2640 12299 Itu Notes Windows Server 2012 Installation and Configuration
2640 12299 Itu Notes Windows Server 2012 Installation and Configuration
com
Course Outline
Planning, Installing, and Conguring Windows Server 2012
Installing and Conguring an Active Directory Domain Controller
Administering Active Directory Objects
Automating Administrative Tasks
Conguring IPv4
Conguring IPv6
Installing and Conguring DHCP
Installing and Conguring DNS
Conguring Storage Spaces and File and Print Services
Conguring Group Policy
Securing Windows Servers
Installing and Conguring Virtual Servers and Clients
OV 1 - 1
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Planning, Installing, and Conguring
Windows Server 2012
Introduction to Windows Server 2012
Describe Windows Server 2012 Management
Plan and Install Windows Server 2012
Congure Windows Server 2012
OV 1 - 2
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Networking Environments
Local clients and servers
Cloud services (public, private, or both)
OV 1 - 3
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Windows Server 2012 Server Roles
Active Directory Certicate Services (AD CS)
Active Directory Domain Services (AD DS)
Active Directory Federation Services (AD FS)
Active Directory Lightweight Directory Services (AD LDS)
Active Directory Rights Management Services (AD RMS)
Application Server
DHCP Server
DNS Server
Fax Server
File and Storage Services
OV 1 - 4
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Windows Server 2012 Server Roles (Cont.)
Hyper-V
Network Policy and Access Services
Print and Document Services
Remote Access
Remote Desktop Services
Volume Activation Services
Web Server (IIS)
Windows Deployment Services (WDS)
Windows Server Update Services (WSUS)
OV 1 - 5
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Windows Server 2012 Features
Windows BitLocker Drive Encryption
Failover Clustering
Group Policy Management
Ink and Handwriting Services
Internet Printing Client
Network Load Balancing (NLB)
Remote Assistance
Remote Server Administration Tools
Simple Mail Transfer Protocol (SMTP) Server
Telnet Client, Telnet Server
Windows PowerShell
Windows Server Backup
Windows System Resource Manager (WSRM)
Wireless Local Area Network (LAN) Service
Windows on Windows (WoW) 64 Support
OV 1 - 6
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
New Features in Windows Server 2012
Command auto-completion
Enhanced storage
Features on Demand
IP Address Management (IPAM) Server
New cmdlets
Resilient File System (ReFS)
Revised Task Manager
User interface
Windows BranchCache
OV 1 - 7
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Comparing Server Roles and Features
Server Roles
Programs that congure a server to perform a specic function for users and/or
computers on the network. Users typically access servers that are hosting server
roles.
Examples: The DHCP Server role leases IP addresses to clients and devices; the DNS
Server role congures the server to nd the IP address for a given FQDN.
Features
Applications that increase the functions the server can perform. In general, users do
not access features.
Examples: You use Windows Server Backup to back up the server, not clients. The
Wireless LAN Service enables you to connect the server to the network wirelessly.
OV 1 - 8
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Windows Server 2012 Editions
Windows Server 2012 Datacenter
Designed for large organizations that need highly virtualized private and hybrid cloud network
environments.
Designed for use by large organizations.
Includes all features of Windows Server 2012 and unlimited virtual machine instances.
Windows Server 2012 Standard
Designed for network environments with minimal virtualization needs.
Includes all features of Windows Server 2012 and two virtual machine instances.
Windows Server 2012 Essentials
Designed for use by small businesses with a maximum of 25 users and 50 network devices.
Tailored to the needs of a small organization with no more than 25 users.
Includes a streamlined interface, conguration for connecting to cloud services, and no support for
virtualization.
Windows Server 2012 Foundation
Designed for very small organizations with up to 15 users.
Includes general-purpose server functionality and no support for virtualization.
OV 1 - 9
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Windows Server 2012 Licensing
Windows Server 2012 Datacenter
Processor license for each CPU in the server.
Client access license (CAL) for each user or device that connects to the server.
Windows Server 2012 Standard
Processor license.
CAL per user or device.
Windows Server 2012 Essentials
Server license that supports a maximum of two server CPUs.
Maximum of 25 users.
Windows Server 2012 Foundation
Server license that supports only one CPU in the server.
Maximum of 15 users.
OV 1 - 10
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Administrative Tools and Tasks
Server Manager
Add and congure server roles.
Examine and congure services.
Monitor events.
Congure server and network settings such as name, domain, and IP addresses.
Evaluate servers and the network (Best Practices Analyzer).
Windows PowerShell
Perform nearly all tasks that can be managed in the GUI.
