Module 2: Managing User and Computer Accounts. Overview Creating User Accounts Creating Computer Accounts Modifying User and Computer Account Properties.

Slides:



Advertisements
Similar presentations
Chapter Five Users, Groups, Profiles, and Policies.
Advertisements

By Rashid Khan Lesson 5-Directory Assistance: Administration Using Active Directory Users and Computers.
1 Module 3 Setting Up User Accounts. 2  Overview Introduction to User Accounts Planning New User Accounts Creating User Accounts Deleting and Renaming.
Module 6: Configuring Windows XP Professional to Operate in a Microsoft Network.
Lesson 17: Configuring Security Policies
Khan Rashid Lesson 11-The Best Policy: Managing Computers and Users Through Group Policy.
Module 4: Implementing User, Group, and Computer Accounts
Chapter 8 Chapter 8: Managing Accounts and Client Connectivity.
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 5: Account Management.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 3: Creating and Managing User Accounts.
11 SUPPORTING LOCAL USERS AND GROUPS Chapter 3. Chapter 3: Supporting Local Users and Groups2 SUPPORTING LOCAL USERS AND GROUPS  Explain the difference.
Lesson 19 – ADMINISTERING WINDOWS 2000 SERVER : THE BASICS.
Lesson 14: Creating and Managing Active Directory Users and Computers
Chapter 8 Chapter 8: Managing the Server Through Accounts and Groups.
Chapter 3 – Creating and Managing User Accounts MIS 431 – Created Spring 2006.
11 WORKING WITH COMPUTER ACCOUNTS Chapter 8. Chapter 8: WORKING WITH COMPUTER ACCOUNTS2 CHAPTER OVERVIEW  Describe the process of adding a computer to.
11 WORKING WITH COMPUTER ACCOUNTS Chapter 8. Chapter 8: WORKING WITH COMPUTER ACCOUNTS2 CHAPTER OVERVIEW Describe the process of adding a computer to.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 3: Creating and Managing User Accounts.
1 Chapter Overview Creating User and Computer Objects Maintaining User Accounts Creating User Profiles.
Module 8: Implementing Administrative Templates and Audit Policy.
Microsoft ® Official Course Module 4 Automating Active Directory Domain Services Administration.
Windows Server 2003 使用者及電腦帳號管理 林寶森
11 WORKING WITH USER ACCOUNTS Chapter 6. Chapter 6: WORKING WITH USER ACCOUNTS2 CHAPTER OVERVIEW Understand the differences between local user and domain.
Module 2: Managing User and Computer Accounts
Module 2 Creating Active Directory ® Domain Services User and Computer Objects.
70-270: MCSE Guide to Microsoft Windows XP Professional Chapter 5: Users, Groups, Profiles, and Policies.
Module 1: Introduction to Administering Accounts and Resources
Working with Workgroups and Domains
Using Group Policy to Manage User Environments. Overview Introduction to Managing User Environments Introduction to Administrative Templates Assigning.
1 User Account Administration Introduction to User Accounts Planning New User Accounts Creating User Accounts Creating User Profiles Creating Home Directories.
6.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 6: Administering User Accounts.
User Manager for Domains.  Manages the user accounts in a domain  It is located in the PDC  While User Manager exists in each NT machine, but it is.
5.1 © 2004 Pearson Education, Inc. Lesson 5: Administering User Accounts Exam Microsoft® Windows® 2000 Directory Services Infrastructure Goals 
Module 10: Configuring Windows XP Professional to Operate in Microsoft Networks.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 10: Managing Users, Groups, Computers and Resources.
Designing Active Directory for Security
Windows Server 2003 Overview 1 Windows 2003 Server Overview Ayaz
11 WORKING WITH USER ACCOUNTS Chapter 6. Chapter 6: WORKING WITH USER ACCOUNTS2 UNDERSTANDING USER ACCOUNTS  Local user accounts  stored in the Security.
DIT314 ~ Client Operating System & Administration CHAPTER 5 MANAGING USER ACCOUNTS AND GROUPS Prepared By : Suraya Alias.
8.1 © 2004 Pearson Education, Inc. Exam Designing a Microsoft ® Windows ® Server 2003 Active Directory and Network Infrastructure Lesson 8: Planning.
Chapter 13 Users, Groups Profiles and Policies. Learning Objectives Understand Windows XP Professional user accounts Understand the different types of.
Active Directory Administration Lesson 5. Skills Matrix Technology SkillObjective DomainObjective # Creating Users, Computers, and Groups Automate creation.
Module 7 Active Directory and Account Management.
Introduction to Microsoft Management Console (MMC) MMC is a common console framework for management applications. MMC provides a common environment for.
Module 1: Introduction to Active Directory Infrastructure
1 Chapter Overview Understanding User Accounts Planning New User Accounts Creating, Modifying, and Deleting User Accounts Setting Properties for User Accounts.
1 Part-1 Chap 5 Configuring Accounts Definitions.
Module 2 Creating Active Directory ® Domain Services User and Computer Objects.
Fall 2011 Nassau Community College ITE153 – Operating Systems Session 21 Administering User Accounts and Groups 1.
1 Chapter Overview Managing Object and Container Permissions Locating and Moving Active Directory Objects Delegating Control Troubleshooting Active Directory.
Guide to MCSE , Enhanced 1 Activity 3-1: Reviewing User Account Properties Objective is to review properties of user accounts through main tabs of.
Module 7: Implementing Security Using Group Policy.
NetTech Solutions Security and Security Permissions Lesson Nine.
Module 10: Implementing Administrative Templates and Audit Policy.
Module 1: Introduction to Administering Accounts and Resources.
Microsoft ® Official Course Module 4 Automating Active Directory Domain Services Administration.
1 Chapter Overview Using Group Objects Understanding Default Groups Creating Group Objects Managing Administrative Access.
Module 3: Managing Groups. Overview Creating Groups Managing Group Membership Strategies for Using Groups Using Default Groups.
Module 4: Managing Access to Resources. Overview Overview of Managing Access to Resources Managing Access to Shared Folders Managing Access to Files and.
6/19/2016 أساسيات الأتصال و الشبكات Communication & Networks Fundamentals lab 4.
Module 4: Managing Access to Resources
Module 1: Introduction to Administering Accounts and Resources
ACTIVE DIRECTORY ADMINISTRATION
ACTIVE DIRECTORY ADMINISTRATION
Active Directory Administration
Creating and Managing User Accounts
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 4: Implementing and Managing Group and Computer Accounts.
Chapter 8: Managing Accounts and Client Connectivity
Presentation transcript:

Module 2: Managing User and Computer Accounts

Overview Creating User Accounts Creating Computer Accounts Modifying User and Computer Account Properties Creating a User Account Template Managing User and Computer Accounts Using Queries to Locate User and Computer Accounts in Active Directory

Lesson: Creating User Accounts What Is a User Account? Names Associated with Domain User Accounts Guidelines for Creating a User Account Naming Convention User Account Placement in a Hierarchy User Account Password Options When to Require or Restrict Password Changes Tools to Create User Accounts Practice: Creating User Accounts Best Practices for Creating User Accounts

What Is a User Account? Multimedia: Types of User Accounts Domain user accounts (stored in Active Directory) Local user accounts (stored on local computer) Windows Server 2003 Domain

Names Associated with Domain User Accounts Name Example User logon name Tadams Pre—Windows 2000 logon name contoso\Tadams User principal logon name LDAP distinguished name CN=terry adams,ou=sales,dc=contoso,dc=msft LDAP relative distinguished name CN=terry adams

Guidelines for Creating a User Account Naming Convention A convention for naming user accounts should accommodate: Employees with identical names Different types of employees, such as temporary or contract employees

User Account Placement in a Hierarchy Geopolitical Design Users North America Users South America Business Design Users Accounting Users Sales

User Account Password Options Account options Description User must change password at next logon Users must change their passwords the next time they log on to the network User cannot change password Users do not have the permissions to change their own password Password never expires Users’ passwords will not expire and do not need to be changed Account is disabled Users cannot log on by using the selected account

When to Require or Restrict Password Changes Option Use this option when you: Require password changes Create new domain accounts Reset passwords Restrict password changes Create local and domain service accounts

Tools to Create User Accounts Tools available to create user accounts Active Directory Users and Computers Command-line utilities Dsadd Net user Batch utilities CSVDE LDIFDE Computer Management MMC to create local users Active Directory Users and Computers Command-line utilities Dsadd Net user Batch utilities CSVDE LDIFDE Computer Management MMC to create local users

Practice: Creating User Accounts In this practice, you will: Create a local user account by using Computer Management Create a domain account by using Active Directory Users and Computers Create a domain user account by using dsadd

Best Practices for Creating User Accounts Best practices for creating local user accounts Limit the number of people who can log on locally Best practices for creating domain user accounts Disable any account that will not be used immediately Require users to change their passwords the first time that they log on Do not use the Users container for ordinary user accounts Rename the Administrator account Use strong passwords

