Windows Server 2003 AD 安裝設定與管理維護 林寶森

Slides:



Advertisements
Similar presentations
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 6 Managing and Administering DNS in Windows Server 2008.
Advertisements

Module 1: Introduction to Active Directory in Windows 2000
Windows Server 2003 使用者群組管理 林寶森
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 1: Introduction to Active Directory.
1 Active Directory (Week 8, Monday 2/26/2007) © Abdou Illia, Spring 2007.
6.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
Administering Active Directory
Hands-On Microsoft Windows Server 2003 Administration Chapter 1 Windows Server 2003 Network Administration.
Hands-On Microsoft Windows Server 2003 Administration Chapter 3 Administering Active Directory.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 7: Planning a DNS Strategy.
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
Domain Name Server © N. Ganesan, Ph.D.. Reference.
Course 6425A Module 2: Configuring Domain Name Service for Active Directory® Domain Services Presentation: 50 minutes Lab: 45 minutes This module helps.
© N. Ganesan, Ph.D., All rights reserved. Active Directory Nanda Ganesan, Ph.D.
By Karan Oberoi.  A directory service (DS) is a software application- or a set of applications - that stores and organizes information about a computer.
Hands-On Microsoft Windows Server 2003 Administration Chapter 1 Windows Server 2003 Network Administration.
Understanding Active Directory
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
© N. Ganesan, Ph.D., All rights reserved. Active Directory Nanda Ganesan, Ph.D.
Module 1: Introduction to Active Directory
Hands-On Microsoft Windows Server 2008 Chapter 8 Managing Windows Server 2008 Network Services.
Hands-On Microsoft Windows Server 2008
Active Directory Implementation Class 4
ADVANCED MICROSOFT ACTIVE DIRECTORY CONCEPTS
Module 1: Installing Active Directory Domain Services
Module 1: Installing Active Directory Domain Services
Overview of Active Directory Domain Services Lesson 1.
Overview of Active Directory Domain Services Lesson 1.
Corso referenti S.I.R.A. – Modulo 2 06 – Active Directory 20/11 – 27/11 – 05/12 11/12 – 13/12 (gruppo 1) 12/12 – 15/12 (gruppo 2) Cristiano Gentili, Massimiliano.
(ITI310) SESSIONS : Active Directory By Eng. BASSEM ALSAID.
Directory services Unit objectives
Microsoft Windows 2003 Server. Client/Server Environment Many client computers connect to a server.
Windows Server 2008 Chapter 4 Last Update
COMP2017 – Server Administration
Module 2: Implementing DNS to Support Active Directory
70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network Chapter 7: Domain Name System.
Chapter 6: Windows Servers
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
Active Directory Windows2003 Server. Agenda What is Active Directory What is Active Directory Building an Active Directory Building an Active Directory.
September 18, 2002 Windows 2000 Server Active Directory By Jerry Haggard.
Module 7 Active Directory and Account Management.
Module 8: Implementing the Placement of Domain Controllers.
Module 1: Introduction to Active Directory Infrastructure
Windows Server 2003 DNS 安裝設定與管理維護 林寶森
 Identify Active Directory functions and Benefits.  Identify the major components that make up an Active Directory structure.  Identify how DNS relates.
Page 1 Active Directory and DNS Lecture 2 Hassan Shuja 09/14/2004.
Module 1: Implementing Active Directory ® Domain Services.
Windows Server 2003 La migrazione da Windows NT 4.0 a Windows Server 2003 Relatore: MCSE - MCT.
DNS DNS overview DNS operation DNS zones. DNS Overview Name to IP address lookup service based on Domain Names Some DNS servers hold name and address.
OVERVIEW OF ACTIVE DIRECTORY
Introduction to Active Directory
Windows Server 2003 基本概念 林寶森
© Wiley Inc All Rights Reserved. MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition.
Module 1: Introduction to Active Directory
Windows Server 2003 群組原則設定與管理 林寶森
Logical and Physical Network Design 1. Active Directory Objects Objects Represent Network Resources (Users,Groups,Computers,Printers) Attributes Store.
Hussain Ali Department of Computer Engineering KFUPM, Dhahran, Saudi Arabia Active Directory.
Windows 2003 Architecture, Active Directory & DNS Lecture # 3 Hassan Shuja 02/14/2006.
Overview of Active Directory Domain Services Lesson 1.
Module 2: Implementing an Active Directory Forest and Domain Structure.
11 IMPLEMENTING ACTIVE DIRECTORY Chapter 2. Chapter 2: IMPLEMENTING ACTIVE DIRECTORY2 REQUIREMENTS FOR ACTIVE DIRECTORY  Microsoft Windows Server 2003.
Overview of Active Directory Domain Services
Overview of Active Directory Domain Services
(ITI310) SESSIONS 6-7-8: Active Directory.
Objectives Differentiate between the different editions of Windows Server 2003 Explain Windows Server 2003 network models and server roles Identify concepts.
Active Directory (November 7, 2016) © Abdou Illia, Fall 2016.
Implementing Active Directory
Presentation transcript:

Windows Server 2003 AD 安裝設定與管理維護 林寶森

Reasons to Maintain a Single Domain Ease of Management Easier Delegation Fewer Members in Domain Admins Group Object Capacity Same as Multiple Domain Structure OUOU OUOUOUOU

Reasons to Create Multiple Domains Distinct domain-level policies Tighter administrative control Decentralized administration Separation and control of affiliate relationships Reduced replication traffic OUOU OUOUOUOU OUOU OUOUOUOU OUOU OUOUOUOU OUOU OUOUOUOU

Installing DNS During the Active Directory Installation The Active Directory Installation Wizard Prompts You to Install and Configure a Local DNS Server if It Does Not Find an Existing DNS Infrastructure Installs the DNS Server Service Creates a Forward Lookup Zone Configures the Zone As Active Directory Integrated To Implement DNS, the Active Directory Wizard: Enables Secure Dynamic Updates for the Zone

Installing and Configuring DNS To Install and Configure DNS Create a Forward Lookup Zone Must be authoritative for your DNS domain Enable dynamic updates Configure the DNS Primary Suffix Assign a Static IP Address Install the DNS Server Service Create a Reverse Lookup Zone (optional)

Establishing the Root Domain Start Installation Wizard Select Domain Controller and Domain Type Specify Required Information –Domain, DNS, and NetBIOS names –Database, log, and shared system volume locations –Select to weaken permissions Active Directory Is Installed Computer Is Domain Controller Active Directory Tools Added

Adding a Domain Controller to an Existing Domain Start Installation Wizard Select Domain Controller Type Specify Required Information –Network credentials –DNS name of domain to join –Database, log, and shared system volume locations Active Directory Is Installed

Creating a Child Domain Start Installation Wizard Select Domain Controller and Domain Type Specify Required Information –Network credentials –DNS names of parent and child domains –Database, log, and shared system volume locations –Select to weaken permissions Active Directory Is Installed

Creating a Tree in an Existing Forest Start Installation Wizard Select Domain Controller and Domain Type Specify Required Information –Network credentials –DNS names of new tree –Database, log, and shared system volume locations –Select to weaken permissions Active Directory Is Installed

The Active Directory Installation Process The installation process Starts the security protocol and sets the security policy Creates the: Active Directory partitions, database, and log files Forest root domain SYSVOL folder Configures the site membership of the domain controller Enables security on the directory service and the file replication folders Applies the password for restore mode Starts the security protocol and sets the security policy Creates the: Active Directory partitions, database, and log files Forest root domain SYSVOL folder Configures the site membership of the domain controller Enables security on the directory service and the file replication folders Applies the password for restore mode

What Are SRV Resource Records? SRV resource records are DNS records that map a service to the computer that provides the service Format of SRV records Example Find Netlogon.dns in systemroot/System32/Config _ldap._tcp.contoso.msft 600 IN SRV london.contoso.msft _Service._Protocol.Name Ttl Class SRV Priority Weight Port Target

