Presentation is loading. Please wait.

Presentation is loading. Please wait.

Copyright Anthony K. Holden, 2003. This work is the intellectual property of the author. Permission is granted for this material to be shared for non-commercial,

Similar presentations


Presentation on theme: "Copyright Anthony K. Holden, 2003. This work is the intellectual property of the author. Permission is granted for this material to be shared for non-commercial,"— Presentation transcript:

1 Copyright Anthony K. Holden, 2003. This work is the intellectual property of the author. Permission is granted for this material to be shared for non-commercial, educational purposes, provided that this copyright statement appears on the reproduced materials and that notice is given that the copying is by permission of the author. To disseminate otherwise or to republish requires written permission from the author.

2 Streamlining Support and Management Through the Implementation of Active Directory Presented by Lehigh University and Caldwell College

3 We are a small, private institution with a corresponding small budget There are approximately 2100 students We have an almost completely Microsoft Windows based environment Windows 2000 Advanced Servers running Active Directory services are the center of it all More than 95% of workstations are running Windows 2000 Professional About Caldwell College

4 Deploying software and patches to our workstations over the network Managing workstation security for the entire campus from one central location An overall reduction of the time and effort necessary to keep software up to date, and to maintain a high percentage of fully functional workstations, allows our staff to pursue other tasks and be proactive in supporting the campus What use is Active Directory?

5 Done with software included with the Windows 2000 Server Resource Kit and group policies The original installation of a program is “pushed” to a computer via Active Directory group policies Sysprep and Ghost are combined to create an image of that computer Updates can be deployed similarly in minutes instead of hours spent walking to each machine Programs are “self healing”.MSI installation files come with many programs and can be created for many more programs that do not come with one Software Deployment

6 A Strategy for Security Set up Organizational Units (OUs) for the staff, faculty, and the computer labsOUs Set a restrictive set of security policies for all computers joined to the Caldwell domain Exempt those computers which require a more open environment (e.g., an employee’s office computer) with a Loopback policy Loopback is assigned by computer A Loopback policy dictates that an alternate set of policies are appplied when a user logs on to that computer

7 Issue: Users saving files to the hard drive Resolution:Hide C:\ drive from users Redirect the Desktop and My Documents to read-only folders on a network share Issue:Users installing programs Resolution:Disable the Windows Installer, any Registry editing tools, the Command prompt, and the Run command on Start Menu Allow only specified programs to run Workstation Security Highlights

8 In two and half years, there have been only four system crashes among our 150+ student lab computers There has been a dramatic decrease in the volume of support requests for our general use computers (see chart)see chart More than 80% of all software on campus is installed via Active Directory group policies Our staff has been able to divert it’s time and resources to other areas such as internal web application development and the expansion of our student employee program, now three times its size in 1999 So How Well Has it Worked?

9

10 OU Diagram 2001 OU Diagram 2001

11 OU Diagram 2002 OU Diagram 2002

12


Download ppt "Copyright Anthony K. Holden, 2003. This work is the intellectual property of the author. Permission is granted for this material to be shared for non-commercial,"

Similar presentations


Ads by Google