- Floating Topic
-
Introducing Active Directory Domain Services
- Information protection
- CIA: Confidentiality ,Integrity ,Availability
- Identity and Access
-
Authentication
- Authentication is the process that verifies a user's identity
-
Credentials :At least two components required
- User name
- Secret , for example, password
-
Authorization
- Resource
- Access Request
- Security Token
-
Active Directory Domains: Trusted Identity Store
- Centralized identity store trusted by all domain members
- Centralized authentication service
- Hosted by a server performing the role of an AD DS domain controller
- Active Directory as a Database
- Active Directory Data Store
-
Administering Active Directory Securely and Efficiently
-
Lesson1 :Work with Active Directory Administration Tools
- Active Directory Administration Snap-Ins
- What Is the Active Directory Administrative Center ?
- Find Active Directory Administration Tools
- Demonstration: Perform Administrative Tasks by Using Active Directory Administrative Tools
-
Active Directory Administration Snap-Ins
- Active Directory Users and Computers
- Active Directory Sites and Services
- Active Directory Domains and Trusts
- Active Directory Schema
-
Find Active Directory Administration Tools
- Active Directory snap-ins and installed on a domain controller
- Install the RSAT on a member client or server
-
Lesson2: Custom Consoles and Least Privilege
- Demonstration: Create a Custom MMC Console for Administering Active Directory
- Secure Administration with Least Privilege , Run As Administrator , and User Account Control
- Demonstration: Secure Administration with User Account Control and Run As Administrator
-
Demonstration : Create a Custom MMC Console for Administering Active Directory
-
In this demonstration , you will see:
- How to create a custom MMC console with multiple snap-ins
- How to register the Active Directory schema snap-in
- Where to save custom console
- Secure Administration with Least privilege , Run Administrator , and User Account Control
-
Options for Locating Objects
- Sorting : Use column headings to find the objects based on the columns
- Searching : provide the criteria for which you want to search
-
Demonstration :Use saved Queries
-
In this demonstration , you will see
- How to create a saved query
- How to distribute a saved query
-
Lesson 4: Use Windows power Shell to Administer Active Directory
- What Is Windows power shell ?
- Installation Requirements for Windows power shell 2.0
- Overview of the Windows power shell syntax
- Windows power shell Cmdlets for Active Directory
- Demonstration : Manage Users and Groups by Using power shell
- What Is Windows power shell ?
-
Managing Users and Service Accounts
-
Demonstration : Create a User Template
-
In this demonstration , you will learn :
- How to create a template user account
- What a template user account is , and why it is useful
-
User Account
- A user account
- A user account can be stored
-
Create Users with templates
- General tab
- Address tab
- Account tab
- Profile tab
- Organization tab
- Member of tab
-
User Account Management
- Account Management involves the following tasks
-
Lesson 1: Create and Administer User Accounts
- User Account
- Demonstration :Create a User Object
- Name Attributes
- Account Attributes
- User Account Management
-
Name Attributes
- User logon name
- User logon name : userprincipalname
- Name or full name
- Display name :display name
-
Module Overview
- Create and Administer User Accounts
- Configure User Object Attributes
- Automate User Account Creation
- Create and Configure Managed Service Account
-
Lesson 2 :Configure User Object Attributes
- A Tour of User Attributes
- View All Attributes
- Modify Attributes of Multiple Users
- Demonstration : Create a User Template
- Create Users with Templates
-
A Tour of User Attributes
-
In this demonstration , you will learn
- How to access the propeties of a user
- The role of each tab in theuser properties dialog box
-
Account Attributes
- Logon Hours
- Log On To
- User must change password at next logon
- User cannot change password
- password never expires
- Account is disabled
- smart card is requireg for interactive logon
-
Managing Groups
-
Define Group Naming Conventions
- Name properties
- Naming conventions
-
Group Scope
-
Four group scopes
- Local
- Global
- Domain Local
- Universal
-
Group Type
- Distribution groups
- Security groups
-
Manage Group Membership
-
Methods
- the group's Member tab
- the member's Member of tab
- the member's Add to a group
-
- Changes to membership do not take effect immediately
-
