
  • Step 7 — Install & Restart: The wizard installs Active Directory Domain Services, and the server restarts to complete its promotion to a fully functioning Domain Controller.

Easy Hinglish Explanation:

Domain Controller banane ka matlab hai ek normal server ko 'boss server' bana dena jo poore network ke logins aur security ko control karega — is process ke baad woh server company ka central directory system ban jaata hai.

Fig 4.1 — Step-by-step Domain Controller Promotion Process

5. AD Object (User / Computer Account) Life Cycle

A user or computer account in Active Directory, once created, moves through a series of well-defined states over its working life, managed by the administrator through Active Directory Users and Computers or PowerShell. Understanding these states is crucial for handling onboarding, temporary access issues, and offboarding correctly.

StateDescription
New / CreatedThe account is created by the admin with a name, initial password or attributes, and assigned to the correct OU and groups.
Active / EnabledThe account is fully usable — the user or computer can authenticate and access resources according to its permissions.
LockedThe account is temporarily blocked, usually after too many failed login attempts, until unlocked by an admin or an automatic timeout.
DisabledThe admin has intentionally turned the account off (e.g., employee on long leave) without deleting it, so it can be re-enabled later.
Deleted / TombstonedThe account is removed when the user leaves or the computer is retired; Active Directory keeps a tombstoned record for a retention period before final removal.

 

Day-to-Day Example:

Think of a gym membership. 'New' is when you first sign up; 'Active' is when your card lets you into the gym; 'Locked' is when it's temporarily frozen after a payment mismatch; 'Disabled' is when you pause your membership while travelling; and 'Deleted' is when you formally cancel it for good.

Fig 5.1 — AD User / Computer Account Life Cycle

6. Types of Active Directory Deployment Environments

Active Directory environments are structured differently depending on the size of the organization, its security needs, and whether identity is managed on-premises, in the cloud, or both. Below is a look at the major deployment types administrators work with.

Fig 6.1 — Major Types of Active Directory Deployment Environments

TypeDefinition & Use CaseSimple Example
Single Domain ForestOne domain acting as the entire forest — the simplest and most common design for small to mid-sized organizations.A regional company with one head office
Multi-Domain ForestSeveral domains under one forest, often split by geography or business unit while still sharing a common schema.A national company with domains per region
Multi-Forest (with Trusts)Two or more separate forests connected by trust relationships so users in one can access resources in another.Two merged companies keeping separate IT
Hybrid (AD + Azure AD Connect)On-premises Active Directory synchronized with Azure AD/Entra ID so identities work across both local and cloud services.A company using both office logins and Microsoft 365
RODC / Branch Office DeploymentA Read-Only Domain Controller placed at a branch site, providing local authentication without holding a fully writable copy of the directory.A small branch office with limited physical security

7. Important Difference / Comparison Tables

Comparison-based questions are very common in exams and interviews. These tables summarize the most important distinctions students must remember clearly.

7.1 Domain Controller vs Member Server

BasisDomain ControllerMember Server
RoleHolds the AD DS database and handles authentication.Joined to the domain but runs other roles (file, web, app).
Directory DataStores and replicates the full (or partial) directory.Does not store directory data.
AuthenticationActively verifies logins for the domain.Relies on a domain controller to verify logins.
Typical CountUsually 2 or more, for redundancy.As many as the organization's workloads require.

7.2 On-Premises AD DS vs Azure AD / Entra ID

BasisOn-Premises AD DSAzure AD / Entra ID
LocationRuns on servers inside the organization's own network.Runs as a cloud identity service managed by Microsoft.
Authentication ProtocolPrimarily Kerberos and NTLM.Primarily OAuth, SAML, and OpenID Connect.
Management ToolActive Directory Users and Computers, Group Policy.Microsoft Entra admin center, Intune/Conditional Access.
Best Suited ForTraditional on-premises networks and legacy apps.Cloud-first organizations and SaaS applications.

