Module 4: Implementing User, Group, and Computer Accounts

Slides:



Advertisements
Similar presentations
Managing User, Computer and Group Accounts
Advertisements

Chapter Five Users, Groups, Profiles, and Policies.
Module 6: Configuring Windows XP Professional to Operate in a Microsoft Network.
Lesson 17: Configuring Security Policies
Windows Server 2003 建立網域間之信任關係
Module 10: Troubleshooting Network Access. Overview Troubleshooting Network Access Resources Troubleshooting LAN Authentication Troubleshooting Remote.
Module 3: Configuring Active Directory Objects and Trusts.
11 WORKING WITH GROUPS Chapter 7. Chapter 7: WORKING WITH GROUPS2 CHAPTER OVERVIEW  Understand the functions of groups and how to use them.  Understand.
Administering Active Directory
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 4: Implementing and Managing Group and Computer Accounts.
Hands-On Microsoft Windows Server 2003 Administration Chapter 3 Administering Active Directory.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 4: Implementing and Managing Group and Computer Accounts.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 4: Implementing and Managing Group and Computer Accounts.
Chapter 8 Chapter 8: Managing the Server Through Accounts and Groups.
11 MANAGING USERS AND GROUPS Chapter 13. Chapter 13: MANAGING USERS AND GROUPS2 OVERVIEW  Configure and manage user accounts  Manage user account properties.
Chapter 3 – Creating and Managing User Accounts MIS 431 – Created Spring 2006.
11 WORKING WITH COMPUTER ACCOUNTS Chapter 8. Chapter 8: WORKING WITH COMPUTER ACCOUNTS2 CHAPTER OVERVIEW  Describe the process of adding a computer to.
Understanding Active Directory
11 WORKING WITH COMPUTER ACCOUNTS Chapter 8. Chapter 8: WORKING WITH COMPUTER ACCOUNTS2 CHAPTER OVERVIEW Describe the process of adding a computer to.
Module 8: Implementing Administrative Templates and Audit Policy.
Chapter 7 WORKING WITH GROUPS.
Windows Server 2003 使用者及電腦帳號管理 林寶森
Course 6421A Module 7: Installing, Configuring, and Troubleshooting the Network Policy Server Role Service Presentation: 60 minutes Lab: 60 minutes Module.
11 WORKING WITH USER ACCOUNTS Chapter 6. Chapter 6: WORKING WITH USER ACCOUNTS2 CHAPTER OVERVIEW Understand the differences between local user and domain.
Module 2: Managing User and Computer Accounts
Guide to MCSE , Enhanced 1 Activity 4-1: Creating and Adding Members to Global Groups Objective: Use Active Directory Users and Computers to create.
Active Directory Administration Lesson 5. Skills Matrix Technology SkillObjective DomainObjective # Creating Users, Computers, and Groups Automate creation.
Module 2 Creating Active Directory ® Domain Services User and Computer Objects.
Module 1: Introduction to Administering Accounts and Resources
CN1276 Server (V3) Kemtis Kunanuraksapong MSIS with Distinction MCT, MCTS, MCDST, MCP, A+
Module 7: Implementing Sites to Manage Active Directory Replication.
Managing Active Directory Domain Services Objects
Module 10: Configuring Windows XP Professional to Operate in Microsoft Networks.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 10: Managing Users, Groups, Computers and Resources.
Chapter 7: WORKING WITH GROUPS
Designing Active Directory for Security
Designing Group Security Designing security groups Designing user rights.
Chapter 13 Users, Groups Profiles and Policies. Learning Objectives Understand Windows XP Professional user accounts Understand the different types of.
September 18, 2002 Windows 2000 Server Active Directory By Jerry Haggard.
Module 3: Configuring Active Directory Objects and Trusts.
Active Directory Administration Lesson 5. Skills Matrix Technology SkillObjective DomainObjective # Creating Users, Computers, and Groups Automate creation.
Module 7 Active Directory and Account Management.
© Wiley Inc All Rights Reserved. MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition.
Module 2: Managing User and Computer Accounts. Overview Creating User Accounts Creating Computer Accounts Modifying User and Computer Account Properties.
Microsoft ® Official Course Module 3 Managing Active Directory Domain Services Objects.
Module 1: Introduction to Active Directory Infrastructure
Module 2 Creating Active Directory ® Domain Services User and Computer Objects.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 4: Implementing and Managing Group and Computer Accounts.
Managing Local Users & Groups. OVERVIEW Configure and manage user accounts Manage user account properties Manage user and group rights Configure user.
Module 3 Creating Groups and Organizational Units.
1 Chapter Overview Managing Object and Container Permissions Locating and Moving Active Directory Objects Delegating Control Troubleshooting Active Directory.
Module 7: Implementing Security Using Group Policy.
Module 10: Implementing Administrative Templates and Audit Policy.
Configuring, Managing and Maintaining Windows Server® 2008 Servers Course 6419A.
Chapter 7 Server Management Policies –User accounts –Groups Rights and permissions Examples.
1 Chapter Overview Using Group Objects Understanding Default Groups Creating Group Objects Managing Administrative Access.
Module 3: Managing Groups. Overview Creating Groups Managing Group Membership Strategies for Using Groups Using Default Groups.
Module 7: Designing Security for Accounts and Services.
Managing User and Service Accounts
ACTIVE DIRECTORY ADMINISTRATION
ACTIVE DIRECTORY ADMINISTRATION
Active Directory Administration
Unit 7 NT1330 Client-Server Networking II Date: 7/26/2016
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 4: Implementing and Managing Group and Computer Accounts.
Greta Mameniskyte IV course 3rd group
Implementing and Managing Group and Computer Accounts
Module 8: Implementing Group Policy
Unit 6 NT1330 Client-Server Networking II Date: 7/19/2016
Presentation transcript:

Module 4: Implementing User, Group, and Computer Accounts

Overview Introduction to Accounts Creating and Managing Multiple Accounts Implementing User Principal Name Suffixes Moving Objects in Active Directory Planning a User, Group, and Computer Account Strategy Planning an Active Directory Audit Strategy

Lesson: Introduction to Accounts Types of Accounts Types of Groups What Are Domain Local Groups? What Are Global Groups? What Are Universal Groups?

Types of Accounts User accounts Computer accounts Group accounts Enables a single sign-on for a user Provides access to resources Computer accounts Enables authentication and auditing of computer access to resources Group accounts Helps simplify administration

Types of Groups Distribution groups Security groups Used only with e-mail applications Not security-enabled Security groups Used to assign rights and permissions to groups of users and computers Used most effectively when nested The functional level determines the type of groups that you can create

What Are Domain Local Groups? A security or distribution group that can contain: Universal groups, global groups, and other domain local groups from its own domain Accounts from any domain in the forest

What Are Global Groups? A security or distribution group that can contain users, groups, and computers as members from its own domain

What Are Universal Groups? A security or distribution group that can contain users, groups, and computers as members from any domain in its forest

Lesson: Creating and Managing Multiple Accounts Tools for Creating and Managing Multiple Accounts How to Create Accounts Using the Csvde Tool How to Create and Manage Accounts Using the Ldifde Tool How to Create and Manage Accounts Using Windows Script Host

Tools for Creating and Managing Multiple Accounts Active Directory Users and Computers Directory Service Tools Dsadd Dsmod Dsrm Csvde and Ldifde Tools Windows Script Host

How to Create Accounts Using the Csvde Tool Your instructor will demonstrate how to create accounts by using the Csvde command-line tool

How to Create and Manage Accounts Using the Ldifde Tool Your instructor will demonstrate how to create and manage accounts by using the Ldifde command-line tool

How to Create and Manage Accounts Using the Windows Script Host Your instructor will demonstrate how to create and manage accounts by using Windows Script Host

Practice: Creating User Accounts In this practice you will create and run a script file that contains commands to create a user account and then you will verify that the user account was created

Lesson: Implementing User Principal Name Suffixes What Is a User Principal Name? Multimedia: How Name Suffix Routing Works How Name Suffix Conflicts Are Detected and Resolved How to Create and Remove a UPN Suffix How to Enable and Disable Name Suffix Routing in Forest Trusts

