Part I.  NOS  Directory Data Store(directory service, database)  Located on Domain Controllers (DCs), globally distributed, replicated (no longer PDCs/BDCs)

Slides:



Advertisements
Similar presentations
Auditing Active Directory Presented to the National State Auditors Association 2014 Information Technology Conference.
Advertisements

Module 5: Creating and Configuring Group Policy
Introduction to Active Directory
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
10.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
Administering Active Directory
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 4: Implementing and Managing Group and Computer Accounts.
Hands-On Microsoft Windows Server 2003 Administration Chapter 3 Administering Active Directory.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 4: Implementing and Managing Group and Computer Accounts.
Chapter 4 Introduction to Active Directory and Account Management
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 4: Implementing and Managing Group and Computer Accounts.
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
Understanding Active Directory
© Wiley Inc All Rights Reserved. MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition.
11 WORKING WITH COMPUTER ACCOUNTS Chapter 8. Chapter 8: WORKING WITH COMPUTER ACCOUNTS2 CHAPTER OVERVIEW Describe the process of adding a computer to.
Guide to MCSE , Enhanced 1 Activity 9-1: Creating a Group Policy Object Using the MMC Objective: To create a GPO using the Group Policy Object Editor.
Chapter 7 WORKING WITH GROUPS.
(ITI310) By Eng. BASSEM ALSAID SESSIONS
Understanding Group Policy on Windows Server 2003 John Howard, IT Pro Evangelist, Microsoft UK
9.1 © 2004 Pearson Education, Inc. Lesson 9: Implementing Group Policy in Windows 2000 Server Exam Microsoft® Windows® 2000 Directory Services Infrastructure.
Chapter 4 Introduction to Active Directory and Account Management
70-270: MCSE Guide to Microsoft Windows XP Professional Chapter 5: Users, Groups, Profiles, and Policies.
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
GROUP POLICY An overview of Microsoft Windows Group Policy.
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 3: Introducing Active Directory.
Corso referenti S.I.R.A. – Modulo 2 07 – Group Policy 20/11 – 27/11 – 05/12 11/12 – 13/12 (gruppo 1) 12/12 – 15/12 (gruppo 2) Cristiano Gentili, Massimiliano.
Module 6: Designing Active Directory Security in Windows Server 2008.
Chapter 7: WORKING WITH GROUPS
Section 3: Designing a Group Policy Infrastructure Overview of Active Directory Introducing the Design Stages for Implementing Group Policy Planning Your.
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
DIT314 ~ Client Operating System & Administration CHAPTER 5 MANAGING USER ACCOUNTS AND GROUPS Prepared By : Suraya Alias.
Active Directory Administration Lesson 5. Skills Matrix Technology SkillObjective DomainObjective # Creating Users, Computers, and Groups Automate creation.
© Wiley Inc All Rights Reserved. MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition.
Introduction to Microsoft Management Console (MMC) MMC is a common console framework for management applications. MMC provides a common environment for.
11.1 © 2004 Pearson Education, Inc. Exam Designing a Microsoft ® Windows ® Server 2003 Active Directory and Network Infrastructure Lesson 11: Planning.
Active Directory Maryam Izadi. Topics Covered NT Vs 2000/2003 Active Directory LDAP MMC.
GPO - WINDOWS SERVER AGENDA: Introduction Group Policy Overview Types of Group Policies/Objects Associated Technologies How to implement.
Section 11: Implementing Software Restriction Policies and AppLocker What Is a Software Restriction Policy? Creating a Software Restriction Policy Using.
 Identify Active Directory functions and Benefits.  Identify the major components that make up an Active Directory structure.  Identify how DNS relates.
Page 1 System and Group Policies Lecture 7 Hassan Shuja 11/02/2004.
Section 4: Understanding the Architecture of Group Policy Processing Group Policy Components in AD DS Understanding the Group Policy Processing Sequence.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 4: Implementing and Managing Group and Computer Accounts.
Module 4 Planning for Group Policy. Module Overview Planning Group Policy Application Planning Group Policy Processing Planning the Management of Group.
1 Group Policies (Week 11, Monday 3/19/2007) © Abdou Illia, Spring 2007.
1 Chapter Overview Managing Object and Container Permissions Locating and Moving Active Directory Objects Delegating Control Troubleshooting Active Directory.
Implementing Group Policy
Week 4 Objectives Overview of Group Policy Group Policy Processing Implementing a Central Store for Administrative Templates.
Implementing a Group Policy Infrastructure
Module 10: Implementing Administrative Templates and Audit Policy.
OVERVIEW OF ACTIVE DIRECTORY
MIS Chapter 41 Chapter 4 – Implementing and Managing Group and Computer Accounts MIS 431 – Created Spring 2006.
Module 6 Creating and Configuring Group Policy. Module Overview Overview of Group Policy Configuring the Scope of Group Policy Objects Evaluating the.
Module 8: Planning for Windows Server 2008 Active Directory Services.
11 DESIGNING AN ADMINISTRATIVE SECURITY STRUCTURE Chapter 7.
CEG 2400 Fall 2012 Directory Services Active Directory Tree Domain.
10.1 © 2004 Pearson Education, Inc. Lesson 10: Specifying Group Policy Settings Exam Microsoft® Windows® 2000 Directory Services Infrastructure.
GROUP POLICY. Group Policy is a hierarchical infrastructure which allows systems administrators to configure computer and user settings from a central.
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
1.1 Microsoft® Windows® 2003 Server Group Policy Management Prof. Abdul Hameed.
Windows Active Directory – What is it? Definition - Active Directory is a centralized and standardized system that automates network management of user.
Windows Enterprise Services.  Introductions  UNM Directory Services  RSAT  Organizational Units (OU)  Active Directory Groups  Naming Convention.
Implementing Active Directory Domain Services
ACTIVE DIRECTORY ADMINISTRATION
(ITI310) SESSIONS 6-7-8: Active Directory.
Active Directory Administration
Windows Server 2008 Administration
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 4: Implementing and Managing Group and Computer Accounts.
Windows Active Directory Environment
Active Directory Organizational Units
Presentation transcript:

Part I

 NOS  Directory Data Store(directory service, database)  Located on Domain Controllers (DCs), globally distributed, replicated (no longer PDCs/BDCs)  Directory data is stored in the Ntds.dit file on each DC (pull data with DSQUERY)  Objects:  Users, Computers, Printers, Faxes, Servers, Services  Containers - Organizational Units (OUs), Groups, Domains  Group Policy Objects (GPOs)

Builtin OU contains default accounts and groups Users OU contains user accounts or additional OUs AD Users and Computers Snap-in

 Houses AD database  Single function  There are 2 types of servers:  Domain Controllers  Member Servers

This icon indicates object is a group (container) This icon indicates object is a single account This icon indicates object is disabled This indicates object type. Valid types are User, Security Group, Distribution Group

 Microsoft recommends as few domains as possible in Active Directory and a reliance on OUs to produce structure and improve the implementation of policies and administration.  The OU is the common level at which to apply GPOs.  The OU is the level at which administrative powers are commonly delegated; however, delegation can be performed on individual objects (or Sites – for another day).

 Protected groups should have limited members and services (each service should be researched for appropriateness):  Enterprise Admins  Schema Admins  Domain Admins  Administrators  Custom groups are created by the entity and should follow a defined naming convention. For example, a group name of HRData should have members from the HR department that are authorized to access sensitive HR data.

(MS Recommendations)

 Can only be performed with Domain Admin, Enterprise Admin, or delegated authority.  Should be a highly-managed task and subject to change management policies and procedures.  More than one policy can be applied to a computer (precedence dictates cumulative effect).  A DC always obtains the account policy from a GPO linked to the domain, which by default is the Default Domain Policy GPO (occurs even if a different policy is applied to the OU that contains the DC).

 Often, separation of duties for the network administration function are described as too difficult to implement, advise delegation. Tasks to delegate:  Help Desk functions  User account Management  Group Management  Group Policy U:\ITA\Section22X\Audit\Questionnaires, Guides, and Other Audit Information\AD

Good for Help Desk Staff Not good HOW TO: Customize the Task List in the Delegation Wizard,” MS Knowledge Base Article

 To return user information for the domain:  dsquery user domainroot  dsquery user OU=Sales,DC=Contoso,DC=Com -o dn  dsquery user domainroot -inactive 3 Results provide all users in the domain Results provide all users in the Sales OU in the Contoso.com domain Results provide all users in the domain that have been inactive for 3 weeks DSQUERY source information:

Command*Description DSQUERY *Finds any object DSQUERY computerFinds computer accounts DSQUERY contactFinds contacts DSQUERY groupFinds group accounts DSQUERY ouFinds OUs DSQUERY partitionFinds AD Partitions DSQUERY quotaFinds object quotas DSQUERY serverFinds domain controllers DSQUERY siteFinds AD sites DSQUERY subnetFinds subnet objects DSQUERY userFinds user accounts * Output is in Unicode.

 Default Administrator account cannot be locked out.  Spaces can be used in Windows passwords.  If protected group is modified it resets after a period of time (one exception)  MS Updates should follow change control process  Delegation wizard is customizable  Delegate permissions using ACL Editor  GPO refresh is minutes, by default

 From my experience:  Loopback policy processing  Computer vs. User Configuration  Kiosk solutions  Non-ADS LDAP repositories  Password-protected screen saver – 4 settings to be effective,.scr file on end-user workstations