Active Directory Virtualization Safeguards and Domain Controller Cloning with Windows Server 2012 Manu Pushpendran Program Manager Microsoft Corporation.

Slides:



Advertisements
Similar presentations
Windows Server 2012 NIC Teaming and SMB Multichannel Solutions
Advertisements

Consumer / personal data Individual work data Team / group work data Personal devices Data location SkyDrive Public cloud SkyDrive Pro SharePoint.
Disks and VMs. Agenda Disk Formats –VHD, VHDx, VMDKs –Format conversions –Disk cloning –Exporting / importing VM Generations –Comparison of Gen 1 and.
Windows Server 2012 Hyper-V Storage Senthil Rajaram Senior PM Microsoft Corporation Taylor Brown Senior SDET Microsoft Corporation.
Windows PowerShell Crash Course Don Jones Concentrated Technology Jeffrey Snover Microsoft WSV321.
AD for Windows 2012 Deeper Dive - Dynamic Access Control and Domain Controller Cloning JONATHAN CORE – DOMAIN CONTROLLER CLONING KEITH BREWER – DYNAMIC.
Office 365 Identity Federation Technology Deep-Dive
What’s New: Windows Server 2012 R2 Tim Vander Kooi Systems Architect
Deploying DNSSEC in Windows Server 2012 David Cates Platform Services Group Microsoft Corporation.
Windows Server Advanced Storage Solutions = Datacenter Elevation Alex Jauch Architect NetApp John Parker Technical Marketing Manager NetApp.
Advanced Active Directory Services Windows Server год на рынке IT образования! 17 лет с Microsoft 1991 – Алексей Кибкало.
What’s New in Active Directory in Windows Server 2012 Dean Wells Active Directory Product Group Microsoft SIA312.
Best Practices for Designing and Consolidating Group Policy for Performance and Security Darren Mar-Elia Group Policy MVP, CTO & Founder SDM Software,
Windows Server 2012 IP Address Management Bala Rajagopalan Group Program Manager Microsoft Corporation WSV 307.
Business Continuity Solutions for SQL Database* applications on Windows Azure Alexander (Sasha) Nosov Principal Program Manager Microsoft.
Deep Dive on Active Directory PowerShell Mudassir Ali Software Development Engineer Microsoft Corporation SIA404.
DANIEL PETRI, PREMIER FIELD ENGINEER, MICROSOFT. TakeawaysNew AD Features Agenda AD Enhancements Areas of Investment / Our Broad Goals Summary of Requirements.
AI-B301 Topics A quick note: There is a lot of information in this session, too much in fact! Slides are heavy and designed for you to review. We’ll.
Installing a New Windows Server 2008 Domain Controller in a New Windows Server 2008 R2.
SIM361. Services Cloud Deployment Fabric Hyper-V Bare Metal Provisioning Hyper-V, VMware, Citrix XenServer Hyper-V, VMware, Citrix XenServer Network Management.
Deploying DNSSEC in Windows Server 2012 Rob Kuehfus Program Manager Microsoft Corporation WSV325.
The Network Files, Case #53: Diagnosing diseases of DNS Presented by Mark Minasi for newsletters, audio sets etc WSV313.
Enabling Disaster Recovery for Hyper-V Workloads Using Hyper-V Replica Shreesh Dubey Principal Group Program Manager Microsoft Corporation VIR302.
Upgrading the Platform - How to Get There!
Active Directory Domain Services on Windows Azure Virtual Machines Samuel Devasahayam Active Directory Product Group Microsoft SIA205.
Accelerating the Power of the Cloud with Microsoft Private Cloud Fast Track and EMC Infrastructure Mike McGhee Solutions Engineer EMC Corporation WSV211.
Chapter 5 Roles and features. objectives Performing management tasks using the Server Manager console Understanding the Windows Server 2008 roles Understanding.
AD DNS SRV RRs Active Directory DNS Service (SRV) Resource Records (RR)
WGUiSW IDOL Windows Server 2012 Active Directory: Domain Services What’s new in Active Directory: Domain Services?
Designing Active Directory Child Domain Sainath K.E.V Directory Services MVP 5/Aug/2015.
Advanced Deployment and Administration of AD DS
Cluster Shared Volumes Reborn in Windows Server 2012: Deep Dive Amitabh Tamhane Vineeth Karinta Program Manager 2 Senior Engineer Microsoft Corporation.
