Chapter 3 – Creating and Managing User Accounts MIS 431 – Created Spring 2006.

Slides:



Advertisements
Similar presentations
Chapter Five Users, Groups, Profiles, and Policies.
Advertisements

XP Tutorial 4 New Perspectives on Microsoft Windows XP 1 Microsoft Windows XP Personalizing Your Windows Environment Tutorial 4.
Lesson 17: Configuring Security Policies
1 Routing and Remote Access Service (Week 15, Friday 4/21/2006) © Abdou Illia, Spring 2006.
Module 4: Implementing User, Group, and Computer Accounts
Chapter 8 Chapter 8: Managing Accounts and Client Connectivity.
MCDST : Supporting Users and Troubleshooting a Microsoft Windows XP Operating System Chapter 6: Configure and Troubleshoot Local User and Group Accounts.
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 5: Account Management.
12.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.
MIS Chapter 51 Chapter 5 – Managing File Access MIS 431 Created Spring 2006.
Chapter 11 - Monitoring Server Performance1 Ch. 11 – Monitoring Server Performance MIS 431 – created Spring 2006.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 3: Creating and Managing User Accounts.
Chapter 6: Configuring Security. Options for Managing Security Configurations LGPO (Local Group Policy Object) –Used if Computer is not part of a domain.
5.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
11 SUPPORTING LOCAL USERS AND GROUPS Chapter 3. Chapter 3: Supporting Local Users and Groups2 SUPPORTING LOCAL USERS AND GROUPS  Explain the difference.
1 Chapter 1 Introduction to Windows Server Two main goals for Net Admin Make network resources available to users Files, folders, printers, etc.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 9: Implementing and Using Group Policy.
Chapter 6: Configuring Security. Group Policy and LGPO Setting Options Software Installation not available with LGPOs Remote Installation Services Scripts.
70-270, MCSE/MCSA Guide to Installing and Managing Microsoft Windows XP Professional and Windows Server 2003 Chapter Six Creating and Managing User.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 3: Creating and Managing User Accounts.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 3: Creating and Managing User Accounts.
1 Chapter Overview Creating User and Computer Objects Maintaining User Accounts Creating User Profiles.
Windows Server 2003 使用者及電腦帳號管理 林寶森
11 WORKING WITH USER ACCOUNTS Chapter 6. Chapter 6: WORKING WITH USER ACCOUNTS2 CHAPTER OVERVIEW Understand the differences between local user and domain.
Module 2: Managing User and Computer Accounts
Module 2 Creating Active Directory ® Domain Services User and Computer Objects.
70-270: MCSE Guide to Microsoft Windows XP Professional Chapter 5: Users, Groups, Profiles, and Policies.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
Using Group Policy to Manage User Environments. Overview Introduction to Managing User Environments Introduction to Administrative Templates Assigning.
September 18, 2002 Introduction to Windows 2000 Server Components Ryan Larson David Greer.
Hands-On Microsoft Windows Server 2008
1 User Account Administration Introduction to User Accounts Planning New User Accounts Creating User Accounts Creating User Profiles Creating Home Directories.
Guide to Operating System Security Chapter 4 Account-based Security.
6.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 6: Administering User Accounts.
User Manager for Domains.  Manages the user accounts in a domain  It is located in the PDC  While User Manager exists in each NT machine, but it is.
