11 WORKING WITH COMPUTER ACCOUNTS Chapter 8. Chapter 8: WORKING WITH COMPUTER ACCOUNTS2 CHAPTER OVERVIEW  Describe the process of adding a computer to.

Slides:



Advertisements
Similar presentations
By Rashid Khan Lesson 5-Directory Assistance: Administration Using Active Directory Users and Computers.
Advertisements

Guide to MCSE , Enhanced 1 Activity 14-1: Browsing Security Templates Objective: To become familiar with built-in security templates Start  Run.
Module 6: Configuring Windows XP Professional to Operate in a Microsoft Network.
Lesson 17: Configuring Security Policies
Module 4: Implementing User, Group, and Computer Accounts
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
11 WORKING WITH GROUPS Chapter 7. Chapter 7: WORKING WITH GROUPS2 CHAPTER OVERVIEW  Understand the functions of groups and how to use them.  Understand.
7.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
6.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 3: Creating and Managing User Accounts.
11 SUPPORTING LOCAL USERS AND GROUPS Chapter 3. Chapter 3: Supporting Local Users and Groups2 SUPPORTING LOCAL USERS AND GROUPS  Explain the difference.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 9: Implementing and Using Group Policy.
Administering Active Directory
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 4: Implementing and Managing Group and Computer Accounts.
Hands-On Microsoft Windows Server 2003 Administration Chapter 3 Administering Active Directory.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 4: Implementing and Managing Group and Computer Accounts.
Lesson 14: Creating and Managing Active Directory Users and Computers
By Rashid Khan Lesson 8-Crowd Control: Controlling Access to Resources Using Groups.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 4: Implementing and Managing Group and Computer Accounts.
11 WORKING WITH COMPUTER ACCOUNTS Chapter 8. Chapter 8: WORKING WITH COMPUTER ACCOUNTS2 CHAPTER OVERVIEW Describe the process of adding a computer to.
Guide to MCSE , Enhanced 1 Activity 9-1: Creating a Group Policy Object Using the MMC Objective: To create a GPO using the Group Policy Object Editor.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 3: Creating and Managing User Accounts.
1 Chapter Overview Creating User and Computer Objects Maintaining User Accounts Creating User Profiles.
Chapter 7 WORKING WITH GROUPS.
Chapter 7 Managing OUs and Active Directory Accounts
Deploying and Managing Software by Using Group Policy.
11 WORKING WITH USER ACCOUNTS Chapter 6. Chapter 6: WORKING WITH USER ACCOUNTS2 CHAPTER OVERVIEW Understand the differences between local user and domain.
Guide to MCSE , Enhanced 1 Activity 4-1: Creating and Adding Members to Global Groups Objective: Use Active Directory Users and Computers to create.
1 Chapter Overview Monitoring Server Performance Monitoring Shared Resources Microsoft Windows 2000 Auditing.
9.1 © 2004 Pearson Education, Inc. Lesson 9: Implementing Group Policy in Windows 2000 Server Exam Microsoft® Windows® 2000 Directory Services Infrastructure.
Module 2 Creating Active Directory ® Domain Services User and Computer Objects.
1 Chapter Overview Understanding Group Policies Implementing Group Policies Using Security Policies Troubleshooting Group Policy Problems.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
1 Week 3 Secure and Efficient Administration of Act. Dir. Work with Active Directory Snap-Ins Custom Consoles and Least Privilege Find Objects in Active.
1 Group Account Administration Introduction to Groups Planning a Group Strategy Creating Groups Understanding Default Groups Groups for Administrators.
11 SECURITY TEMPLATES AND PLANNING Chapter 7. Chapter 7: SECURITY TEMPLATES AND PLANNING2 OVERVIEW  Understand the uses of security templates  Explain.
8.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 8: Introducing Computer Accounts.
Managing Active Directory Domain Services Objects
5.1 © 2004 Pearson Education, Inc. Lesson 5: Administering User Accounts Exam Microsoft® Windows® 2000 Directory Services Infrastructure Goals 
Chapter 7: WORKING WITH GROUPS
11 MANAGING AND DISTRIBUTING SOFTWARE BY USING GROUP POLICY Chapter 5.
11 WORKING WITH USER ACCOUNTS Chapter 6. Chapter 6: WORKING WITH USER ACCOUNTS2 UNDERSTANDING USER ACCOUNTS  Local user accounts  stored in the Security.
Managing Groups, Folders, Files and Security Local Domain local Global Universal Objects Folders Permissions Inheritance Access Control List NTFS Permissions.
Active Directory Administration Lesson 5. Skills Matrix Technology SkillObjective DomainObjective # Creating Users, Computers, and Groups Automate creation.
Module 9: Preparing to Administer a Server. Overview Introduction to Administering a Server Configuring Remote Desktop to Administer a Server Managing.
Microsoft ® Official Course Module 3 Managing Active Directory Domain Services Objects.
Module 2 Creating Active Directory ® Domain Services User and Computer Objects.
Working with Users and Groups Lesson 5. Skills Matrix Technology SkillObjective DomainObjective # Introducing User Account Control Configure and troubleshoot.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 4: Implementing and Managing Group and Computer Accounts.
Managing Local Users & Groups. OVERVIEW Configure and manage user accounts Manage user account properties Manage user and group rights Configure user.
Guide to MCSE , Enhanced1 Activity 1-1: Determining the Windows Server 2003 Edition Installed on a Server Objective is to determine the edition of.
Fall 2011 Nassau Community College ITE153 – Operating Systems Session 21 Administering User Accounts and Groups 1.
1 Chapter Overview Managing Object and Container Permissions Locating and Moving Active Directory Objects Delegating Control Troubleshooting Active Directory.
NetTech Solutions Supporting Local Users and Groups Lesson Three.
© Wiley Inc All Rights Reserved. MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition.
Administering Groups Chapter Eight. Exam Objectives In this Chapter:  Plan a security group hierarchy based upon delegation requirements  Plan a security.
1 Active Directory Administration Tasks And Tools Active Directory Administration Tasks Active Directory Administrative Tools Using Microsoft Management.
Working with Users and Groups Lesson 5. Skills Matrix Technology SkillObjective DomainObjective # Introducing User Account Control Configure and troubleshoot.
MIS Chapter 41 Chapter 4 – Implementing and Managing Group and Computer Accounts MIS 431 – Created Spring 2006.
1 Chapter Overview Using Group Objects Understanding Default Groups Creating Group Objects Managing Administrative Access.
6/19/2016 أساسيات الأتصال و الشبكات Communication & Networks Fundamentals lab 4.
Configuring the User and Computer Environment Using Group Policy Lesson 8.
Module 9: Preparing to Administer a Server
ACTIVE DIRECTORY ADMINISTRATION
ACTIVE DIRECTORY ADMINISTRATION
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 4: Implementing and Managing Group and Computer Accounts.
Implementing and Managing Group and Computer Accounts
Module 9: Preparing to Administer a Server
Presentation transcript:

11 WORKING WITH COMPUTER ACCOUNTS Chapter 8

Chapter 8: WORKING WITH COMPUTER ACCOUNTS2 CHAPTER OVERVIEW  Describe the process of adding a computer to an Active Directory domain  Create and manage computer objects  Troubleshoot computer accounts  Describe the process of adding a computer to an Active Directory domain  Create and manage computer objects  Troubleshoot computer accounts

Chapter 8: WORKING WITH COMPUTER ACCOUNTS3 UNDERSTANDING COMPUTER OBJECTS  Logical representation in Active Directory of the physical computer object  Can be granted permissions to other objects and be subject to group policy  Can be made a member of a group  Logical representation in Active Directory of the physical computer object  Can be granted permissions to other objects and be subject to group policy  Can be made a member of a group

Chapter 8: WORKING WITH COMPUTER ACCOUNTS4 ADDING COMPUTERS TO A DOMAIN  Step 1: Create a computer account in Active Directory  Step 2: Join the computer to the domain  Step 1: Create a computer account in Active Directory  Step 2: Join the computer to the domain

Chapter 8: WORKING WITH COMPUTER ACCOUNTS5 CREATING COMPUTER OBJECTS  Computer object must exist in Active Directory before computer can be joined to the domain.  Computer object can be created using Active Directory Users and Computers or a command-line tool such as Dsadd.  Computer account can also be created during the domain joining process.  Computer object must exist in Active Directory before computer can be joined to the domain.  Computer object can be created using Active Directory Users and Computers or a command-line tool such as Dsadd.  Computer account can also be created during the domain joining process.

