Implementing Active Directory

Slides:



Advertisements
Similar presentations
UNIVERSITY OF EDUCATION BY H.M.ISHTIAQ RAFIQUE. Domain Name Structure.
Advertisements

MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 6 Managing and Administering DNS in Windows Server 2008.
Windows Server 2003 AD 安裝設定與管理維護 林寶森
Overview of Active Directory Domain Services
6.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
Lesson 18 – INSTALLING AND SETTING UP WINDOWS 2000 SERVER.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
1 Chapter 1 Introduction to Windows Server Two main goals for Net Admin Make network resources available to users Files, folders, printers, etc.
Chapter 13 Chapter 13: Managing Internet and Network Interoperability.
Hands-On Microsoft Windows Server 2003 Administration Chapter 3 Administering Active Directory.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 7: Planning a DNS Strategy.
Chapter 8: Network Operating Systems and Windows Server 2003-Based Networking Network+ Guide to Networks Third Edition.
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
Domain Name Server © N. Ganesan, Ph.D.. Reference.
© N. Ganesan, Ph.D., All rights reserved. Active Directory Nanda Ganesan, Ph.D.
Understanding Active Directory
Installing a New Windows Server 2008 Domain Controller in a New Windows Server 2008 R2.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
1 Chapter Overview Creating User and Computer Objects Maintaining User Accounts Creating User Profiles.
Guide to MCSE , Enhanced 1 Activity 10-1: Restarting Windows Server 2003 Objective: to restart Windows Server 2003 Start  Shut Down  Restart Configure.
ADVANCED MICROSOFT ACTIVE DIRECTORY CONCEPTS
Course 6421A Module 7: Installing, Configuring, and Troubleshooting the Network Policy Server Role Service Presentation: 60 minutes Lab: 60 minutes Module.
Ch 8-3 Working with domains and Active Directory.
Module 1: Installing Active Directory Domain Services
Overview of Active Directory Domain Services Lesson 1.
Overview of Active Directory Domain Services Lesson 1.
11 REVIEWING MICROSOFT ACTIVE DIRECTORY CONCEPTS Chapter 1.
COMP2017 – Server Administration
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
MCTS Guide to Microsoft Windows Server 2008 Applications Infrastructure Configuration (Exam # ) Chapter Two Deploying Windows Servers.
Name Resolution Domain Name System.
70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network Chapter 7: Domain Name System.
Chapter 18: Windows Server 2008 R2 and Active Directory Backup and Maintenance BAI617.
Chapter 6: Windows Servers
Module 1: Installing and Upgrading to Exchange Server 2003.
Implementing Active Directory Lesson 2. Skills Matrix Technology SkillObjective DomainObjective # Installing a New Active Directory Forest Configure a.
11 MANAGING AND DISTRIBUTING SOFTWARE BY USING GROUP POLICY Chapter 5.
Security Planning and Administrative Delegation Lesson 6.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 5: Active Directory Logical Design.
Installing and Using Active Directory Written by Marc Zacharko.
Step By Step Windows Server 2003 Installation Guide Step By Step Windows Server 2003 Installation Guide.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
Implementing Active Directory Lesson 2. Skills Matrix Technology SkillObjective DomainObjective # Installing a New Active Directory Forest Configure a.
How to configure DNS for a Windows 2000 domain? 1.Start the Install/Remove Programs Control Panel Applet (Start - Settings - Control Panel - Add/Remove.
 Identify Active Directory functions and Benefits.  Identify the major components that make up an Active Directory structure.  Identify how DNS relates.
Global Catalog and Flexible Single Master Operations (FSMO) Roles
Page 1 Active Directory and DNS Lecture 2 Hassan Shuja 09/14/2004.
Module 1: Implementing Active Directory ® Domain Services.
1 Chapter Overview Managing Object and Container Permissions Locating and Moving Active Directory Objects Delegating Control Troubleshooting Active Directory.
1 Active Directory Administration Tasks And Tools Active Directory Administration Tasks Active Directory Administrative Tools Using Microsoft Management.
OVERVIEW OF ACTIVE DIRECTORY
© Wiley Inc All Rights Reserved. MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition.
11 GLOBAL CATALOG AND FLEXIBLE SINGLE MASTER OPERATIONS (FSMO) ROLES Chapter 4.
Overview of Active Directory Domain Services Lesson 1.
Module 2: Implementing an Active Directory Forest and Domain Structure.
11 IMPLEMENTING ACTIVE DIRECTORY Chapter 2. Chapter 2: IMPLEMENTING ACTIVE DIRECTORY2 REQUIREMENTS FOR ACTIVE DIRECTORY  Microsoft Windows Server 2003.
Overview of Active Directory Domain Services
Implementing Active Directory Domain Services
Global Catalog and Flexible Single Master Operations (FSMO) Roles
Overview of Active Directory Domain Services
Objectives Differentiate between the different editions of Windows Server 2003 Explain Windows Server 2003 network models and server roles Identify concepts.
Unit 3 NT1330 Client-Server Networking II Date: 1/6/2016
Global Catalog and Flexible Single Master Operations (FSMO) Roles
Network Administration
Microsoft Windows Server 2003 Active Directory Infrastructure
Global Catalog and Flexible Single Master Operations (FSMO) Roles
Planning a Group Policy Management and Implementation Strategy
Security Planning and Administrative Delegation
How to install and manage exchange server 2010 OP Saklani.
Presentation transcript:

Implementing Active Directory Lesson 2

Skills Matrix Technology Skill Objective Domain Objective # Installing a New Active Directory Forest Configure a forest or a domain 2.1 Establishing and Maintaining Trust Relationships Configure trusts 2.2 Configuring Active Directory Lightweight Directory Services Configure Active Directory Lightweight Directory Services (AD LDS) 3.1 Configuring a Read-Only Domain Controller Configure the Read-Only Domain Controller (RODC) 3.3

Server Manager Located in Administrative Tools. Allows you to: Can also be accessed by right-clicking My Computer and selecting Manage. Allows you to: Add roles such as DNS server or Active Directory Domain Services role. Perform system diagnostics. Configure system services. Drill down into specific administrative tools. Break from the Power and show the Server Manager and what it has to offer. Also show how to manage roles within Server Manager. You can also mention that Server Manager is new to Windows Server 2008.

Server Manager

Requirements for Active Directory A server running Windows Server 2008 Standard Edition, Windows Server 2008 Enterprise Edition, or Windows Server 2008 Datacenter Edition (Full version or Server Core). An administrator account and password on the local machine. Web Edition does not offer Active Directory.

Requirements for Active Directory An NT file system (NTFS) partition for the SYSVOL folder structure. 200 MB minimum free space on the previously mentioned NTFS partition for Active Directory database files. 50 MB minimum free space for the transaction log files. Transmission Control Protocol/Internet Protocol (TCP/IP) must be installed and configured An authoritative DNS server for the DNS domain that supports service resource (SRV) records. Recommends to support incremental zone transfers and dynamic updates. Again, DNS is required to install Active Directory. For Windows, NTFS is the only way to go.

Installing Active Directory To install Active Directory, you will need to first add the Active Directory Domain Services role using Server Manager. Different from earlier versions of Windows, you need to first add the role before you can run dcpromo to install Active Directory.

Installing Active Directory

Installing Active Directory The Active Directory Installation Wizard, dcpromo, will guide you through any of the following installation scenarios: Adding a domain controller to an existing environment. Creating an entirely new forest structure. Adding a child domain to an existing domain. Adding a new domain tree to an existing forest. Demoting domain controllers and eventually removing a domain or forest. Same as earlier versions, dcpromo installs Active Directory. You should consider using a virtual server to show how to install Active Directory

Choosing the Deployment Configuration

Post-Installation Tasks Upon completion of the Active Directory installation, you should verify a number of items: Application directory partition creation. Aging and scavenging for zones. Forward lookup zones and SRV records. Reverse lookup zones.

Application Partitions

Aging and Scavenging of DNS Records Aging and scavenging are processes that can be used by Windows Server 2008 DNS to clean up the DNS database after DNS records become “stale” or out of date. Without this process, the DNS database would require manual maintenance to prevent server performance degradation and potential disk-space issues.

