70-742 Identity with Windows Server 2016 Exam Guide
Exam 70-742, titled “Identity with Windows Server 2016,” validated identity-management skills built around Windows Server 2016, especially Active Directory Domain Services and Group Policy. Microsoft described the intended candidate as someone experienced with Windows Server who manages identities with that platform. The exam is retired, so the key decision is not how to schedule it, but whether its objectives are useful as a skills checklist while you select a current Microsoft credential or plan Windows Server study.
Should you still prepare for 70-742?
No. 70-742 is a retired Microsoft exam and cannot be treated as a currently schedulable certification target. Use its published objectives for historical Windows Server identity study, migration planning, or interview preparation, but verify an active credential before investing in exam-specific preparation.
Microsoft’s retirement guidance states that candidates cannot take a retired exam or earn the associated certification or credential after retirement. Previously earned credentials remain on the candidate’s Microsoft Learn transcript. A Microsoft Q&A response also identifies the 70-740, 70-741, and 70-742 exams as retired.
This changes the preparation decision. If your employer specifically asks for MCSA: Windows Server 2016 or 70-742, confirm whether the request means practical Windows Server identity experience, a historical transcript entry, or a current certification. Those are different outcomes. A retired exam guide can help with the first, but it cannot create a new exam result.
Microsoft has explained that its certification portfolio shifted toward role-based credentials and that training content for retired areas may remain available. The official replacement discussions do not establish an exact replacement for 70-742, so do not label a current Azure or Windows Server credential as a one-to-one substitute without checking its live objectives.
A sensible next action
Open Microsoft’s current certification catalogue and compare active credentials with the work you want to perform. The available evidence does not establish a direct replacement for 70-742. Treat any replacement as a career-alignment choice rather than an automatic continuation of the old exam.
Who was 70-742 designed for?
The exam served Windows Server professionals who managed identities with Windows Server 2016 functionality. It was not presented as a general introduction to Windows administration; Microsoft’s preparation session specifically targeted people experienced with Windows Server who were considering 70-742 or 70-743.
The published audience profile included familiarity with Active Directory Certificate Services, Active Directory Federation Services, Active Directory Rights Management Services, and Web Application Proxy. That profile suggests a candidate working across identity services rather than only creating user accounts in a small domain.
For modern preparation, use this audience description as a readiness test. You should be able to explain how an identity requirement maps to a directory object, policy, authentication service, certificate service, federation component, or application proxy. If those relationships are unfamiliar, begin with Windows Server identity fundamentals instead of memorizing objective labels.
A useful distinction is operational depth. An administrator may know how to create a user through a console but still struggle to diagnose delegation, replication, policy inheritance, or authentication flow. The 70-742 scope was better suited to candidates who could connect configuration choices with the behavior of a Windows Server identity environment.
What skills did the outline measure?
The outline centered on installing, configuring, managing, and maintaining Active Directory Domain Services, together with implementing Group Policy Objects. It also expected awareness of adjacent identity technologies and included both graphical administration and Windows PowerShell automation.
The official objective-change document identifies “Install and Configure Active Directory Domain Services (AD DS)” as 20–25% of the exam objectives. Keep the domain label attached to that percentage: it describes the AD DS installation and configuration domain, not the exam as a whole and not a general pass threshold.
Within the AD DS installation and configuration domain, the listed tasks included installing new forests, adding or removing domain controllers, upgrading domain controllers, configuring global catalog servers, transferring or seizing operations-master roles, and configuring read-only domain controllers.
The outline also covered creating and managing Active Directory users, computers, groups, and organizational units, including automation with Windows PowerShell. These are connected tasks: object placement affects policy scope, group membership affects authorization, and automation affects repeatability and administrative control.
Group Policy Objects formed another central area. Prepare to reason about how policy is implemented and managed, not simply recognize the acronym. A useful exercise is to start with a requirement, identify the appropriate policy location, determine which computers or users receive it, and then verify the resulting configuration.
The adjacent technologies matter because identity decisions often cross service boundaries. AD CS concerns certificate services, AD FS concerns federation, AD RMS concerns rights management, and Web Application Proxy concerns access to applications. Study their roles and relationships without assuming that a single service solves every authentication or authorization requirement.
How should you turn the objectives into lab work?
Build a small, repeatable Windows Server identity lab and use each objective to generate a configuration task, a verification task, and a recovery question. This approach is a practical recommendation, not an official exam requirement, and it is more useful than reading objective names without testing the underlying behavior.
