Windows Server 2012 Richard Oertle Subject Matter Expert / Instructor www.NetComLearning.com October 25 th, 2012.

Slides:



Advertisements
Similar presentations
Auditing Microsoft Active Directory
Advertisements

IP ADDRESS MANAGEMENT [IPAM]
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 4 Installing and Configuring the Dynamic Host Configuration Protocol.
Module 5: Creating and Configuring Group Policy
Managing User Settings with Group Policy
1 Week #1 Objectives Review clients, servers, and Windows network models Differentiate among the editions of Server 2008 Discuss the new Windows Server.
Chapter 9 Chapter 9: Managing Groups, Folders, Files, and Object Security.
10.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
Lesson 16: Creating Group Policy Objects
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 11 Managing and Monitoring a Windows Server 2008 Network.
Installing and Maintaining ISA Server. Planning an ISA Server Deployment Understand the current network infrastructure Review company security policies.
Welcome Course 20410B Module 0: Introduction Audience
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 7 Configuring File Services in Windows Server 2008.
Understanding Active Directory
1 Chapter Overview Creating User and Computer Objects Maintaining User Accounts Creating User Profiles.
Sharepoint Portal Server Basics. Introduction Sharepoint server belongs to Microsoft family of servers Integrated suite of server capabilities Hosted.
Master Expert Associat e Microsoft Certified Solutions Master (MCSM) Microsoft Certified Solutions Expert (MCSE) Microsoft Certified Solutions Associate.
4/20/2017 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
11 SHARING FILE SYSTEM RESOURCES Chapter 9. Chapter 9: SHARING FILE SYSTEM RESOURCES2 CHAPTER OVERVIEW Create and manage file system shares and work with.
Microsoft ® Official Course Module 12 Monitoring, Managing, and Recovering AD DS.
Module 1: Installing Active Directory Domain Services
Course 6425A Module 9: Implementing an Active Directory Domain Services Maintenance Plan Presentation: 55 minutes Lab: 75 minutes This module helps students.
(ITI310) SESSIONS : Active Directory By Eng. BASSEM ALSAID.
Module 2 Creating Active Directory ® Domain Services User and Computer Objects.
Module 1 Introduction to Managing Microsoft® Windows Server® 2008 Environment.
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
Deploying and Managing Windows Server 2012
Module 10 Configuring and Managing Storage Technologies.
Hands-On Microsoft Windows Server 2008
Managing Active Directory Domain Services Objects
Hands-On Microsoft Windows Server Security Enhancements in Windows Server 2008 Windows Server 2008 was created to emphasize security –Reduced attack.
5.1 © 2004 Pearson Education, Inc. Lesson 5: Administering User Accounts Exam Microsoft® Windows® 2000 Directory Services Infrastructure Goals 
Managing User and Service Accounts
Module 15: Manage the Windows ® Small Business Server 2008 Environment Using Group Policy.
11 MANAGING AND DISTRIBUTING SOFTWARE BY USING GROUP POLICY Chapter 5.
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
Managing User Desktops with Group Policy
Optimizing File Services
Chapter 13 Users, Groups Profiles and Policies. Learning Objectives Understand Windows XP Professional user accounts Understand the different types of.
Maintaining Active Directory Domain Services
MCSE Guide to Microsoft Exchange Server 2003 Administration Chapter Two Installing and Configuring Exchange Server 2003.
Module 11: Implementing ISA Server 2004 Enterprise Edition.
Module 6: Configuring User Environments Using Group Policy.
Planning a Microsoft Windows 2000 Administrative Structure Designing default administrative group membership Designing custom administrative groups local.
Microsoft Virtual Academy Module 8 Managing the Infrastructure with VMM.
Module 5: Implementing Group Policy
Module 1: Implementing Active Directory ® Domain Services.
Czy są zmiany w AD Domain Services Windows 2012 Andrzej Kokociński
Module 5: Creating and Configuring Group Policies.
Module 4 Planning for Group Policy. Module Overview Planning Group Policy Application Planning Group Policy Processing Planning the Management of Group.
Implementing Group Policy
Module 7: Implementing Security Using Group Policy.
Week 4 Objectives Overview of Group Policy Group Policy Processing Implementing a Central Store for Administrative Templates.
Implementing a Group Policy Infrastructure
Module 12: Configuring and Managing Storage Technologies
Master Expert Associat e Microsoft Certified Solutions Master (MCSM) Microsoft Certified Solutions Expert (MCSE) Microsoft Certified Solutions Associate.
Module 6 Creating and Configuring Group Policy. Module Overview Overview of Group Policy Configuring the Scope of Group Policy Objects Evaluating the.
Module 8 Implementing Security Using Group Policy.
Certification Overview.
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
QUESTION 1: Your role of Network Administrator at ABC.com includes the management of the Active Directory Domain Services (AD DS) domain named ABC.com.
Windows Certification Paths OR MCSA Windows Server 2012 Installing and Configuring Windows Server 2012 Exam (20410) Administering Windows Server.
Microsoft Installing & Configuring Windows Server Exam Questions Answers Powered By:
Managing User Desktops with Group Policy
Managing User and Service Accounts
Implementing Active Directory Domain Services
Windows Server 2012.
CIS 409Competitive Success/tutorialrank.com
CIS 409 Education for Service-- tutorialrank.com.
Presentation transcript:

Windows Server 2012 Richard Oertle Subject Matter Expert / Instructor October 25 th, 2012

Windows Server 2012 New Features and Certifications Certification Changes Microsoft Certified Solution Expert in Windows Server 2012 Microsoft Certified Solution Administrator in Windows Server 2012 Administration Changes Screen and Navigation changes PowerShell changes Version 3.0 with 2400 cmdlets

Starting from the beginning: Become an MCSA Pass the following 3 tests to gain the equivalent of passing the test Installing and Configuring Windows Server® Administering Windows Server® Configuring Advanced Windows Server® 2012 Services Then consider continuing on for an MCSE in the 3 previous categories of Desktop, Private cloud or Server Administration

Upgrading from MCITP to MCSE Must renew MCSE status every three years! MCITP upgrade test is (course 20417) MCITP accepted certifications includes: Lync Administrator SharePoint Administrator Desktop Administrator Enterprise Messaging Administrator Windows Server 2008 Administrator

Pass the upgrade test THEN: Take and pass the specialist area tests shown below Determine which of 3 MCSE specialist areas to focus on: MCSE in Server Infrastructure Designing and Implementing a Server Infrastructure Implementing an Advanced Server Infrastructure MCSE in Desktop Infrastructure Implementing a Desktop Infrastructure Implementing Desktop Application Environments

MCSE Information continued MCSE in Private Cloud Infrastructure Monitoring and Operating a Private Cloud with System Center 2012, Course (5 days) Configuring and Deploying a Private Cloud with System Center 2017, Course (5 days)

Some of the New Administration features of Windows Server 2012

Active Directory Administrative Center, is a task-oriented tool based on Windows PowerShell

Password Settings Objects You can use fine-grained password policies to specify multiple password policies within a single domain Fine-grained password policies: Apply only to user objects (or inetOrgPerson objects) and global security groups Cannot be applied to an OU directly Do not interfere with custom password filters that you might use in the same domain

Configuring Password Settings Objects Windows Server 2012 provides two tools for configuring PSOs Windows PowerShell cmdlets New-ADFineGrainedPasswordPolicy Add-FineGrainedPasswordPolicySubject Active Directory Administrative Center Is a graphical user interface Uses Windows PowerShell cmdlets to create and manage PSOs

Managed Service Account Use to automate password and SPN management for service accounts used by services and applications Requires a Windows Server 2008 R2 or Windows Server 2012 server installed with:. NET Framework 3.5.x Active Directory module for Windows PowerShell Recommended to run with AD DS configured at the Windows Server 2008 R2 functional level or higher Can be used in a Windows Server 2003 or 2008 AD DS environment: With Windows Server 2008 R2 schema updates With Active Directory Management Gateway Service

Group Managed Service Accounts Group managed service accounts extend the capability of standard managed service accounts by: Enabling an MSA to be used on more than one computer in the domain Storing MSA authentication information on domain controllers Group MSA requirements: Must have at least one Windows Server 2012 domain controller Must have a KDS root key created for the domain

The Central Store The Central Store: Is a central repository for ADMX and ADML files Is stored in SYSVOL Must be created manually Is detected automatically by Windows Vista or Windows Server 2008 Windows Vista or Windows Server 2008 workstation ADMX files Domain controller with SYSVOL Domain controller with SYSVOL

Group Policy Preferences Group Policy preferences expand the range of configurable settings within a GPO Group Policy preferences: Enable IT professionals to configure, deploy, and manage settings that were not manageable by using Group Policy Can be created, deleted, replaced, or updated Are natively supported on Windows Server 2008 and Vista SP2 or newer

Comparing Group Policy Preferences and GPO Settings Group Policy SettingsGroup Policy Preferences Strictly enforce policy settings by writing the settings to areas of the registry that standard users cannot modify Are written to the normal locations in the registry that the application or operating system feature uses to store the setting Typically disable the user interface for settings that Group Policy is managing Do not cause the application or operating system feature to disable the user interface for the settings they configure Refresh policy settings at a regular interval Refresh preferences by using the same interval as Group Policy settings by default

Group policy Management Editor Allows editing of the ADMX file Extends the functionality of GPMC

Features of Group Policy Preferences Is used to configure additional options that control the behavior of a Group Policy preference item Targeting Features Determines to which users and computers a preference item applies Common Tab