Bulk administer objects.
Active Directory Users and Computers; Active Directory Administration
Center
Create and manage Active Directory objects.
Group Policy Management
Create and congure group policies.
Performance Monitor
Monitor server and network performance.
OV 1 - 11
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Administrative Tools and Tasks (Cont.)
Task Manager
Monitor server and network functionality, and performance.
Resource Monitor
Monitor server resources.
Task Scheduler
Create and schedule administrative tasks to run automatically.
Various MMCs, such as the DNS console
Perform server-role specic tasks.
Remote Desktop
Perform remote management.
WinRM
Perform remote management from a command-line interface.
OV 1 - 12
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Introduction to Server Manager
Manage conguration of multiple servers.
Review server event logs.
Install and congure additional roles.
Manage Windows services on each server.
Launch PowerShell for command-line administration.
OV 1 - 13
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
The Server Manager Interface
OV 1 - 14
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Multi-Server Management
Shows all servers running a particular service in the domain
Gives quick statistics about each server and service
Can open the management console for each service on each server
Can open other management tools:
RDP
PowerShell
Add Roles and Features
Computer Management
NIC Teaming
Performance Counters
Shut Down
OV 1 - 15
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
The Dashboard Pane
Top section displays a list of steps for conguring a server.
Bottom section displays birds eye view thumbnails of servers.
OV 1 - 16
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
All Servers Pane
View a series of sections:
Servers
Events
Services
Best Practices Analyzer
Performance
Roles and Features
OV 1 - 17
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
The File and Storage Services Pane
When selected, displays a second level of options:
Servers
Volumes
Disks
Storage Pools
Shares
iSCSI
OV 1 - 18
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
The File and Storage Services Pane (Cont.)
OV 1 - 19
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Windows Server 2012 System
Requirements
Hardware Component Minimum Requirement Recommended Hardware
Processor 1.4 GHz 64-bit processor 3.1 GHz or faster
RAM 512 MB 16 GB or more
Disk space 32 GB 128 GB or larger
DVD drive
Super VGA (800x600) or higher resolution monitor
Keyboard and mouse
Internet access
Additional hardware needed:
OV 1 - 20
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Windows Server 2012 Installation
Methods
Optical media such as a DVD
USB drive
Network share
Mounted ISO image
Windows Deployment Services (WDS)
System Center Conguration Manager (SCCM)
Virtual Machine Manager templates
OV 1 - 21
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Installation Types
Fresh install
Upgrade
Migration
OV 1 - 22
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Installation Modes
Server Core
Server with the graphical user interface (GUI)
Server with the Minimal Server Interface
OV 1 - 23
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Upgrade Paths for Windows Server 2012
Current Version of Windows Server Can Upgrade To
Windows Server 2008 Standard with SP2 or Windows
Server 2008 Enterprise with SP2
Windows Server 2012 Standard, Windows Server 2012
Datacenter
Windows Server 2008 Datacenter with SP2 or
Windows Server 2008 R2 Datacenter with SP1
Windows Server 2012 Datacenter
Windows Web Server 2008 or Windows Web Server
2008 R2
Windows Server 2012 Standard
Windows Server 2008 R2 Standard with SP1 or
Windows Server 2008 R2 Enterprise with SP1
Windows Server 2012 Standard, Windows Server 2012
Datacenter
OV 1 - 24
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Migrating to Windows Server 2012
You must migrate the following services from an older server to a Windows
Server 2012 server:
Active Directory Federation Services
Health Registration Authority
Hyper-V
IP Conguration
Network Policy Server
Print and Document Services
Remote Access
Windows Server Update Services
OV 1 - 25
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Installation Planning Worksheet
OV 1 - 26
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
O"ine Images
Create and deploy server image using DISM
Create image le
Create answer le
Modify image le
OV 1 - 27
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Server Core Conguration
Assign a static IP address to the server.
Change the computer name and domain membership.
Implement network adapter teaming.
Enable Remote Desktop.
Activate the server.
OV 1 - 28
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
The Windows Server GUI Interface
Advantages of the full server with the graphical interface:
Contains all graphical administrative utilities.
Supports local and remote installation, conguration, and removal of server roles.
Provides use of MMC to create additional graphical consoles.
Disadvantages of the full server with the graphical interface:
Is less secure.
Uses more disk space.
Consumes more RAM.
