Windows 2000 Server Practicum Ac. J. 2002-2003 Prof. Koen De Bosschere ir. Ronny Blomme.

Slides:



Advertisements
Similar presentations
Linux-oefening Operationele Aspecten van Besturingssystemen Prof. Koen De Bosschere ir. Ronny Blomme.
Advertisements

Managing User, Computer and Group Accounts
1 Preparing Windows 2000 installation (Week 3, Wednesday 2/25/2006) © Abdou Illia, Spring 2006.
Windows Server 2003 使用者群組管理 林寶森
Chapter 9 Chapter 9: Managing Groups, Folders, Files, and Object Security.
Introduction to Active Directory
6.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
11 SUPPORTING LOCAL USERS AND GROUPS Chapter 3. Chapter 3: Supporting Local Users and Groups2 SUPPORTING LOCAL USERS AND GROUPS  Explain the difference.
1 Chapter 1 Introduction to Windows Server Two main goals for Net Admin Make network resources available to users Files, folders, printers, etc.
Chapter 6: Configuring Security. Group Policy and LGPO Setting Options Software Installation not available with LGPOs Remote Installation Services Scripts.
Hands-On Microsoft Windows Server 2003 Chapter 2 Installing Windows Server 2003, Standard Edition.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
5.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 5: Working with File Systems.
Hands-On Microsoft Windows Server 2003 Administration Chapter 6 Managing Printers, Publishing, Auditing, and Desk Resources.
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
Network+ Guide to Networks, Fourth Edition Chapter 8 Network Operating Systems and Windows Server 2003-Based Networking.
Windows Server 2003 Windows Server Family Products Windows Server 2003 Web Edition Windows Server 2003 Standard Edition Windows Server 2003 Enterprise.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
1 Chapter Overview Creating User and Computer Objects Maintaining User Accounts Creating User Profiles.
Tasks Necessary for Setting Up a Hard Disk Initializing the disk with basic or dynamic storage type Creating partitions on basic disks or volumes on dynamic.
11 WORKING WITH USER ACCOUNTS Chapter 6. Chapter 6: WORKING WITH USER ACCOUNTS2 CHAPTER OVERVIEW Understand the differences between local user and domain.
Test Review. What is the main advantage to using shadow copies?
Hands-On Microsoft Windows Server 2008 Chapter 1 Introduction to Windows Server 2008.
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 3: Introducing Active Directory.
Chapter 4 Windows NT/2000 Overview. NT Concepts  Domains –A group of one or more NT machines that share an authentication database (SAM) –Single sign-on.
A+ Guide to Managing and Maintaining Your PC Fifth Edition Chapter 15 Installing and Using Windows XP Professional.
Chapter-4 Windows 2000 Professional Win2K Professional provides a very usable interface and was designed for use in the desktop PC. Microsoft server system.
1 Group Account Administration Introduction to Groups Planning a Group Strategy Creating Groups Understanding Default Groups Groups for Administrators.
IOS110 Introduction to Operating Systems using Windows Session 7 1.
Chapter 7: WORKING WITH GROUPS
Gorman, Stubbs, & CEP Inc. 1 Introduction to Operating Systems Lesson 12 Windows 2000 Server.
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
Windows 2000 Operating System -- Active Directory Service COSC 516 Yuan YAO 08/29/2000.
11 WORKING WITH USER ACCOUNTS Chapter 6. Chapter 6: WORKING WITH USER ACCOUNTS2 UNDERSTANDING USER ACCOUNTS  Local user accounts  stored in the Security.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
Managing Groups, Folders, Files and Security Local Domain local Global Universal Objects Folders Permissions Inheritance Access Control List NTFS Permissions.
A+ Guide to Managing and Maintaining Your PC Fifth Edition Chapter 13 Understanding and Installing Windows 2000 and Windows NT.
© Wiley Inc All Rights Reserved. MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition.
FORESEC Academy FORESEC Academy Security Essentials (V)
Introduction to Microsoft Management Console (MMC) MMC is a common console framework for management applications. MMC provides a common environment for.
1 Introduction to Microsoft Windows 2000 Windows 2000 Overview Windows 2000 Architecture Overview Windows 2000 Directory Services Overview Logging On to.
Active Directory Maryam Izadi. Topics Covered NT Vs 2000/2003 Active Directory LDAP MMC.
1 Administering Shared Folders Understanding Shared Folders Planning Shared Folders Sharing Folders Combining Shared Folder Permissions and NTFS Permissions.
Chapter 14 Supporting Windows 2000 Professional. 14 You Will Learn… n About the different operating systems within the Windows 2000 suite n About the.
Chapter 10 Chapter 10: Managing the Distributed File System, Disk Quotas, and Software Installation.
Introduction to Microsoft Windows 2000 Welcome to Chapter 1 Windows 2000 Server.
Chapter 10: Rights, User, and Group Administration.
Working with Workgroups and Domains Lesson 9. Objectives Understand users and groups Create and manage local users and groups Understand the difference.
Working with Users and Groups Lesson 5. Skills Matrix Technology SkillObjective DomainObjective # Introducing User Account Control Configure and troubleshoot.
NetTech Solutions Security and Security Permissions Lesson Nine.
Administering Groups Chapter Eight. Exam Objectives In this Chapter:  Plan a security group hierarchy based upon delegation requirements  Plan a security.
Module 10: Implementing Administrative Templates and Audit Policy.
Working with Users and Groups Lesson 5. Skills Matrix Technology SkillObjective DomainObjective # Introducing User Account Control Configure and troubleshoot.
MIS Chapter 41 Chapter 4 – Implementing and Managing Group and Computer Accounts MIS 431 – Created Spring 2006.
1 Chapter Overview Using Group Objects Understanding Default Groups Creating Group Objects Managing Administrative Access.
Windows 2003 Architecture, Active Directory & DNS Lecture # 3 Hassan Shuja 02/14/2006.
1 Introduction to Shared Folders Shared folders provide network users access to files. Users connect to the shared folder over the network. Users must.
Chapter 1 Introducing Windows Server 2012/R2
DIT314 ~ Client Operating System & Administration
Implementing Active Directory Domain Services
Introduction to Operating Systems
Active Directory Administration
Objectives Differentiate between the different editions of Windows Server 2003 Explain Windows Server 2003 network models and server roles Identify concepts.
Active Directory Stored collection of information about objects
Windows Server 2008 Administration
Windows Server 2003 使用者群組管理
Chapter 9: Managing Groups, Folders, Files, and Object Security
Introducing NTFS Reliability Security Long file names Efficiency
Presentation transcript:

