Active Directory Boundaries - Purpose Replication Boundaries Security Boundaries.

Slides:



Advertisements
Similar presentations
Active Directory: Beyond The Basics
Advertisements

Active Directory and Group Policy Blackhat Amsterdam Raymond Forbes.
Lesson 16: Configuring Domain Controllers
How to Succeed with Active Directory Robert Williams, PhD CEO Secure Logistix Corporation.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 1: Introduction to Active Directory.
Chapter 6 Introducing Active Directory
Chapter 4 Chapter 4: Planning the Active Directory and Security.
Introduction to Active Directory
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
CS603 Active Directory February 1, 2001.
Introduction to Dfs. Limits of Dfs 260 characters per file path 32 alternatives per volume 1 Dfs root per server Unlimited Dfs roots per domain Volumes.
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
Understanding Active Directory
Advanced Active Directory Deployments Rick Claus IT Pro Advisor Microsoft Canada
Vikram Thakur Introduction to Active Directory Structure.
1 Chapter Overview Creating Sites and Subnets Configuring Intersite Replication Troubleshooting Active Directory Replication.
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 10: Configuring and Maintaining the Active Directory Infrastructure.
Copyright line. Configuring the Active Directory Infrastructure Exam Objectives  Working with Forests and Domains  Working with Sites  Working with.
Active Directory Implementation Class 4
Chapter 4: Active Directory Design and Security Concepts
ADVANCED MICROSOFT ACTIVE DIRECTORY CONCEPTS
Overview of Active Directory Domain Services Lesson 1.
Nassau Community College
(ITI310) SESSIONS : Active Directory By Eng. BASSEM ALSAID.
BZUPAGES.COM An Introduction to. BZUPAGES.COM Introduction Large corporations today face the following problems Finding a certain file. Seeing everything.
11 REVIEWING MICROSOFT ACTIVE DIRECTORY CONCEPTS Chapter 1.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 7: Active Directory Replication.
Session 6 Windows Platform Dina Alkhoudari. Learning Objectives What is Active Directory Logical components of active directory Physical components of.
Module 7: Implementing Sites to Manage Active Directory Replication.
SERVER I SLIDE: 6. SERVER I Topics: Objective 4.3: Deploy and configure the DNS service Objective 5.1: Install domain controllers.
Active Directory Operations Masters. Overview  Active Directory updates generally multimaster Changes can be made on any DC  Some exceptions — single.
CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
Module 7 Active Directory and Account Management.
Company Confidential 1 A Course on Global Catalog And Flexible Single Master Operations (Fsmo) Roles Prepared for: *Stars* New Horizons Certified Professional.
1 Week 8 – Manage Sites and Replication Configure Sites and Subnets Configure the Global Catalog and Application Partitions Configure Replication.
Operations Master / FSMO Roles in Active Directory : Suhail Ashfaq Butt.
© Wiley Inc All Rights Reserved. MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition.
Working with Active Directory Sites BAI516. Logical Versus Physical Structure Logical Forest Trees Domains OUs Leaf objects Physical IP Subnets/Sites.
Global Catalog and Flexible Single Master Operations (FSMO) Roles
Page 1 Active Directory and DNS Lecture 2 Hassan Shuja 09/14/2004.
10.1 © 2004 Pearson Education, Inc. Exam Designing a Microsoft ® Windows ® Server 2003 Active Directory and Network Infrastructure Lesson 10: Planning.
Windows Server 2003 站台設定與管理
Module 4: Configuring Active Directory Sites and Replication.
70-412: Configuring Advanced Windows Server 2012 services
OVERVIEW OF ACTIVE DIRECTORY
Introduction to Active Directory
© Wiley Inc All Rights Reserved. MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition.
© Compiled by David Brewster Networking Diploma – Orange Group S Class Presentation: Operations Master Roles.
11 WORKING WITH ACTIVE DIRECTORY SITES Chapter 3.
Global Catalog and Flexible Single Master Operations (FSMO) Roles BAI516.
Unit 4 NT1330 Client-Server Networking II Date: 1/13/2016
Module 8: Planning for Windows Server 2008 Active Directory Services.
Module 4: Configuring Active Directory ® Domain Sevices Sites and Replication.
11 GLOBAL CATALOG AND FLEXIBLE SINGLE MASTER OPERATIONS (FSMO) ROLES Chapter 4.
Windows 2003 Architecture, Active Directory & DNS Lecture # 3 Hassan Shuja 02/14/2006.
1 Introduction to Active Directory Directory Services Uniquely identify users and resources on a network Provide a single point of network management.
MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition (70-294) Chapter 1: Overview of the Active.
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
Planning an Active Directory Deployment Lesson 1.
Overview of Active Directory Domain Services Lesson 1.
Working with Active Directory Sites Lesson 3. Logical Versus Physical Structure Logical Forest Trees Domains OUs Leaf objects Physical IP Subnets/Sites.
Active Directory Replication (Part 1) Paige Verwolf Support Professional Microsoft Corporation © 1999 Microsoft Corporation. All rights reserved.
Global Catalog and Flexible Single Master Operations (FSMO) Roles
Active Directory Fundamentals
Active Directory and Group Policy
(ITI310) SESSIONS 6-7-8: Active Directory.
Global Catalog and Flexible Single Master Operations (FSMO) Roles
Chapter 4: Planning the Active Directory and Security
FSMO Roles and Global Catalog Servers
Global Catalog and Flexible Single Master Operations (FSMO) Roles
Presentation transcript:

Active Directory Boundaries - Purpose Replication Boundaries Security Boundaries

Active Directory Boundaries - Types Geographic vs Organizational Contiguous vs Discontigous namespace i.e. oldcompany1.newcompany.com and oldcompany2.newcompany.com are 2 contiguous namespaces

Prestaging forestprep and domainprep Removal

Removing Domains or Trees ADMT pruning/grafting ADMTv3.1

Functional Levels Viewing Raising Interoperability UPN – User Principal Name

Simplifying Logon Each user Has a unique down-level logon name Can have multiple friendly UPN's

Trust Basics Trusts allow communication between the boundaries of domains and forests 1 way Trust 2 way Trust

Transitive Trusts Extend permissions across multiple domains Automatically created as new domain joins a tree or new child is created

Forest Trusts Forest wide Selective authentication

External Trusts Non-Transitive NT4.0 or Kerebos compatible

Shortcut Trust Transitive Speeds up authentication and authorization

Identity Security Identification (SID) filtering

Create Sites Balance service delivered to all locations. Inventory the number of users at each site Inventory the types of WAN links

Create AD Subnets Associate subnets with the site location that has the closest DC

Configure Site Links Site Links = WAN links Star vs Mesh

Associating Link Costs Cost = Speed/Availability of WAN

Configure Infrastructure Manually link Operational Masters with their backup servers

Global Catalog Servers Deploy Global Catalog servers at each site when possible

Replication Each domain can have its own replication topology and schedule Different events have different priorities to trigger replication

DFS DFS – Distributed File System Method for synchronizing shared folders

DFS DFS – Distributed File System Method for synchronizing shared folders Conflict and Deleted folder Good for application distribution or other read-only data

Replication - Automatic Knowledge Consistency Checker (KCC) Bridgehead Server Intersite Topology Generator

Replication - Automatic Knowledge Consistency Checker (KCC) Bridgehead Server Intersite Topology Generator Scheduling IP and SMTP protocols

Replication - Manual Designate a specific bridgehead server Make a one way replication partnership Manually force replication after making changes to AD

Global Catalog Server DC that contains information about other Domains

Promotion Use the AD snap-in Sites and Services Partial Attribute Set

Alternate Methods UGMC – Universal Group Membership Caching

Domain Operations Masters PDC emulator Relative ID (RID) Infrastructure

Forest Operations Masters Schema Master Domain Naming

Operations Master Seize vs Transfer Backup Placement

Schema Master Schema can be extended with various tools Placement should be on a Global Catalog Time Service is important for successful upgrades