Developing with uConnect

Slides:



Advertisements
Similar presentations
ADM 493 Digging Deep into the Active Directory LDP.
Advertisements

Chapter 6 Introducing Active Directory
Chapter 4 Chapter 4: Planning the Active Directory and Security.
1 Active Directory (Week 8, Monday 2/26/2007) © Abdou Illia, Spring 2007.
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
CS603 Active Directory February 1, 2001.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
1 Chapter 1 Introduction to Windows Server Two main goals for Net Admin Make network resources available to users Files, folders, printers, etc.
Administering Active Directory
Hands-On Microsoft Windows Server 2003 Administration Chapter 1 Windows Server 2003 Network Administration.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 4: Implementing and Managing Group and Computer Accounts.
Hands-On Microsoft Windows Server 2003 Administration Chapter 3 Administering Active Directory.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 4: Implementing and Managing Group and Computer Accounts.
Chapter 4 Introduction to Active Directory and Account Management
By Rashid Khan Lesson 8-Crowd Control: Controlling Access to Resources Using Groups.
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
By Karan Oberoi.  A directory service (DS) is a software application- or a set of applications - that stores and organizes information about a computer.
Understanding Active Directory
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
Module 1: Introduction to Active Directory
Hands-On Microsoft Windows Server 2008
Chapter 7 WORKING WITH GROUPS.
Hands-On Microsoft Windows Server 2008
03/07/08 © 2008 DSR and LDAP Authentication Avocent Technical Support.
Corso referenti S.I.R.A. – Modulo 2 06 – Active Directory 20/11 – 27/11 – 05/12 11/12 – 13/12 (gruppo 1) 12/12 – 15/12 (gruppo 2) Cristiano Gentili, Massimiliano.
Nassau Community College
(ITI310) SESSIONS : Active Directory By Eng. BASSEM ALSAID.
Chapter 11: Directory Services. Directory Services A directory service is a database that contains information about all objects on the network. Directory.
BZUPAGES.COM An Introduction to. BZUPAGES.COM Introduction Large corporations today face the following problems Finding a certain file. Seeing everything.
Directory services Unit objectives
Windows Server 2008 Chapter 4 Last Update
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 3: Introducing Active Directory.
ADM 493 Digging Deep into the Active Directory with LDP John Craddock Principal Consultant Sally Storey Consultant.
Introduction To OpenLDAP Directory Services. What is a Directory Service? A specialized database optimized for reading, browsing, and searching. No complicated.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 10: Managing Users, Groups, Computers and Resources.
KAPLAN SCHOOL OF INFORMATION SYSTEMS AND TECHNOLOGY Welcome to Unit 4 IT278 Network Administration Course Name – IT278 Network Administration Instructor.
SERVER I SLIDE: 6. SERVER I Topics: Objective 4.3: Deploy and configure the DNS service Objective 5.1: Install domain controllers.
Chapter Two Defining Network Objects. Chapter Objectives Describe how a workstation communicates with the network, and list the software components required.
Module 7 Active Directory and Account Management.
MCSE Guide to Microsoft Exchange Server 2003 Administration Chapter Five Managing Addresses.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 4: Implementing and Managing Group and Computer Accounts.
Hands-On Microsoft Windows Server 2008 Chapter 4-Part 1 Introduction to Active Directory and Account Manager.
1 Chapter Overview Managing Object and Container Permissions Locating and Moving Active Directory Objects Delegating Control Troubleshooting Active Directory.
Introduction to Active Directory
MCSE Guide to Microsoft Exchange Server 2003 Administration Chapter Three Managing Recipients.
Module 1: Introduction to Active Directory
Logical and Physical Network Design 1. Active Directory Objects Objects Represent Network Resources (Users,Groups,Computers,Printers) Attributes Store.
Hussain Ali Department of Computer Engineering KFUPM, Dhahran, Saudi Arabia Active Directory.
Active Directory. Computers in organizations Computers are linked together for communication and sharing of resources There is always a need to administer.
CEG 2400 Fall 2012 Directory Services Active Directory Tree Domain.
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
Planning an Active Directory Deployment Lesson 1.
Active Directories: Purpose and Structure Chrystom Ciganko IFMG352 Final Presentation.
Overview of Active Directory Domain Services
Implementing Active Directory Domain Services
Using Microsoft Identity Manger with SharePoint 2016 to fill the User Profile Sync Gap Max Fritz Senior Systems Consultant Now Micro.
ACTIVE DIRECTORY ADMINISTRATION
Overview of Active Directory Domain Services
Active Directory Fundamentals
Active Directory Administration
(ITI310) SESSIONS 6-7-8: Active Directory.
CONFIGURING LDAP Authentication (rsso 9.1)
Active Directory Administration
Active Directory Stored collection of information about objects
Unit 3 NT1330 Client-Server Networking II Date: 1/6/2016
Active Directory (November 7, 2016) © Abdou Illia, Fall 2016.
Windows Active Directory Environment
CNT 4603: System Administration Fall 2010
Presentation transcript:

