Active Directories: Purpose and Structure Chrystom Ciganko IFMG352 Final Presentation.

Slides:



Advertisements
Similar presentations
Microsoft Active Directory
Advertisements

Active Directory and Group Policy Blackhat Amsterdam Raymond Forbes.
COMP091 OS1 Active Directory. Some History Early 1990s Windows for Workgroups introduced peer-to-peer networking based on SMB over netbios (tcp/ip still.
How to Succeed with Active Directory Robert Williams, PhD CEO Secure Logistix Corporation.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 1: Introduction to Active Directory.
Chapter 6 Introducing Active Directory
Chapter 4 Chapter 4: Planning the Active Directory and Security.
Introduction to Active Directory
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
CS603 Active Directory February 1, 2001.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
By Karan Oberoi.  A directory service (DS) is a software application- or a set of applications - that stores and organizes information about a computer.
Understanding Active Directory
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
Hands-On Microsoft Windows Server 2008
Vikram Thakur Introduction to Active Directory Structure.
ADVANCED MICROSOFT ACTIVE DIRECTORY CONCEPTS
Overview of Active Directory Domain Services Lesson 1.
Overview of Active Directory Domain Services Lesson 1.
Nassau Community College
(ITI310) SESSIONS : Active Directory By Eng. BASSEM ALSAID.
BZUPAGES.COM An Introduction to. BZUPAGES.COM Introduction Large corporations today face the following problems Finding a certain file. Seeing everything.
Directory services Unit objectives
11 REVIEWING MICROSOFT ACTIVE DIRECTORY CONCEPTS Chapter 1.
Session 6 Windows Platform Dina Alkhoudari. Learning Objectives What is Active Directory Logical components of active directory Physical components of.
Windows Server 2008 Chapter 4 Last Update
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 3: Introducing Active Directory.
Windows 2000 Operating System -- Active Directory Service COSC 516 Yuan YAO 08/29/2000.
SERVER I SLIDE: 6. SERVER I Topics: Objective 4.3: Deploy and configure the DNS service Objective 5.1: Install domain controllers.
September 18, 2002 Windows 2000 Server Active Directory By Jerry Haggard.
CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
Module 7 Active Directory and Account Management.
Session 7 Windows Platform Eng. Dina Alkhoudari. Learning Objectives Active Directory review Managing users and groups Single Master Operations Delegation.
Company Confidential 1 A Course on Global Catalog And Flexible Single Master Operations (Fsmo) Roles Prepared for: *Stars* New Horizons Certified Professional.
Operations Master / FSMO Roles in Active Directory : Suhail Ashfaq Butt.
Global Catalog and Flexible Single Master Operations (FSMO) Roles
Page 1 Active Directory and DNS Lecture 2 Hassan Shuja 09/14/2004.
Hands-On Microsoft Windows Server 2008 Chapter 4-Part 1 Introduction to Active Directory and Account Manager.
Installing a Domain Controller
OVERVIEW OF ACTIVE DIRECTORY
Introduction to Active Directory
© Wiley Inc All Rights Reserved. MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition.
© Compiled by David Brewster Networking Diploma – Orange Group S Class Presentation: Operations Master Roles.
Hussain Ali Department of Computer Engineering KFUPM, Dhahran, Saudi Arabia Active Directory.
Active Directory. Computers in organizations Computers are linked together for communication and sharing of resources There is always a need to administer.
Global Catalog and Flexible Single Master Operations (FSMO) Roles BAI516.
11 GLOBAL CATALOG AND FLEXIBLE SINGLE MASTER OPERATIONS (FSMO) ROLES Chapter 4.
CEG 2400 Fall 2012 Directory Services Active Directory Tree Domain.
Windows 2003 Architecture, Active Directory & DNS Lecture # 3 Hassan Shuja 02/14/2006.
MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition (70-294) Chapter 1: Overview of the Active.
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
Overview of Active Directory Domain Services
Active Directory Replication (Part 1) Paige Verwolf Support Professional Microsoft Corporation © 1999 Microsoft Corporation. All rights reserved.
Implementing Active Directory Domain Services
Global Catalog and Flexible Single Master Operations (FSMO) Roles
Overview of Active Directory Domain Services
Active Directory Fundamentals
Active Directory and Group Policy
Active Directory Administration
(ITI310) SESSIONS 6-7-8: Active Directory.
Active Directory Stored collection of information about objects
Examining a Windows NT Infrastructure (2)
Chapter 4: Planning the Active Directory and Security
Active Directory Fundamentals
Unit 5 NT1330 Client-Server Networking II Date: 7/12/2016
Microsoft Active Directory
Global Catalog and Flexible Single Master Operations (FSMO) Roles
ACTIVE DIRECTORY An Overview.. By Karan Oberoi.
Presentation transcript:

Active Directories: Purpose and Structure Chrystom Ciganko IFMG352 Final Presentation

What is Active Directory? Directory service used to store information about objects within a domain, to organize these objects, and to centralize a network

Goals of AD High Scalability Compatibility with older NOS's Administration is simplified

DNS Absolutely vital for AD  Must be correctly configured or AD will not work AD's locating server All servers must be registered in the DNS Points the user (unaware) to the proper authentication server for login

Standards used by AD Kerberos for authentication X.500 for structure X.509 for cert-based authentication DNS for ease of machine communication LDAP for authorization

Active Directory structure Hierarchical framework of objects Objects: Resources(printers)‏ Services( )‏ Users(accounts and groups)‏  Uniquely identified by: Name Attributes  Defined by: Schema  Determines kinds of objects within the Active Directory

Methods of structure Order of the levels Forest – the entire collection of all objects  Contains all trust-linked trees Tree – collection of all domains Domain – collection of most objects  Objects can be contained in Organizational Units(OU's)‏ Can assign Group Policy Objects(GPO's)‏  Flow down to users/groups

Forest Compilation of Trees Contains single Root-Tree  First Domain installed  100% required Sub-Trees must be added to the Root-Tree or no Forest is created

Tree Hierarchal structure of Domains Transitive Trusts  Type of trust that is extended beyond two domains to other trusted domains in the tree Sub-Domains must be added to the Root- Domain or there's no tree

Domain Building block for AD Created by Domain Controllers (DC's)‏ Controller of  System Policies  Administration  Traffic

Schema Definition of all the AD's  Attributes  Syntaxes  Object-type or classes Only one consistent Schema per Forest Can be matched with a Database Schema

Server roles Domain Controller  Flexible single master operation (FSMO)‏ Specialized DC tasks  Primary Domain Controller (PDC)‏  Backup Domain Controller (BDC)‏ Global Catalog Member Server

Domain Controller Requirement for AD Control Schema, Configuration, and Domain partitions  Schema: Defines object classes within Forest  Configuration: Defines physical structure(topology)‏  Domain: Contains objects within the domain All DC's Schema and Configuration partitions within Forest are sync'd Domain partition only sync'd with other DC's within that domain

Organizational Units (OU's)‏ Carry out the structure within the Domain Are not assigned the specific rights Used for administrative reasons Can be nested if needed

Multi-domain forests Knowledge Consistency Checker(KCC)‏  Creation of replication topology Again, DC's only sync with DC's Global catalog (GC) servers  Contained within a DC  Create global listing of all objects within all domains

Global Catalog Server Required for logon Contains copy of all Objects for the entire Forest Answers AD search requests

Uses of AD Update all computers by updating an object within the forest or tree Managing user groups  Grant access to particular users  Deny access (deny always overrides grant)‏

Example of domain users/groups

Resources eric/0,295582,sid68_gci ,00.html