What Is a User Principal Name? A logon name that is used only for logging on to a Windows Server 2003 network Advantages Unique in Active Directory Can be the same as a user’s e-mail address suzanf@contoso.msft

Multimedia: How Name Suffix Routing Works contoso.msft adatum.msft Trust john@contoso.msft

How Name Suffix Conflicts Are Detected and Resolved Name suffix conflicts occur when A DNS name is already in use A NetBIOS name is already in use A domain SID conflicts with another name suffix SID Name suffix conflicts in a domain cause access to that domain from outside the forest to be denied

How to Create and Remove a UPN Suffix Your instructor will demonstrate how to create and remove a UPN suffix

How to Enable and Disable Name Suffix Routing in Forest Trusts Your instructor will demonstrate how to enable and disable name suffix routing in forest trusts

Practice: Creating UPN Suffixes In this practice, you will create a name suffix for a second-level domain, and then enable name suffix routing between two forests

Lesson: Moving Objects in Active Directory What Is SID History? Implications of Moving Objects How to Move Objects Within a Domain How to Move Objects Between Domains How to Use LDP to View Properties of Moved Objects

What Is SID History? SID History Is a list of all SIDs that were assigned to a user account Provides a migrated user account with continuity of access to resources

Implications of Moving Objects Within a domain No change to SID or GUID Within a forest New SID SID history Same GUID Across forests New GUID

How to Move Objects Within a Domain Your instructor will demonstrate how to move Active Directory objects within a domain

How to Move Objects Between Domains Your instructor will demonstrate how to move objects between domains

How to Use LDP to View Properties of Moved Objects Your instructor will demonstrate how to view the properties of objects by using the LDP utility

Practice: Moving Objects In this practice, you will use Ldp.exe to: Examine the SID, SIDHistory, and GUID of a user object. Move a user object to another organizational unit in the same domain. View any changes to the SID, SIDHistory, and GUID of the user object.

Lesson: Planning a User, Group, and Computer Account Strategy Guidelines for Naming Accounts Guidelines for Setting a Password Policy Guidelines for Authenticating, Authorizing, and Administering Accounts Guidelines for Planning a Group Strategy

Guidelines for Naming Accounts Define naming conventions for: User account names that identify the user Computers that identify the owner, location, and computer type Groups that identify the group type, its location, and the purpose of the group

Guidelines for Setting a Password Policy Set Enforce password history to at least 24 passwords remembered Set the maximum password age to no more than 42 days Set the minimum password age to at least 2 days Set password length to at least 8 characters Enable the setting Password must meet complexity requirements

Guidelines for Authenticating, Authorizing, and Administering Accounts Set the account lockout threshold policy setting to a high value Protect administrative accounts Use multifactor authentication Implement a role-based security model for granting permissions Disable the Administrator account and apply a least privilege policy to accounts

Guidelines for Planning a Group Strategy Assign users with common job responsibilities to global groups Create a domain local group for sharing resources Add global groups that require access to resources to domain local groups Use universal groups to grant access to resources in multiple domains Use universal groups when membership is static

Practice: Planning an Account Strategy In this practice, you will determine: An account naming strategy A password policy An authentication, authorization, and administration strategy A group strategy for your forest

Lesson: Planning an Active Directory Audit Strategy Why Audit Access to Active Directory? Guidelines for Monitoring Changes to Active Directory

Why Audit Access to Active Directory? To record all successful changes to Active Directory To track access to a resource or by a specific account To detect and log failed access attempts

Guidelines for Monitoring Changes to Active Directory Enable: Auditing of account management events Success auditing of policy changes Failure auditing for system events Failure auditing of policy change events and account management events when necessary

Practice: Planning an Audit Strategy In this practice, you will determine which audit policies to enable for Active Directory

Lab A: Implementing an Account and Audit Strategy Planning an Account and Audit Strategy Creating Accounts by Using the Csvde Tool Creating a UPN Suffix Moving a Group of Users