7.3 Server Core vs Desktop Experience

BasisServer CoreDesktop Experience
InterfaceCommand line / PowerShell only, no GUI shell.Full graphical desktop, like client Windows.
Resource UsageLower disk, memory, and patching footprint.Higher resource usage due to GUI components.
Attack SurfaceSmaller — fewer components to exploit.Larger — more components running by default.
Typical UseDomain controllers, core infrastructure roles.Roles needing GUI-based tools or third-party apps.

7.4 FSMO Roles Overview

FSMO RoleScopePrimary Purpose
Schema MasterForest-wide (one per forest)Controls updates to the Active Directory schema.
Domain Naming MasterForest-wide (one per forest)Manages adding or removing domains in the forest.
RID MasterDomain-wide (one per domain)Allocates blocks of unique security IDs to each DC.
PDC EmulatorDomain-wide (one per domain)Handles time sync, password changes, and legacy compatibility.
Infrastructure MasterDomain-wide (one per domain)Keeps cross-domain object references up to date.

7.5 Windows Server 2019 vs Windows Server 2022

BasisWindows Server 2019Windows Server 2022
Security BaselineTLS 1.2 standard, Windows Defender ATP.Secured-core server support, TLS 1.3, stronger defaults.
Hybrid CloudBasic Azure integration via Windows Admin Center.Deeper Azure Arc integration for hybrid management.
NetworkingStandard SMB and networking stack.SMB over QUIC and improved networking performance.
Support FocusWidely deployed, strong legacy app compatibility.Newer hardware, tighter default security posture.

Easy Hinglish Explanation:

Windows Server 2019 aur 2022 dono ko admin lagbhag same tareeke se manage karte hain, lekin 2022 mein security by default zyada strong hai aur cloud (Azure) ke saath integration bhi behtar hai.

8. Scenario-Based Questions (Practice)

These questions test your practical understanding of the concepts covered above. Try answering them yourself first, then check the given answer and reasoning.

Q1. A new server is promoted as a Domain Controller, but users report that logins are inconsistent depending on which office they connect from. What should be checked first?

Answer: Active Directory Sites and Subnets configuration, and replication health between domain controllers.

Why / Reason: If sites and subnets are not configured correctly, users may be authenticated by a distant domain controller instead of the nearest one, or replication delays may mean different DCs briefly hold different data.

Q2. An administrator wants to apply a stricter password policy only to the Finance department's user accounts, not the whole company. What is the right approach?

Answer: Create a Fine-Grained Password Policy (or a GPO linked to the Finance department's Organizational Unit) rather than changing the domain-wide default policy.

Why / Reason: The default domain password policy applies to everyone in the domain; targeted policies need either fine-grained password policies or a GPO scoped to the specific OU containing the Finance accounts.

Q3. A company's only Domain Controller fails unexpectedly, and no user can log in anywhere in the office. What design flaw does this reveal?

Answer: The organization lacked a second Domain Controller for redundancy.

Why / Reason: With only one DC, authentication has a single point of failure; deploying at least two domain controllers with replication ensures logins continue even if one server goes down.

Q4. An admin needs to check which server currently holds the PDC Emulator role during a troubleshooting task. Which type of role are they looking for?

Answer: An FSMO (Flexible Single Master Operation) role.

Why / Reason: PDC Emulator is one of the five FSMO roles; identifying its current holder (via Active Directory Users and Computers or PowerShell) is a common step in resolving time-sync or password-related issues.

Q5. A branch office has poor, unreliable connectivity to the main data center, but still needs fast local logins without holding a fully writable copy of company-wide directory data. What should be deployed there?

Answer: A Read-Only Domain Controller (RODC).

Why / Reason: An RODC provides local authentication and reduces the security exposure of placing a fully writable DC in a less secure location, which fits a branch office with limited physical security and unreliable links.

Q6. A company migrating gradually to Microsoft 365 wants existing on-premises accounts to also work for cloud services during the transition. What should be configured?