Hyper-V Storage Senthil Rajaram Senior PM Microsoft Corporation.
Building Integration Solutions using BizTalk On-Premises and on Azure Javed SikanderRajesh Ramamirtham Group Program ManagerProgram Manager AZR211.
What’s New in Active Directory in Windows Server 2012 Pete WSV312.
Best Practices and Lessons Learned: Private Cloud Deployment in the Enterprise Ryan Sokolowski Senior Consultant, Microsoft Consulting Services Microsoft.
Keep Your Information Safe! Josh Heller Sr. Product Manager Microsoft Corporation SIA206.
Using the Windows Server 2012 Server Manager for Remote and Multi-Server Management Wale Martins Senior Program Manager Microsoft Corporation WSV335.
Maintaining Active Directory Domain Services
EXL321. Lync 2010 Planning tool+ Planning guides+ * new in LS significant enhancements in LS 2010.
From Virtualization Management to Private Cloud with SCVMM 2012 Dan Stolts Sr. IT Pro Evangelist Microsoft Corporation
What's New with IIS 8 Performance, Scalability, and Security Robert McMurray Program Manager Microsoft Corporation WSV332.
A Lap Around Windows Azure Active Directory Stuart Kwan Lead Principal Program Manager Microsoft Corporation SIA209.
Building Hosted Private and Public Clouds Using Windows Server 2012 Yigal Edery Principal Program Manager Microsoft Corporation Joshua Adams Senior Program.
Windows Server 2012 IP Address Management Tyler Barton Program Manager Microsoft Corporation WSV 307.
Czy są zmiany w AD Domain Services Windows 2012 Andrzej Kokociński
What’s New in Active Directory in Windows Server 2012 Samuel Devasahayam Active Directory Product Group Microsoft Ulf Simon-Weidner Senior Consultant,
Microsoft Azure Active Directory. AD Microsoft Azure Active Directory.
Free, online, technical courses Take a free online course. Microsoft Virtual Academy.
Enabling Disaster Recovery for Hyper-V Workloads Using Hyper-V Replica Vijay Sistla Senior Program Manager Microsoft Corporation VIR302.
App Controller Tabrez Mohammed Yuan Zheng Program Managers Microsoft Corporation MGT303.
Installing Domain Controllers Dcpromo RIP Provides XML file and PowerShell command to automate adding the role Can be run remotely.
Building a Highly Available Failover Cluster Solution with Windows Server 2012 from the Ground UP Rob Hindman Program Manager Microsoft Corporation Lalithra.
Complete VM Mobility Across the Datacenter Server Virtualization Hyper-V 2012 Live Migrate VM and Storage to Clusters Live Migrate VM and Storage Between.
Building a Highly Available Failover Cluster Solution with Windows Server 2012 from the Ground UP Rob Hindman Program Manager Microsoft Corporation WSV324.
Keep Your Information Safe! Josh Heller Sr. Product Manager Microsoft Corporation SIA206.
Deploying Private Clouds (Lessons Learned from the Windows Server 2012 TAP) Pat Fetty and Allen Stewart Principal Program Manager and Principal Group Program.
Windows Server 2012 Active Directory - what’s in it for me? Tony Murray, Directory Services MVP.
Windows Server 2012: How hot can it be? Show me! Chris Spanougakis MCT MVP [DS] IT Consultant / Trainer SystemPlus IT Consulting & Training.
Windows Server 2012 Overview Michael Leworthy Senior Product Manager Microsoft Corporation WSV205.
Demystifying Forefront Edge Security Technologies – TMG and UAG Richard Hicks Director – Sales Engineering Celestix Networks, Inc. SIA208.
How to (un)destroy your Active Directory
What’s New with IIS 8: Open Web Platform for Cloud
Deploy and get started with Microsoft Advanced Threat Analytics
Migrating your IaaS infrastructure from ASM to ARM without downtime
Samuel Devasahayam Active Directory Product Group Microsoft
TechEd /23/ :44 AM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered.
TechEd /28/ :51 PM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered.
FSMO Roles and Global Catalog Servers
Mikael Nystrom Senior Executive Consultant TrueSec
Presentation transcript:

Active Directory Virtualization Safeguards and Domain Controller Cloning with Windows Server 2012 Manu Pushpendran Program Manager Microsoft Corporation SIA317

Importance of Virtualization in IT Virtualization Challenges with Active Directory Today Enabling a Seamless Virtualized Active Directory Experience in Windows Server 2012 Rapid Deployment of Virtual Domain Controllers through Cloning elastic scale, faster disaster recovery, etc.

Importance of Virtualization in IT Virtualization Challenges with Active Directory Today Enabling a Seamless Virtualized Active Directory Experience in Windows Server 2012 Rapid Deployment of Virtual Domain Controllers through Cloning elastic scale, faster disaster recovery, etc.

Importance of Virtualization in IT Virtualization Challenges with Active Directory Today Enabling a Seamless Virtualized Active Directory Experience in Windows Server 2012 Rapid Deployment of Virtual Domain Controllers through Cloning elastic scale, faster disaster recovery, etc.

Logical Clock

Timeline of events TIME: T2TIME: T3TIME: T4 Create Snapshot T1 Snapshot Applied! USN: 100 ID: ARID Pool: USN: 100 ID: ARID Pool: USN: 250 ID: ARID Pool: more users created = 200 DC2 receives updates: USNs >200 = 250 USN: 200 ID: ARID Pool: users added DC2 receives updates: USNs >100 DC1 DC2 TIME: T1

Importance of Virtualization in IT Virtualization Challenges with Active Directory Today Enabling a Seamless Virtualized Active Directory Experience in Windows Server 2012 Rapid Deployment of Virtual Domain Controllers through Cloning elastic scale, faster disaster recovery, etc.

Timeline of events TIME: T2TIME: T3TIME: T4 Create Snapshot T1 Snapshot Applied! USN: 100 ID: AsavedVMGID: G1 USN: 100 ID: A USN: ID: B +150 users created: VM generation ID difference detected: EMPLOY SAFETIES = 200 USN: 200 ID: A +100 users added DC2 receives updates: USNs >100 DC1 DC2 TIME: T1 VMGID: G1 savedVMGID: G1VMGID: G1 savedVMGID: G1VMGID: G2 savedVMGID: G2VMGID: G2 DC2 again accepts updates: USNs >100 USN re-use avoided and USN rollback PREVENTED : all 250 users converge correctly across both DCs … missing users replicate back to DC1 = 200 = 250

Importance of Virtualization in IT Virtualization Challenges with Active Directory Today Enabling a Seamless Virtualized Active Directory Experience in Windows Server 2012 Rapid Deployment of Virtual Domain Controllers through Cloning elastic scale, faster disaster recovery, etc.

DC1 DC2 DC3 DC1 DC2 DC3 DC1 DC2 DC3 contoso.com

DC1 DC2 DC3 DC1 DC2 DC3 DC1 DC2 DC3 contoso.com

1. Identify suitable source virtual DC 2. Authorize source DC by adding it to ‘Cloneable Domain Controllers’ group Pre-provisioned with Control Access Right (CAR) on domain-NC object (domain head) 3. Run New-ADDCCloneConfigfile Verifies pre-requisites, e.g. PDC FSMO is running Windows Server 2012 (more later on this) Verifies authorization (by checking group membership) Let’s you specify name, IP address, DNS servers, site, etc. Provide an empty file to auto-generate values Sample file provided in box at %windir%\system32\SampleDCCloneConfig.xml Schema file provided in box at %windir%\system32\DCCloneConfigSchema.xsd 4. Run Get-ADDCCloningExcludedApplicationList [-generateXML] 5. Shutdown and export source DC 6. Restart source DC 7. Import clone of source DC as many times as desired and start clone VMs

DCCloneConfig.xml sample

demo Domain Controller Cloning

PDC Source Clone3 Hyper-V Clone2 Clone1

BOOT No Yes REBOOT INTO DSRM Yes No Yes No BOOT NORMALLY No Yes

Breakout Sessions SIA312 What's New in Active Directory in Windows Server 2012 SIA404 Deep Dive on Windows Server Active Directory PowerShell SIA319 The Evolution of Active Directory Recovery SIA402 How to (un)Destroy Your Active Directory: Reloaded SIA207 Windows Server 2012 Dynamic Access Control Overview SIA341 Windows Server 2012 Dynamic Access Control Deep Dive for Active Directory and Central Authorization Policies Hands-on Labs SIA11-HOL Windows Server 2012 Active Directory Deployment and Management Enhancements SIA21-HOL Using Dynamic Access Control to Automatically and Centrally Secure Data in Windows Server 2012 Find Me Later At Windows Server 2012 Active Directory and Dynamic Access Control booth

Talk to our Experts at the TLC #TE(sessioncode) DOWNLOAD Windows Server 2012 Release Candidate microsoft.com/windowsserver Hands-On Labs DOWNLOAD Windows Azure Windowsazure.com/ teched

Scan the Tag to evaluate this session now on myTechEd Mobile