Active Directory Fundamentals Thomas Lee Chief Technologist QA

Slides:



Advertisements
Similar presentations
Active Directory Fundamentals
Advertisements

Implementing and Administering AD DS Sites and Replication
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 6 Managing and Administering DNS in Windows Server 2008.
Understanding Group Policy on Windows Server 2003 Michael J. Murphy TechNet Presenter
Chapter 6 Introducing Active Directory
Introduction to Active Directory
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
CS603 Active Directory February 1, 2001.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
Chapter 4 Introduction to Active Directory and Account Management
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
Windows Server 2008 Network Access Protection (NAP) Technical Overview.
Making Identity and Access Management Real – The Early Days Brian Lauge Pedersen Senior Technology Specialist.
By Karan Oberoi.  A directory service (DS) is a software application- or a set of applications - that stores and organizes information about a computer.
TNT Welcome to this evening’s TechNet Event We would like to bring your attention to the key elements of the TechNet programme; the central information.
TNT Microsoft Exchange Server 2003 Disaster Recovery Michael J. Murphy TechNet Presenter
TNT Welcome to this TechNet Event We would like to bring your attention to the key elements of the TechNet programme; the central information and.
Understanding Active Directory
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
Module 1: Introduction to Active Directory
Hands-On Microsoft Windows Server 2008
Hands-On Microsoft Windows Server 2008
TNQ How To Deploy A Windows 2000 Active Directory In Your Organization Name Title Department Microsoft Corporation.
Vikram Thakur Introduction to Active Directory Structure.
Active Directory Implementation Class 4
Welcome to this evening’s TechNet Event We would like to bring your attention to the key elements of the TechNet programme; the central information and.
Nassau Community College
(ITI310) SESSIONS : Active Directory By Eng. BASSEM ALSAID.
Directory services Unit objectives
11 REVIEWING MICROSOFT ACTIVE DIRECTORY CONCEPTS Chapter 1.
Chapter 4 Introduction to Active Directory and Account Management
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 7: Active Directory Replication.
Session 6 Windows Platform Dina Alkhoudari. Learning Objectives What is Active Directory Logical components of active directory Physical components of.
Windows Server 2008 Chapter 4 Last Update
Small Business Server 2003 Technical Overview Part 1.
Module 7: Implementing Sites to Manage Active Directory Replication.
Working with domains and Active Directory
Microsoft Confidential Zelko Kecman Microsoft Windows 2000 Server Directory Services.
Designing Active Directory for Security
A detailed look at the Microsoft Windows Infrastructure at UWE including Active Directory (AD), MIIS, Exchange, SMS, IIS, SQL Server, Terminal Services.
TNT Welcome to this evening’s TechNet Event We would like to bring your attention to the key elements of the TechNet programme; the central information.
Active Directory Boundaries - Purpose Replication Boundaries Security Boundaries.
SERVER I SLIDE: 6. SERVER I Topics: Objective 4.3: Deploy and configure the DNS service Objective 5.1: Install domain controllers.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
Designing Authentication for a Microsoft Windows 2000 Network Designing Authentication in a Microsoft Windows 2000 Network Designing Kerberos Authentication.
Module 7 Active Directory and Account Management.
Session 7 Windows Platform Eng. Dina Alkhoudari. Learning Objectives Active Directory review Managing users and groups Single Master Operations Delegation.
Managing Windows Server 2003 and Active Directory Best Practices ธนินทร์ น้อยรังษี Tanin Noirungsee Technology Specialist Microsoft (Thailand)
© Wiley Inc All Rights Reserved. MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition.
Page 1 Active Directory and DNS Lecture 2 Hassan Shuja 09/14/2004.
Introduction to Active Directory Domain Services
10.1 © 2004 Pearson Education, Inc. Exam Designing a Microsoft ® Windows ® Server 2003 Active Directory and Network Infrastructure Lesson 10: Planning.
Module 4: Configuring Active Directory Sites and Replication.
TNT ISA Server 2004 Technical Overview What we will cover:  Improvements over ISA Server 2000  Exploring the new user interface  Configuring.
OVERVIEW OF ACTIVE DIRECTORY
Introduction to Active Directory
Module 1: Introduction to Active Directory
11 WORKING WITH ACTIVE DIRECTORY SITES Chapter 3.
Active Directory design recommended practices Mark Cribben Consultant.
Module 4: Configuring Active Directory ® Domain Sevices Sites and Replication.
1 Introduction to Active Directory Directory Services Uniquely identify users and resources on a network Provide a single point of network management.
MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition (70-294) Chapter 1: Overview of the Active.
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
Overview of Active Directory Domain Services Lesson 1.
Active Directory Replication (Part 1) Paige Verwolf Support Professional Microsoft Corporation © 1999 Microsoft Corporation. All rights reserved.
(ITI310) SESSIONS 6-7-8: Active Directory.
Active Directory Fundamentals
Active Directory Fundamentals
Active Directory Fundamentals
Presentation transcript:

Active Directory Fundamentals Thomas Lee Chief Technologist QA

What we will cover:  Domain, Trees, Forests  Domain Controllers, Sites  The Domain Naming Service  Replication  Operations Masters  Lots of demos….