Answer: Azure AD Connect to synchronize identities between on-premises Active Directory and Azure AD/Entra ID (a Hybrid Join setup).

Why / Reason: Azure AD Connect keeps on-premises and cloud identities in sync, letting users authenticate consistently across both environments during a gradual migration.

Q7. Two companies have merged but want to keep their existing, separate Active Directory forests while still letting employees access some shared resources across both. What should be configured?

Answer: A Trust Relationship between the two forests.

Why / Reason: A forest trust allows authenticated users from one forest to access permitted resources in another, without merging the two directories or duplicating every account.

Q8. An organization wants domain controllers to run with the smallest possible attack surface and the least maintenance overhead. What installation option should be chosen?

Answer: Server Core installation of Windows Server.

Why / Reason: Server Core omits the graphical shell and many optional components, reducing the number of things that need patching and the surface available for attackers to exploit.

9.1 Basic Interview Questions

1. What is Windows Server?

Windows Server is Microsoft's server operating system, designed to provide centralized infrastructure services like authentication, file sharing, networking, and application hosting to an organization.

2. What is Active Directory?

Active Directory is Microsoft's directory service that stores information about users, computers, and groups, allowing administrators to manage authentication and policies for an organization from one central place.

3. What is a Domain Controller?

A Domain Controller is a server running Active Directory Domain Services that stores the directory database and handles authentication and authorization for a domain.

4. What is the difference between a Forest, a Tree, and a Domain?

A Domain is the basic administrative unit, related domains sharing a naming structure form a Tree, and one or more trees sharing a schema form a Forest, the top-level security boundary.

5. What are FSMO roles?

FSMO roles are five special responsibilities — Schema Master, Domain Naming Master, RID Master, PDC Emulator, and Infrastructure Master — held by specific domain controllers to avoid conflicting directory changes.

6. What is a Group Policy Object (GPO)?

A GPO is a collection of configuration settings created by an admin and linked to a domain, site, or organizational unit, which automatically applies to all linked users or computers.

7. What is the purpose of DNS in an Active Directory environment?

DNS lets client computers locate domain controllers and services by name, which Active Directory depends on for logins and replication to function correctly.

8. What is the difference between Server Core and Desktop Experience?

Server Core is a minimal installation managed via command line with no graphical shell, while Desktop Experience includes the full graphical interface, at the cost of a larger footprint.

9. What is Active Directory replication?

Replication is the automatic process of copying directory changes made on one domain controller to every other domain controller, keeping the directory consistent across the domain.

10. What is a Read-Only Domain Controller (RODC)?

An RODC is a domain controller that holds a read-only copy of the Active Directory database, typically deployed at branch offices with limited physical security.

9.2 Practical / Scenario-Based Interview Questions

1. Users in one office report slow logins compared to another office. How would you investigate?

I would check whether that office has its own local domain controller and whether Active Directory Sites and Subnets are configured correctly, since misconfigured sites can send login requests to a distant DC over a slow link.

2. You need to give the helpdesk team the ability to reset passwords, but nothing else. How would you set this up?

I would delegate control at the appropriate Organizational Unit using the Delegation of Control Wizard, granting only the 'Reset Password' permission instead of making them full domain admins.

3. A GPO applied at the domain level is not affecting one specific department's computers. What would you check?

I would verify the department's computer accounts are in the correct OU the GPO is linked to, check for a blocked inheritance setting or a conflicting GPO with higher precedence, and run gpresult to confirm which policies are actually applying.

4. How would you explain the difference between an on-premises AD and Azure AD to a manager with no technical background?

I'd explain that on-premises AD is like a private office ledger the company keeps and controls itself, while Azure AD is like a ledger stored and maintained by Microsoft in the cloud, which is easier to access from anywhere but managed differently.

5. A company wants to reduce the risk of a single domain controller failure taking down all logins. What would you recommend?

I would recommend deploying at least two domain controllers in different physical locations or racks, with healthy replication between them, so authentication continues even if one server or site goes offline.