What’s New in Active Directory: Windows Server 2008 R2 Brian Desmond Thursday, March 4 th, 2009.

Slides:



Advertisements
Similar presentations
Copyright line. Configuring Server Roles in Windows 2008 Exam Objectives New Roles in 2008 New Roles in 2008 Read-Only Domain Controllers (RODCs) Read-Only.
Advertisements

What’s New in Windows Server 2008 AD?
By Rashid Khan Lesson 5-Directory Assistance: Administration Using Active Directory Users and Computers.
IP ADDRESS MANAGEMENT [IPAM]
What’s New in Active Directory in Windows Server 2012 Dean Wells Active Directory Product Group Microsoft SIA312.
Brian Desmond Moran Technology Consulting
Windows Server “Longhorn” RDP Airlift. Managing AD with PowerShell; Creating custom administrative consoles Dmitry Sotnikov CTO, Windows Management Quest.
Chapter 6 Introducing Active Directory
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
Administering Active Directory
Hands-On Microsoft Windows Server 2003 Administration Chapter 3 Administering Active Directory.
Lesson 14: Creating and Managing Active Directory Users and Computers
Windows Server 2012 What’s new ? AuthorKrzysztof Pytko Wroclaw 2012
Understanding Active Directory
A centralized system.  Active Directory is Microsoft's trademarked directory service, an integral part of the Windows architecture. Like other directory.
HalFILE 3.0 Active Directory Integration. halFILE 3.0 AD – What is it? Centralized organization of network objects and security – servers, computers,
Chapter 7 WORKING WITH GROUPS.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 12: Managing and Implementing Backups and Disaster Recovery.
© 2005 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice Advanced Samba Administration Part.
Module 8: Designing Active Directory Disaster Recovery in Windows Server 2008.
John Craddock Infrastructure & Security Architect XTSeminars Ltd Session Code: SIA319.
1 Active Directory Windows Server 2008 R2 Updates.
Microsoft ® Official Course Module 12 Monitoring, Managing, and Recovering AD DS.
Overview of Active Directory Domain Services Lesson 1.
Course 6425A Module 9: Implementing an Active Directory Domain Services Maintenance Plan Presentation: 55 minutes Lab: 75 minutes This module helps students.
Chapter 12: Additional Active Directory Server Roles
Module 2 Creating Active Directory ® Domain Services User and Computer Objects.
Module 1 Introduction to Managing Microsoft® Windows Server® 2008 Environment.
WGUiSW IDOL Windows Server 2012 Active Directory: Domain Services What’s new in Active Directory: Domain Services?
Chapter 2: Installing and Upgrading to Windows Server 2008 R2 BAI617.
Deploying and Managing Windows Server 2012
Overview of Access and Information Protection
Chapter 4 Windows NT/2000 Overview. NT Concepts  Domains –A group of one or more NT machines that share an authentication database (SAM) –Single sign-on.
MCTS Guide to Microsoft Windows Server 2008 Applications Infrastructure Configuration (Exam # ) Chapter Two Deploying Windows Servers.
Hands-On Microsoft Windows Server 2008 Chapter 1 Introduction to Windows Server 2008.
IT Pro Connections 2009 The cutting edge event for IT pros Active Directory in Depth Χρήστος Σπανουγάκης MCT, MVP.
What’s New in Active Directory in Windows Server 2012 Pete WSV312.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 12: Managing and Implementing Backups and Disaster Recovery.
Chapter 6: Windows Servers
Maintaining Active Directory Domain Services
Active Directory Administration Lesson 5. Skills Matrix Technology SkillObjective DomainObjective # Creating Users, Computers, and Groups Automate creation.
Craig A. Brown Practice Leader – Microsoft Global Knowledge MCT, Since 1996 MCSA/MCSE NT/2000/2003 MCDST MCITP: ES / CS.
1 Windows 2008 Configuring Server Roles and Services.
Module 1: Configuring Windows Server Module Overview Describe Windows Server 2008 roles Describe Windows Server 2008 features Describe Windows Server.
Planning a Microsoft Windows 2000 Administrative Structure Designing default administrative group membership Designing custom administrative groups local.
Module 14: Securing Windows Server Overview Introduction to Securing Servers Implementing Core Server Security Hardening Servers Microsoft Baseline.
Module 1: Implementing Active Directory ® Domain Services.
Czy są zmiany w AD Domain Services Windows 2012 Andrzej Kokociński
Master Data Management & Microsoft Master Data Services Presented By: Jeff Prom Data Architect MCTS - Business Intelligence (2008), Admin (2008), Developer.
What’s New in Active Directory in Windows Server 2012 Samuel Devasahayam Active Directory Product Group Microsoft Ulf Simon-Weidner Senior Consultant,
Week 4 Objectives Overview of Group Policy Group Policy Processing Implementing a Central Store for Administrative Templates.
1 Active Directory Administration Tasks And Tools Active Directory Administration Tasks Active Directory Administrative Tools Using Microsoft Management.
Active Directory. Computers in organizations Computers are linked together for communication and sharing of resources There is always a need to administer.
Labs. Session 1 Lab 1: Designing an Active Directory Forest Infrastructure in Windows Server 2008 Exercise 1: Designing an Active Directory Forest Exercise.
Module 14: Advanced Topics and Troubleshooting. Microsoft ® Windows ® Small Business Server (SBS) 2008 Management Console (Advanced Mode) Managing Windows.
4.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 12: Implementing Security.
Directory Services CS5493/7493. Directory Services Directory services represent a technological breakthrough by integrating into a single management tool:
BE-com.eu Brussel, 26 april 2016 EXCHANGE 2010 HYBRID (IN THE EXCHANGE 2016 WORLD)
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
QUESTION 1: Your role of Network Administrator at ABC.com includes the management of the Active Directory Domain Services (AD DS) domain named ABC.com.
©2011 Quest Software, Inc. All rights reserved. Quick, Scalable Restore of Granular Objects Recovery Manager for Active Directory.
Windows Server 2012 Active Directory - what’s in it for me? Tony Murray, Directory Services MVP.
Lesson 6: Configuring Servers for Remote Management
ACTIVE DIRECTORY ADMINISTRATION
Active Directory Fundamentals
Active Directory Administration
Exam in just 24 hours!!! Pass your exam in first attempt by the help of our latest braindumps
Tech·Ed North America /7/2019 6:55 AM
MS-200 Planning and Configuring a Messaging Platform Pass Your Exam in One Attempt.
Presentation transcript:

What’s New in Active Directory: Windows Server 2008 R2 Brian Desmond Thursday, March 4 th, 2009

About Brian Chicago based Active Directory & Exchange consultant – Moran Technology Consulting MS MVP for Active Directory since 2003 Author of Active Directory, 4 th Ed from O’Reilly website & blog:

Agenda  Active Directory Recycle Bin Managed Service Accounts Offline Domain Join Authentication Mechanism Assurance Active Directory PowerShell Active Directory Administrative Center

Active Directory Recycle Bin Problem: – Accidental deletions cause downtime – Restoring is complicated – Primary AD Disaster Recovery scenario Solution – Online restoration of object and all attributes

Object Lifecycle Tombstoned Object Deleted ObjectRecycled ObjectGarbage Collected Live Object 180 days (default)

Recycle Bin Prerequisites New Terms Deleted Object – Objects currently in the recycle bin Recycled Object – Objects after the recycle bin Equivalent to a legacy tombstone Requirements Windows Server 2008 R2 Forest Functional Level AD LDS – new 2008 R2 “Application Mode” Recycle Bin optional feature enabled

RECYCLE BIN DEMO

Agenda Active Directory Recycle Bin  Managed Service Accounts Offline Domain Join Authentication Mechanism Assurance Active Directory PowerShell Active Directory Administrative Center

