Windows Server ® 2008 and Windows Server ® 2008 R2 Active Directory ® Domain Services Infrastructure Planning and Design Published: February 2008 Updated:

Slides:



Advertisements
Similar presentations
Internet Information Services 7.0 and Internet Information Services 7.5 Infrastructure Planning and Design Published: June 2008 Updated: November 2011.
Advertisements

Selecting the Right Network Access Protection (NAP) Architecture Infrastructure Planning and Design Published: June 2008 Updated: November 2011.
Windows® Deployment Services
Windows Server ® 2008 File Services Infrastructure Planning and Design Published: June 2010 Updated: November 2011.
Active Directory and Group Policy Blackhat Amsterdam Raymond Forbes.
Microsoft ® System Center Configuration Manager 2007 R3 and Forefront ® Endpoint Protection Infrastructure Planning and Design Published: October 2008.
DirectAccess Infrastructure Planning and Design Published: October 2009 Updated: November 2011.
Module 14: Implementing an Active Directory Infrastructure.
Microsoft ® Forefront ® Unified Access Gateway Infrastructure Planning and Design Published: December 2009 Updated: July 2010.
Malware Response Infrastructure Planning and Design Published: February 2011 Updated: November 2011.
Windows Server ® 2008 Active Directory ® Domain Services Infrastructure Planning and Design Series Published: February 2008 Updated: July 2009.
Windows Server ® Virtualization Infrastructure Planning and Design Published: November 2007 Updated: July 2010.
70-297: MCSE Guide to Designing a Microsoft Windows Server 2003 Active Directory and Network Infrastructure Chapter 2: Developing the Active Directory.
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
CS603 Active Directory February 1, 2001.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
Microsoft ® Application Virtualization 4.5 Infrastructure Planning and Design Series.
Windows Server Virtualization Infrastructure Planning and Design Series.
Understanding Active Directory
Microsoft ® Application Virtualization 4.6 Infrastructure Planning and Design Published: September 2008 Updated: February 2010.
Module 1: Installing Active Directory Domain Services
11 REVIEWING MICROSOFT ACTIVE DIRECTORY CONCEPTS Chapter 1.
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 3: Introducing Active Directory.
Windows ® Deployment Services Infrastructure Planning and Design Published: February 2008 Updated: January 2012.
Windows Server ® Virtualization Infrastructure Planning and Design Published: November 2007 Updated: January 2012.
Microsoft ® Application Virtualization 4.6 Infrastructure Planning and Design Published: September 2008 Updated: November 2011.
Microsoft ® SQL Server ® 2008 and SQL Server 2008 R2 Infrastructure Planning and Design Published: February 2009 Updated: January 2012.
Microsoft ® System Center Operations Manager Infrastructure Planning and Design Published: November 2012.
Active Directory ® Certificate Services Infrastructure Planning and Design Published: June 2010 Updated: November 2011.
Microsoft ® System Center Operations Manager 2007 Infrastructure Planning and Design Published: June 2008 Updated: July 2010.
Windows ® User State Virtualization Infrastructure Planning and Design Published: August 2010.
Selecting the Right Virtualization Technology Infrastructure Planning and Design Series.
Internet Information Services 7.0 Infrastructure Planning and Design Series.
Selecting the Right Virtualization Technology Infrastructure Planning and Design Published: November 2007 Updated: November 2011.
Module 2 Designing Microsoft® Exchange Server 2010 Integration with the Current Infrastructure.
Windows Server ® 2008 File Services Infrastructure Planning and Design Published: October 2008 Updated: July 2009.
Microsoft ® System Center Service Manager Infrastructure Planning and Design Published: December 2010 Updated: April 2012.
Microsoft ® System Center Service Manager 2010 Infrastructure Planning and Design Published: December 2010.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 5: Active Directory Logical Design.
Maintaining Active Directory Domain Services
Designing Authentication for a Microsoft Windows 2000 Network Designing Authentication in a Microsoft Windows 2000 Network Designing Kerberos Authentication.
Microsoft ® Exchange Server 2010 with Service Pack 1 Infrastructure Planning and Design Published: December 2010 Updated: July 2011.
Microsoft ® System Center Data Protection Manager 2007 with Service Pack 1 Infrastructure Planning and Design Published: January 2009 Updated: July 2010.
Windows Server ® 2008 R2 Remote Desktop Services Infrastructure Planning and Design Published: November 2009.
Company Confidential 1 A Course on Global Catalog And Flexible Single Master Operations (Fsmo) Roles Prepared for: *Stars* New Horizons Certified Professional.
Microsoft ® Enterprise Desktop Virtualization Infrastructure Planning and Design Published: March 2009 Updated: November 2011.
Windows Server ® 2008 R2 Remote Desktop Services Infrastructure Planning and Design Published: July 2008 Updated: February 2011.
Module 1: Introduction to Active Directory Infrastructure
Windows Server ® 2008 and Windows Server 2008 R2 Print Services Infrastructure Planning and Design Published: June 2010 Updated: November 2011.
Global Catalog and Flexible Single Master Operations (FSMO) Roles
Module 1: Implementing Active Directory ® Domain Services.
10.1 © 2004 Pearson Education, Inc. Exam Designing a Microsoft ® Windows ® Server 2003 Active Directory and Network Infrastructure Lesson 10: Planning.
Microsoft ® System Center Virtual Machine Manager 2008 R2 Infrastructure Planning and Design Series Published: June 2008 Updated: September 2009.
Integrating Active Directory with eDirectory ™ Using Novell Account Manager Reid Oakes Technical Team Manager Novell, Inc.
Microsoft ® Forefront ™ Identity Manager 2010 Infrastructure Planning and Design Published: June 2010.
OVERVIEW OF ACTIVE DIRECTORY
Introduction to Active Directory
Dynamic Datacenter Infrastructure Planning and Design Published: April 2010 Updated: July 2010.
Global Catalog and Flexible Single Master Operations (FSMO) Roles BAI516.
Module 8: Planning for Windows Server 2008 Active Directory Services.
11 GLOBAL CATALOG AND FLEXIBLE SINGLE MASTER OPERATIONS (FSMO) ROLES Chapter 4.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 6: Active Directory Physical Design.
MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition (70-294) Chapter 1: Overview of the Active.
Microsoft® System Center Virtual Machine Manager 2008
Overview of Active Directory Domain Services
Global Catalog and Flexible Single Master Operations (FSMO) Roles
Examining a Windows NT Infrastructure (2)
FSMO Roles and Global Catalog Servers
Unit 5 NT1330 Client-Server Networking II Date: 7/12/2016
Global Catalog and Flexible Single Master Operations (FSMO) Roles
Presentation transcript:

