70-742 Identity with Windows Server 2016: Status, Skills, and a Practical Study Plan
Exam 70-742, Identity with Windows Server 2016, validated identity-management knowledge for administrators working with Windows Server 2016, particularly Active Directory Domain Services and Group Policy. It was intended for people already experienced with Windows Server rather than beginners seeking a current entry point. The key decision is now straightforward: use the published objectives to build or refresh legacy Windows Server identity skills, but do not plan an exam appointment or pursue it as a new credential because the exam is retired.
Can you still take 70-742?
No. Microsoft retired the remaining exams associated with MCSA, MCSD, and MCSE certifications on January 31, 2021, which includes the MCSA: Windows Server 2016 path to which 70-742 belonged.
Microsoft’s retirement policy is clear about the practical consequence: after an exam retires, candidates cannot take that exam or earn its associated certification or credential. That makes old registration pages, reseller listings, sample score reports, and claims of available appointments poor grounds for a scheduling decision. Do not spend preparation money on the assumption that an exception, a remote delivery option, or a legacy test center can make 70-742 available.
The retirement does not erase a credential earned before retirement. Microsoft states that certifications already earned remain on the Microsoft Learn profile transcript. That distinction matters for employers and managers reviewing an existing record: a historical certification can still be listed accurately with its earned date and retired status, but it is not a certification a new candidate can obtain now.
Treat 70-742 study as technical development or as support for an environment that still uses the relevant Windows Server identity components. If your objective is a current Microsoft credential, start by identifying the job role and platform skills your employer needs, then review Microsoft’s active role-based certification options rather than looking for a booking route for this retired exam.
What did 70-742 validate?
70-742 was titled Identity with Windows Server 2016 and focused on managing identities with Windows Server 2016 functionality. Its central technical theme was the design, deployment, administration, and maintenance of directory-based identity services.
Microsoft’s published material says the exam covered installing, configuring, managing, and maintaining Active Directory Domain Services (AD DS). That wording is broader than knowing where to click in an administrative console. A useful study approach is to connect each operation to its effect on authentication, directory replication, administrative delegation, service availability, and recovery choices.
The scope also included Group Policy Objects (GPOs). For a candidate using this outline as a learning plan, that calls for more than recognizing policy names. You should be able to reason through where a policy belongs, which identities or computers it targets, how organizational-unit structure affects administration, and how you would confirm the intended result in a controlled environment.
Microsoft’s stated audience profile included familiarity with Active Directory Certificate Services, Active Directory Federation Services, Active Directory Rights Management Services, and Web Application Proxy. These are identity-adjacent services with different purposes. Keep them separate in your notes: certificates support trust and cryptographic operations; federation supports identity relationships; rights management addresses protection of content; and a proxy can publish selected web applications. The supplied outline supports familiarity with these technologies, but it should not be read as evidence of a current exam blueprint or current product recommendation.
Who benefits from studying the retired objectives?
The objectives remain useful for Windows Server administrators who support established identity infrastructure, troubleshoot AD DS changes, or need a structured way to assess their own operational knowledge. They are not a suitable route for someone whose immediate need is a new Microsoft certification.
Microsoft described the intended audience as candidates who manage identities using Windows Server 2016 functionality. Its certification-preparation session was designed for people experienced with Windows Server who were interested in 70-742 or 70-743. Those descriptions imply that hands-on administrative context was expected; they do not establish formal prerequisites, and no prerequisites should be inferred from them.
This legacy outline can be a good fit when your job includes a Windows Server 2016 estate and you need to understand why a domain-controller placement decision, a global catalog change, a role transfer, or a GPO deployment can affect users and systems. It is also useful for an experienced administrator who wants an orderly refresher before taking on directory-service maintenance responsibilities.
It is a weaker fit for a candidate whose only goal is to add a currently obtainable badge to a résumé. Microsoft’s retirement announcement explains its shift toward role-based training and certifications, which are maintained around changing cloud solution areas. In that situation, define the role you are moving toward and investigate current options; do not mistake a detailed legacy skills plan for an active certification path.
Which AD DS tasks deserve the most attention?
Install and Configure Active Directory Domain Services (AD DS) accounted for 20–25% of the published 70-742 objectives. For a legacy study plan, give this domain deliberate lab time because it joins architecture, deployment, change control, and recovery-sensitive administration.
The published AD DS installation objectives included installing new forests, adding or removing domain controllers, upgrading domain controllers, configuring global catalog servers, transferring or seizing operations-master roles, and configuring read-only domain controllers. Do not turn that list into a set of disconnected commands. For each task, write down the trigger for the change, the dependencies to check first, the risk created by a mistake, and the verification evidence you would gather afterward.