Windows 2000 Server Practicum Ac. J Prof. Koen De Bosschere ir. Ronny Blomme

Doel van de oefening ! Configureren en beheren van een Windows 2000 server 1 File system: partition, share, … 1 Accounts: user, group, … 1 Security: access rights, policy, …

VMWare  Virtuele PC, 128MB ram  Non-persistent disk, 4GB: Reset (of Power Off + Power On) = oefening herbeginnen. Windows2000 shutdown = oefening herbeginnen. Windows2000 Restart is OK  Network: host only  in VMWare venster of via Power menu

Win2000 Edities  Windows 2000 Professional  vergelijk: Windows NT Workstation  Windows 2000 Server  active directory services: netwerkbeheer van gebruikers en andere middelen  Windows 2000 Advanced Server  high availability (clustering), scalability (smp: 8)  Windows 2000 Datacenter Server  load balancing, enhanced clustering

Domain/Workgroup

Active Directory  Stored collection of information about objects  Database of network objects  Information related to network resources to facilitate locating and managing objects  Identifies users and resources  Provides a way to organize and access users and resources  Allows you to perform a number of functions  Acts as administration tool and end-user tool

Structuur  Objecten (verzameling attributen) * object class = logische groepering van objecten (vb. Users, Groups, Computers)  Organizational units (OUs) * logische administratieve groepen in een domein  Domains: security boundary  Trees: hiërarchie van domeinen  Forests: verzameling trees (zonder dns hiërarchie)

