Windows Enterprise Services.  Introductions  UNM Directory Services  RSAT  Organizational Units (OU)  Active Directory Groups  Naming Convention.

Slides:



Advertisements
Similar presentations
AD Child Domains By: Joan Carter 05/29/2003. Who can bring up a child domain in AD.ASU.EDU?  Campus/college/VP level units  Considerations: Is there.
Advertisements

File Server Organization and Best Practices IT Partners June, 02, 2010.
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 6 Managing and Administering DNS in Windows Server 2008.
Module 6: Configuring Windows XP Professional to Operate in a Microsoft Network.
Lesson 17: Configuring Security Policies
Module 5: Creating and Configuring Group Policy
Managing User Settings with Group Policy
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
Chapter 9 Chapter 9: Managing Groups, Folders, Files, and Object Security.
6.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
15.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
10.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 9: Implementing and Using Group Policy.
Chapter 6: Configuring Security. Group Policy and LGPO Setting Options Software Installation not available with LGPOs Remote Installation Services Scripts.
Chapter 5: Configuring Users and Groups. Windows Vista User Accounts User accounts are the primary means of authentication Built-in Accounts –Administrator:
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
By Rashid Khan Lesson 8-Crowd Control: Controlling Access to Resources Using Groups.
Hands-On Microsoft Windows Server 2003 Administration Chapter 6 Managing Printers, Publishing, Auditing, and Desk Resources.
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 7 Configuring File Services in Windows Server 2008.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
Guide to MCSE , Enhanced 1 Activity 9-1: Creating a Group Policy Object Using the MMC Objective: To create a GPO using the Group Policy Object Editor.
Chapter 7 WORKING WITH GROUPS.
Chapter 7 Managing OUs and Active Directory Accounts
Active Directory: OU Administration December 17th, pm Daniels 407.
Introduction to Active Directory December 10th, pm Daniels 407.
Module 1: Introduction to Administering Accounts and Resources
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 3: Introducing Active Directory.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
1 Week 3 Secure and Efficient Administration of Act. Dir. Work with Active Directory Snap-Ins Custom Consoles and Least Privilege Find Objects in Active.
1 Group Account Administration Introduction to Groups Planning a Group Strategy Creating Groups Understanding Default Groups Groups for Administrators.
Chapter 7: WORKING WITH GROUPS
Part I.  NOS  Directory Data Store(directory service, database)  Located on Domain Controllers (DCs), globally distributed, replicated (no longer PDCs/BDCs)
IOS110 Introduction to Operating Systems using Windows Session 8 1.
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
Managing Groups, Folders, Files and Security Local Domain local Global Universal Objects Folders Permissions Inheritance Access Control List NTFS Permissions.
Active Directory Administration Lesson 5. Skills Matrix Technology SkillObjective DomainObjective # Creating Users, Computers, and Groups Automate creation.
Microsoft ® Official Course Module 3 Managing Active Directory Domain Services Objects.
Introduction to Microsoft Management Console (MMC) MMC is a common console framework for management applications. MMC provides a common environment for.
Module 7 Configure User and Computer Environments By Using Group Policy.
Active Directory Maryam Izadi. Topics Covered NT Vs 2000/2003 Active Directory LDAP MMC.
1 Administering Shared Folders Understanding Shared Folders Planning Shared Folders Sharing Folders Combining Shared Folder Permissions and NTFS Permissions.
Planning a Microsoft Windows 2000 Administrative Structure Designing default administrative group membership Designing custom administrative groups local.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 11: Group Policy for Corporate Policy.
Module 5: Creating and Configuring Group Policies.
Module 4 Planning for Group Policy. Module Overview Planning Group Policy Application Planning Group Policy Processing Planning the Management of Group.
1 Chapter Overview Managing Object and Container Permissions Locating and Moving Active Directory Objects Delegating Control Troubleshooting Active Directory.
Company Confidential 1 A Course on Planning A Group Policy Management And Implementation Strategy Prepared for: *Stars* New Horizons Certified Professional.
© Wiley Inc All Rights Reserved. MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition.
11 PLANNING A GROUP POLICY MANAGEMENT AND IMPLEMENTATION STRATEGY Chapter 10.
Administering Groups Chapter Eight. Exam Objectives In this Chapter:  Plan a security group hierarchy based upon delegation requirements  Plan a security.
Module 6: Configuring User Environments Using Group Policies.
Active Directory. Computers in organizations Computers are linked together for communication and sharing of resources There is always a need to administer.
Module 6 Creating and Configuring Group Policy. Module Overview Overview of Group Policy Configuring the Scope of Group Policy Objects Evaluating the.
Module 3: Managing Groups. Overview Creating Groups Managing Group Membership Strategies for Using Groups Using Default Groups.
Windows 2003 Architecture, Active Directory & DNS Lecture # 3 Hassan Shuja 02/14/2006.
1 Introduction to Shared Folders Shared folders provide network users access to files. Users connect to the shared folder over the network. Users must.
GROUP POLICY. Group Policy is a hierarchical infrastructure which allows systems administrators to configure computer and user settings from a central.
This courseware is copyrighted © 2016 gtslearning. No part of this courseware or any training material supplied by gtslearning International Limited to.
1.1 Microsoft® Windows® 2003 Server Group Policy Management Prof. Abdul Hameed.
Essential Services Lesson 5. Objectives Naming Resolution In today’s networks, you assign logical addresses, such as with IP addressing. Unfortunately,
Active Directory Administration
Objectives Differentiate between the different editions of Windows Server 2003 Explain Windows Server 2003 network models and server roles Identify concepts.
Windows Server 2008 Administration
Presentation transcript:

Windows Enterprise Services

 Introductions  UNM Directory Services  RSAT  Organizational Units (OU)  Active Directory Groups  Naming Convention  Joining Workstations  File Services  Sharing & Security tabs  GPOs  OU Administrators Responsibilities  Troubleshooting tools  Guidelines  Support

 LAMB – Authoritative Source of information for AD – Process of NetID creation, org code to OU mapping, account retention  Active Directory – Microsoft’s implementation of LDAP – Empty root – Colleges and HSC domains

 RSAT (Remote Server Administration Tools) – allows administrators to run snap-ins and tools on a remote computer to manage features and roles – Computers includes the AD Users and (ADUC) and Group Policy Management tools  Windows 7  Windows 8

 Delegate responsibility to UNM departments and affiliates  OU Admins are responsible for their own OU structures  Enterprise Admins oversee entire forest  Standard Sub-OUs we create for you: Accounts - populated by LDAP. DO NOT DISABLE OR DELETE Groups - where you create groups Servers – your departmental servers here SvcAcnts – privileged application or admin accounts Workstations - your workstations. PRESTAGE COMPUTERS BEFORE JOINING TO AD

 Group Types: – Security Groups  Universal: Cross forest  Global: Between domains  Domain Local: In your domain – Distribution Groups: Not what it used to be!  Microsoft’s Best Practice - AGDLP – The order to assign user permissions to resources - Accounts, Global, Domain Local, Permissions – Role based security provisioning  User Roles correspond to a global group  Security Roles are assigned to a domain local group  Demo

 Workstations, Servers & Printers – ABC-LN – ABC153WEB01 – ABC Konika284  Groups – ABC-OUAdmins-DL – ABC-OUAdmins-GG  Service Accounts – sqlABCSVC (SQL service in ABC dept) – ahABCSVC (admin acct in ABC dept)  Group Policy Objects (GPOs) – ABC-Classroom 103 File Share

 Pre-stage all computers – Use your svc account – Demo  Join workstations to colleges.ad.unm.edu – Local vs. domain user profiles – Netdom join /d:colleges.ad.unm.edu ABC-DC8MRSJ1 /OU:OU=Workstations,OU=ABC,DC=colleges,DC=ad,DC=unm,DC=edu /ud:colleges\ahabcsvc /pd:MySecretPassword – Add-Computer –DomainName colleges.ad.unm.edu –OUPath “OU=Workstations,OU=ABC,DC=colleges,DC=ad,DC=unm,DC=edu” – Credential colleges\ahabcsvc -Restart

 Centralized storage and backup  Mapped drives – Shared and Home directories

 Sharing – Create a Domain Local group for your department – Grant access to that group  Security – NTFS – Full Control should only be given to OU Admins – Do not remove Domain Admins group – Combination of Modify, Read & Execute, List folder contents, Read and Write permissions may be assigned to User groups – NTFS permissions should be less permissive than Sharing permissions

 Group Policy Objects – Customized MMC – Default GPOs we create for you – How to request and test GPOs – Support model  Scripts vs Preferences  Loopback Processing Mode

 Support for your end users  Managing your department’s resources  Managing permissions for resources  Securing your department’s data

 Command line tools – demo – Nslookup - queries DNS entries and ip lookup – Ping - see if a host is reachable by IP. Firewall restrictions can limit this – Telnet - verifies a port is open on a resource – Gpudate /force - will immediately apply any group policy you have put in place instead of waiting – Gpresult /r /v - will detail what group policies are applied to the workstation and user  Powershell

 Please… – Do not remove Domain Admins group – Do not use your regular NetID for admin work. Always “Run as different user”. – Do not delete accounts.  Recycle Bin with 2008R2  Common Problems – Typos when pre-staging – Wired vs. wireless – AD is not down… (If it is, we already know it!) – Disabled & expired accounts – Changing group membership

 Contact IT Service Desk – – Submit incident or service request  FastInfo  aining/_layouts/15/start.aspx#/SitePages/Home.aspx aining/_layouts/15/start.aspx#/SitePages/Home.aspx 

Thank you