Configuring Zones for Dynamic Updates DNS Dynamic Update Protocol –Allows clients to automatically update DNS servers –Can be used in conjunction with DHCP DNS Server Request for IP address 1 Assign IP address of Assign IP address of Zone Database Computer DHCP Server Windows XP / 2003 client updates forward resource record on DNS server Windows XP / 2003 client updates forward resource record on DNS server DHCP updates reverse resource record for Windows XP / 2003 clients and both resource records for other clients DHCP updates reverse resource record for Windows XP / 2003 clients and both resource records for other clients

What Are Active Directory Integrated Zones? Active Directory Integrated Zones Are primary and stub DNS zones that are stored as objects in the Active Directory database Can be stored in an application or a domain partition Offer the following benefits  Multimaster replication  Secure dynamic updates  Standard zone transfers to other DNS servers Are primary and stub DNS zones that are stored as objects in the Active Directory database Can be stored in an application or a domain partition Offer the following benefits  Multimaster replication  Secure dynamic updates  Standard zone transfers to other DNS servers

Removing Active Directory Remove Active Directory by: –Using the Active Directory Installation Wizard –Providing appropriate administrative credentials The Active Directory Installation Wizard Performs Specific Removal Operations Depending on the Type of Domain Controller Domain Controller Provide Credentials:  Enterprise Admins group member  Domain Admins group member Provide Credentials:  Enterprise Admins group member  Domain Admins group member Remove Active Directory

What Is a User Principal Name? A logon name that is used only for logging on to a Windows Server 2003 network Advantages –Unique in Active Directory –Can be the same as a user ’ s address

What Are Directory Partitions? Active Directory Database Configurable replication Domain Forest Schema Configuration Definitions and rules for creating and manipulating objects and attributes Information about the Active Directory structure Information about domain- specific objects Information about applications Contains:

What Is a Schema? A forest-wide definition of object classes and attributes that can be extended Schema changes can be redefined or deactivated Examples of object class User Computer Printer Examples of attributes accountExpires department distinguishedName directReports dNSHostName operatingSystem repsFrom repsTo firstName lastName

What Are Distinguished Names? Distinguished names identify an object's domain and path to reach it Contoso.msft Finance Sales Suzan Fine CN=Suzan Fine,OU=Sales,OU=Finance,DC=contoso,DC=msft Relative distinguished name

What Is the Global Catalog? A repository that contains a subset of the attributes of all objects in Active Directory Global Catalog Read Only

Creating a Global Catalog Server NTDS Settings Properties General ObjectSecurity NTDS Settings Description: Query Policy: Global Catalog Server OKCancel Apply Global Catalog Provides Universal group membership information for the account Domain information when using user principal names during logon Global Catalog Provides Universal group membership information for the account Domain information when using user principal names during logon

When to Customize a Global Catalog Server firstName lastName address accountExpires distinguishedName firstName lastName address accountExpires distinguishedName Common Attributes Global Catalog Server Create additional attributes Add only the additional attributes that you query or refer to frequently department firstName lastName address accountExpires distinguishedName department firstName lastName address accountExpires distinguishedName Changed Attributes

Adding Object Attributes to the Global Catalog company Properties General company Show objects of this class while browsing. Deactivate this attribute. Index this attribute in the Active Directory. Ambiguous Name Resolution (ANR) Replicate this attribute to the Global Catalog. Attribute is copied when duplicating a user. Company Company Unicode String 1 64 Common Name: Description: X.500 0ID: Syntax and Range Syntax: Minimum: Maximum: This attribute is single-valued. OKCancelApply

What Is Forest and Domain Functionality? Network environment Domain functional levels Forest functional levels Windows 2000 mixed-mode domain Windows 2000 native-mode domain Windows Server 2003 Domain Windows Server 2003 Interim Enable forest-wide or domain-wide Active Directory features