Vikram Thakur Introduction to Active Directory Structure.

Slides:



Advertisements
Similar presentations
Microsoft Active Directory
Advertisements

Active Directory: Beyond The Basics
Active Directory and Group Policy Blackhat Amsterdam Raymond Forbes.
How to Succeed with Active Directory Robert Williams, PhD CEO Secure Logistix Corporation.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 1: Introduction to Active Directory.
70-297: MCSE Guide to Designing a Microsoft Windows Server 2003 Active Directory and Network Infrastructure Chapter 2: Developing the Active Directory.
Chapter 6 Introducing Active Directory
Introduction to Active Directory
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
CS603 Active Directory February 1, 2001.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
Administering Active Directory
Hands-On Microsoft Windows Server 2003 Administration Chapter 3 Administering Active Directory.
Chapter 4 Introduction to Active Directory and Account Management
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
By Karan Oberoi.  A directory service (DS) is a software application- or a set of applications - that stores and organizes information about a computer.
Understanding Active Directory
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
Module 1: Introduction to Active Directory
Hands-On Microsoft Windows Server 2008
Active Directory Implementation Class 4
Chapter 4: Active Directory Design and Security Concepts
ADVANCED MICROSOFT ACTIVE DIRECTORY CONCEPTS
Overview of Active Directory Domain Services Lesson 1.
Overview of Active Directory Domain Services Lesson 1.
Nassau Community College
(ITI310) SESSIONS : Active Directory By Eng. BASSEM ALSAID.
BZUPAGES.COM An Introduction to. BZUPAGES.COM Introduction Large corporations today face the following problems Finding a certain file. Seeing everything.
Directory services Unit objectives
11 REVIEWING MICROSOFT ACTIVE DIRECTORY CONCEPTS Chapter 1.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 7: Active Directory Replication.
Session 6 Windows Platform Dina Alkhoudari. Learning Objectives What is Active Directory Logical components of active directory Physical components of.
Windows Server 2008 Chapter 4 Last Update
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 3: Introducing Active Directory.
Designing Active Directory for Security
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 5: Active Directory Logical Design.
SERVER I SLIDE: 6. SERVER I Topics: Objective 4.3: Deploy and configure the DNS service Objective 5.1: Install domain controllers.
Active Directory Operations Masters. Overview  Active Directory updates generally multimaster Changes can be made on any DC  Some exceptions — single.
Designing Authentication for a Microsoft Windows 2000 Network Designing Authentication in a Microsoft Windows 2000 Network Designing Kerberos Authentication.
Module 7 Active Directory and Account Management.
Session 7 Windows Platform Eng. Dina Alkhoudari. Learning Objectives Active Directory review Managing users and groups Single Master Operations Delegation.
Company Confidential 1 A Course on Global Catalog And Flexible Single Master Operations (Fsmo) Roles Prepared for: *Stars* New Horizons Certified Professional.
 Identify Active Directory functions and Benefits.  Identify the major components that make up an Active Directory structure.  Identify how DNS relates.
Page 1 Active Directory and DNS Lecture 2 Hassan Shuja 09/14/2004.
Introduction to Active Directory Domain Services
Module 1: Implementing Active Directory ® Domain Services.
Hands-On Microsoft Windows Server 2008 Chapter 4-Part 1 Introduction to Active Directory and Account Manager.
Active Directory Infrastructure Microsoft Windows 2003 Active Directory Infrastructure MCSE Exam
MCITP Guide to Microsoft Windows Server 2008 Enterprise Administration (Exam #70-647) Chapter 1 Designing Active Directory Domain Services.
Installing a Domain Controller
OVERVIEW OF ACTIVE DIRECTORY
Introduction to Active Directory
Module 1: Introduction to Active Directory
Hussain Ali Department of Computer Engineering KFUPM, Dhahran, Saudi Arabia Active Directory.
11 GLOBAL CATALOG AND FLEXIBLE SINGLE MASTER OPERATIONS (FSMO) ROLES Chapter 4.
CEG 2400 Fall 2012 Directory Services Active Directory Tree Domain.
Windows 2003 Architecture, Active Directory & DNS Lecture # 3 Hassan Shuja 02/14/2006.
1 Introduction to Active Directory Directory Services Uniquely identify users and resources on a network Provide a single point of network management.
MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition (70-294) Chapter 1: Overview of the Active.
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
Planning an Active Directory Deployment Lesson 1.
Overview of Active Directory Domain Services Lesson 1.
Active Directories: Purpose and Structure Chrystom Ciganko IFMG352 Final Presentation.
Overview of Active Directory Domain Services
Active Directory Replication (Part 1) Paige Verwolf Support Professional Microsoft Corporation © 1999 Microsoft Corporation. All rights reserved.
Implementing Active Directory Domain Services
Overview of Active Directory Domain Services
Active Directory and Group Policy
Presentation transcript:

Vikram Thakur Introduction to Active Directory Structure

Agenda  Introduction to Active Directory  FSMO Roles  Replication  Active Directory deployment planning  Guiding principles  Structure planning  More information

Introduction to Active Directory  What is it?  How does it help?  How is it stored?  Where is it stored?  Can it’s scope be extended?