Tools for Group Management
- Active Directory Users and computers
- Windows power shell with Active Directory Module (R2 only )
- DS commands
-
protect Groups form Accidental Deletion
- In the Active Directory Users and computers snap-in ,click the View menu and make sure that Advanced Features is selected
- Open the properties dialog box for a group
- On the Object tab , select the protect Object Form Accidental Deletion check box
- click OK
-
Convert group Type and Scope
- In Active `Directory Users and Computers , you can change group
-
In Active Directory Users and Computers , you can change the group
- Global universal
- Domain universal
- Universal global
- Universal domain local
-
Managing Computer Accounts
-
Requirements for Joining a Computer to the Domain
- You must have permissions in Active Directory Domain Services that allow you to join a Computer to the domain
- you must be a member of the local Administrators group on the computer to change its domain or workgroup membership
-
Workgroups , Domains , and Trusts
- In domain , Active Directory is the authority for authentication
- In workgroup , SAM is the authority for authentication
-
prestage Computer Account
- prestage (pre _create ) a computer in the correct OU
- Computer Name and Computer Name (pre - windows 2000) should be the same
-
Secure Computer Creation and Joins
- Prestage computer objacts in OUs
- Requires no prestaging
-
The Computer,s Container and Organizational Units
-
The default Computers container is a container not an organizatonalUnit object
- Cannot link GPOs to a container
- Cannot create sub-OUs in a container
-
Best practice is to create OUs for computer objects Server
- Servers
- Client
-
Configure Computer Attributes
-
Useful attributes
- Description
- Managed By
-
Automate Computet Account Creation
- CSVDE
- LDIFDE
-
Move a computer
- Using Active Directory Users and
- Right-click the computer , and then click Move
-
computers Account and Secure Channel
- Computers have accounts
- Scenarios where a secure channel can be broken
-
Reset a Computer Account
- Do not simply remove a computer form the rejoin
- Options for resetting the secure channel
- Active Directory Users and computers
- Right - click the computer , and then click Reset Account
- Requires the computer to rejoin the domain and restart
-
Delete and Recycle Computer Accounts
- Right-click the computet ,and then click Delete
-
Recognize Computer Account problems
- Logon messages
-
Event log errors,including key words such as
- Password
- Trust
- Secure channel
- Missing computer account in Active Directory
-
Rename a Computer
- Use System properties of the computer to rename the computer and its account correctly
-
lmplementing a Group Policy ln Frastructure .
-
Module overview
- understand Group policy
- Implement GPO
- Manage Group policy scope
-
Verview of policies
-
Divided between
- user
- computer
-
Group policy objects
- container for on or more policy setting
- managed with the GPMC
- Stored in Group policy objects container
-
GOP Scope
- Scope
- GPO Links
-
Group policy Refresh
- when GPO and their setting and are applied
- Computer configuration
- user configuration
-
Review the computer of Group policy
- Setting
- Scope
- Application
- Tools
-
Tow default GPO
- De fault Domain policy
- De fault Domain controllers policy
-
Manage GPO and This Setting
- copy and paste
- Back up
- Save Report
- Delete
- Rename
-
Configuring Domain Name System
-
Install and Manage the DNS Server Role
- Installation Methods
- DNS Manager Snap-In
-
Create a Zone
- Right - click
- Select zone type
- Specify replication
-
Create Resource Records
- Right - click the zone
- Dialog box appears specific to the record type you choose
- Active Directory -Integrated Zones
- Domain Controller Location
- Read - Only DNS Zones
-
Prerequesites for Deploying an RODC
- Ensure the forest functional level is Windows Server 2003 higher
- Ensure that there is at least one writeable domain controller running Windows Server 2008
-
Administering AD DS Domain Controllers
-
Install a Domain controller by using the win dows Interface
- To install a domain controller
- DCPROMO . exe
-
options for Installing Domain controller in a Domain
- Installing additional domain controllers
- Install a new windows server 2008 child domain
- Install a new domain tree in a forest
-
understand single master operations
- In any multi master replication topology
- Many terms used for single master operations in AD DS
- Roles
-
operations master Roles
- forest - wide
- Domain - wide
-
Identify operations masters
- user interface tools
- command -line tools