Introduction To Active Directory
Introduction To Active Directory
Directory
Tech Coordinator Feast
2007
– Groups
• Two types – Security and Distribution
• Domain Local – Include Global/Universal
Groups, Applies to Local Domain only
• Global – Includes Only Domain Local
Groups, Applies to any Domain in the forest
that is trusted
• Universal – Included Anywhere, Applies
Anywhere
Active Directory Users and
Computers
Users
– Login/out Options
– Login script - c:\WINDOWS\SYSVOL\sysvol\
district87.org\scripts
– Home Directory Setup
Active Directory Users and
Computers
• Shares/Permissions
– Most Restrictive = Winner
– Denied = Denied NO MATTER WHAT
– 2003 Shares now default to READ ONLY instead
of Full Control
– Rule of Thumb, Control access through folder
permissions not share permissions.
Active Directory Users and
Computers
– Creating OUs
» Reasons for OUs
» Separating Computers and Users
– FSMO Roles
» Operations Manager
» RID
» PDC Emulator
» Infrastructure
Active Directory Sites and Services
– Quick overview
– FSMO Roles
» Domain Naming Operations Manager
Active Directory Schema
ADSI Edit
• Install – Windows 2000/2003 Support Tools
(On the CD Under /Supports/Tools)
• Quick overview
• MMC
– Brief Overview
– Useful for putting together a common set of tools for
different levels of use
• Adminpak.msi
• OU Permissions
– Turn on Advanced Features in the View Menu
– Ex: Setup a group of staff that can ONLY
change/reset student passwords
• Set permissions in User Objects, Properties Tab
– Read/Write Account Restrictions
• Set permissions in User Objects, Object Tab
– Change Password
– Reset Password
• Adding a new AD Server
– Run dcpromo
– Setup a new site if it is replicating data
over a WAN link
– Setup extra services if needed
• Removing an AD Server Gracefully
– Transfer All 5 FSMO Roles and Global Catalog
Role
– Transfer any services such as
DHCP/WINS/DNS/RIS to another machine.
– Use dcpromo to demote the machine
• Removing an AD Server Ungracefully
– http://www.petri.co.il/transferring_fsmo_roles.htm
– Change Global Catalog Server to a different server
– Delete out the old Server in AD Management or
using ADSI Edit.
That is it!!!!!