Begin with a documented domain design. Record the intended forest, domain, site, domain controllers, DNS dependencies, global catalog placement, and administrative boundaries. Then install a new forest and write down what changed at each stage. The goal is to understand prerequisites and sequencing, not to reproduce an undocumented click path.
Add and remove a domain controller in a controlled exercise. Before making the change, identify what services and directory roles it holds. Afterward, verify directory health, name resolution, replication-related behavior, and client access. A removal exercise should include a clear distinction between a planned demotion and a failure scenario; do not treat forced removal as the normal procedure.
Practice operations-master role management as a decision exercise. Identify the role holder, explain why a transfer is appropriate, and separately explain when seizure would be considered. Record the operational consequences and the checks you would perform after the change. This turns terminology into an administrative judgment.
Configure a global catalog server and a read-only domain controller in scenarios that explain why each exists. For the global catalog, focus on directory search and forest-wide identity needs. For the read-only domain controller, focus on constrained deployment and the security or location assumptions that make it appropriate.
Create users, computers, groups, and organizational units using both administrative tools and PowerShell. Use a naming convention, document the intended OU structure, and repeat the same operation safely. Then test what happens when an object is placed in the wrong OU or receives an unintended group membership.
Finish each lab with verification. Ask which account can perform the action, which object or service should show the result, how a client would experience the change, and what evidence would distinguish a configuration error from a connectivity or replication problem.
A practical lab record
For every exercise, keep four notes: the requirement, the change, the verification method, and the rollback or recovery step. This record exposes gaps quickly. If you can perform a task but cannot verify its outcome or explain recovery, the topic is not yet ready for confident technical discussion.
What study order reduces wasted effort?
Study directory foundations before policy and specialty services. A reliable sequence is domain and forest structure, domain-controller operations, directory objects, Group Policy, PowerShell automation, and then the surrounding identity services. This order follows the dependencies between the topics and is a recommended learning plan rather than a published exam sequence.
First, establish the vocabulary and architecture of AD DS. Learn how forests, domains, domain controllers, global catalogs, sites, users, computers, groups, and organizational units relate to one another. Without this model, later troubleshooting becomes a list of isolated procedures.
Next, work through domain-controller lifecycle operations. Install a forest, add a controller, consider upgrades, configure global catalog behavior, manage operations-master roles, and explore read-only domain controllers. Keep a change log so that each operation has a stated purpose and a validation step.
Then move to directory administration. Create and manage users, computers, groups, and OUs. Compare individual administration with scripted administration. For every object type, identify ownership, naming, placement, permissions, and the effect of group membership or OU location.
After that, study Group Policy through inheritance and scope. Create a policy requirement, decide where it belongs, predict who or what should receive it, and validate the result. Include a deliberate conflict or misplacement in the lab so you learn to trace unexpected settings rather than merely configure expected ones.
Use PowerShell throughout the directory portion, not as a last-minute topic. Script a small set of repeatable tasks, inspect objects, and make the script safe to rerun. Explain each command in terms of the directory change it causes and the evidence you would use to confirm success.
Reserve the final study block for AD CS, AD FS, AD RMS, and Web Application Proxy. Map each service to its identity purpose and dependencies. The audience profile explicitly names these technologies, but the supplied evidence does not provide detailed objective weights for each one, so avoid assigning them unsupported priority percentages.
How can you tell whether your preparation is strong enough?
Use explanation and troubleshooting as readiness measures. You are in better shape when you can select a design, carry out the change, verify it, and diagnose an unexpected result without relying on memorized answer patterns. Because the exam is retired, this self-check is more valuable than chasing an exam-style score.
Create scenario prompts from the official domains. For example, ask how you would add a domain controller, place a global catalog, manage an operations-master role, structure OUs, automate account creation, or implement a Group Policy requirement. Answer from a blank page before opening your notes.
For each answer, include four elements: the requirement, the relevant Windows Server identity component, the implementation sequence, and the verification evidence. If you can name only a tool or command, your understanding may be procedural but incomplete.
Use failure scenarios rather than only successful builds. Consider an unavailable domain controller, an object in the wrong OU, an unexpected group membership, a policy applied outside its intended scope, or an identity service with an unmet dependency. The point is to practice diagnosis, not to predict questions.
Review your notes against the published outline after every lab cycle. Mark each objective as demonstrated, explained, or still uncertain. Do not convert the 20–25% figure for the “Install and Configure Active Directory Domain Services (AD DS)” domain into a claim about how many questions appear; the supplied source does not provide question counts.
What mistakes should you avoid?