Hands-On Microsoft Windows Server Security Enhancements in Windows Server 2008 Windows Server 2008 was created to emphasize security –Reduced attack.
Managing Network Security ref: Overview Using Group Policy to Secure the User Environment Using Group Policy to Configure Account Policies.
5.1 © 2004 Pearson Education, Inc. Lesson 5: Administering User Accounts Exam Microsoft® Windows® 2000 Directory Services Infrastructure Goals 
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 10: Managing Users, Groups, Computers and Resources.
Windows Server 2003 Overview 1 Windows 2003 Server Overview Ayaz
Security Planning and Administrative Delegation Lesson 6.
11 WORKING WITH USER ACCOUNTS Chapter 6. Chapter 6: WORKING WITH USER ACCOUNTS2 UNDERSTANDING USER ACCOUNTS  Local user accounts  stored in the Security.
PC Maintenance: Preparing for A+ Certification Chapter 23: Using a Windows Network.
DIT314 ~ Client Operating System & Administration CHAPTER 5 MANAGING USER ACCOUNTS AND GROUPS Prepared By : Suraya Alias.
1 Chapter Overview Configuring Account Policies Configuring User Rights Configuring Security Options Configuring Internet Options.
8.1 © 2004 Pearson Education, Inc. Exam Designing a Microsoft ® Windows ® Server 2003 Active Directory and Network Infrastructure Lesson 8: Planning.
Chapter 13 Users, Groups Profiles and Policies. Learning Objectives Understand Windows XP Professional user accounts Understand the different types of.
September 18, 2002 Windows 2000 Server Active Directory By Jerry Haggard.
Module 2: Managing User and Computer Accounts. Overview Creating User Accounts Creating Computer Accounts Modifying User and Computer Account Properties.
70-270: MCSE Guide to Microsoft Windows XP Professional 1 Windows XP Professional User Accounts Designed for use as a network client for: Windows NT Windows.
Introduction to Microsoft Management Console (MMC) MMC is a common console framework for management applications. MMC provides a common environment for.
1 Chapter Overview Understanding User Accounts Planning New User Accounts Creating, Modifying, and Deleting User Accounts Setting Properties for User Accounts.
Configuring the User and Computer Environment Using Group Policy Lesson 8.
1 Part-1 Chap 5 Configuring Accounts Definitions.
NT4 SP4 Security Jack Schmidt - Fermilab
CHAPTER Creating and Managing Users and Groups. Chapter Objectives Explain the use of Local Users and Groups Tool in the Systems Tools Option to create.
Module 2 Creating Active Directory ® Domain Services User and Computer Objects.
Fall 2011 Nassau Community College ITE153 – Operating Systems Session 21 Administering User Accounts and Groups 1.
NetTech Solutions Supporting Local Users and Groups Lesson Three.
NetTech Solutions Security and Security Permissions Lesson Nine.
CHAPTER 5 MANAGING USER ACCOUNTS & GROUPS. User Accounts Windows 95, 98 & Me do not need a user account like Windows XP Professional to access computer.
MIS Chapter 41 Chapter 4 – Implementing and Managing Group and Computer Accounts MIS 431 – Created Spring 2006.
Chapter 7 Server Management Policies –User accounts –Groups Rights and permissions Examples.
Configuring the User and Computer Environment Using Group Policy Lesson 8.
Guide to Operating Systems, 5th Edition
Creating and Managing User Accounts
Greta Mameniskyte IV course 3rd group
Chapter 8: Managing Accounts and Client Connectivity
Setting up home folders and roaming profiles
Security Planning and Administrative Delegation
Presentation transcript:

Chapter 3 – Creating and Managing User Accounts MIS 431 – Created Spring 2006

MIS 4312 Introduction User account – object in Active Directory Requires authentication to connect Control access to network resources Monitor access by auditing resources (logs) Create account Use standard naming structures Control password policy and ownership Include additional attributes such as phone number, address as required elements

MIS 4313 User Account Properties

MIS 4314 AD Added Properties The default Users and Groups dialog box in offers standard choices. AD Users and Computers adds Directory information Special login restrictions Domain information Much more

MIS 4315 User Authentication Users must first be authenticated by a domain controller before gaining access to the network (e.g., they log in as we do Novell) Process has two parts Interactive authentication (to the client PC) User can choose full network log in or just log in to the local workstation Network authentication User’s credentials are passed on to the network resource or service and checked

MIS 4316 Authentication Protocols Kerberos 5 (primary AD method) Supported by Windows 2000, XP; WS03 Method is transparent to the user NTLM – Used for OS that don’t support Kerberos Ex: NT Server

MIS 4317 User Profiles Where user’s unique settings are stored Customized desktop Favorites Start button Cookies My Documents My Recent Documents NetHood PrintHood More items… Send to list Templates Application data Local settings Stored in the Documents and Settings folder for each user Types – local and roaming

MIS 4318 Local Profiles Created when a new user logs in first time Settings are copied from a standard folder called Default User in Documents & Settings THUS changing the settings in Default User will cause those settings to be created for each subsequent new user Change this in System Properties Advanced tab Whenever a user makes a change to settings, they are stored in their local profile Subsequent logins will use just those settings for that user

MIS 4319 Roaming Profiles Stored on the server, these are used by the client when the user authenticates to the network Replaces the local profile with the one used on that particular client workstation Helpful when users move between computers Can convert a local profile to a roaming profile Universal Naming Convention (UNC) format: \\serverXX\profile\username \\serverXX\profile\username

MIS Creating AD Users and Computers Active Directory Users and Computers tool In Administrative Tools menu Can also be added to a custom MMC Select an object, right click, New, click User Shortcut: click on the User icon in the toolbar Shortcut: click on the Group icon in toolbar User can be moved to another object by dragging (new since WS00) Or using rt-click and Move command

MIS New User Parameters For nearly every user, will specify User logon name Full name (F, M, L) Password Password properties (cannot change, change at first login, password never expires, etc) Account expires (Never, End of xxx)

MIS More User Parameters General tab – directory type information Address tab – more directory information Account – user name, logon hours, account options (password, expiration) Member Of – which groups, set primary group Dial-In – allow remote access or VPN Other tabs: Environment, Sessions, Profile, Telephones, Profile, Remote control, etc.

MIS User Account Templates Create a template and all users configured through it will have same settings! (time saver) Can modify the profile for user specific settings To create, in the first name box start it with underscore, as _MIS431 Template Do all of the settings you want To use it, copy this template and then modify as desired

MIS Command Line Utilities Can create user accounts from command line Quicker But, fewer choices can be set easily here Commands DSADD – adds objects DSMOD – modify object settings DSQUERY – queries for objects DSMOVE – moves objects to a different location DSRM – remove an object from directory

MIS Command Line contd. Parameters for commands -pwd – password -memberof – groups user is member of - – address for new user -profile – profiel path for the user -disabled – whether acct is enable or disabled EX: dsadd user “cn=Paul Kohut,cn=Users,dc=dovercorp,dc=net” –pwd Password01 –memberof “cn=domain guests,cn=users,dc=domain01,dc=dovercorp,dc=net ” – –profile \\server01\profiles\paul kohut - disabled no \\server01\profiles\paul kohut

MIS Bulk Import/Export Used when transitioning from one directory service to another for large companies Can also populate a secondary database such as an HRM application Two utilities CSVDE – supports import/export to CSV file LDIFDE – same but in LDAP interchange format (LDIF)

MIS Account Policies A node in Group Policy (more in Ch. 11) These can cause trouble with a user logging in Find Group Policy object at domain level called Default Domain Policy Rt click the domain object (domain controller) in AD Users and Computers and choose Properties Click on Group Policy tab

MIS Password Policy settings Enforce password history - # of passwords to remember before a user can reuse an old password Maximum password age – # days when it must be changed Minimum password age - # days before it can be changed Minimum password length - # characters (1-14) Password complexity requirement – cannot include account name, at least 6 characters long, include 3 of 4 elements: uppercase, lowercase, numbers, symbol Store password using reversible encryption – clear text

MIS Account Lockout settings When the user fails to enter proper user name and password within X times Account lockout duration – how long before can log in again Account lockout threshold - # of incorrect login attempts before lock out occurs Reset account lockout counter after - # of minutes before the lockout counter is reset to zero.

MIS Auditing Authentication Auditing appears in more detail in Ch 14 Be default, WS03 DC audits success logon events only – appears in security log Can turn on “failure” logon events to track attempts to log in – shown in Security log Access Audit Policy node which is available in Computer Configuration – Windows Settings – Security Settings – Local Policies (Fig p. 134)

MIS Authentication Troubleshooting If a user cannot log in, check the list on p. 135 Incorrect user name or password Account lockout Account disabled Logon hour restriction Workstation restriction Domain controller (cannot locate one) Client time settings Down-level client issues UPN logon issues Users unable to log on locally to specific server Remote access logon issues (dial up/VPN) Terminal Services logon issues