Developing with uConnect

What is uConnect? Microsoft Active Directory (Directory Services) Microsoft Exchange (email and smtp routing) Domain Name System (DNS) Used to authorize and authenticate users and computers Utilizes Lightweight Directory Access Protocol (LDAP)

AD Forest Configuration Parent domain: ad3.ucdavis.edu Child domains: ou.ad3.ucdavis.edu ex.ad3.ucdavis.edu Trust with Microsoft Office365

AD Servers AD Directory Services servers are called domain controllers (dc) Each uConnect domain has domain controllers Most uConnect DCs also function as Global Catalog servers Global Catalog server stores its own full, writable domain replica (all objects and all attributes) plus a partial, read-only replica of every other domain in the forest.

AD Object Types Organization Unit (OU) Group Computer User Contact

AD Search Components AD Server Search Base Scope Filter Attributes

Search Base The location in AD from which the LDAP search begins Distinguished Name format Examples: OU=ucdUsers,DC=ad3,DC=ucdavis,DC=edu OU=COE,OU=Departments,DC=ou,DC=ad3,DC=ucdavis,DC=edu DC=ad3,DC=ucdavis,DC=edu DC=ou,DC=ad3,DC=ucdavis,DC=edu

Important uConnect OUs Campus members accounts are in AD3 OU=ucdUsers,DC=ad3,DC=ucdavis,DC=edu PPS Department Groups OU=ucdDepts,DC=ad3,DC=ucdavis,DC=edu Departments OU=COE,OU=Departments,DC=ou,DC=ad3,DC=ucdavis,DC=edu

Search Scope Sets how deep to search within the search base Base: search of the base object only One Level: search of the immediately subordinate objects to the base. Does not include the base object Subtree: search of the base object and the entire subtree

Search Filter Selects which AD object(s) to return Examples: (&(objectClass=user)(sAMAccountName=dbunn)) (&(objectclass=computer)(|(name=coe-w10)(sAMAccountName=coe-w10$))) (&(objectClass=group)(mail=* )) (&(objectClass=group)(whenChanged>=20161011083000.0Z)) (&(objectclass=group)(|(groupType=8)(groupType=-2147483640))(extensionAttribute3=UCDBoxSync))

Search Attributes The desired AD object properties to view Pulling all attributes make large searches slower Vary depending upon AD object type Special handling is required for groups with over 1,500 members Names in camel case userPrincipalName, distinguishedName, proxyAddresses, displayName

Searching for Unique Objects cn values unique only at the OU level objectSid and sAMAccount values are only unique at the domain level distinguishedName values are unique across AD forest but easily changed by moving AD object objectGuid and userPrincipalName unique across the AD forest objectGuid never changes and stored in little endian format

Pulling AD Group by objectGuid via C# .NET

Please remember a group's “cn” can lie

Group Membership Changes When modifying a group, use a domain controller in the same domain Pull the distinguishedName of the user to be added or removed When syncing with Campus data sources make sure nested groups and OU domain accounts are not removed

Code Demo