Active Directory Implementation Class 4

Slides:



Advertisements
Similar presentations
Microsoft Active Directory
Advertisements

Lecture 8 Active Directory Structure. Domains Domains group network objects and OUs into a unit with a security boundary. By default, security policies.
Windows Server 2003 AD 安裝設定與管理維護 林寶森
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 1: Introduction to Active Directory.
70-297: MCSE Guide to Designing a Microsoft Windows Server 2003 Active Directory and Network Infrastructure Chapter 2: Developing the Active Directory.
Chapter 6 Introducing Active Directory
Chapter 4 Chapter 4: Planning the Active Directory and Security.
Introduction to Active Directory
6.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
1.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
Hands-On Microsoft Windows Server 2003 Administration Chapter 1 Windows Server 2003 Network Administration.
By Rashid Khan Lesson 4-Preparing to Serve: Understanding Microsoft Networking.
Chapter 4 Introduction to Active Directory and Account Management
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
Understanding Active Directory
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
Module 1: Introduction to Active Directory
Hands-On Microsoft Windows Server 2008
Vikram Thakur Introduction to Active Directory Structure.
Module 1: Installing Active Directory Domain Services
Overview of Active Directory Domain Services Lesson 1.
Nassau Community College
Directory services Unit objectives
11 REVIEWING MICROSOFT ACTIVE DIRECTORY CONCEPTS Chapter 1.
Chapter 4 Introduction to Active Directory and Account Management
Session 6 Windows Platform Dina Alkhoudari. Learning Objectives What is Active Directory Logical components of active directory Physical components of.
Windows Server 2008 Chapter 4 Last Update
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 3: Introducing Active Directory.
Working with domains and Active Directory
Microsoft Confidential Zelko Kecman Microsoft Windows 2000 Server Directory Services.
Designing Active Directory for Security
Active Directory Boundaries - Purpose Replication Boundaries Security Boundaries.
Windows 2000 Operating System -- Active Directory Service COSC 516 Yuan YAO 08/29/2000.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 5: Active Directory Logical Design.
SERVER I SLIDE: 6. SERVER I Topics: Objective 4.3: Deploy and configure the DNS service Objective 5.1: Install domain controllers.
Designing Authentication for a Microsoft Windows 2000 Network Designing Authentication in a Microsoft Windows 2000 Network Designing Kerberos Authentication.
Module 7 Active Directory and Account Management.
Company Confidential 1 A Course on Global Catalog And Flexible Single Master Operations (Fsmo) Roles Prepared for: *Stars* New Horizons Certified Professional.
1 Windows 2008 Configuring Server Roles and Services.
Module 11: Read-Only Domain Controllers. Overview Describe the Read-Only Domain Controllers role Use Read-Only Domain Controllers.
Module 6: Designing Name Resolution. Module Overview Collecting Information for a Name Resolution Design Designing a DNS Server Strategy Designing a DNS.
Page 1 Active Directory and DNS Lecture 2 Hassan Shuja 09/14/2004.
Module 1: Implementing Active Directory ® Domain Services.
Windows Server 2003 La migrazione da Windows NT 4.0 a Windows Server 2003 Relatore: MCSE - MCT.
10.1 © 2004 Pearson Education, Inc. Exam Designing a Microsoft ® Windows ® Server 2003 Active Directory and Network Infrastructure Lesson 10: Planning.
Hands-On Microsoft Windows Server 2008 Chapter 4-Part 1 Introduction to Active Directory and Account Manager.
Active Directory Infrastructure Microsoft Windows 2003 Active Directory Infrastructure MCSE Exam
70-412: Configuring Advanced Windows Server 2012 services
MCITP Guide to Microsoft Windows Server 2008 Enterprise Administration (Exam #70-647) Chapter 1 Designing Active Directory Domain Services.
Module 3 Planning for Active Directory®
Installing a Domain Controller
OVERVIEW OF ACTIVE DIRECTORY
Introduction to Active Directory
© Wiley Inc All Rights Reserved. MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition.
Module 1: Introduction to Active Directory
Logical and Physical Network Design 1. Active Directory Objects Objects Represent Network Resources (Users,Groups,Computers,Printers) Attributes Store.
Module 8: Planning for Windows Server 2008 Active Directory Services.
11 GLOBAL CATALOG AND FLEXIBLE SINGLE MASTER OPERATIONS (FSMO) ROLES Chapter 4.
1 Implementing Active Directory Planning Active Directory Implementation Installing Active Directory Operations Master Roles Implementing an Organizational.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 6: Active Directory Physical Design.
Windows 2003 Architecture, Active Directory & DNS Lecture # 3 Hassan Shuja 02/14/2006.
7.1 © 2004 Pearson Education, Inc. Exam Designing a Microsoft ® Windows ® Server 2003 Active Directory and Network Infrastructure Lesson 7: Planning.
MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition (70-294) Chapter 1: Overview of the Active.
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
Planning an Active Directory Deployment Lesson 1.
Network Administration
Chapter 4: Planning the Active Directory and Security
Microsoft Active Directory
Presentation transcript:

Active Directory Implementation Class 4 CSIS 165 – Week 2B Exams 70-217 & 70-294 Copyright Scott Wallihan, 2005

Active Directory – Class 4 Ch 5 – AD Logical Design Ch 6 – AD Physical Design

Ch 5 – AD Logical Design

Ch 5 – AD Logical Design Choosing DNS Names Justifying Additional Forests Justifying Additional Domains Identifying Trust Requirements Designing Organizational Units Domain Functional Levels Upgrading from Windows NT

Choosing DNS Names Two primary role of domain names External Internet presence AD & Internal resource identification Three DNS namespace design options Use one DNS namespace for Internet & AD Use discontinuous DNS Namespace for AD Use a subdomain of Internet Namespace for AD

Using a single DNS namespace Advantages: Requires only one domain Naming for email addresses is seamless Disadvantages: Manually maintained DNS server for Internet Solution: Ideal for companies desiring simplicity Use a subset DNS server in a DMZ to service Internet name resolutions

Discontinuous DNS Namespace Advantages Totally obfuscates internal namespace Disadvantages: Typically requires DNS forwarder – But this solution is typically used in closed environments Remark: An uncommon solution Used in high security environments

Subdomain DNS Namespace Advantages: Ideal support for forest root domain Supports AD-aware dynamic DNS for the Internet presence – an uncommon requirement Easily replicates existing DNS topology Disadvantages: More domains = more domain controllers = $$$ Solution: The only choice for larger companies Don’t use a Windows Domain on the Internet unless AD-aware DNS is required – Use zone files

Justifying Additional Forests Forests contain: A single AD schema A single physical configuration A single global catalog A single Enterprise Admins group Trusts between all domains Factors justifying an additional forest: The need to support incompatible schemas The need to totally separate Enterprise Admins The need for trust isolation – maximum security

Justifying Additional Domains Domains define: Security principals Account policies Domain Administrators Factors justifying additional domains: The need for differing account policies The need to separate domain administrators

Trusts Default two-way, transitive trusts Shortcut trusts Forest trusts Realm trusts External trusts (Windows NT)

Organizational Units Organizational units permit: Application of group policy Delegation of sub administration

Designing Organizational Units Common uses of organizational units: Geographical location Department

Domain & Forest Functional Levels Windows 2000 mixed mode Windows 2000 native Windows Server 2003 interim Windows Server 2003

Upgrading Windows NT Domains In-place upgrade Domain consolidation

Ch 6 – AD Physical Design

Ch 6 – AD Physical Design Understanding & Managing Replication Sites & Subnets Site Links Locating Domain Controllers Site Link Bridges Locating Global Catalog Servers

Managing Replication By default, all domain controllers: Problems: Are members of the same site Replicate with all other DC’s in a ring Problems: DC’s determine replication randomly DC’s replicate frequently By default, replication traffic is not compressed. Solution: Create sites to define replication boundaries

Sites & Subnets Sites defined: A collection of one or more well-connected subnets Sites direct clients’ access to resources: Global catalog servers DFS servers Domain Controllers Default-First-Site-Name site Domain controllers are placed in here by default

Site Links Site links define replication paths between subnets Site links define a replication schedule and method

Site Link Bridges By default, all site links are bridged. This permits replication to occur between all sites In non-fully routed environments, site link bridges define which sites can communicate with each other

Locating Domain Controllers Every domain should have at least two domain controllers Large sites should have two or more DC’s Small sites should have one DC

Locating Global Catalog Servers Every domain MUST have one global catalog server Global catalog and Infrastructure master role should be on separate domain controllers Every site that processes logons must have one global catalog server To circumvent this requirement: Run domain in “Windows Server 2003” mode Enable Universal group caching – site object In organizations with one domain, place a global catalog on every domain controller

Review Ch 5 – AD Logical Design Ch 6 – AD Physical Design