Christopher Chapman | MCT Content PM, Microsoft Learning, PDG Planning, Microsoft.

Slides:



Advertisements
Similar presentations
© 2010 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
Advertisements

Deploying and Managing Active Directory Certificate Services
Feature: Purchase Requisitions - Requester © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names.
Chapter 9 Deploying IIS and Active Directory Certificate Services
MIX 09 4/15/ :14 PM © 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
DESIGNING A PUBLIC KEY INFRASTRUCTURE
16.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 9: Planning and Managing Certificate Services.
Understanding Active Directory
Chapter 11: Active Directory Certificate Services
CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
Understanding Active Directory
Windows Optimized Desktop: Enhance Security & Control.
Understanding Active Directory
Configuring Active Directory Certificate Services Lesson 13.
Feature: Web Client Keyboard Shortcuts © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are.
Christopher Chapman | MCT Content PM, Microsoft Learning, PDG Planning, Microsoft.
Session 1.
Built by Developers for Developers…. © 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names.
Deploying PKI Inside Microsoft The experience of Microsoft in deploying its own corporate PKI Published: December 2003.
Christopher Chapman | MCT Content PM, Microsoft Learning, PDG Planning, Microsoft.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Configuring Directory Certificate Services Lesson 13.
© 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or.
Module 9: Fundamentals of Securing Network Communication.
Maintaining Network Health. Active Directory Certificate Services Public Key Infrastructure (PKI) Provides assurance that you are communicating with the.
Module 9: Designing Public Key Infrastructure in Windows Server 2008.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
© 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or.
demo Instance AInstance B Read “7” Write “8”

customer.
03 | Word Templates Brian Meier| Senior Lead Program Manager.
demo © 2008 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Creating and Managing Digital Certificates Chapter Eleven.
demo Demo.
Microsoft Virtual Academy Windows Intune for IT Pros Jump Start M05: Windows Intune Policies David Tesar Richard Harrison.
Microsoft Virtual Academy Preparing for the Windows 8.1 MCSA Module 5: Managing Devices & Resource Access.
demo QueryForeign KeyInstance /sm:body()/x:Order/x:Delivery/y:TrackingId1Z
projekt202 © 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are.
© 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks.
© 2008 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or.
04 | Business Analyzer Brian Meier| Senior Lead Program Manager.

Building and extending the internal PKI
Cloud Roadshow. Advanced Web Development using Angular with Office 365 APIs.
11 | Managing User Info Jeremy Foster Michael Palermo
Deployment Planning Services
O365 & AZURE ADDS Mladen Baranek, Miadria
Deployment Planning Services
6/17/2018 5:54 AM OSP322 Getting the best of both worlds, making the most of SharePoint hybrid search solutions Shyam Narayan Microsoft © 2013 Microsoft.
Information Protection
Возможности Excel 2010, о которых следует знать
Windows Store for Business
Azure AD Domain Services
Office Mac /30/2018 © 2010 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
Title of Presentation 12/2/2018 3:48 PM
Microsoft Virtual Academy
Microsoft Virtual Academy
Microsoft Virtual Academy
8/04/2019 9:13 PM © 2006 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
Виктор Хаджийски Катедра “Металургия на желязото и металолеене”
Шитманов Дархан Қаражанұлы Тарих пәнінің
Title of Presentation 5/24/2019 1:26 PM
Build /27/2019 © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION.
Microsoft Virtual Academy
Presentation transcript:

Christopher Chapman | MCT Content PM, Microsoft Learning, PDG Planning, Microsoft

Microsoft Virtual Academy Active Directory Certificate Services (AD CS)

What is AD CS? What does AD CS do/provide? Module Overview

Overview of Active Directory Certificate Services Understanding Active Directory Certificate Services Certificates Implementing Certificate Enrollment and Revocation

Lesson 1: Overview of Active Directory Certificate Services What Is a Certification Authority? How CA Hierarchies Work Options for Implementing CAs Options for Integrating AD CS and AD DS Demonstration: Tools for Managing AD CS

What Is a Certification Authority? A Certification Authority (CA) is an entity entrusted to issue certificates to: Individuals Computers Organizations Services A Certification Authority (CA) is an entity entrusted to issue certificates to: Individuals Computers Organizations Services These certificates verify the identity and other attributes of the certificate subject to other entities

How CA Hierarchies Work Reasons for deploying more than a single server CA hierarchy: Usage Organizational divisions Geographic divisions Load balancing CA hierarchies include a root CA and one or more levels of subordinate CAs Restrict administrative access High availability

Options for Implementing Certification Authorities When implementing a CA solution, you can: Use an internal private CA Use an external public CA Internal CAs are less expensive and provide more administrative options, but the issued certificates are not trusted by external clients

EnterpriseStand-Alone Can use without AD DSX Uses Group Policy for Trusted Root propagation X Publishes certificates and CRL to AD DSX Can enforce credential checks during enrollment X Can have subject name generated automatically from logon credentials X Can use certificate templatesX Can be used to generate smart card Windows domain authentication certificates X Can use certificate auto-enrollmentX Options for Integrating AD CS and AD DS

Demo: Tools for Managing AD CS Certification Authority Certificate Templates Online Responder Enterprise PKI Certificates

Lesson 2: Understanding Active Directory Certificate Services Certificates What Are Digital Certificates? How Public Keys and Private Keys Work Demonstration: Using Certificates to Secure Data What Are Certificate Templates?

What Are Digital Certificates? A certificate is a digital file with two parts Base certificate informationPublic Key Public keys are distributed to all clients who request the key Private keys are stored only on the computer from which the certificate was requested

SSL (Encrypted) Web Server Web Client Plaintext Different keys are used to encrypt and decrypt the message Encrypt Decrypt Private Key Public Key How Public Keys and Private Keys Work

Demonstration: Using Certificates to Secure Data In this demonstration, you will see how to use certificates to secure data

What Are Certificate Templates? Certificate templates : Define what certificates can be issued by the CAs Define certificates used for various purposes Define which security principals have permissions to read, enroll, and configure the certificate template

Lesson 3: Implementing Certificate Enrollment and Revocation Options for Implementing Certificate Enrollment Demonstration: Using Web Enrollment to Obtain Certificates Administering Certificate Enrollment Demonstration: Administering Certificate Requests Options for Automating Certificate Enrollment What is Certificate Revocation? Demonstration: Revoking Certificates

Options for Implementing Certificate Enrollment What methods are used for certificate enrollment? Web Enrollment Manual/Offline Enrollment Automatic Enrollment

Demo: Using Web Enrollment to Obtain Certificates In this demonstration, you will see how to use Web enrollment to obtain certificates

Administering Certificate Enrollment To obtain a certificate using manual enrollment: Create a certificate request Submit certificate request to CA Obtain administrative approval for certificate Retrieve certificate from CA and install on client

Demo: Administering Certificate Requests In this demonstration, you will see how to administer certificate requests

Domain Computer Enterprise CA Group Policy Group Policy triggers automatic request Auto-enroll is enabled on the template from which the requested certificate is created Options for Automating Certificate Enrollment

What Is Certificate Revocation? Clients can ensure the certificate has not been revoked by using the following methods: Online Certificate Status Protocol responder service (OCSP) Certificate Revocation Lists (CRLs) Certificate revocation occurs when a certificate is invalidated before its expiration period

Demonstration: Revoking Certificates In this demonstration, you will see how to revoke certificates

Module Review and Takeaways Review Questions Summary of AD CS

Thanks for Watching!

©2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Office, Azure, System Center, Dynamics and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.