W2K Migration Experiences Jack Schmidt Windows Policy Committee.

Slides:



Advertisements
Similar presentations
Single Sign-On with GRID Certificates Ernest Artiaga (CERN – IT) GridPP 7 th Collaboration Meeting July 2003 July 2003.
Advertisements

Establishing an OU Hierarchy for Managing and Securing Clients Base design on business and IT needs Split hierarchy Separate user and computer OUs Simplifies.
1 Preparing Windows 2000 installation (Week 3, Wednesday 2/25/2006) © Abdou Illia, Spring 2006.
ASSUME BREACH PREVENT BREACH + Research & Preparation First Host Compromised Hours Domain Admin Compromised Data Exfiltration (Attacker.
15.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
ASU Windows 2000 AD Environment OU Presentation. Agenda OU structure Domain Admin Support OU Administrator Control/Access Migration from NT to W2K OU.
1 SLAC Windows Migration Bob Cowles Presented for the SLAC Windows Migration Project HEPNT, Fermilab October 24, 2002.
Microsoft Windows Domains Structure and Services Chatziioannidis Christos Computer & Informatics Engineer Computer & Networking Services Computer Technology.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
OIT's Unity Labs Active Directory Windows Environment.
HalFILE 3.0 Active Directory Integration. halFILE 3.0 AD – What is it? Centralized organization of network objects and security – servers, computers,
Chapter 7 WORKING WITH GROUPS.
Local Administrator Meeting Brian Drendel.
9.1 © 2004 Pearson Education, Inc. Lesson 9: Implementing Group Policy in Windows 2000 Server Exam Microsoft® Windows® 2000 Directory Services Infrastructure.
Update to TIMGroup January Outline Introduction Where are we now? Where are we going? What can be done to prepare? What are the options?
FNAL Configuration Management Jack Schmidt Cyber Security Workshop May th 2006.
Chapter 4 Windows NT/2000 Overview. NT Concepts  Domains –A group of one or more NT machines that share an authentication database (SAM) –Single sign-on.
September 18, 2002 Introduction to Windows 2000 Server Components Ryan Larson David Greer.
Beams Division Local Administrators Meeting 9/17/02 Brian Drendel.
W2k Security At FNAL Jack Schmidt FNAL W2K Migration Working Group Chair April 16.
Chapter 7: WORKING WITH GROUPS
Windows 2003 Overview Lecture 1. Windows Networking Evolution Windows for Workgroups – peer-to-peer networking built into the OS Windows NT – separate.
Active Directory Academic IT Directors December 6 th 2005.
Windows NT 4.0 Demo. Windows NT: Brief overview Operating system for pentium and alpha based machines Multi tasking operating system Multi-account operating.
FNAL System Patching Design Jack Schmidt, Al Lilianstrom, Andy Romero, Troy Dawson, Connie Sieh (Fermi National Accelerator Laboratory) Introduction FNAL.
SMS 2003 Deployment and Managing Windows Security Rafal Otto Internet Services Group Department of Information Technology CERN 26 May 2016.
Module 5: Designing a Terminal Services Infrastructure.
Designing Authentication for a Microsoft Windows 2000 Network Designing Authentication in a Microsoft Windows 2000 Network Designing Kerberos Authentication.
Windows 2000 University of Colorado. Background Limited enterprise services: MIT K5 in labs, modems and some desktops, starting directories now, no identifier.
DFS & Active Directory Joshua Hedges |Brandon Maxfield | Robert Rivera | Will Zilch.
ACTIVE DIRECTORY : AN INTRODUCTION The Network Team Knox County Schools.
FORESEC Academy FORESEC Academy Security Essentials (V)
11.1 © 2004 Pearson Education, Inc. Exam Designing a Microsoft ® Windows ® Server 2003 Active Directory and Network Infrastructure Lesson 11: Planning.
Active Directory Harikrishnan V G 18 March Presentation titlePage 2 Agenda ► Introduction – Active Directory ► Directory Service ► Benefits of Active.
W2K and Kerberos at FNAL Jack Mark
1 Windows 2008 Configuring Server Roles and Services.
Planning a Microsoft Windows 2000 Administrative Structure Designing default administrative group membership Designing custom administrative groups local.
Current Deployment (NT4) n Minimal central infrastructure u DHCP/DNS service (non NT) u WINS service (but not supported) u Software image repository u.
Module 14: Securing Windows Server Overview Introduction to Securing Servers Implementing Core Server Security Hardening Servers Microsoft Baseline.
Page 1 System and Group Policies Lecture 7 Hassan Shuja 11/02/2004.
W2K and Kerberos at FNAL Jack Schmidt Mark Kaletka.
Module 4 Planning for Group Policy. Module Overview Planning Group Policy Application Planning Group Policy Processing Planning the Management of Group.
W2K Migration Status Report W2k Migration Working Group February 21, 2001.
CD W2K Desktop Migration Jack Schmidt 12/5/2001. W2K Migration Plan 1. Migrate users/desktops to provide kerberos authentication. Resources still in NT4.
WolfTech RoundTable March Attendees WolfTech – CNR – BME – CCCE – Others –
1 Chapter 13: RADIUS in Remote Access Designs Designs That Include RADIUS Essential RADIUS Design Concepts Data Protection in RADIUS Designs RADIUS Design.
Configuring, Managing and Maintaining Windows Server® 2008 Servers Course 6419A.
Active Directory. Computers in organizations Computers are linked together for communication and sharing of resources There is always a need to administer.
Module 3 l Objectives –Identify the security risks associated with specific NT Services –Understand the risk introduced by specific protocols –Identify.
CEG 2400 Fall 2012 Directory Services Active Directory Tree Domain.
LM/NTLMv1 Retirement Hosted by LSP Services.
Chapter 6 Server Management: Domains Workgroup Domain Trust Relationship Examples.
Module 1: Introduction to Windows 2000 and Networking.
IS 4506 Windows NTFS and IIS Security Features.  Overview Windows NTFS Server security Internet Information Server security features Securing communication.
Overview Microsoft Windows XP Pro (SP2) Microsoft Windows Server 2003 User accounts and groups File sharing and file permissions Password/Lockout Policy.
City-wide Active Directory Project Town Hall II
Module 1: Introduction to Administering Accounts and Resources
Network Operating Systems Examples
MCSA VCE
NTC 324 RANK Education Your Life - ntc324rank.com.
Windows NT to 2000/XP Migration at SLAC
Goals Introduce the Windows Server 2003 family of operating systems
ASU West Windows 2000 Environment
Implementing Client Security on Windows 2000 and Windows XP Level 150
NTC 328 Great Wisdom/tutorialrank.com. NTC 328 All Assignments For more course tutorials visit NTC 328 Assignment Week 1 Practice.
Windows Active Directory Environment
ACTIVE DIRECTORY An Overview.. By Karan Oberoi.
Module 8: Implementing Group Policy
Designing IIS Security (IIS – Internet Information Service)
Presentation transcript:

W2K Migration Experiences Jack Schmidt Windows Policy Committee

Outline Background Migration Timeline Present Status Outstanding Issues

NT4 Domain Structure BSS TDFNALD0 D0Level3DMACS BDControls BEAMS Controls Systems CD,CDF,ESH, FESS,LS, PPD, VMS File Servers, and Web trust ESE

Win2k Original Domain Structure WIN FERMI OU’s for Div/Sec/Exp’s BD ControlsD0 ControlsBSS

Win2k Current Domain Structure WIN FERMI OU’s for Div/Sec/Exp’s D0 Controls

Migration Timeline Fall 2000 – Windows Migration Working Group formed Objective- “Provide Windows users with a secure environment to easily share resources across the site and with other labs.”

Migration Timeline Winter/Spring 2001 –Computer Security mandates all systems be ‘kerberized’ and user accounts be centralized. –Authentication issues MIT KDC or Microsoft AD –Allow NTLM authentication? »NTLMv2 vs NTLM/LM

Migration Timeline Summer/Fall 2001 –Dynamic DNS Issues All systems or just DCs? –Implementation Plan –Test Domain/Production Domain creation Fall/Winter 2001 –Production Domain/NT4 Domain Trust Issues Microsoft bug –Limited User Migration Clone NT4 user issues

Migration Timeline Winter/Spring 2002 –Administration Issues Prevent Creation/Deletion of Users Prevent override of critical security policies Domain Admins/OU Managers/OU Admins –Domain Controller Management Issues Spring/Summer 2002 –Critical System Plan –CNAS Synchronization –Migration Deadline set to Dec 2002 by Computer Security

Migration Timeline Summer/Fall 2002 –Service/Captive account procedures defined Service: backups, antivirus Captive: controls, teststands –Terminal Service Security research –Remote Control Software Security research –Workstation Migration increases Fall/Winter 2002 –Windows Policy Committee formed Reports to Directorate –Remote Control Software recommendation (IPSEC solution)

Migration Timeline Winter/Spring 2003 –Migration Continues –Terminal Server findings –NetBIOS block work Exception forms VPN Testing

Present Status

Unresolved Issues Collapsing NT4 Domains Macintosh Authentication Special NT4 Domains Terminal Servers/Wincenters not kerberized. VPN and AD Authentication testing Win95/98/NT4/2k workgroups & standalones, etc.

Comments? Questions?