OV 1 - 29
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Full Server with GUI Conguration
Perform the same tasks as with conguring Server Core:
1. Assign a static IP address to the server.
2. Change the computer name and domain membership.
3. Implement network card teaming.
4. Enable Remote Desktop.
5. Activate the server.
OV 1 - 30
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Congure Server with a Static IP Address
Assign a static
IP address,
subnet mask,
and default
gateway
Assign at least
one DNS server
address
OV 1 - 31
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
The Computer Name/Domain
Changes Dialog Box
OV 1 - 32
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Network Card Teaming
OV 1 - 33
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Enable Remote Desktop
OV 1 - 34
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Reective Questions
1. In what scenario do you think its best to install Windows Server 2012
Server Core?
2. After conguring a server, why should you consider switching it from the
GUI version of Windows Server 2012 to the Server Core version?
OV 2- 1
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Installing and Conguring an Active
Directory Domain Controller
Overview of Active Directory
Install an Active Directory Domain Controller
OV 2- 2
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
The Active Directory Physical Hierarchy
Fuller.loca
l domain
Rochester
.fuller.loc
al domain
Boston.
fuller.loca
l domain
Each domain contains
domain controllers,
users, computers,
printers, and so on
OV 2- 3
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
The Active Directory Logical Hierarchy
Fuller.loca
l domain
Rochester
.fuller.loc
al domain
Boston.
fuller.loca
l domain
OU = Headquarters
OU = Rochester
OU = Boston
OU =
Sales
OU =
Accounting
OU = Admin
OU = Bookstore
Site = Rochester
Site = Boston
OV 2- 4
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Active Directory Components
Domain controllers
Data store
Global catalog servers
Read-only domain controllers (RODCs)
Domain
Domain tree
Forest
Site
OU
Partition
Schema
OV 2- 5
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Active Directory Containers
Forest
Tree or domain tree
Domain
Site
Organizational unit
OV 2- 6
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Domain Controllers
Domain controllers perform these tasks:
Store a copy of the AD DS database in the NTDS.dit le.
Host a copy of the SYSVOL folder.
Authenticate users for log on purposes and also for access to resources.
Synchronize the SYSVOL folder using either File Replication Service (FRS)
or Distributed File Service (DFS) replication.
OV 2- 7
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Global Catalog Server
Global catalog servers perform these functions in the forest:
Contain a copy of the global catalog, which has references to every object
in the forest.
Enable users and administrators to search for objects such as computers
and printers distributed throughout the forest.
Support cross-domain searches.
OV 2- 8
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Operations Master Roles
Domain controllers can also host forest-wide or domain-level operations
master roles:
Schema master: Is responsible for updates to the schema.
Domain naming master:
Processes domain name changes.
Adds or removes domains or application directory partitions to or from the forest.
Adds replicas of application directory partitions to other domain controllers.
Adds or removes cross-reference objects to or from external directories.
RID master: Allocates blocks of relative identiers (RIDs) to every domain
controller in the domain.
Infrastructure master: Updates references to objects in its own domain
that point to objects in other domains, and also updates references to its
local objects.
PDC emulator:
Supplies the correct time to the domain.
Stores the most-recent password changes.
Administers Group Policy and Distributed File System (DFS).
OV 2- 9
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Reective Questions
1. What are the advantages of using Active Directory Domain Services?
2. Which types of installations do you expect to perform most often in your
working environment?
OV 3 - 1
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Administering Active Directory Objects
Design and Create an Active Directory Hierarchy
Manage Users
Manage Computers
Manage Groups
Delegate Administrative Tasks
OV 3 - 2
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Types of Active Directory Design
Geographical location
Organizational chart
Functional structure
Hybrid structure
OV 3 - 3
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Active Directory Structure:
Geographical Design
Create domains and organizational units based on geographic locations for
your organization.
fuller.local
us.fuller.local eu.fuller.local
paris.eu.fuller.loca
l
london.eu.fuller.loca
l
rochester.us.fuller.loc
al
atlanta.us.fuller.local
Root Level
Domain
Country Domains
City Domains
OV 3 - 4
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Active Directory Structure: Organizational
Chart Design
Create domains and organizational units based on the organizations
organizational chart.
fuller.local
marketing.fuller.loc
al
production.fuller.loc
al
paris.production
.fuller.local
rochester.productio
n
.fuller.local
rochester.marketing.
fuller.local
atlanta.marketing.
fuller.local
Root Level
Domain
Departmental
Domains
City Domains
OV 3 - 5
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Active Directory Structure: Functional
Design
fuller.local
publishing.fuller.loc
al
administrative.fuller.loc
al
sales.fuller.local accounting.fuller.local
Root Level
Domain
Functional Domains
Create domains and organizational units based on the organizational
chart structure.