Installatie Win Voorbereiding  Minimum hardware vereisten  Hardware Compatibility List  Disk partitionering  FAT of NTFS  Licentie-schema: “per-server” of “per-seat”  Workgroup of Domain  Nieuwe installatie of Update  Backup huidige configuratie

Installatie Win2000  Bootable CDROM  4 setup-floppies + CDROM e: cd bootdisk makeboot a:  Update vanuit WinNT3.51, WinNT4.0 (geen conversie van workstation naar server)  Unattended install

Bestandensysteem  NTFS  file en directory beveiliging  disk compressie  disk quota  encryptie  FAT16 - FAT32  compatibiliteit met andere besturingssystemen

Installatieverloop  Pre-Copy phase  Text Mode phase  GUI Mode phase

Disk Management: storage types

Disk management snap-in

NTFS 5.0 (skip)  Reparse points (hierarchical storage management + monteren van een logisch volume in een lege directory)  Native Structured Storage (NSS)  Disk quotas  Sparse file support  Line tracking and object identifiers  Change Journal  CD and DVD support

Shared Folder Permissions  van toepassing op folders, niet op individuele bestanden.  bieden geen bescherming indien de toegang gebeurt via de lokale computer, enkel bescherming indien toegang via netwerk  enige bescherming op FAT volumes.  default folder permission: Everyone Full Control.  allow or deny shared folder permissions to individual users or to user groups.  Assign permissions to groups instead of user accounts to simplify access administration.

Administrative Shared Folders  C$, D$, E$,...  Admin$ = C:\Winnt (the system root folder)  Print$ = C:\Winnt\System32\Spool\Drivers (voor gedeelde printers)

NTFS Permissions: richtlijnen  Group resources into application, data, and home folders.  Use NTFS permissions to control access to files and folders.  Assign permissions to groups rather than individual user accounts.  When assigning permissions to home folders, centralize home folders on a network volume separate from applications and the operating system.  When assigning permissions to working data or applications folders, remove the default Full Control permission from the Everyone group.  When assigning permissions to public data folders, assign Modify permission and Read & Execute permission to the Users group and Full Control permission to the Creator Owner.  It is better not to assign permissions than to deny permissions.  Users should assign permissions to files and folders they own.

Distributed File System (Dfs)

Dfs links

Active Directory Services  Domain Modes: Mixed of Native  Organizational Units en hun objecten: – Each Active Directory object is a distinct named set of attributes that represents a specific network resource. – Before objects are added to Active Directory services, you should create the OUs that will contain those objects.

Active Directory Objects  Wijzigen van “attributes values”: Object Properties  Verplaatsen van Objecten  Opzoeken van Objecten (skip) ContactGroupUser Shared Folder Printer Computer

Win2000 User Accounts  Domain user accounts:  worden gecreëerd in een OU  Local user accounts:  niet in de Active Directory  Built-in user accounts:  Administrator  Guest

User Profile / Home Directory  C:\Documents and Settings\  Roaming profiles vs local user profile  Mandatory profiles  Ntuser.dat vs Ntuser.man  Home directory  shared folder, NTFS permissions

Groepen  Security en Distribution groepen  Scope: " Domain local (assign permissions to resources) " Global (users met dezelfde rechten) " Universal (enkel in native mode) - domeinoverschrijdend  Nesting (beperk u tot 2 niveaus)  Builtin: Account Operators, Admins, Guests...

Group Policy  Centraal beheer van de gebruikers- (desktop)omgeving  Controle over de programma’s die beschikbaar zijn voor de gebruiker, welke beschikbaar zijn op zijn desktop of in het Start menu  Active Directory - Group Policy Container - Group Policy Object  Group Policy Template (o.a. logon logoff scripts) %systemroot%\SYSVOL\sysvol\microsoft.com\Policies\...

Niet in deze oefening...  Beheer van Printer services  Netwerkprotocollen en services  Routing en Remote Access Service (o.a. VPN)  Security: PKI, Cryptografie, Certificaten, Kerberos, Auditing  Reliability / Availability  Monitoring en optimalisatie  Application servers, IIS