A practical lab sequence begins with a disposable directory environment. First document the intended forest and domain layout before installing anything. Next add a domain controller and confirm the directory behaves as expected. Then work through removal and re-addition in a planned order. This sequence exposes the difference between a design choice and a routine administrative action without placing a production directory at risk.
Global catalog and operations-master-role scenarios deserve written decision notes. Ask what service or user activity would be affected, whether another healthy domain controller is available, and whether the action is a normal transfer or a recovery action. The distinction between transferring and seizing operations-master roles is easy to blur when studying from short notes. Build a decision table that states the condition, the preferred action, and the validation you would perform.
Read-only domain controllers should be studied as an architectural choice, not merely another installation option. In your notes, record the business or site condition that could make a read-only role appropriate, the administrative trade-off it introduces, and the identity-related security assumptions that need review. This turns memorization into an explanation you can use during real change planning.
How should you study identity objects and automation?
Practice managing users, computers, groups, and organizational units as a connected administrative system, including the use of Windows PowerShell. The published outline explicitly included creating and managing these Active Directory objects and automation with Windows PowerShell.
Start with organizational-unit design. Create a small, understandable hierarchy that separates users, computers, and delegated administration boundaries. Before creating objects, state what the structure is meant to accomplish. A hierarchy built only to resemble a diagram is less valuable than one that lets you explain where a policy would link or where an administrator’s scope should stop.
Next, build an object-lifecycle exercise. Create representative user and computer objects, place them intentionally, establish group memberships that reflect a simple access decision, and then change the requirements. Move an object, modify group membership, or revise the organizational-unit structure. At each step, document the expected impact before making the change. The habit of predicting outcomes is more valuable than repeatedly following a saved command sequence.
Use PowerShell to repeat safe, clearly defined tasks rather than using it only to produce a one-time script. Begin with read operations that inventory the objects you created. Progress to controlled creation or modification in the lab. Finally, make the script report what changed and retain the input assumptions. A script that performs a change without a way to check the result is a frequent operational weakness.
Avoid studying object types as isolated definitions. A user account may be placed in an organizational unit, assigned to groups, affected by GPO targeting, and governed by a delegation model. Draw those relationships on one page. When a lab outcome is unexpected, trace the path through structure, membership, policy, and administration instead of immediately rebuilding the environment.
How should you approach Group Policy?
Study GPOs by working from a desired configuration to the organizational scope and verification method needed to achieve it. Microsoft’s outline confirms that implementing Group Policy Objects was within the 70-742 scope.
Begin with a small policy goal in a lab, such as applying a configuration to a defined set of computers or users. Identify the target first, then decide where the relevant objects belong in your directory structure. This prevents a common mistake: creating a GPO before deciding who should receive it and how you will recognize an unintended result.
Keep a policy worksheet with four fields: business requirement, intended target, implementation location, and verification result. The worksheet makes policy study concrete and forces you to distinguish a correctly created GPO from a correctly applied one. After a change, inspect the affected account or device in the lab and compare the observed result with the prediction you wrote beforehand.
Use failure scenarios deliberately. Put a test object in an unexpected organizational unit, alter the intended scope, or introduce a conflicting configuration in the lab. Then diagnose the result with a documented, repeatable method. This is better preparation for administrative work than collecting screenshots of successful configurations.
Do not assume that every directory-management problem is a GPO problem. Object placement, group membership, delegation boundaries, domain-controller health, and the broader AD DS design may all matter. A disciplined troubleshooting note should identify the policy hypothesis, the evidence to collect, and the condition that would rule that hypothesis out.
What roadmap makes the legacy content manageable?
A staged roadmap should move from AD DS foundations to object administration, GPO implementation, and the adjacent identity services named in the audience profile. The purpose is to build usable understanding of the retired objectives, not to simulate an unavailable exam appointment.
Stage 1 is environment and terminology. Set up a safe, nonproduction practice environment that you can reset. Map forest, domain, domain controller, organizational unit, user, computer, group, global catalog, and operations-master roles in your own words. Do not advance until you can explain the relationship between these concepts without relying on a diagram copied from a course.
Stage 2 is AD DS deployment and change operations. Work through the published installation tasks one at a time: create a forest, add or remove a domain controller, consider an upgrade scenario, configure global catalog placement, and distinguish transfer from seizure of operations-master roles. Maintain a change record containing the pre-change state, intended action, expected result, and actual result. This record becomes your targeted revision material.