Windows Server ® 2008 and Windows Server ® 2008 R2 Active Directory ® Domain Services Infrastructure Planning and Design Published: February 2008 Updated: July 2010

What Is IPD? Guidance that clarifies and streamlines the planning and design process for Microsoft ® infrastructure technologies IPD: Defines decision flow Describes decisions to be made Relates decisions and options for the business Frames additional questions for business understanding IPD guides are available at

Getting Started Active Directory Domain Services

Purpose and Overview Purpose To provide design guidance for Windows Server ® 2008 Active Directory Domain Services (AD DS) Overview Determine process for AD DS design Assist designers in the decision-making process Provide design assistance based on best practices and real-world experience

Active Directory Domain Services Decision Flow SCMITA MAP w/ CAL Tracker

Decision Flow Start Path: Determine Domain and Forest Components

Determine the Number of Forests How Many Forests? Option 1: Single forest Option 2: Multiple forests Multiple Forest Drivers Multiple schemas Resource forests Forest administrator distrust Legal regulations for application or data access

Determine the Number of Domains How Many Domains? Option 1: Single domain Option 2: Multiple domains Multiple Domain Drivers Large number of frequently changing attributes Reduce replication traffic Control replication traffic over slow links Preserve legacy Active Directory

Assign Domain Names Task 1: Assign the NetBIOS Name Maximum effective length of 15 characters Use a NetBIOS name that is unique across corporation s Task 2: Assign DNS Name DNS name consists of host name and network name Ensure uniqueness by not duplicating existing registered Internet domain names Register all top-level domain names with InterNIC Name should not represent business unit or division

