Identity with Windows Server covers the installation, administration, and configuration of Microsoft Active Directory. Students promote a standard Windows server to a domain controller by deploying Active Directory, then administer it — creating user accounts, groups, and organizational units — and go on to create and manage Group Policy Objects, Active Directory Certificate Services, Active Directory Federation Services, Web Application Proxy, and Active Directory Rights Management Services.
Within the SCNS taxonomy, CTS is the Computer Technology and Skills prefix. Daytona State publishes it at 3 credits with prerequisite CTS2308, offered in fall. It appears at approximately three Florida institutions, and sits alongside CTS2302C Windows Active Directory in this repository.
Identity is the most consequential subject in enterprise infrastructure. Active Directory determines who a user is, what they can reach, and what policy applies to their machine — which means it is simultaneously the foundation of an organization's IT and the single most valuable target in it.
Florida course inventories carry this number as CTS2358C. Daytona State publishes CTS2358 without the C at 3 credits. The 60 contact hours reported here follows the convention this repository's CTS integrated courses use consistently. Note also that the Windows Server sequence is numbered inconsistently across Florida — this repository carries CTS2302C "Windows Active Directory" with substantially overlapping content, and Daytona State's prerequisite here is CTS2308, a third number in the family. SCNS equivalency does not cross numbers; read the catalog description and have any transfer evaluated in writing.
The most important context for this course, and it reframes the entire subject.
In most enterprise compromises, the attacker's objective is domain administrator privilege, because it confers control of every joined machine and account. Active Directory is therefore not merely infrastructure to be configured — it is the thing being attacked, and configuration decisions are security decisions.
Techniques a student should know by name, because defending against them shapes good administration: credential theft and lateral movement, in which an attacker harvests credentials from one machine and reuses them on another; Kerberoasting, which extracts service account credentials offline and is why service accounts need long, complex passwords; and golden and silver ticket attacks, which forge authentication tickets and are why the krbtgt account and domain controller security matter disproportionately.
The administrative practices that follow are the course's real content:
The techniques and defenses in this area evolve continuously — rule 11 applies; verify current Microsoft guidance rather than relying on a textbook.
The most-used and most-misunderstood feature in the course. Group Policy applies in a defined order — local, site, domain, then organizational unit, with nested OUs applying in sequence — and later application generally overwrites earlier. On top of that sit block inheritance, enforcement, security filtering, and WMI filtering, each of which changes what actually applies.
The consequence is that "the policy isn't working" is one of the most common support requests in a Windows environment, and the answer is almost always in the interaction rather than in the policy itself. Two habits address it: use the diagnostic tools — gpresult and the Group Policy Modeling and Results wizards report what actually applied and why, which removes the guesswork entirely; and design the OU structure for policy and delegation from the start, because an OU structure built to mirror the organization chart usually fights the policy requirements.
The related discipline: change one thing at a time and document it. A domain with two hundred undocumented GPOs accumulated over a decade is a real and common situation, and it is unmaintainable.
A career-relevant point about where this material sits. On-premises Active Directory remains widespread and is not disappearing, but the centre of gravity in identity has shifted toward cloud directory services and toward hybrid arrangements in which an on-premises directory synchronizes with a cloud identity provider.
What that means for a student: the concepts in this course — authentication, authorization, federation, claims, certificates, and policy — transfer directly, and are in fact the foundation of the cloud material. The specific tooling changes. A graduate who understands why federation exists and what a claim is will learn the cloud implementation quickly; one who memorized a wizard will not.
Practically: add cloud identity to this coursework rather than treating it as a separate path, and expect employers to want both. The federation and Web Application Proxy content in this course is precisely the bridge, which is a good reason not to skip it as legacy material.
Courses built around a specific vendor certification carry a distinctive risk: the vendor retires the certification and the course keeps its number. Microsoft has repeatedly restructured its certification programme — the MCSA and MCSE server tracks were retired and replaced by role-based certifications, and individual exams are retired on published schedules.
Three practical consequences:
The single most effective study method for this course, and the one that also produces something to talk about in an interview.
Windows Server evaluation editions are free, and a laptop with 16 GB of memory will run a domain controller, a member server, and a client. Build a domain from nothing. Create OUs, users, and groups. Write GPOs and watch them apply. Then break things deliberately — seize a role, corrupt replication, delete an OU and perform an authoritative restore, lock yourself out and recover.
Two reasons this matters more than in most courses. Infrastructure administration is learned by troubleshooting, and a lab is the only place a student can safely cause the failures they will later have to fix. And a candidate who can describe a specific problem they created and solved is materially more credible than one who lists a course.
This course appears at roughly three institutions statewide, which is a small base. Content, credit value, and emphasis vary more than they would for a widely taught course. Read your own institution's catalog description and syllabus rather than assuming this guide describes your section exactly, and have any transfer evaluated in writing.
Daytona State publishes CTS2358 at 3 credits with prerequisite CTS2308, offered in fall. The 60 contact hours follows the convention used across this repository's CTS integrated courses. Confirm on your syllabus, and confirm which server version your section uses — the version materially affects the hands-on work.
Assessment is predominantly hands-on laboratory work: build, configure, verify, and troubleshoot in a virtualized environment. Expect practical examinations in which a configuration must be produced rather than described.
The first digit of an SCNS number denotes the year of offering, not transferability. Courses at the 1000 and 2000 levels transfer transparently between Florida public institutions, and 3000 to 4000 is unproblematic since both are upper division. The boundary that actually matters is 2000 to 3000, where lower-division credit generally cannot satisfy an upper-division requirement.
Generated September 2, 2026 · Updated September 2, 2026