CN1260 Client Operating System Kemtis Kunanuraksapong MSIS with Distinction MCT, MCITP, MCTS, MCDST, MCP, A+

Slides:



Advertisements
Similar presentations
Chapter Five Users, Groups, Profiles, and Policies.
Advertisements

By Rashid Khan Lesson 5-Directory Assistance: Administration Using Active Directory Users and Computers.
Chapter 9 Chapter 9: Managing Groups, Folders, Files, and Object Security.
Chapter 4 Chapter 4: Planning the Active Directory and Security.
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
MCDST : Supporting Users and Troubleshooting a Microsoft Windows XP Operating System Chapter 6: Configure and Troubleshoot Local User and Group Accounts.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
11 SUPPORTING LOCAL USERS AND GROUPS Chapter 3. Chapter 3: Supporting Local Users and Groups2 SUPPORTING LOCAL USERS AND GROUPS  Explain the difference.
Administering Active Directory
Hands-On Microsoft Windows Server 2003 Administration Chapter 3 Administering Active Directory.
Chapter 5: Configuring Users and Groups. Windows Vista User Accounts User accounts are the primary means of authentication Built-in Accounts –Administrator:
Chapter 4 Introduction to Active Directory and Account Management
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
Understanding Active Directory
11 WORKING WITH COMPUTER ACCOUNTS Chapter 8. Chapter 8: WORKING WITH COMPUTER ACCOUNTS2 CHAPTER OVERVIEW Describe the process of adding a computer to.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
1 Chapter Overview Creating User and Computer Objects Maintaining User Accounts Creating User Profiles.
Authentication, Authorization and Accounting
CN1260 Client Operating System Kemtis Kunanuraksapong MSIS with Distinction MCT, MCITP, MCTS, MCDST, MCP, A+
11 WORKING WITH USER ACCOUNTS Chapter 6. Chapter 6: WORKING WITH USER ACCOUNTS2 CHAPTER OVERVIEW Understand the differences between local user and domain.
70-270: MCSE Guide to Microsoft Windows XP Professional Chapter 5: Users, Groups, Profiles, and Policies.
Understanding Workgroups and Active Directory Lesson 3.
Working with Workgroups and Domains
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 3: Introducing Active Directory.
CN1260 Client Operating System Kemtis Kunanuraksapong MSIS with Distinction MCT, MCITP, MCTS, MCDST, MCP, A+
CN1176 Computer Support Kemtis Kunanuraksapong MSIS with Distinction MCT, MCTS, MCDST, MCP, A+
September 18, 2002 Introduction to Windows 2000 Server Components Ryan Larson David Greer.
1 Group Account Administration Introduction to Groups Planning a Group Strategy Creating Groups Understanding Default Groups Groups for Administrators.
CN1276 Server (V3) Kemtis Kunanuraksapong MSIS with Distinction MCT, MCTS, MCDST, MCP, A+
Hands-On Microsoft Windows Server 2008
Hands-On Microsoft Windows Server Security Enhancements in Windows Server 2008 Windows Server 2008 was created to emphasize security –Reduced attack.
5.1 © 2004 Pearson Education, Inc. Lesson 5: Administering User Accounts Exam Microsoft® Windows® 2000 Directory Services Infrastructure Goals 
Module 10: Configuring Windows XP Professional to Operate in Microsoft Networks.
Chapter 7: WORKING WITH GROUPS
Designing Active Directory for Security
CN1260 Client Operating System Kemtis Kunanuraksapong MSIS with Distinction MCT, MCITP, MCTS, MCDST, MCP, A+
Windows Server 2003 Overview 1 Windows 2003 Server Overview Ayaz
Security Planning and Administrative Delegation Lesson 6.
11 WORKING WITH USER ACCOUNTS Chapter 6. Chapter 6: WORKING WITH USER ACCOUNTS2 UNDERSTANDING USER ACCOUNTS  Local user accounts  stored in the Security.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
DIT314 ~ Client Operating System & Administration CHAPTER 5 MANAGING USER ACCOUNTS AND GROUPS Prepared By : Suraya Alias.
1 Chapter Overview Configuring Account Policies Configuring User Rights Configuring Security Options Configuring Internet Options.
Chapter 13 Users, Groups Profiles and Policies. Learning Objectives Understand Windows XP Professional user accounts Understand the different types of.
September 18, 2002 Windows 2000 Server Active Directory By Jerry Haggard.
CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
Introduction to Microsoft Management Console (MMC) MMC is a common console framework for management applications. MMC provides a common environment for.
Module 3 Configuring File Access and Printers on Windows ® 7 Clients.
CN2140 Server II Kemtis Kunanuraksapong MSIS with Distinction MCT, MCITP, MCTS, MCDST, MCP, A+
Module 3 Configuring File Access and Printers on Windows 7 Clients.
Working with Workgroups and Domains Lesson 9. Objectives Understand users and groups Create and manage local users and groups Understand the difference.
Module 3: Configuring File Access and Printers on Windows 7 Clients
Working with Users and Groups Lesson 5. Skills Matrix Technology SkillObjective DomainObjective # Introducing User Account Control Configure and troubleshoot.
CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
Managing Local Users & Groups. OVERVIEW Configure and manage user accounts Manage user account properties Manage user and group rights Configure user.
1 Chapter Overview Managing Object and Container Permissions Locating and Moving Active Directory Objects Delegating Control Troubleshooting Active Directory.
NetTech Solutions Supporting Local Users and Groups Lesson Three.
Module 3: Planning Administrative Access. Overview Determining the Appropriate Administrative Model Designing Administrative Group Strategies Planning.
CN1260 Client Operating System Kemtis Kunanuraksapong MSIS with Distinction MCT, MCITP, MCTS, MCDST, MCP, A+
Working with Users and Groups Lesson 5. Skills Matrix Technology SkillObjective DomainObjective # Introducing User Account Control Configure and troubleshoot.
1 Chapter Overview Using Group Objects Understanding Default Groups Creating Group Objects Managing Administrative Access.
CEG 2400 Fall 2012 Directory Services Active Directory Tree Domain.
11 SECURITY PLANNING AND ADMINISTRATIVE DELEGATION Chapter 6.
CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
6/19/2016 أساسيات الأتصال و الشبكات Communication & Networks Fundamentals lab 4.
Windows Active Directory – What is it? Definition - Active Directory is a centralized and standardized system that automates network management of user.
Essential Services Lesson 5. Objectives Naming Resolution In today’s networks, you assign logical addresses, such as with IP addressing. Unfortunately,
Authentication, Authorization and Accounting Lesson 2.
Objectives Differentiate between the different editions of Windows Server 2003 Explain Windows Server 2003 network models and server roles Identify concepts.
Presentation transcript:

CN1260 Client Operating System Kemtis Kunanuraksapong MSIS with Distinction MCT, MCITP, MCTS, MCDST, MCP, A+

Agenda Chapter 3: Understanding Workgroups and Active Directory Quiz Exercise

Workgroup A group of computer form into a peer-to-peer network. ▫User accounts are decentralized and stored on each individual computer

Authentication and Logins Authentication ▫The process of identifying an individual ▫Username and password Authorization ▫The process of giving individuals access to system objects based on their identity Auditing ▫The process of keeping track of a user’s activity while accessing the network resources

Authentication Methods A user can authenticate using one or more of the following methods: ▫What they know  A password or Personal Identity Number (PIN). ▫What they own or possess  Such as a passport, smart card, or ID card ▫What a user is  Biometric factors based on fingerprints, retinal scans, voice input, or other forms

Password The most common method of authentication A secret series of characters that enables a user to access a file, computer, or program A complex or strong password ▫6 or more characters long ▫Cannot contain the user’s account name or parts of the user’s full name ▫A mix of characters, upper and lower case, number, and non-alphanumeric characters

User Account Enables a user to log on to a computer and domain Can be used for auditing There are two types of user accounts: ▫The local user account ▫The domain user account

Local User Account A local user account allows a user to log on and gain access to the computer where the account was created. Security Account Manager (SAM) database ▫Located on the local computer ▫Stores the local user account

User Accounts (Cont.) Three groups of local user accounts: ▫Administrator ▫Standard ▫Guest Creating and managing local user accounts: ▫User Accounts in the Control Panel  See Figure 3-1 on Page 57 ▫Local Users and Groups MMC snap-in  See Figure 3-2 on Page 59

User Profile A collection of folders and data that store the user’s current desktop environment and application settings, is associated with each user account ▫C:\Users folder ▫See Figure 3-3 on Page 60

Credential Manager Store credentials, such as usernames and passwords that you use to log on to websites or other computers, on a network Credentials are saved in special folders on your computer called vaults.