The biggest mistake is preparing as though 70-742 were still available. Confirm exam status first, then decide whether your goal is historical knowledge, job capability, transcript verification, or a current credential. A large study investment makes sense only when it supports one of those clearly stated outcomes.
Do not assume that a current Microsoft certification is an exact replacement. Microsoft Q&A material says there is no exact replacement for the retired exam, while directing candidates toward current certification options. Compare current objectives and role coverage instead of relying on similar product names.
Do not study AD DS as a collection of console clicks. A candidate who can create an account but cannot explain OU placement, group membership, role ownership, directory-service dependencies, or verification has not developed a durable administrative model.
Do not leave PowerShell until the end. The outline explicitly included automation with Windows PowerShell for Active Directory users, computers, groups, and organizational units. Practice readable, repeatable commands and understand the objects they modify.
Do not treat adjacent services as interchangeable. AD CS, AD FS, AD RMS, and Web Application Proxy address different identity-related purposes. Build a comparison table with each service’s role, dependencies, and the type of access or protection it supports.
Do not use dumps, leaked material, or memorized answer sets as a substitute for knowledge. They are especially unsuitable for a retired exam because they cannot solve the scheduling problem and may teach obsolete, inaccurate, or context-free procedures. Use the official outline to create your own lab and explanation exercises instead.
Finally, do not claim readiness from familiarity with terminology alone. Require yourself to demonstrate a change and explain how you would prove that it worked. That standard is useful whether you pursue a current credential or simply need to manage a Windows Server identity environment.
What is the most useful four-stage roadmap?
A four-stage roadmap keeps the retired exam’s content useful without pretending that an exam appointment is available. Stage one establishes the architecture, stage two builds operational fluency, stage three tests troubleshooting and automation, and stage four redirects the result toward a current professional objective.
Stage one: clarify the destination. Decide whether you need Windows Server identity competence, evidence of historical certification, or a current Microsoft credential. Check the official retirement guidance and current catalogue before choosing resources. If a manager or recruiter named 70-742, ask what outcome they actually require.
Stage two: build the core lab. Document a forest and domain design, install AD DS, add a domain controller, work with global catalog configuration, explore operations-master role transfer and seizure concepts, and examine read-only domain-controller use. Keep the environment isolated and record both successful and failed procedures.
Stage three: administer and automate. Create users, computers, groups, and OUs. Apply and troubleshoot Group Policy. Repeat selected tasks with PowerShell. Add scenario prompts involving permissions, placement, unintended policy scope, and unavailable infrastructure. Review the official domain list and close gaps through another lab cycle.
Stage four: consolidate and redirect. Produce a short technical portfolio containing your design notes, PowerShell examples, verification checks, and troubleshooting decisions. Then compare those demonstrated skills with an active certification or training path. The supplied evidence does not name a current one-to-one successor, so make that selection based on your intended role and Microsoft’s live requirements.
Your immediate checklist is straightforward: confirm that 70-742 is retired, save the official objective document, list the AD DS and Group Policy tasks you can perform, identify the four named adjacent technologies you need to review, build or access a practice lab, and inspect current Microsoft credentials before booking anything.
What should you verify with Microsoft before making a credential decision?
Verify exam availability, current credential requirements, and any scheduling or accommodation question through Microsoft’s current credentials resources rather than an archived page or third-party listing. The supplied support page identifies separate routes for certification support, exam appointment issues, delivery-partner issues, and language or accommodation requests.
For a retired-exam question, begin with the retirement policy and the official exam-availability or credentials-support channels. Microsoft’s support material says that previously earned credentials remain on a Learn profile transcript, while retired exams cannot be taken to earn the associated credential.
If language support or an accommodation matters for a current exam, check the current support instructions for that selected exam. The supplied support information discusses extra time in specific circumstances, but it does not establish delivery details for retired 70-742, so do not transfer those arrangements to this exam.
Keep your Microsoft Learn profile information accurate if you are pursuing a current credential. The supplied support guidance directs candidates to log in to the intended Learn Profile and update legal-name information through profile settings. This is an administrative preparation step for a live credential, not a way to reactivate 70-742.
Conclusion
70-742 remains a useful historical map of Windows Server 2016 identity administration, particularly AD DS, Group Policy, directory-object management, PowerShell automation, and related identity services. It is not a current exam target. Use the official outline to structure hands-on learning, test your ability to explain and verify changes, and then choose a live Microsoft credential only after comparing its current objectives with your intended role. That sequence protects your study time and keeps the decision grounded in what you can actually demonstrate.