Streamlining Support and Management through the Implementation of Active Directory Educause 2003 Mid-Atlantic Regional Gale D. Fritsche –

Slides:



Advertisements
Similar presentations
Establishing an OU Hierarchy for Managing and Securing Clients Base design on business and IT needs Split hierarchy Separate user and computer OUs Simplifies.
Advertisements

Module 6: Configuring Windows XP Professional to Operate in a Microsoft Network.
Welcome Overview of this Session Introduction The Migration –Active Directory (replacing Novell) – & Calendar – from iPlanet to Outlook –Network.
Active Directory: Final Solution to Enterprise System Integration
16.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.
Michael Donovan, River Campus Libraries – 12/03 DocuShare Overview and Training.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
11 SUPPORTING LOCAL USERS AND GROUPS Chapter 3. Chapter 3: Supporting Local Users and Groups2 SUPPORTING LOCAL USERS AND GROUPS  Explain the difference.
10.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 9: Implementing and Using Group Policy.
Understanding Networks I. Objectives Compare client and network operating systems Learn about local area network technologies, including Ethernet, Token.
Gale D. Fritsche Lehigh University Library and Technology Services Client Service Insanity A Campus-wide Novell to Active Directory Migration EDUCAUSE.
Ch 9 Managing Active Directory User Accounts. Objectives Create Organizational Unit Creating User Accounts in Active Directory Disabling, Enabling, and.
Installing a New Windows Server 2008 Domain Controller in a New Windows Server 2008 R2.
1 Chapter Overview Creating User and Computer Objects Maintaining User Accounts Creating User Profiles.
Hands-On Microsoft Windows Server 2008 Chapter 8 Managing Windows Server 2008 Network Services.
Configuring Active Directory Certificate Services Lesson 13.
Guide to MCSE , Enhanced 1 Activity 10-1: Restarting Windows Server 2003 Objective: to restart Windows Server 2003 Start  Shut Down  Restart Configure.
UW Windows Authentication Group Multiple forest scenario task force - Testing report and recommendations.
Module 1: Introduction to Administering Accounts and Resources
Microsoft Windows 2003 Server. Client/Server Environment Many client computers connect to a server.
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
© 2011 PLANET TECHNOLOGIES, INC. Augmenting User Profiles with Line of Business Data Patrick Curran, MCT APRIL 28, 2012.
1 ISA Server 2004 Installation & Configuration Overview By Nicholas Quinn.
One to One instructions Installing and configuring samba on Ubuntu Linux to enable Linux to share files and documents with Windows XP.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
MCTS Guide to Microsoft Windows Server 2008 Applications Infrastructure Configuration (Exam # ) Chapter Two Deploying Windows Servers.
Database Security and Auditing: Protecting Data Integrity and Accessibility Chapter 3 Administration of Users.
Using Mail Mac OS X. Opening Mail First of all, click on this icon in the dock (or in your Applications folder) to bring up Mail.
Beams Division Local Administrators Meeting 9/17/02 Brian Drendel.
© 2011 PLANET TECHNOLOGIES, INC. Extending User Profiles with Line of Business Data Patrick Curran, MCT FEBRUARY 24, 2013.
One-To-One Instruction How to install MS Exchange with a two user setup on Windows Server 2003.
5.1 © 2004 Pearson Education, Inc. Lesson 5: Administering User Accounts Exam Microsoft® Windows® 2000 Directory Services Infrastructure Goals 
CIM6400 CTNW (04/05) 1 CIM6400 CTNW Lesson 6 – More on Windows 2000.
Home Media Network Hard Drive Training for Update to 2.0 By Erik Collett Revised for Firmware Update.
Windows 2003 Overview Lecture 1. Windows Networking Evolution Windows for Workgroups – peer-to-peer networking built into the OS Windows NT – separate.
Microsoft Active Directory(AD) A presentation by Robert, Jasmine, Val and Scott IMT546 December 11, 2004.
Copyright 2000 eMation SECURITY - Controlling Data Access with
Security Planning and Administrative Delegation Lesson 6.
Installing and Using Active Directory Written by Marc Zacharko.
EMerge Browser Managed Security Platform Module 3: Startup eMerge Certification Course  Physical connection  TCP/IP Characteristics of PC  Initial connection.
DIT314 ~ Client Operating System & Administration CHAPTER 5 MANAGING USER ACCOUNTS AND GROUPS Prepared By : Suraya Alias.
Chapter 13 Users, Groups Profiles and Policies. Learning Objectives Understand Windows XP Professional user accounts Understand the different types of.
MCTS Guide to Microsoft Windows Server 2008 Applications Infrastructure Configuration (Exam # ) Chapter Four Windows Server 2008 Remote Desktop Services,
1 Windows 2008 Configuring Server Roles and Services.
Planning a Microsoft Windows 2000 Administrative Structure Designing default administrative group membership Designing custom administrative groups local.
MCTS Guide to Microsoft Windows Server 2008 Applications Infrastructure Configuration (Exam # ) Chapter Five Windows Server 2008 Remote Desktop Services,
Windows 2000 Certificate Authority By Saunders Roesser.
1 Chapter Overview Understanding User Accounts Planning New User Accounts Creating, Modifying, and Deleting User Accounts Setting Properties for User Accounts.
1 Part-1 Chap 5 Configuring Accounts Definitions.
Security Windows 2000 Richard Goldman © December 4, 2001.
Chapter 10: Rights, User, and Group Administration.
Office of Information Technology Help Desk: ECS 020 Phone: Web UMBC Uploading your personal.
McGraw-Hill/Irwin The Interactive Computing Series © 2002 The McGraw-Hill Companies, Inc. All rights reserved. Microsoft Access 2002 Using Access Tools.
Security Planning and Administrative Delegation Lesson 6.
Module 4 Planning for Group Policy. Module Overview Planning Group Policy Application Planning Group Policy Processing Planning the Management of Group.
Managing Local Users & Groups. OVERVIEW Configure and manage user accounts Manage user account properties Manage user and group rights Configure user.
Fall 2011 Nassau Community College ITE153 – Operating Systems Session 21 Administering User Accounts and Groups 1.
DHP Agenda: How to Access Web Interface of the DHP-1320 on Access Point Mode How to Access Web Interface of the DHP-1320 on Router Mode How to Change.
Module 1: Introduction to Administering Accounts and Resources.
Unit 7 ITT TECHNICAL INSTITUTE NT1330 Client-Server Networking II Date: 2/3/2016 Instructor: Williams Obinkyereh.
Business Objects XIr2 Windows NT Authentication Single Sign-on 18 August 2006.
Basic Web Design UVICELL Week 4 Templates and site management Week 4 Templates and site management.
Group policy.
Assignment # 8.
Module 1: Introduction to Administering Accounts and Resources
Objectives Differentiate between the different editions of Windows Server 2003 Explain Windows Server 2003 network models and server roles Identify concepts.
Printer Admin Print Job Manager
Administering Your Network
Security Planning and Administrative Delegation
Presentation transcript:

Streamlining Support and Management through the Implementation of Active Directory Educause 2003 Mid-Atlantic Regional Gale D. Fritsche – Tony Casamassa – Copyright Gale Fritsche and Tony Casamassa 2003

Lehigh University Background  Private research university located 90 miles west of NYC  Approx 4500 undergraduates and 1900 graduate students  Merged organization – Library and Technology Services consists of Libraries and Computing  Library and Technology Services staff of approx. 160  Approximately 90% Windows PCs, 5% Mac and 5% (other Linux etc.)  Approximately 2200 Faculty/Staff PCs on campus

Microsoft’s Active Directory Microsoft’s Active Directory provides a scalable enterprise directory service which allows for centralized management of Microsoft resources. This presentation describes how AD was integrated into our existing network infrastructure and used to centrally manage Windows XP computers and other Microsoft resources.

Lehigh’s Infrastructure Prior to Implementing Active Directory. Lehigh uses Novell’s NDS as a directory service for LAN based file and print sharing. The Andrew File System (AFS) for UNIX based authentication. The Novell and AFS user IDs and passwords are synced through a central web site. So why add another directory service?

Reasons Lehigh Uses Active Directory  Centralization of Windows XP user authentication. Retain the use of existing user ID’s and passwords for authentication.  Increased demand for FrontPage web services on IIS. Retain the use of existing user ID’s and passwords for authentication.  Windows 2000 Server Management. The number of production Windows 2000 servers increased. Dual server management roles with other departments and outside vendors.  Management of Windows XP systems.