Service Account Issues Key problems – Infinite lifetime – Elevated rights Passwords – Set once and never rotated – IT personnel take passwords with them

Managed Service Accounts Automatic management – Passwords – Service Principal Names Integrated support – Service Control Manager – IIS 7.5 Application Pools

Agenda Active Directory Recycle Bin Managed Service Accounts  Offline Domain Join Authentication Mechanism Assurance Active Directory PowerShell Active Directory Administrative Center

Offline Domain Join Problem – Domain join requires network connectivity – Domain join requires a reboot to complete Solution – Offline domain join enables pre-provisioning of computer accounts – Computer account info is injected into machine while it is offline – Machine processes injected data at boot and becomes a full domain member without reboot I think a flowchart slide would be advantageous to this topic

Agenda Active Directory Recycle Bin Managed Service Accounts Offline Domain Join  Authentication Mechanism Assurance Active Directory PowerShell Active Directory Administrative Center

Auth Mechanism Assurance Feature enables securing resources based on authentication mechanism – Requiring smartcard logon – Requiring high encryption certificates Mapping occurs in AD – Certificate OID is mapped to a SID – SID is injected into user’s token at logon

Auth Mechanism Assurance Authentication Assurance requires “compound” ACLs to be useful Need to allow for ALLOW “Brian Desmond” – AND REQUIRE High Assurance Certificate Use tool like Active Directory Federation Services to implement this

Auth Mechanism Assurance High Assurance Sales Users We want users who meet both criteria

Agenda Active Directory Recycle Bin Managed Service Accounts Offline Domain Join Authentication Assurance  Active Directory PowerShell Active Directory Administrative Center

Active Directory PowerShell Replaces numerous disjointed administrative tools Single point of entry for administrative tasks – End-to-End manageability with other roles such as Exchange, Group Policy, etc Communicates with AD via a Web Service – Web service will be made available for pre Windows Server 2008 R2 domain controllers

PowerShell Advantages Consistent vocabulary and syntax – Verbs: Add, New, Get, Set, Remove, Clear … – Nouns: ADObject, ADUser, ADComputer, ADDomain, ADForest, ADGroup, ADAccount, ADDomainController, etc Easily discovered – No need to find, install, or learn other tools, utilities or commands Flexible output – Output from one cmdlet easily consumed by another PowerShell Providers – Brings file system like navigation to Active Directory

LDAP AD Web Services S.DS.P / S.DS.AM / S.DS.AD AD PowerShell MUX WCF.NET WPF.NET Windows Server 2008 R2 WCF. NET Windows Server 2008 ADUC/ADSS/ADDT WSHWSH ADSI LDAP MMC … GUI DS RPC-Based Protocols … DSRSAM CLI AD Core DS RPC-Based Protocols … … DSR SAM AD Admin Center GUI BPA

POWERSHELL DEMO

Agenda Active Directory Recycle Bin Managed Service Accounts Offline Domain Join Authentication Mechanism Assurance Active Directory PowerShell  Active Directory Administrative Center

AD Administrative Center New Active Directory UI written from the ground up – Task based interface – Interface designed with progressive disclosure in mind All UI tasks are frontends to AD PowerShell Interface supports multiple domains, forests

ADAC DEMO

Best Practices Analyzer Rules based Active Directory Health Check – Detect common misconfigurations – Prevent common support calls Rules updated by Microsoft quarterly Integrated with Server Manager

What’s New? Windows Server 2008 coverage: – Read Only Domain Controllers (RODCs) – Fine Grained Password Policies (FGPPs) – Auditing and security improvements – Windows Server 2008 upgrade procedure – DNS enhancements (such as GlobalName zones) Exchange 2007 integration & scripting Windows PowerShell & Active Directory.NET Active Directory programming New user interface features Lots of new diagrams and figures Active Directory, 4 th Edition Best selling Active Directory title Learn More!

Resources – mailing list Windows Hi-Ed mailing list Microsoft TechNet Forums

Questions?