Domain Controller  These are ‘Logon’ or ‘Authenticating’ servers with the NTDS Directory  Under any circumstances there should be at least 2 of these DCs  They check for DB Consistency  They maintain the domain information

AD Properties  It doesn’t require the PDC/BDC structure anymore….that went away with NT4  ‘Delegation’ is possible…more later  It provides an LDAP interface to other applications  Multiple Domains can be a part of a single AD with Inter Site Trust (Forests)

Storage Structure of AD  Comprises of 2 parts  Transaction Logs  Database  SYSVOL (old NETLOGON)

FSMO FSMO – Flexible Single Master of Operations  Schema  PDC  RID  Domain Naming  Infrastructure

Global Catalogs (GCs)  Hold limited form of AD  Can be modified by using the SCHMGMT.DLL  Used for location of resources

Replication  AD works in Multi-Master mode by default  Happens every 5 minutes  Default – Every DC replicates with 2 other DCs  KCC is part of LSASS (Monitoring that will tell you when you need another DC)  USN (Update Sequence Number)

Planning and Deployment

Deployment Planning  Three steps  Assess your environment  Create Active Directory structure plan  Create migration plan 2. Plan 3. Migrate 1. Assess

Guiding Principles  Keep it simple  Aim for the ideal design  Evaluate several alternatives  Anticipate change

Structure Planning  Deliverable: planning documents Forest plan Domain plan OU plan

Forest Planning  Start with a forest plan Forest plan Domain plan OU plan Site topology

Configuration  Site topology  Domain hierarchy Schema  Class definitions  Attribute definitions Forest Planning Concepts Forest User Principal Name Globalcatalog

Forest Planning Methodology  Start with a single forest  Create change control policy  Schema Admins and Enterprise Admins group membership  Multiple forests may be required  Cannot agree on change control  Division requires own schema or config  Complete trust undesirable

Forest Planning Inter-forest Considerations  Users must be aware of structure  Explicit query to domain outside forest  Import objects from other forests  Config, schema managed separately  One-way, non-transitive trust only

Forest Planning Examples  Central authority  Single forest  Conglomerate, autonomous division  May require multiple forests  ISP or hosting scenario  Multiple forests  No reason to share schema, config or to have complete trust

Domain Planning  Create a domain plan for each forest Forest plan Domain plan OU plan

Domain Planning Concepts  A domain is a partition of a forest  Unit of partitioning for replication  Administrative and policy boundary  Scope of authority of Domain Admins  Policy and access control do not flow between domains

Domain Planning Methodology Forest plan Domain plan OU plan Select Forest Root CreateHierarchy DNS Support Partition

Domain Planning Partitioning  Start with a single domain  Justify each additional domain  Example justification  Administrative partitioning (admin/policy)  Physical partitioning (replication)  Upgrade existing domain in-place

Domain Planning Obsolete Reasons to Partition  WinNT 4.0: 40,000 object limit  Active Directory tests: 1,500,000+  Primary Domain Controller (PDC) availability requirements  Active Directory is multi-master  Delegation of administration  Resource domains no longer needed  Delegate within a domain using OUs

OU Planning  Create an OU plan for each domain Forest plan Domain plan OU plan

OU Planning Concepts  An Organizational Unit (OUs) is a container inside a domain  Nested to create hierarchical structure  Not a security principal  Easily changed  Typically not exposed to users  Depth does not impact performance

OU Planning Methodology Forest plan Domain plan OU plan DelegateAdministration Apply Group Policy

OU Planning Delegate Administration  Objects can be permission on a per- attribute basis  Very flexible delegation possible  Minimize number of Domain Admins  Example procedure 1. Delegate full control 2. Delegate full control per-object class 3. Delegate control of specific attribute

OU Planning Apply Group Policy  Group policy is used to control desktop configurations  Applied to Users and Computers  Associated with Sites, Domains, or Organizational Units  Create OUs to apply unique policy  Filter application of policy using access control

Summary  Deployment planning  Assess current environment  Structure planning  Migration planning  Start with structure planning  Forest, domain, OU  Guiding principles  Keep it simple  Anticipate change

For More Information  Read the Windows 2003 Deployment Guide (on the Windows 2003 CD)  Read the Distributed Systems book in the Windows 2003 Resource Kit  Watch for whitepapers on the Windows 2003 Server home page

Scenario Discussion – time permitting