Deploying a Cloned Virtualized Domain Controller You can safely clone an existing virtual domain controller by: 1. Creating a DcCloneConfig.xml file and storing it in the AD DS database location 2. Taking the VDC offline and exporting it 3. Creating a new virtual machine by importing the exported VDC Export the VDC Import the VDC DcCloneConfig.xml to AD DS database location

Overview of the Active Directory Module for Windows PowerShell The Active Directory module for Windows PowerShell provides full administrative functionality in these areas: User management Computer management Group management OU management Password policy management Searching and modifying objects Forest and domain management Domain controller and operations masters management Managed service account management Site replication management Central access and claims management

Windows PowerShell Web Access Allows remote management of computers by running Windows PowerShell sessions in a web browser. Powershell replaces tab completion with Visual Studio style drop down options Many former scripts are now compiled into cmdlets

Polls

What Is NTDSUtil? With NTDSUtil you can: Manage and control single master operations Perform AD DS database maintenance Perform offline defragmentation Create and mount snapshots Move database files Maintain domain controller metadata Reset Directory Services Restore Mode password

Creating AD DS Snapshots Create a snapshot of Active Directory NTDSUtil Mount the snapshot to a unique port NTDSUtil Expose the snapshot Right-click the root node of Active Directory Users and Computers, and choose Connect to Domain Controller Enter serverFQDN:port View (read-only) snapshot Cannot directly restore data from the snapshot Recover data Connect to the mounted snapshot, and export/reimport objects with LDIFDE Restore a backup from the same date as the snapshot Manually reenter data

Configuring the Active Directory Recycle Bin? Active Directory Recycle Bin provides a way to restore deleted objects without AD DS downtime Uses Windows PowerShell with Active Directory Module or the Active Directory Administrative Center to restore objects

Dynamic Access Control Dynamic Access Control provides: A safety net over all file server-based resources Data identification Access control to files File access auditing Optional RMS protection integration

What Is FSRM? FSRM Enables the following functionality: Storage quota management File screening management Storage reports management Classification management File management tasks

Using FSRM to Manage Quotas, File Screens, and Storage Reports What Is Quota Management? What Are Quota Templates? Monitoring Quota Usage What Is File Screening Management? What Are File Groups? What Are a File Screen Templates and File Screen Exceptions? What Are Storage Reports? What Is a Report Task? Demonstration: How to Use FSRM to Manage Quotas, File Screens, and Generate On-Demand Storage Reports

Monitoring Quota Usage You can monitor quota usage by: Viewing quota information in the FSRM console Generating a quota usage report Creating soft quotas Using the Get-FSRMQuota Windows PowerShell cmdlet

File Screening Management File screen management provides a method for controlling the types of files that can be saved on file servers File screen management consists of: Creating file screens Defining file screen templates Creating file screen exceptions Creating file groups

Storage Reports Storage reports provide information about file usage on a file server Types of storage reports include: Duplicate Files File Screening Audit Files by File Group, Owner, or Property Folders by Property Large Files Quota Usage Least and most recently accessed files

Classification Management Classification management enables you to create and assign classification properties to files using an automated mechanism Payroll.rpt Classification Property Classification Rule IsConfidential File Management Task

Classification Properties A Classification Properties is a configurable value that can be assigned to a file Classification properties can be any of the following: Yes/No Date/Time Number Multiple choice list Ordered list String Multi-String

Options for Storage Optimization in Windows Server 2012 Storage optimization features include: File access auditing Features on Demand Data deduplication NFS data stores

Implementing IPAM What Is IPAM? IPAM Architecture Requirements for IPAM Implementation Managing IP Addressing Using IPAM IPAM Management and Monitoring Considerations for Implementing IPAM

What Is IPAM? IPAM facilitates IP management in organizations with complex networks by enabling administration and monitoring of DHCP and DNS

Managing IP Addressing Using IPAM IP address blocks IP address ranges IP addresses IP inventory IP address range groups You can view and manage the IP address space using the following views: DNS and DHCP servers DHCP scopes DNS zone monitoring Server groups You can monitor the IP address space using the following views:

IPAM Management and Monitoring With IPAM, you can: Monitor IP address space utilization Monitor DNS and DHCP health Configure many DHCP properties and values from the IPAM console Use the event catalog to view a centralized repository for all configuration changes

What Is iSCSI? iSCSI transmits SCSI commands over IP networks iSCSI client that runs the iSCSI Initiator TCP/IP protocol iSCSI Target Server Storage Array

iSCSI Target Server and iSCSI Initiator

Considerations for Implementing iSCSI Storage Deploy the solution on fast networks Design a highly available network infrastructure for your iSCSI storage solution. Design an appropriate security strategy for the iSCSI storage solution Follow the vendor-specific best practices for different types of deployments The iSCSI storage solution team must contain IT administrators from different areas of specialization Design application-specific iSCSI storage solutions together with application specific administrators, such as Exchange Server and SQL Server administrators Consider the following when designing your iSCSI storage solution:

Thank You! Back to Rinchen Stick around for Raffle and Q&As