Select the Forest Root Domain Establish Forest Root Domain Structure: Option 1: Use a planned domain Option 2: Dedicated forest root domain Additional Considerations: Determine time synch strategy Consider cost of final structure Consider complexity of final structure

Decision Flow Path A: Determine Organizational Unit (OU) Structure

Design the OU Structure Choose an OU Design: Task 1: Design OU configuration for delegation of administration Task 2: Design OU configuration for group policy application

Decision Flow Path B: Determine Domain Controller Placement and Operations Master Role Placement

Determine Domain Controller Placement Placement of the Domain Controllers: Task 1: Hub locations Task 2: Satellite locations

Determine the Number of Domain Controllers Number of Domain Controllers Needed and Their Type: Task 1: Determine number of domain controllers Task 2: Determine type of domain controllers placed in location

Determine Global Catalog Placement Global Catalog Locations and Number Needed: Task 1: Determine global catalog locations and counts

Determine Global Catalog Placement Considerations: Locate near applications that rely on global catalog Number of users at the location greater than 100 WAN link availability Roaming users at location Use of universal group caching How many global catalog servers?

Determine Operations Master Role Placement Domain Roles Primary domain controller (PDC) emulator operations master Relative ID (RID) operations master Infrastructure operations master Forest Roles Schema operations master Domain naming operations master

Determine Operations Master Role Placement Operations Master Role Placement: Task 1: FSMO placement

Decision Flow Path C: Determine Site Design and Structure

Create the Site Design Creating the Site Design: Task 1: Create a site for the location Task 2: Associate location to nearest defined site

Create a Site Link Design Creating the Site Link Design: Task 1: Determine the site link design

Create the Site Link Bridge Design Creating the Site Link Bridge Design: Option 1: Default behavior Option 2: Custom site link bridge

Decision Flow Path D: Determine Domain Controller Configuration

Determine Domain Controller Configuration Plan Domain Controller Configuration: Task 1: Identify minimum disk space requirements for each domain controller Task 2: Identify memory requirements for each domain controller Task 3: Determine processor requirements Task 4: Identify network requirements for each domain controller

Active Directory Domain Services Dependencies Direct Dependencies Domain Name Service (DNS) Lightweight Directory Access Protocol (LDAP) Indirect Dependencies Windows Internet Naming Services (WINS)

Whats Next? – Discuss, Rinse, Repeat Implement your design Test and refine design along the way

Summary and Conclusion Organizations should base the design of their AD DS infrastructure on business and technical requirements Considerations should include: The scope of the network and environment Technical requirements and considerations Additional business requirements Designing an AD DS infrastructure to meet these requirements Validating the overall approach Provide feedback to

Find More Information Download the full document and other IPD guides: Contact the IPD team: Access the Microsoft Solution Accelerators website:

Questions?

Addenda: Benefits for Consultants or Partners IPD in Microsoft Operations Framework 4.0 Active Directory Domain Services in Microsoft Infrastructure Optimization

Benefits of Using the Active Directory Domain Services Guide Benefits for Business Stakeholders/Decision Makers – Most cost-effective design solution for implementation – Alignment between the business and IT from the beginning of the design process to the end Benefits for Infrastructure Stakeholders/ Decision Makers – Authoritative guidance – Business validation questions ensuring solution meets requirements of business and infrastructure stakeholders – High integrity design criteria that includes product limitations – Fault-tolerant infrastructure – Infrastructure thats sized appropriately for business requirements

Benefits of Using the Active Directory Domain Services Guide (Continued) Benefits for Consultants or Partners – Rapid readiness for consulting engagements – Planning and design template to standardize design and peer reviews – A leave-behind for pre- and post-sales visits to customer sites – General classroom instruction/preparation Benefits for the Entire Organization – Using the guide should result in a design that will be sized, configured, and appropriately placed to deliver a solution for achieving stated business requirements

IPD in Microsoft Operations Framework 4.0 Use MOF with IPD guides to ensure that people and process considerations are addressed when changes to an organizations IT services are being planned.

Active Directory Domain Services in Microsoft Infrastructure Optimization