Lesson: Creating Computer Accounts What Is a Computer Account? Why Create a Computer Account? Where Computer Accounts Are Created in a Domain Computer Account Options Practice: Creating a Computer Account

What Is a Computer Account? Identifies a computer in a domain Provides a means for authenticating and auditing computer access to the network and to domain resources Is required for every computer running:  Windows Server 2003  Windows XP Professional  Windows 2000  Windows NT

Why Create a Computer Account? Security  Authentication  Auditing Management  Software deployment  Desktop management  Hardware and software inventory through Systems Management Server

Where Computer Accounts Are Created in a Domain Computers that join a domain are created in the Computers container Computer accounts can be moved to or created in other organizational units Computer accounts can be moved to or created in other organizational units

Computer Account Options

Practice: Creating a Computer Account In this practice, you will: Create a computer account by using Active Directory Users and Computers Create a computer account by using dsadd

Lesson: Modifying User and Computer Account Properties When to Modify User and Computer Account Properties Properties Associated with User Accounts Renaming a User Account Properties Associated with Computer Accounts Practice: Modifying User and Computer Account Properties

When to Modify User and Computer Account Properties Modify user account properties to: Make it easier to use search capabilities to find users Match a company’s organizational hierarchy Determine the group membership of a user account Make it easier to use search capabilities to find users Match a company’s organizational hierarchy Determine the group membership of a user account Modify computer account properties to: Assist in asset tracking (Location property) Document who manages a computer (Managed By property) Assist in asset tracking (Location property) Document who manages a computer (Managed By property)

Properties Associated with User Accounts The Properties dialog box for a user account contains:

Renaming a User Account The Rename User dialog box

Properties Associated with Computer Accounts The Properties dialog box for a computer account contains:

Practice: Modifying User and Computer Account Properties In this practice, you will modify user and computer account properties

Lesson: Creating a User Account Template What Is a User Account Template? What Properties Are in a Template? Guidelines for Creating User Account Templates Practice: Creating a User Account Template

What Is a User Account Template? Employs a user account with properties meeting common user requirements Makes creating user accounts with standardized configurations more efficient User Account Template

What Properties Are in a Template? TabProperties copied Address All properties except Street Address Account All properties except Logon Name Profile All properties except Profile path and Home folder reflect new user’s logon name Organization All properties except Title Member Of All properties

Guidelines for Creating User Account Templates Create a separate classification for each department Create a separate group for short-term and temporary employees Set user account expiration dates for short-term and temporary employees Disable the account template Identify the account template

Practice: Creating a User Account Template In this practice, you will create a user account template

Lesson: Managing User and Computer Accounts Why Enable or Disable User and Computer Accounts? What Are Locked-Out User Accounts? When to Reset User Passwords When to Reset Computer Accounts Practice: Resetting and Disabling a User Account

Why Enable or Disable User and Computer Accounts? Scenarios for disabling accounts User takes a leave of absence Creating accounts that will not be used immediately User takes a leave of absence Creating accounts that will not be used immediately Tools available for disabling or enabling accounts Active Directory Users and Computers Dsmod command Active Directory Users and Computers Dsmod command

What Are Locked-Out User Accounts? Account lockout thresholds:  Define the number of failed logon attempts  Prevent hackers from guessing user passwords Logon failures can occur:  At the logon screen  At a screen saver protected by a password  When accessing network resources

When to Reset User Passwords Reset a password when a user forgets his or her password After the local user’s password has been reset, the user can no longer access some types of information

When to Reset Computer Accounts Reset computer accounts when: Computers fail to authenticate to the domain Passwords need to be synchronized

Practice: Resetting and Disabling a User Account In this practice, you will: Reset a user account password Disable user accounts

Lesson: Using Queries to Locate User and Computer Accounts in Active Directory Multimedia: Introduction to Locating User and Computer Accounts in Active Directory Search Types What Is a Saved Query? Importing and Exporting Saved Queries Practice: Using Saved Queries to Locate Users and Computers in Active Directory

Multimedia: Introduction to Locating User and Computer Accounts in Active Directory This presentation will explain how to locate objects in Active Directory

Search Types Basic query criteria include: Object type Location General values associated with the object, such as name and description

What Is a Saved Query?

Importing and Exporting Saved Queries

Practice: Using Queries to Locate Users and Computers in Active Directory In this practice, you will: Create a query to find computer accounts in the sales department Export the query as an XML file in the Admin_tools shared folder

Lab: Managing User and Computer Accounts In this lab, you will: Create user accounts Create computer accounts Use queries to locate objects Modify user and computer properties