Stage 3 is daily identity administration. Create and manage users, computers, groups, and organizational units, then automate a narrow repetitive task with Windows PowerShell. Add a recovery-minded review: identify what information you would need before changing or deleting an object and how you would confirm the post-change state. The objective is controlled administration, not speed alone.
Stage 4 is policy implementation. Create a handful of narrowly scoped GPO exercises, including at least one result that does not apply as expected. Use the policy worksheet to trace the target and record evidence. Keep this stage separate from broad AD DS deployment work at first; combining every feature in a single large lab often makes troubleshooting too opaque to teach useful lessons.
Stage 5 is identity-service orientation and consolidation. Review the distinct roles of Active Directory Certificate Services, Active Directory Federation Services, Active Directory Rights Management Services, and Web Application Proxy as described in the audience profile. Then revisit your weakest AD DS or GPO scenario without notes. If you cannot explain why you chose an action and how you would validate it, return to the relevant lab rather than adding more passive reading.
What preparation mistakes should you avoid?
The largest mistake is treating retired-exam material as a path to a schedulable certification. Confirm the credential status before buying training, planning leave, or choosing a target date; 70-742 cannot be taken because it is retired.
A second mistake is learning administrative actions as unconnected steps. Installing a domain controller, configuring a global catalog server, transferring an operations-master role, or linking a GPO each has a reason, a scope, and a validation requirement. For every lab action, require yourself to state those three items before you make the change.
Avoid building one oversized lab too early. A complicated environment can conceal whether a failed result comes from directory design, object placement, a policy setting, permissions, or an automation error. Start with a minimal reproducible setup, change one variable, verify it, and preserve a short record. Complexity can be added after the baseline is reliable.
Do not substitute question banks, copied answer keys, or purported leaked exam content for learning. Apart from the fact that 70-742 is unavailable, those materials do not build the operational judgment needed to manage identity services. A better revision method is to create your own scenario prompts from the published objectives and explain the change, consequence, and verification method aloud or in writing.
Finally, do not assume there is an exact successor exam. A Microsoft Q&A response concerning 70-742 said there would not be an exact replacement. That is why a current-certification decision should start with current job requirements and Microsoft’s active role-based portfolio, rather than a search for an identically scoped replacement.
What delivery and support details still matter?
There are no current 70-742 delivery, scheduling, price, duration, language, or scoring details to plan around because the exam is retired. Any historical details found outside an official current booking flow should not be used to make an appointment decision.
For active Microsoft certification exams, Microsoft directs candidates with appointment and scheduling issues to its exam delivery partners, and it provides a Credentials Support route for other certification issues. Its support guidance also notes that candidates whose selected exam is not available in their native language may apply for extra exam time. Those are general support policies, not available delivery features for 70-742.
If you already earned a related retired credential, check your Microsoft Learn profile transcript rather than relying on old emails or third-party records. Microsoft states that credentials earned before retirement remain on the transcript. If the issue concerns a current exam or a profile detail, use Microsoft’s current support process and verify the specific credential’s status before taking further action.
Choose the right next action
Choose technical study if you administer a legacy Windows Server identity environment; choose a current role-based path if you need a new credential. Separating those goals prevents wasted preparation and makes the 70-742 outline useful for the right reason.
For legacy operations, turn the roadmap into a work-focused skills inventory. Mark each AD DS installation task, object-management activity, PowerShell exercise, and GPO scenario as either observed, practiced in a lab, or performed under an approved operational process. The gaps marked “observed” are strong candidates for supervised practice and documented runbooks.
For career development, write down the work you want to perform over the next role change: hybrid administration, cloud services, security, endpoint management, or another defined responsibility. Microsoft’s retirement communications point candidates toward role-based training and certifications that are kept current with changing services. Use that direction to investigate active choices rather than trying to revive an old exam path.
For an existing credential record, retain the historical title accurately and be ready to explain the skills it represented: Windows Server 2016 identity management, AD DS, GPOs, and familiarity with related identity services. Pair it with evidence of current learning or current responsibilities where appropriate. The retired credential can describe past achievement, while your present learning plan demonstrates where your skills are going next.
Conclusion
70-742 is no longer an exam you can schedule or use to earn the MCSA: Windows Server 2016 credential. Its published objectives still offer a focused learning map for AD DS deployment, identity-object management, PowerShell automation, and GPO implementation in legacy environments. Build those skills through controlled lab changes and documented validation. If certification is the goal, shift the search to active role-based options aligned with the work you intend to do.