Prerequisite Knowledge  Understanding of what a directory service is  Networking skills! Level 200+

Agenda  Active Directory Logical Concepts  Active Directory Physical Concepts  DNS  Replication  Operations Masters

Active Directory Logical Concepts Domains  Boundary of Security  NOT!!!  Boundary of Authentication  Boundary of Replication  Domain NC Replication  Boundary of DNS Namespace  Boundary of Administration KAPOHO.NET

Active Directory Logical Concepts Trees  Hierarchy of Domains forming a contiguous DNS namespace  Transitive Trust Relationships between domains  All domains in a Tree share:  Schema  Configuration  Global Catalog KAPOHO.NET EUROPE.KAPOHO.NET HAWAII.KAPOHO.NET MAUI.HAWAII.KAPOHO.NET

 Hierarchy of Domains forming a contiguous or disjoint namespace  Transitive Trust Relationships  All Domains in a Forest share:  Schema  Configuration  Global Catalog PSP.CO.UK KAPOHO.NET HAWAII.KAPOHO.NET Active Directory Logical Concepts Forests

 Containers within Domains  Distinct Units of Administration  Unique to Domains  Two main uses:  Delegation  Policies Active Directory Logical Concepts Organizational Units

Agenda  Active Directory Logical Concepts  Active Directory Physical Concepts  DNS  Replication  Operations Masters

Active Directory Physical Concepts Domain Controllers Primary Domain Controller (PDC) Backup Domain Controller (BDC) Domain Controllers (DC)

 What is a Site?  A set of well-connected IP subnets  Site Usage  Locating Services (e.g. Logon, DFS)  Replication  Group Policy Application  Sites are connected with Site Links  Connects two or more sites Active Directory Physical Concepts Sites

Active Directory Physical Concepts Site Topology Company.com america.company.com europe.company.com DC Site A Site B Site C DC GC DC DC = Domain Controller GC = Global Catalog

 Partial Replica of all Objects in the Forest  Configurable subset of Attributes  Fast Forest-wide searches  Required at Logon for Universal Group Membership  Win2k3 – Universal Group Caching Active Directory Physical Concepts Global Catalog

Agenda  Active Directory Logical Concepts  Active Directory Physical Concepts  DNS  Replication  Operations Masters

DNS  DNS is fundamental to AD  No DNS == No AD  Even on a single server!  You have options over:  DNS Topology  DNS Namespace  DNS Server

 SRV Records to locate services (req’d.)  DDNS for Dynamic Update (desired)  Windows 2000 and up, DNS also provides:  Incremental Zone Transfer  Active Directory Integrated  Single replication topology  Multi-master replication  Secure Dynamic update Tip: Use the latest version of BIND! DNS DNS

DNS DNS Implementations  No existing DNS infrastructure  Deploy Microsoft DNS  Existing DNS meets requirements  Existing DNS not adequate:  Choice 1: Update Server  Choice 2: Migrate to Microsoft DNS  Choice 3: Delegate a subdomain to Microsoft DNS

Agenda  Active Directory Logical Concepts  Active Directory Physical Concepts  DNS  Replication  Operations Masters

 Naming Contexts that are replicated  Schema Naming Context  Configuration Naming Context  Domain Naming Context  Multi-Master Replication  Intra-site Bi-directional Ring Topology  Inter-site Spanning Tree Topology  Synchronous RPC over TCP/IP  Asynchronous SMTP Replication Replication Details

 Schema  Definitions of attributes  Replicated to all DCs in the forest  Configuration  AD Structure (domains, sites, and where the DCs are)  Replicated to all DCs in the forest  Domain  Domain specific objects (users, groups, computers, and OUs)  Replicated to all DCs in its domain Replication Naming Contexts

 Intra-Site Replication: AD replication between DCs within a Site  Inter-site Replication: AD replication between Sites Replication Replication Topologies

 RPC Replication in a Site  No compression  Assumes good network connections  Uses notification process  5 minutes-2k  Less – 2k3  KCC Generates a bi-directional Ring with extra edges Tip: Always let KCC generate the intra-site replication topology when possible Replication Intra-Site Replication