Active Directory A directory service stores, organizes, and provides access to information in a directory It is used for locating, managing, administering, and organizing common items and network resources, such as volumes, folders, files, printers, users, groups, devices, telephone numbers, and other objects

Active Directory A technology created by Microsoft that provides a variety of network services, including: ▫Lightweight Directory Access Protocol (LDAP) ▫Kerberos-based and single sign-on (SSO) authentication ▫DNS-based naming and other network information ▫Central location for network administration and delegation of authority

Domain A logical unit of computers and network resources that defines a security boundary

Domain Controller A Windows server that stores a replica of the account and security information of the domain and defines the domain boundaries A server that is not running as a domain controller is known as a member server

Active Directory Consoles Several MMC snap-in consoles to manage Active Directory: ▫Active Directory Users and Computers ▫Active Directory Domains and Trusts ▫Active Directory Sites and Services ▫Active Directory Administrative Center ▫Group Policy Management Console (GPMC)

Organizational Units To help organize objects within a domain and minimize the number of domains, you can use organizational units, commonly seen as OU OUs can be used to hold users, groups, computers, and other organizational units An organizational unit can only contain objects that are located in a domain

Delegating Administration You can assign a range of administrative tasks to the appropriate users and groups

Active Directory Objects A distinct, named set of attributes or characteristics that represents a network resource ▫Computers, users, groups, and printers A 128-bit unique number called a globally unique identifier (GUID) or security identifier (SID) ▫If a user changes his or her name, GUID remains the same

Domain User A domain user account is stored on the domain controller and allows you to gain access to resources within the domain See Figure 3-4 and 3-5 on Page 65 ▫Domain user properties sheet See Figure 3-6 on Page 66 ▫Specify logon hours

Computer Account For authenticating and auditing the computer’s access to a Windows network and its access to domain resources

Groups A collection or list of user accounts or computer accounts Group Types ▫Security group ▫Distribution group Group scopes ▫Domain Local group ▫Global group ▫Universal group

Group Policies Controls the working environment for user accounts and computer accounts ▫Provides the centralized management and configuration of operating systems, applications, and users’ settings in an Active Directory environment Group policies can be set ▫Locally on the workstation ▫Domain Level Group policies are applied in the following order: ▫Local -> Site -> Domain -> OU

Rights and Permissions A user right authorizes a user to perform certain actions on a computer such as logging on to a system interactively or backing up files and directories on a system ▫See Figure 3-8 on Page 71 for list of user’s rights Permission defines the type of access that is granted to an object ▫Assigned permissions are NTFS files and folders, printers and Active Directory objects. ▫Access control list (ACL) which lists all users and groups that have access to the object.

Account Lockout Policy Specifies the number of unsuccessful logon attempts ▫To lock the account ▫Specifies the duration that the account remains locked ▫See Figure 3-9 on Page 72

Password Control Group policies can be used to control ▫How often a user changes a password ▫How long the password is ▫A complex password ▫See Figure 3-10 on Page 74 To help manage passwords ▫Computer Configuration\Windows Settings\ Security Settings\ Account Policies\Password Policy

Auditing Auditing is not enabled by default To enable auditing, you specify what types of system events to audit using group policies or the local security policy ▫Security Settings\Local Policies\Audit Policy ▫See Figure 3-11 on Page 75 To audit NTFS files, NTFS folders, and printers is a two-step process ▫Enable Object Access using group policies ▫Specify which objects you want to audit

Troubleshooting Authentication Issues The users forgot their password Caps lock or num lock key on Language defined and that the keyboard is operating fine If the time is off, authentication can fail If computer is not part of the domain or is not trusted, you will not be able to log in to the domain

Assignment Submit these before class over on Thursday ▫Fill in the blank ▫Multiple Choice ▫True / False Submit these before class start on Monday ▫Lab 3