Chapter 8: WORKING WITH COMPUTER ACCOUNTS6 CREATING COMPUTER OBJECTS USING ACTIVE DIRECTORY USERS AND COMPUTERS

Chapter 8: WORKING WITH COMPUTER ACCOUNTS7 CREATING COMPUTER OBJECTS USING DSADD.EXE  Allows computer account creation to be scripted  Provides a mechanism to create large amounts of computer accounts at one time  Allows computer account creation to be scripted  Provides a mechanism to create large amounts of computer accounts at one time

Chapter 8: WORKING WITH COMPUTER ACCOUNTS8 CREATING COMPUTER OBJECTS USING NETDOM.EXE  Command-line utility  Simpler to use than Dsadd  Must be extracted from the support.cab archive in the \Support\Tools folder on the Windows Server 2003 installation CD  Command-line utility  Simpler to use than Dsadd  Must be extracted from the support.cab archive in the \Support\Tools folder on the Windows Server 2003 installation CD

Chapter 8: WORKING WITH COMPUTER ACCOUNTS9 JOINING COMPUTERS TO A DOMAIN

Chapter 8: WORKING WITH COMPUTER ACCOUNTS10 JOINING A DOMAIN USING NETDOM.EXE  Allows computers to be joined to the domain from a command line  Allows scripts to be developed to streamline the process of joining a computer to a domain  Allows computers to be joined to the domain from a command line  Allows scripts to be developed to streamline the process of joining a computer to a domain

Chapter 8: WORKING WITH COMPUTER ACCOUNTS11 CREATING COMPUTER OBJECTS WHILE JOINING THE DOMAIN

Chapter 8: WORKING WITH COMPUTER ACCOUNTS12 JOINING A DOMAIN DURING OPERATING SYSTEM INSTALLATION

Chapter 8: WORKING WITH COMPUTER ACCOUNTS13 LOCATING COMPUTER OBJECTS  The Computers container  The Domain Controllers OU  The Computers container  The Domain Controllers OU

Chapter 8: WORKING WITH COMPUTER ACCOUNTS14 LOCATING DOMAIN CONTROLLER COMPUTER OBJECTS  Computer accounts for domain controllers are placed in the system-created domain controllers OU by default.  The Default Domain Controllers Policy GPO is applied to the container.  Computer accounts for domain controllers are placed in the system-created domain controllers OU by default.  The Default Domain Controllers Policy GPO is applied to the container.

Chapter 8: WORKING WITH COMPUTER ACCOUNTS15 LOCATING OTHER COMPUTER OBJECTS  Non–domain-controller computer accounts are placed in the Computers system-created container by default.  Container does not support group policy  Non–domain-controller computer accounts are placed in the Computers system-created container by default.  Container does not support group policy

Chapter 8: WORKING WITH COMPUTER ACCOUNTS16 REDIRECTING COMPUTER OBJECTS  Allows an alternative default location for computer accounts to be specified.  Use the Redircmp.exe command-line utility.  Works only on Windows Server 2003 domain functional level.  Can be overridden by explicit computer account creation commands.  Allows an alternative default location for computer accounts to be specified.  Use the Redircmp.exe command-line utility.  Works only on Windows Server 2003 domain functional level.  Can be overridden by explicit computer account creation commands.

Chapter 8: WORKING WITH COMPUTER ACCOUNTS17 MANAGING COMPUTER OBJECTS  Computer objects have properties.  Can be viewed and configured through Active Directory Users and Computers  Computer objects have properties.  Can be viewed and configured through Active Directory Users and Computers

Chapter 8: WORKING WITH COMPUTER ACCOUNTS18 MODIFYING COMPUTER OBJECT PROPERTIES

Chapter 8: WORKING WITH COMPUTER ACCOUNTS19 DELETING, DISABLING, AND RESETTING COMPUTER OBJECTS Deleting  Removes the computer account from Active Directory Disabling  Prevents the computer from being used to log on to the domain Resetting  Reestablishes relationship between a computer and Active Directory Deleting  Removes the computer account from Active Directory Disabling  Prevents the computer from being used to log on to the domain Resetting  Reestablishes relationship between a computer and Active Directory

Chapter 8: WORKING WITH COMPUTER ACCOUNTS20 DELETING COMPUTER OBJECTS  Manually through Active Directory Users and Computers  Automatically by changing the domain membership on the computer  Using a command-line tool such as Dsrm  Manually through Active Directory Users and Computers  Automatically by changing the domain membership on the computer  Using a command-line tool such as Dsrm