OV 3 - 6
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Active Directory Structure: Hybrid Design
fuller.local
publishing.fuller.loc
al
admin.fuller.local sales.fuller.local accounting.fuller.local
Root Level
Domain
Functional Domains
Create domains and organizational units based on the organizational
chart structure.
Atlanta
Location Domains
or Organizational
Units
Rochester Rochester Rochester Rochester Boston
Atlanta
Boston
OV 3 - 7
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
The Fuller & Ackerman Wide Area
Network
OV 3 - 8
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
The Active Directory Administrative Tools
Graphical Administrative Tools
Active Directory Users and Computers
Active Directory Sites and Services
Active Directory Domains and Trusts
Active Directory Schema
Remote Server Administration Tools (RSAT)
Active Directory Administrative Center
Windows PowerShell Commands
Add-ADGroupMember
Disable-ADAccount
Get-ADDomain
Move-ADObject
New-ADGroup, New-ADOrganizationalUnit, New-ADUser
Remove-ADGroup, Remove-ADGroupMember, Remove-ADUser
Command-Line Utilities
Dsadd, Dsget, Dsmod
Dsmove, Dsquery, Dsrm
OV 3 - 9
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Tools for Creating User Accounts
Active Directory Users and Computers
Active Directory Administrative Center
PowerShell command New-ADUser
Command-line utility Dsadd.exe
OV 3 - 10
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
User Proles
User proles contain the information necessary to establish the users
desktop environment:
The Prole Path
Location where desktop settings are stored.
Also referred to as a roaming prole.
Logon Scripts
Batch les that map drive letters to network resources.
Home Folder Location
A folder you create to store the users folders and les.
OV 3 - 11
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Default Active Directory Objects
Builtin
Computers
Domain Controllers
ForeignSecurityPrincipals
Managed Service Accounts
Users
OV 3 - 12
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
User Account Templates
Reduces workload of creating users.
Has all non-user specic congurations including group memberships.
Best practices:
Create the user account with an underscore at the beginning of the name.
Leave the account disabled.
Never let anyone use the template to log on.
Dont congure template with information that is user-specic.
OV 3 - 13
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
The Computers Container
Default system container in Active Directory.
New computer accounts are created here by default.
Cannot have group policy directly applied to it.
Has a relative distinguished name of CN=Computers.
Redircmp.exe can be used to change the default computer container.
Best practices:
Specify another container as you create the computer account.
Move computer accounts out of this default container into real OUs.
OV 3 - 14
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Location Conguration
A best practice is to create OUs specically to hold computer accounts.
It is common to create parent OUs by geography or department.
Child OUs can be for desktops or laptops.
Other child OUs can be for users, administrators, and resources.
Separate computers into OUs to delegate control and apply policy.
OV 3 - 15
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Permissions Management
By default, the following have permissions to create computer objects:
Enterprise Admins
Domain Admins
Administrators
Account Operators
You should restrict membership to administrator groups.
Delegate control over an OU by using the Delegate Control wizard.
OV 3 - 16
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Secure Channels
Like users, computers log on to the domain.
Ordinarily there is no need to manually reset a computer account.
If for some reason the computer cannot access its own account, you may
have to perform a secure channel reset.
You can reset a computer account using the following tools:
Active Directory Users and Computers
DSmod
netdom
NLTest
PowerShell
OV 3 - 17
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Types of Groups
Security
Distribution
OV 3 - 18
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Group Scopes
Local
Domain Local
Global
Universal
OV 3 - 19
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Default Management Groups
Schema Admins
Enterprise Admins
Domain Admins
Administrators
Server Operators
Account Operators
Backup Operators
Print Operators
OV 3 - 20
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Active Directory Domain Services
Permissions
You can assign permissions to Active Directory objects:
Users
Computers
Groups
It is a best practice to delegate control to an entire OU.
E#ective permissions are cumulative from individual permissions and
group membership.
OV 3 - 21
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Reective Questions
1. Do you foresee using user account templates in your organization?
Why or why not?
2. Do you think you will delegate control to OUs in your organization?
Why or why not?
OV 4 - 1
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Automating Administrative Tasks
Introduction to Windows PowerShell
Use Windows PowerShell to Manage Active Directory Objects
Use Command-Line Tools to Administer Active Directory
Use Bulk Operations
OV 4 - 2
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Common PowerShell Uses for
Administrators
Add and remove Windows Server roles and features.
Manage services.
List processes.
Create, list, and manage le systems.
View event logs.
Manage the Windows registry.
Manage monitoring tools.
Add, delete, and manage AD DS objects.