Lehigh University Active Directory Structure  Lehigh University has adapted a simple Active Directory structure using a single domain ad.lehigh.edu. A delegation was added to our existing DNS servers referring our Active Directory DNS servers as authoritative for the zone ad.lehigh.edu.  The organizational structure for faculty/staff and students was replicated from our existing Novell NDS structure.

Lehigh University Active Directory Structure

 A “computers” organizational unit was added to each top level departmental OU to store the computer objects for the department.

Lehigh University Active Directory Structure  Active Directory user accounts were created from the existing Novell NDS user accounts. A synchronize program was written which duplicated the NDS accounts in the Active Directory. This program also set the password for the Active Directory account to the existing NDS / AFS password.  A program was written to accept input from our existing accounts web page. This program synced WEB based account creation, deletion, and password changes to the Active Directory accounts.

Lehigh University Active Directory Structure

Windows XP Implementation  The Client Services team performs the setup of new systems for faculty / staff users. Since new systems started to ship with Windows XP, procedures were developed to incorporate the XP systems into Active Directory. Computer object management - A easy method was needed to locate and manage the computer objects for faculty / staff in Active Directory.  A computer object web site was created to provide the Client Services team with a simple tool to create and delete computer objects in the correct location within Active Directory.computer object web

Management Groups in Active Directory  Management groups for each functional area of the Client Services team were created in Active Directory Management groups  ADM-WorkGrp-Mgr  A&S-WorkGrp-Mgr  BUS-WorkGrp-Mgr  ENG-WorkGrp-Mgr  IR-WorkGrp-Mgr  EDU-WorkGrp-Mgr  The management groups provide rights to manage computer objects within the associated computer organizational unit. In addition the appropriate management group is added to the local admin group on each Windows XP system during the initial setup. This allows administrator access to the local computer for the members of the management group.associated computer organizational unitlocal admin group

Setting up Windows XP Client Computers  Active Directory computer preparation  Adding computers to the AD domain  Add Local Administrator Users/Groups  Copying profile settings (if necessary)  End User Education and Documentation

Active Directory computer preparation  Acquire Admin password from end user (if they have one)end user  Obtain Ethernet Address Obtain Ethernet Address  Rename the computer (reboot) Rename the computer  Add the computer object to Active Directory Add the computer object

Adding Computers to the AD Domain  Right click on My Computer and then select Properties  Select the Computer Name tab  Select Member of Domain and enter "ad.lehigh.edu" as the domain nameenter "ad.lehigh.edu"  Click Ok (receive a confirmation message) and Reboot

Add Local Administrator Users/Groups  Go to the Control Panel then Administrative Tools and select Computer Management  Select Local Users and Groups, and then Groups and right click On Administrators and select propertiesLocal Users and Groups  Click on the Add button to add a user or group to the local administrators groupAdd  Add the AD user to the Local Admin Group if requested

Copying Profile Settings (if necessary) o Logon to the Windows XP system as someone with administrator rights. An account that is a member of the local Administrators group.  Make sure that the account that you login with is not the account profile that you are trying to copy. o Go to Control Panel then System and the Advanced Tab. o Select User Profiles Settings and click on the user profile that you want to copy and click on the Copy To button.click on the user profile o Click the Browse Button and go to C:\Documents and Settings and go to the directory you would like to overwrite.Browse Button o Click on the Change button and then Enter the valid Active directory name and click Check Names and click OK.Check Names o Verify that the Active Directory Profile is correct and then click OK to confirm the copy.Active Directory Profile

End User Education and Documentation  Train end users on account usage AD vs. Local accounts  Explain how the consultant admin group account is used Address security concerns (demonstrate encryption feature)  Focus on Advantages of Using AD – Remote Access, Group Policies disabled change password option on Client computers – because we want users to change it via account webpage)

Questions? Anthony Holden – Linda Dickenson – Gale D. Fritsche – Tony Casamassa –

Obtain Ethernet Address

Confusion

Rename Computer

Computer Object Web Site – Initial Screen

Add a Computer Object to Active Directory

Add Verify Message

Result Message

Computer Object Added to Correct Location

Computer Organizational Unit Permissions

Group Security in Windows XP Client

Active Directory Security Groups

Computer Object Web Site – Initial Screen

Add a Computer Object to Active Directory

Add Verify Message

Result Message

Add User to Local Admin Group

Adding a User or Group

Add a Computer to the AD Domain

Copying Profile Information

Copying Profiles

Enter Profile Name

Finalizing Profile Copy