Implementing Active Directory Domain Services

Slides:



Advertisements
Similar presentations
Module 5: Creating and Configuring Group Policy
Advertisements

Chapter 6 Introducing Active Directory
Introduction to Active Directory
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
Hands-On Microsoft Windows Server 2003 Administration Chapter 3 Administering Active Directory.
Chapter 4 Introduction to Active Directory and Account Management
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
Understanding Active Directory
Hands-On Microsoft Windows Server 2008
Chapter 7 WORKING WITH GROUPS.
Hands-On Microsoft Windows Server 2008
Vikram Thakur Introduction to Active Directory Structure.
ADVANCED MICROSOFT ACTIVE DIRECTORY CONCEPTS
Module 1: Installing Active Directory Domain Services
Module 1: Installing Active Directory Domain Services
Overview of Active Directory Domain Services Lesson 1.
Overview of Active Directory Domain Services Lesson 1.
(ITI310) SESSIONS : Active Directory By Eng. BASSEM ALSAID.
9.1 © 2004 Pearson Education, Inc. Lesson 9: Implementing Group Policy in Windows 2000 Server Exam Microsoft® Windows® 2000 Directory Services Infrastructure.
11 REVIEWING MICROSOFT ACTIVE DIRECTORY CONCEPTS Chapter 1.
Active Directory Administration Lesson 5. Skills Matrix Technology SkillObjective DomainObjective # Creating Users, Computers, and Groups Automate creation.
Chapter 4 Introduction to Active Directory and Account Management
Module 1 Introduction to Managing Microsoft® Windows Server® 2008 Environment.
Session 6 Windows Platform Dina Alkhoudari. Learning Objectives What is Active Directory Logical components of active directory Physical components of.
Windows Server 2008 Chapter 4 Last Update
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 3: Introducing Active Directory.
Module 12: Designing an AD LDS Implementation. AD LDS Usage AD LDS is most commonly used as a solution to the following requirements: Providing an LDAP-based.
A detailed look at the Microsoft Windows Infrastructure at UWE including Active Directory (AD), MIIS, Exchange, SMS, IIS, SQL Server, Terminal Services.
KAPLAN SCHOOL OF INFORMATION SYSTEMS AND TECHNOLOGY Welcome to Unit 4 IT278 Network Administration Course Name – IT278 Network Administration Instructor.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 5: Active Directory Logical Design.
Maintaining Active Directory Domain Services
Active Directory Administration Lesson 5. Skills Matrix Technology SkillObjective DomainObjective # Creating Users, Computers, and Groups Automate creation.
Module 6: Implementing Group Policy. Overview Implementing Group Policy Objects Implementing GPOs in a Domain Managing the Deployment of Group Policy.
Module 7 Active Directory and Account Management.
1 Windows 2008 Configuring Server Roles and Services.
GPO - WINDOWS SERVER AGENDA: Introduction Group Policy Overview Types of Group Policies/Objects Associated Technologies How to implement.
 Identify Active Directory functions and Benefits.  Identify the major components that make up an Active Directory structure.  Identify how DNS relates.
Introduction to Active Directory Domain Services
Module 1: Implementing Active Directory ® Domain Services.
Windows Server 2003 La migrazione da Windows NT 4.0 a Windows Server 2003 Relatore: MCSE - MCT.
Module 5: Creating and Configuring Group Policies.
Hands-On Microsoft Windows Server 2008 Chapter 4-Part 1 Introduction to Active Directory and Account Manager.
Module 3 Creating Groups and Organizational Units.
Module 3 Planning for Active Directory®
Installing a Domain Controller
OVERVIEW OF ACTIVE DIRECTORY
Introduction to Active Directory
Module 1: Introduction to Active Directory
Hussain Ali Department of Computer Engineering KFUPM, Dhahran, Saudi Arabia Active Directory.
CEG 2400 Fall 2012 Directory Services Active Directory Tree Domain.
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
Overview of Active Directory Domain Services Lesson 1.
Module 8: Implementing Group Policy. Overview Multimedia: Introduction to Group Policy Implementing Group Policy Objects Implementing GPOs on a Domain.
Active Directories: Purpose and Structure Chrystom Ciganko IFMG352 Final Presentation.
Module 2: Implementing an Active Directory Forest and Domain Structure.
Assignment # 8.
Overview of Active Directory Domain Services
Module 1: Introduction to Administering Accounts and Resources
Overview of Active Directory Domain Services
(ITI310) SESSIONS 6-7-8: Active Directory.
Active Directory Administration
Objectives Differentiate between the different editions of Windows Server 2003 Explain Windows Server 2003 network models and server roles Identify concepts.
MCSA VCE
Unit 3 NT1330 Client-Server Networking II Date: 1/6/2016
Windows Server 2008 Administration
Network Administration
Windows Active Directory Environment
Module 8: Implementing Group Policy
Unit 6 NT1330 Client-Server Networking II Date: 7/19/2016
Presentation transcript:

Implementing Active Directory Domain Services

Module Overview Introducing AD DS Implementing AD DS Managing Users, Groups, and Computers Implementing Organizational Units Implementing Group Policy

Introducing AD DS The AD DS Forest The AD DS Schema What Is a Domain? AD DS Trees Organizational Units Trust Relationships

The AD DS Forest Domain Trust Forest contoso.com tailspintoys.com corp.contoso.com test.contoso.com orders.tailspintoys.com clients.tailspintoys.com Forest

The schema is the framework of which AD DS is composed The AD DS Schema The schema is the framework of which AD DS is composed Example class objects include: Organizational units Users Computers Example attributes include: Description User name Computer location

A domain is created when you promote a server to a What Is a Domain? A domain is created when you promote a server to a domain controller A domain is: An administrative boundary A replication boundary An authentication boundary

Implementing AD DS What Is a Domain Controller? What Is a Read-Only Domain Controller? AD DS Sites AD DS Replication Configuring DNS for AD DS

What Is a Domain Controller? Domain controllers : Provide authentication Host operations master roles Host the global catalog Support group policies and SYSVOL Provide for replication

What Is a Read-Only Domain Controller? RODCs host read-only partitions of the AD DS database, only accept replicated changes to AD DS, and never initiate replication RODC RODCs provide: Additional security for branch office with limited physical security Additional security if applications must run on a domain controller RODCs: Cannot hold operations master roles or be configured as replication bridgehead servers Can be deployed on servers running Windows Server 2008 R2 Server core for additional security

AD DS Sites Bellevue Seattle Redmond

Configuring DNS for AD DS Considerations: You can install DNS as part of the domain controller deployment process You can integrate the DNS zone into AD DS Use secure dynamic updates for your DNS zone Use multiple DNS servers to provide for high availability and load balancing SRV records enable the location of AD DS and other services

Managing Users, Groups, and Computers What Are User Accounts? What Are Groups? Nesting Groups Default Built-In Groups Computer Accounts Account Management Best Practices

What Are User Accounts? ü ü ü A user account is an object that contains all of the information that defines a user in Windows Server 2008 R2 With a user account, you can: Allow or deny users to log on based on their identity ü Grant users access to processes and services ü Manage users' access to resources ü

What Are Groups? A group is a collection of user accounts, computer accounts, contacts, and other groups that you can manage as a single unit Two main types of groups: Security Distribution Three scopes of groups: Domain local Global Universal

Default Built-In Groups You can use the built-in groups to simplify administration

Computer Accounts The most commonly used properties for computer accounts in AD DS are the Location and Managed By properties

Implementing Organizational Units Why Use Organizational Units?

Why Use Organizational Units? Organizational units in a domain An OU is a container within a domain Computer Account User Account You can deploy your OUs into a hierarchical structure based on geography, department, resources, management requirements, or a combination of all of these

Implementing Group Policy What Is a GPO? Applying GPOs Creating and Managing GPOs Policies and Preferences

What Is a GPO? Group Policy enables IT administrators to automate one-to-many management of users and computers Use Group Policy to: Apply standard configurations Deploy software Enforce security settings Enforce a consistent desktop environment Local Group Policy is always in effect for local and domain users and local computer settings

Applying GPOs Computer starts User logs on Computer settings applied Refresh Interval: Every 90 minutes Computer settings applied Startup scripts run User logs on Refresh Interval: Every 90 minutes User settings applied Logon scripts run

Creating and Managing GPOs You can use a number of tools to create and manage GPOs, including the Group Policy Management Console

Summary Introducing AD DS Implementing AD DS Managing Users, Groups, and Computers Implementing Organizational Units Implementing Group Policy