 Replication between Sites  DS-RPC (RPC over IP) or SMTP Transports  SMTP can be used only between  GCs across Sites  DCs of different domains and in different sites  Compression  10%-20% of original size  Scheduled Replication Inter-Site Replication

 Site Links link two or more sites  Cost and schedules can be specified  Transitive (can be disabled)  Site-Link Bridges  Bridge two or more site links  Bridgehead servers  KCC generates a minimum cost spanning tree Tip: Always let KCC generate the replication topology Replication Site-Links, Bridges and Bridgehead Servers

Agenda  Active Directory Logical Concepts  Active Directory Physical Concepts  DNS  Replication  Operations Masters

 Schema  Perform updates to schema  Sends updates to all DCs  One per forest  Default is the first DC installed  Domain  Performs add/remove of domains and cross-references to external DS  One per forest  Default is the first DC installed Operations Masters Schema and Domain

 Primary Domain Controller (PDC)  Acts as a PDC for requests from NT clients  One per domain  Relative Identifier (RID)  Generates pools of security identifiers to be distributed to DCs in the domain  One per domain  Infrastructure  updates SIDs and domains that are moved in and out of the domain Operations Masters PDC, RID and Infrastructure

Summary  There are Logical and Physical concept  DNS  Plenty of Information

For More Information…  Main TechNet Web site at  Additional resources to support this Session page can be found at

MS Press Inside information for IT Professionals To find the latest IT Professional related titles visit

Third Party Publications Supplementary Publications for IT Pros These books can be found and purchased at all good book stores and on-line retailers

Microsoft Learning Training Resources for IT Professionals  Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure  Course Number: 2279  Availability: Now  Detailed Syllabus: To locate a training provider, please access Microsoft Certified Technical Education Centers are Microsoft’s premier partners for training services QA Special Offer on ALL IT Professional Training 50% off – all QA courses running 1 st Week in January % off all other courses running in January

Assess your Readiness Microsoft Skills Assessment What is Microsoft Skills Assessment?  Self-study learning tool to evaluate readiness for product and technology solutions, instead of job-roles (certification)  Windows Server 2003, Exchange Server 2003, Windows Storage Server 2003, Visual Studio.NET, Office 2003  Free, online, unproctored, and available to anyone  Answers, “Am I ready?”  Determines skills gaps, provides learning plans with Microsoft Official Curriculum courses, plus more Microsoft learning content suggestions such as TechNet resources  Post your High Score to see how you stack up  visit

Become a Microsoft Certified Systems Administrator (MCSA)  What is the MCSA certification?  For IT professionals who manage and maintain networks and systems based on the Microsoft Windows Server operating system  How do I become an MCSA on Microsoft Windows 2000?  Pass 3 core exams  Pass 1 elective exam or 2 CompTIA certifications  Where do I get more information?  For more information about certification requirements, exams, and training, visit

Become A Microsoft Certified Systems Engineer (MCSE)  What is the MCSE certification?  Premier certification for IT professionals who analyze the business requirements and design, plan, and implement the infrastructure for business solutions based on the Microsoft Windows Server System integrated server software.  How do I become an MCSE on Microsoft Windows 2003?  Pass 6 core exams  Pass 1 elective exams from a comprehensive list  Where do I get more information?  For more information about certification requirements, exams, and training options, visit

Demonstrate Your Security or Messaging Specialization  What are MCSA/MCSE specializations?  MCSA and MCSE specializations allow IT professionals to highlight specific expertise or technical focus within their job role.  What specializations are available?  MCSA: Security  MCSA: Messaging  MCSE: Security  MCSE: Messaging  Where do I get more information?  For more information about MCSA and MCSE specialization requirements, exams, and training options, visit or

What is TechNet?  Put the right answers at your fingertips  TechNet is the comprehensive collection of resources to help IT implementers plan, deploy, and manage Microsoft products successfully  Monthly updates delivered on DVD or CD  The definitive resource to help you evaluate, deploy and maintain Microsoft products TechNet Subscription  Accessible at  Online resources and community  Subscriber-only Online Services TechNet Web Site  Bi-weekly e-newsletter  Security updates, new resources, and special offers TechNet Flash  Briefings on the latest Microsoft products and technologies  Hands-on, “how to” information TechNet Events and Web Casts  User Groups  Managed Newsgroups TechNet Communities

Where Can I Get TechNet?  Visit TechNet Online at  Register for the TechNet Flash  Join the TechNet Online forum at  Become a TechNet Subscriber at  Attend More TechNet Events or view on-line