Chapter 3
Chapter 3
Chapter 3
Global Catalog
Domain Controller
Organizational Unit
Tree
Domain
What Are Active Directory Partitions?
Active
Active Directory
Directory partitions
partitions contain
contain discreet
discreet information
information about
about
the
the AD
AD DS
DS directory
directory
Domain Partition
Configuration
Partition
Schema Partition
AD DS
DC Database
Application
Partition (optional)
What Is Active Directory Replication?
Active
Active Directory
Directory partitions
partitions contain
contain discreet
discreet information
information about
about
the
the AD
AD DS
DS directory
directory
AD DS AD DS
DC Database Database
DC
What Are Active Directory Sites?
Active
Active Directory
Directory sites
sites are
are objects
objects stored
stored in
in the
the directory
directory
representing
representing network
network topology
topology
Site
Site Site
Site links
Demonstration: How to setup Active Directory
Domain Services
In this demonstration, you will see how to:
• Install AD DS on Windows Server 2008 R2
• Install AD DS on Windows Server 2012 R2
Domain and Forest Functional Levels
Domain
Domain and
and forest
forest functional
functional levels
levels define
define the
the level
level of
of Active
Active
Directory
Directory functionality
functionality supplied
supplied by
by all
all domain
domain controllers
controllers
within
within aa domain
domain or
or forest
forest
Domain and Forest Functional Levels (Cont’d)
Operations Master Roles
Operations
Operations Master
Master Roles
Roles are
are assigned
assigned to
to a
a server
server that
that is
is
responsible
responsible for
for performing
performing that
that role’s
role’s task
task
Active
Active Directory
Directory Administration
Administration snap-ins
snap-ins consist
consist of
of four
four
different
different Microsoft
Microsoft Management
Management Console
Console snap-ins
snap-ins
• User Management
• Computer Management
• Group Management
• Organizational Unit Management
• Password Policy Management
• Searching and modifying objects
• Forest and Domain Management
• Domain Controller and Operations Master Management
• Managed Service Account Management
2.3 Managing User Accounts
• What Is a User Account?
• User Account Password Options
• User Account Attributes
• Demonstration: Configuring User Accounts
• What Is a User Account Template?
What Is a User Account?
A
A user
user account
account is
is an
an object
object that
that enables
enables authentication
authentication and
and
access
access to
to local
local and
and network
network resources
resources
Local
Local accounts
accounts enable
enable log
log on
on to
to a
a single
single computer
computer and
and
local
local resources
resources
• General
• Account
• Profile
• Organization
• Member Of
• Dial-in
Demonstration: Configuring User Accounts
In this demonstration, you will see how to do the following:
• Create and configure an AD DS user account by using
Active Directory Users and Computers
• Create and configure an AD DS user account by using
Active Directory Administrative Center
• Create and configure an AD DS user account by using
Windows PowerShell
What Is a User Account Template?
A
A user
user account
account template
template is
is an
an account
account with
with common
common properties
properties
already
already configured
configured
Offline
Offline domain
domain join
join is
is a
a new
new process
process can
can be
be used
used by
by computers
computers
that
that run
run Windows
Windows 7 7 or
or Windows
Windows Server
Server 2008
2008 R2
R2 to
to join
join a
a domain
domain
without
without contacting
contacting a
a domain
domain controller
controller
• Copy the blob.txt file to NYC-CL1 and run this command from NYC-
CL1, even if disconnected from the domain
There
There are
are a
a number
number of
of tools
tools that
that can
can be
be used
used to
to automate
automate the
the
computer
computer account
account creation
creation process
process
Tool Examples:
• DSAdd.exe
• Netdom.exe
• CSVDE
• LDIFDE
• Windows PowerShell
Managing
Managing computer
computer accounts
accounts requires
requires several
several management
management tasks
tasks
ProductionDept
Executives
ACL_Read_Production_Folders
MarketingDept
Group Types and Scope
• Distribution
• Domain Local
• Global
• Universal
What Are Global Groups?
Members:
•• User
User and
and Computer
Computer accounts
accounts from
from the
the same
same
domain
domain as
as the
the global
global group
group
•• Global
Global groups
groups from
from the
the same
same domain
domain as
as the
the global
global group
group
Permissions:
Global
Global groups
groups can
can be
be assigned
assigned permissions
permissions in
in any
any domain
domain in
in
the
the forest
forest or
or any
any trusting
trusting domain
domain
Usage:
•• Manage
Manage directory
directory objects
objects that
that require
require daily
daily maintenance,
maintenance, such
such
as
as user
user and
and computer
computer accounts
accounts
•• Group
Group users
users who
who have
have similar
similar network
network access
access requirements
requirements
Permissions:
Can
Can be
be assigned
assigned permissions
permissions in
in any
any domain
domain in
in the
the forest
forest or
or
any trusting domain
any trusting domain
Usage:
•• Use
Use to
to combine
combine groups
groups that
that span
span domains
domains
Usage:
Usage:
•• Use
Use to
to define
define and
and manage
manage access
access to
to resources
resources in
in a
a single
single domain
domain
Permissions:
Permissions:
Member
Member permissions
permissions can
can be
be assigned
assigned only
only within
within the
the same
same domain
domain as
as
the domain local group
the domain local group
Can
Can be
be converted
converted to:
to:
•• Universal
Universal (if
(if no
no other
other domain
domain local
local groups
groups exist
exist as
as members)
members)
What Is Group Nesting?
Nesting
Nesting allows
allows for
for groups
groups to
to be
be
members
members ofof other
other groups
groups
When
When nesting,
nesting, apply
apply the
the AGDLP
AGDLP or
or AGUDLP
AGUDLP principle
principle
2.6 Using Queries to Locate Objects in AD DS