Why Study with PlanetCert?
The Latest Questions
Practice questions and exam topics aligned with the current exam objectives.
Detailed Explanations
Go beyond the answer. Master the material with comprehensive learning and professional explanations for every concept.

AI-Powered Insights
Personalized preparation guidance that adapts to your performance and identifies weak spots automatically.
Exam Information
Official specifications published by Microsoft
Exam Format
Registration
Validity
70-744 Exam Topics and Domains
70-744 is organized into 6 weighted domains. Expect to work with Group Policy, PowerShell, Active Directory, Hyper-V, and more.
Implement Server Hardening Solutions
Configure disk and file encryption
- Deploy and manage BitLocker Drive Encryption in various scenarios
- Configure disk and file-level encryption
- Implement recovery procedures for encrypted data
- Determine appropriate encryption solutions for different use cases
Implement server patching and updating solutions
- Deploy and configure Windows Server Update Services
- Manage update approvals and deployments
- Troubleshoot update delivery issues
Implement malware protection
- Implement comprehensive malware protection using Windows Defender
- Configure application whitelisting with AppLocker
- Deploy Code Integrity and Control Flow Guard policies
Protect credentials
- Deploy and configure Credential Guard for credential protection
- Implement NTLM blocking to enforce stronger authentication
Create security baselines
- Create and manage security baselines using Microsoft Security Compliance Toolkit
- Deploy security configurations to various server types
Secure a Virtualization Infrastructure
Implement a Guarded Fabric solution
- Deploy and configure Host Guardian Service
- Implement both Admin-trusted and TPM-trusted attestation
- Manage and troubleshoot guarded hosts
Implement Shielded and encryption-supported VMs
- Create and configure Shielded VMs
- Implement encryption-supported VMs
- Troubleshoot virtualization security issues
Secure a Network Infrastructure
Configure Windows Firewall
- Configure Windows Firewall with Advanced Security
- Create and manage firewall rules using multiple methods
- Implement authenticated firewall exceptions
Implement Software Defined Datacenter Firewall
- Implement Software Defined Networking firewall solutions
- Configure datacenter-level access controls
Secure network traffic
- Implement IPsec for network traffic protection
- Secure SMB and DNS protocols
- Analyze network traffic for security threats
Manage Privileged Identities
Implement Enhanced Security Administrative Environment (ESAE)
- Design Enhanced Security Administrative Environment architectures
- Implement clean source principals for privileged access
Implement Just-In-Time (JIT) Administration
- Deploy Microsoft Identity Manager for Privileged Access Management
- Configure and manage time-based privileged access
- Implement request and approval workflows
Implement Just-Enough-Administration (JEA)
- Implement Just-Enough-Administration endpoints
- Create session configuration and role capability files
- Deploy JEA using Desired State Configuration
Implement Privileged Access Workstations (PAWs)
- Deploy Privileged Access Workstations
- Configure security policies for administrative access
- Enable Remote Credential Guard for secure remote administration
Implement Local Administrator Password Solution (LAPS)
- Install and configure Local Administrator Password Solution
- Manage local administrator passwords at scale
- Implement secure password retrieval processes
Implement Threat Detection Solutions
Configure advanced audit policies
- Implement advanced audit policies for security monitoring
- Configure PowerShell logging for threat detection
- Use multiple methods to deploy audit configurations
Install and configure Microsoft Advanced Threat Analytics (ATA)
- Deploy Microsoft Advanced Threat Analytics
- Configure threat detection and alerting
- Investigate and respond to security threats
Determine threat detection solutions using Operations Management Suite (OMS)
- Determine appropriate OMS deployment scenarios
- Implement security and auditing with OMS
- Utilize Log Analytics for threat detection
Implement Workload-Specific Security
Secure application development and server workload infrastructure
- Deploy and secure Nano Server workloads
- Implement Windows Server and Hyper-V containers
- Apply security policies to specialized workloads
Implement secure file services infrastructure and Dynamic Access Control (DAC)
- Deploy and configure File Server Resource Manager
- Implement Dynamic Access Control for claim-based permissions
- Configure Work Folders for secure file synchronization
- Implement file access auditing for compliance
How do I earn this certification?
Passing 70-744 earns the MCSE: Core Infrastructure certification. It sits in the Windows Server Infrastructure track.
- 70-743 - Upgrading Your Skills to MCSA: Windows Server 2016
- 70-413 - Designing and Implementing a Server Infrastructure
- 70-414 - Implementing an Advanced Server Infrastructure
- 70-537 - Configuring and Operating a Hybrid Cloud with Microsoft Azure Stack
- AZ-500 - Microsoft Azure Security TechnologiesModern cloud-focused security certification for professionals transitioning from on-premises Windows Server security
- SC-200 - Microsoft Security Operations AnalystSecurity monitoring and threat detection focus, complementary to infrastructure security
- SC-300 - Microsoft Identity and Access AdministratorIdentity and privileged access management, aligns with 70-744 content on JIT, JEA, and PAM
- AZ-140 - Configuring and Operating Microsoft Azure Virtual DesktopFor professionals managing secure virtual desktop environments
Practice with Precision
The PlanetCert Simulator mirrors the real exam environment with authentic questions and timed pressure.
How to study for this exam?
The most effective way to prepare for 70-744 is by using the PlanetCert Simulator to practice questions and review detailed explanations.
What's changed on this exam?
- RETIRED
- Last content update: 2017-11-03
- Announcement date: 2020-06-30
- BitLocker Windows Server 2025 Concepts from 70-744 remain foundational but implementation has evolved • Release date: 2024-11-01
- Guarded Fabric / Shielded VMs Windows Server 2025 Technology remains relevant for high-security Hyper-V environments • Release date: 2024-11-01
- Advanced Threat Analytics (ATA) ATA deprecated, replaced by cloud-native Defender for Identity
- Operations Management Suite (OMS) OMS evolved into Azure Monitor and Microsoft Sentinel
Who should take this exam?
- 3+ years of experience with Windows Server administration
- Strong understanding of Active Directory
- Experience with Windows Server security features
- Knowledge of networking and virtualization
- Familiarity with PowerShell scripting