OV 4 - 3
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Windows PowerShell Features
Simplied syntax
Updated help
Enhanced module discovery
Session recovery
The show command
Web access
Delegated administration
Safety
OV 4 - 4
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
PowerShell Get-Help Command
OV 4 - 5
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Update Help
Download the latest help le.
If Update Help cannot contact the Microsoft site, you can cancel and
continue.
OV 4 - 6
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Get-Help Service
OV 4 - 7
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Common Cmdlet Verbs
Add
Backup
Clear
Close
Disable
Enable
Install
Get
New
Set
Show
Stop
Suspend
Uninstall
Rename
Note: some words such as backup or new are treated as single
verbs in PowerShell.
OV 4 - 8
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Common Event Viewer Cmdlets
Get-EventLog
Show-EventLog
Clear-EventLog
Limit-EventLog
OV 4 - 9
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
The Get-EventLog Command
Get-EventLog retrieves log entries.
Must include the name of the event log le.
-Newest <number> gives most recent entries only.
OV 4 - 10
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Service Cmdlets
Start-Service
Get-Service
Stop-Service
Suspend-Service
Resume-Service
Set-Service
Restart-Service
OV 4 - 11
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Process Cmdlets
Start-Process
Get-Process
Stop-Process
Wait-Process
Debug-Process
OV 4 - 12
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
An Advanced PowerShell Cmdlet
Get-Counter Counter \Processor(_Total)\% Processor Time
SampleInterval 10 MaxSamples 100
OV 4 - 13
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
The -Whatif Parameter
-WhatIf shows what would happen without actually doing it.
OV 4 - 14
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
The -Conrm Parameter
The -Conrm parameter executes a command with conrmation.
Note: PowerShell will still ask you to conrm if the action will be taken
on more than one object.
OV 4 - 15
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
PowerShell ISE
OV 4 - 16
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
PowerShell ISE Scripting Pane
The Scripting pane is available on the toolbar.
OV 4 - 17
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Execution Policies
Restricted Scripts will not execute.
RemoteSigned Locally created scripts will run; downloaded scripts
must be digitally signed.
AllSigned Scripts signed by a trusted publisher will run.
Unrestricted Any script, signed or unsigned, will run.
Set-ExecutionPolicy Unrestricted
OV 4 - 18
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
User Management PowerShell Cmdlets
Get-AdUser
New-ADUser
Set-ADUser
Enable-ADAccount
DisableADAccount
Remove-ADUser
Unlock-ADAccount
Set-ADAccountPassword
Set-ADAccountExpiration
OV 4 - 19
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Parameters for User Account
Management
AccountExpirationDate<DateTime>
AccountPassword<securestring>
CannotChangePassword<Boolean>
ChangePasswordatlogon<Boolean>
Department<String>
DisplayName<String>
HomeDirectory<String>
ProlePath
EmailAddress
OV 4 - 20
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Display All User Accounts
Get-ADUser lter *
OV 4 - 21
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
View User Properties
Get-ADUser Tracy White Properties *
OV 4 - 22
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Users Home Folder Set Up in PowerShell
Set-ADUser Tracy White HomeDirectory \\Users\tracywhitehomedir
OV 4 - 23
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Inactive and Disabled Accounts
Right-click an account in Active Directory Users and Computers to enable
or disable it.
PowerShell examples:
Get-ADUser lter department eq Training | Enable-ADAccount
$90Days = (get-date).adddays(-90)
Get-ADUser -lter {(lastlogondate -le $90Days) -and (enabled -eq $true)} | Disable-
ADAccount
OV 4 - 24
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Group Management Cmdlets
Perform individual operations.
Create scripts to perform bulk operations.
Windows PowerShell Cmdlet Description
Get-ADGroup Displays property values for groups
New-ADGroup Creates new groups
Set-ADGroup Modies group properties
Remove-ADGroup Deletes groups
OV 4 - 25
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Parameters for Group Management
Groups have over 40 properties.
Get-ADGroup identity Users Property * Returns all properties
Parameter Description
Name Denes the group name.
GroupScope Denes the group scope as domain local, global, or universal. You must
include this parameter.
DisplayName Denes the Lightweight Directory Access Protocol (LDAP) display name.
ManagedBy Denes a user or group that can manage the group.
Path Denes the organizational unit (OU) in which the group is created.
SamAccountName Denes a name that is backward compatible with older operating
systems.
OV 4 - 26
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Viewing Group Properties in PowerShell
Get-ADGroup identity Users Returns most common properties
OV 4 - 27
Copyright 2013 IT University Online All rights reserved. www.ituniversityonline.com
Verifying Group Creation