Chapter 8: WORKING WITH COMPUTER ACCOUNTS21 DISABLING COMPUTER OBJECTS

Chapter 8: WORKING WITH COMPUTER ACCOUNTS22 RESETTING A COMPUTER OBJECT  Necessary when replacing or upgrading a computer system  Allows an appropriately named new system to use an existing computer account  Necessary when replacing or upgrading a computer system  Allows an appropriately named new system to use an existing computer account

Chapter 8: WORKING WITH COMPUTER ACCOUNTS23 MANAGING REMOTE COMPUTERS  Allows you to perform management tasks across the network  Actually a shortcut to the Computer Management MMC snap-in  Allows you to perform management tasks across the network  Actually a shortcut to the Computer Management MMC snap-in

Chapter 8: WORKING WITH COMPUTER ACCOUNTS24 MANAGING COMPUTER OBJECTS FROM THE COMMAND LINE Dsmod  Used to modify existing computer account objects Dsrm  Used to remove computer account objects from Active Directory Dsmod  Used to modify existing computer account objects Dsrm  Used to remove computer account objects from Active Directory

Chapter 8: WORKING WITH COMPUTER ACCOUNTS25 MANAGING COMPUTER OBJECT PROPERTIES WITH DSMOD.EXE  Can be used to modify properties of existing computer account objects  Useful for creating scripts and batch files to automate changes  Cannot be used to create or delete computer account objects  Can be used to modify properties of existing computer account objects  Useful for creating scripts and batch files to automate changes  Cannot be used to create or delete computer account objects

Chapter 8: WORKING WITH COMPUTER ACCOUNTS26 DELETING COMPUTER OBJECT PROPERTIES WITH DSRM.EXE  Can be used to delete computer account objects from the command line  Requires confirmation of deletion unless the - noprompt switch is used  Can be used to delete computer account objects from the command line  Requires confirmation of deletion unless the - noprompt switch is used

Chapter 8: WORKING WITH COMPUTER ACCOUNTS27 TROUBLESHOOTING COMPUTER ACCOUNTS: PROBLEMS  Messages at logon indicate that a domain controller cannot be contacted, that the computer account might be missing, or that the trust between the computer and the domain has been lost.  Error messages or entries in an event log indicate similar problems or suggest that passwords, trusts, secure channels, or relationships with the domain or a domain controller have failed.  A computer account is missing in Active Directory.  Messages at logon indicate that a domain controller cannot be contacted, that the computer account might be missing, or that the trust between the computer and the domain has been lost.  Error messages or entries in an event log indicate similar problems or suggest that passwords, trusts, secure channels, or relationships with the domain or a domain controller have failed.  A computer account is missing in Active Directory.

Chapter 8: WORKING WITH COMPUTER ACCOUNTS28 TROUBLESHOOTING COMPUTER ACCOUNTS: SOLUTIONS  Reset the computer account in Active Directory.  If the computer account is missing, create a computer account.  If the computer still belongs to the domain, you must remove it from the domain by changing its membership to a workgroup.  Rejoin the computer to the domain.  Reset the computer account in Active Directory.  If the computer account is missing, create a computer account.  If the computer still belongs to the domain, you must remove it from the domain by changing its membership to a workgroup.  Rejoin the computer to the domain.

Chapter 8: WORKING WITH COMPUTER ACCOUNTS29 SUMMARY  A computer object represents a specific system on the network.  To add a computer to a domain, you must create a computer object for it in Active Directory and then join the physical computer to the object.  To create computer objects, you can use the Active Directory Users and Computers console, the Dsadd utility, or the Netdom utility.  A computer object represents a specific system on the network.  To add a computer to a domain, you must create a computer object for it in Active Directory and then join the physical computer to the object.  To create computer objects, you can use the Active Directory Users and Computers console, the Dsadd utility, or the Netdom utility.

Chapter 8: WORKING WITH COMPUTER ACCOUNTS30 SUMMARY (continued)  Computer objects for non–domain controllers are placed in the Computers container by default.  Computer object have a SID that Active Directory uses to reference the computer in its group memberships and other permissions.  The typical steps for troubleshooting a computer object problem include creating or resetting the object, removing the computer from the domain, and rejoining it to the domain.  Computer objects for non–domain controllers are placed in the Computers container by default.  Computer object have a SID that Active Directory uses to reference the computer in its group memberships and other permissions.  The typical steps for troubleshooting a computer object problem include creating or resetting the object, removing the computer from the domain, and rejoining it to the domain.

Chapter 8: WORKING WITH COMPUTER ACCOUNTS31