Aging and Scavenging of DNS Records

DNS Records Make sure Forward Lookup zone is created. Make sure Host (A) record is created for your server. Make sure DNS domains are created: _msdcs _sites _tcp _udp

DNS Records Should show DNS zone that you created while installing Active Directory.

Raising the Domain Functional Level Open Active Directory Domains and Trusts from the Administrative Tools folder. Right-click the domain you wish to raise and select Raise Domain Functional Level. Again review the features of higher domain and forest functional level introduced in chapter 1.

Raising the Forest Functional Level Open Active Directory Domains and Trusts from the Administrative Tools folder. Right-click the Active Directory Domains and Trusts icon in the console tree and select Raise Forest Functional Level.

Raising the Forest Functional Level If your domains have not all been raised to at least Windows Server 2003, you will receive an error indicating that raising the forest functional level cannot take place yet. If all domains have met the domain functionality criteria of Windows Server 2008, you can click Raise to proceed.

Removing Active Directory Click the Start menu, key dcpromo and then press Enter.

Schema Management Console Some commercial applications such as Microsoft Exchange will modify the schema as a part of their installation process. You can also extend the schema manually using the Active Directory Schema snap-in. To modify the schema manually, you must be a member of the Schema Admins group. The Active Directory Schema snap-in should be installed on the domain controller holding the Schema Master Operations role.

Installing the Schema Management Snap-in From a command prompt, key regsvr32 schmmgmt.dll. Close the Command Prompt window, click Start, and then select Run. Key mmc /a in the dialog box and click OK. Click the File menu and select Add/Remove Snap-in. Schema should rarely be changed.

Trust Relationship Trust relationships exist to make resource accessibility easier between domains and forests. Many trust relationships are established by default during the creation of the Active Directory forest structure. Trust relationships can be created using the Active Directory Domains and Trusts from the Administrative Tools folder.

Trust Relationships Four trust types can be manually established in Windows Server 2008: Shortcut trusts - Used to shorten the “tree-walking” process for users who require frequent access to resources elsewhere in the forest. Cross-forest trusts - Allows you to create two-way transitive trusts between separate forests. External trusts - Used to configure a one-way non-transitive trust. Realm trusts - Allows you to configure trust relationships between Windows Server 2008 Active Directory and a UNIX MIT Kerberos realm.

Revoking a Trust Using Netdom Open a command prompt and type the following text: Netdom trust TrustingDomainName /d:TrustedDomainName /remove Press Enter. Repeat these steps for the other end of the trust relationship.

User Principal Name (UPN) The name of a system user in an e-mail address format. username@domainname Based on Internet RFC 822. You can logon with domainname/username or UPN.

Changing the Default Suffix for User Principal Names Open Active Directory Domains and Trusts from the Administrative Tools folder. Right-click Active Directory Domains and Trusts and choose Properties. Click the UPN Suffix tab, key the new suffix, and click Add. Key more than one suffix if your forest has more than one tree and then click OK.

Summary Active Directory requires DNS to be installed. DNS does not have to be installed on a Windows Server 2003 machine, but the version of DNS used does need to support SRV records for Active Directory to function. Planning the forest and domain structure should include a checklist that can be referenced for dialog information required by the Active Directory Installation Wizard.

Summary Verification of a solid Active Directory installation includes verifying DNS zones and the creation of SRV records. Additional items, such as reverse lookups, aging, and scavenging, also should be configured. Application directory partitions are automatically created when Active Directory integrated zones are configured in DNS. These partitions allow replica placement within the forest structure.

Summary System classes of the schema cannot be modified, but additional classes can be added. Classes and attributes cannot be deleted, but they can be deactivated. Planning forest and domain functionality is dependent on the need for down-level operating system compatibility. Raising a forest or domain functional level is a procedure that cannot be reversed.

Summary Four types of manual trusts can be created: shortcut, external, cross-forest, and realm trusts. Manual trusts can be created by using Active Directory Domains and Trusts or netdom at a command line.

Summary UPNs provide a mechanism to make access to resources in multiple domains user-friendly. UPNs follow a naming format similar to email addresses. You must be a member of the Enterprise Admins group to add additional suffixes that can be assigned at user object creation.