DANIEL PETRI, PREMIER FIELD ENGINEER, MICROSOFT. TakeawaysNew AD Features Agenda AD Enhancements Areas of Investment / Our Broad Goals Summary of Requirements.

Slides:



Advertisements
Similar presentations
What’s New in Windows Server 2008 AD?
Advertisements

IP ADDRESS MANAGEMENT [IPAM]
Active Directory Virtualization Safeguards and Domain Controller Cloning with Windows Server 2012 Manu Pushpendran Program Manager Microsoft Corporation.
Advanced Active Directory Services Windows Server год на рынке IT образования! 17 лет с Microsoft 1991 – Алексей Кибкало.
What’s New in Active Directory in Windows Server 2012 Dean Wells Active Directory Product Group Microsoft SIA312.
Module 6: Configuring Windows XP Professional to Operate in a Microsoft Network.
Lesson 16: Configuring Domain Controllers
Active Directory Disaster Recovery Paul Simmons Support Engineer Directory Services Microsoft Corporation.
Chapter 6 Introducing Active Directory
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
11 SUPPORTING LOCAL USERS AND GROUPS Chapter 3. Chapter 3: Supporting Local Users and Groups2 SUPPORTING LOCAL USERS AND GROUPS  Explain the difference.
Hands-On Microsoft Windows Server 2003 Administration Chapter 3 Administering Active Directory.
Windows Server 2012 What’s new ? AuthorKrzysztof Pytko Wroclaw 2012
Technical Overview. PLEASE READ (hidden slide) To deliver this presentation effectively, you need to be familiar with Windows Server 2008 R2 management.
AI-B301 Topics A quick note: There is a lot of information in this session, too much in fact! Slides are heavy and designed for you to review. We’ll.
Understanding Active Directory
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
Active Directory in Windows Server 2012, 2012 R2, and beyond
Upgrading the Platform - How to Get There!
Active Directory Domain Services on Windows Azure Virtual Machines Samuel Devasahayam Active Directory Product Group Microsoft SIA205.
Microsoft ® Official Course Module 12 Monitoring, Managing, and Recovering AD DS.
Module 1: Installing Active Directory Domain Services
Overview of Active Directory Domain Services Lesson 1.
Course 6425A Module 9: Implementing an Active Directory Domain Services Maintenance Plan Presentation: 55 minutes Lab: 75 minutes This module helps students.
Efi Bregman Principal Consultant Microsoft Consulting Services Israel.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 7: Active Directory Replication.
WGUiSW IDOL Windows Server 2012 Active Directory: Domain Services What’s new in Active Directory: Domain Services?
Advanced Deployment and Administration of AD DS
Deploying and Managing Windows Server 2012
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 3: Introducing Active Directory.
Implementing Dynamic Host Configuration Protocol
Technology Overview. Agenda What’s New and Better in Windows Server 2003? Why Upgrade to Windows Server 2003 ?  From Windows NT 4.0  From Windows 2000.
Managing Active Directory Domain Services Objects
What’s New in Active Directory in Windows Server 2012 Pete WSV312.
Designing Active Directory for Security
Managing User and Service Accounts
September 18, 2002 Windows 2000 Server Active Directory By Jerry Haggard.
Maintaining Active Directory Domain Services
Designing Authentication for a Microsoft Windows 2000 Network Designing Authentication in a Microsoft Windows 2000 Network Designing Kerberos Authentication.
Microsoft ® Official Course Module 3 Managing Active Directory Domain Services Objects.
Global Catalog and Flexible Single Master Operations (FSMO) Roles
Introduction to Active Directory Domain Services
Module 1: Implementing Active Directory ® Domain Services.
Czy są zmiany w AD Domain Services Windows 2012 Andrzej Kokociński
What’s New in Active Directory in Windows Server 2012 Samuel Devasahayam Active Directory Product Group Microsoft Ulf Simon-Weidner Senior Consultant,
Chapter 4- Part3. 2 Implementing User Profiles A local user profile is automatically created at the local computer when you log on with an account for.
Installing Domain Controllers Dcpromo RIP Provides XML file and PowerShell command to automate adding the role Can be run remotely.
Installing a Domain Controller
OVERVIEW OF ACTIVE DIRECTORY
Global Catalog and Flexible Single Master Operations (FSMO) Roles BAI516.
11 GLOBAL CATALOG AND FLEXIBLE SINGLE MASTER OPERATIONS (FSMO) ROLES Chapter 4.
Microsoft ® Lync™ Server 2010 Setup and Deployment Module 04 Microsoft Corporation.
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
QUESTION 1: Your role of Network Administrator at ABC.com includes the management of the Active Directory Domain Services (AD DS) domain named ABC.com.
©2011 Quest Software, Inc. All rights reserved. Quick, Scalable Restore of Granular Objects Recovery Manager for Active Directory.
Windows Server 2012 Active Directory - what’s in it for me? Tony Murray, Directory Services MVP.
Pass Microsoft Installing and Configuring Windows Server 2012 exam in just 24 HOURS! 100% REAL EXAM QUESTIONS ANSWERS Microsoft Installing.
Managing User and Service Accounts
Exam In The First Attempt?
Global Catalog and Flexible Single Master Operations (FSMO) Roles
Samuel Devasahayam Active Directory Product Group Microsoft
Overview of Active Directory Domain Services
Active Directory Fundamentals
Microsoft Braindumps Questions Answers
What’s New in Active Directory in Windows Server 2012
BACHELOR’S THESIS DEFENSE
BACHELOR’S THESIS DEFENSE
BACHELOR’S THESIS DEFENSE
Global Catalog and Flexible Single Master Operations (FSMO) Roles
Presentation transcript:

DANIEL PETRI, PREMIER FIELD ENGINEER, MICROSOFT

TakeawaysNew AD Features Agenda AD Enhancements Areas of Investment / Our Broad Goals Summary of Requirements

Simplified Server Management Takeaways Virtualization That Just Works Simplified Management of Active Directory Simplified Deployment of Active Directory

Windows Server Management Philosophy

The new Windows Server Manager

Solution Invest in remote multi-server management Improve admin-to-server ratio Principled UI Design Minimize context switching Glance-able, relevant & actionable information Easier ramp to automation Requirements For Windows Server 2012 – OOB For Windows 8 – install RSAT To manage Windows Server 2008/R2 – Install WMF 3.0,.NET 4.0, Enable PowerShell remoting, install KB Simplified Server Management

Server Management Demo

MiscellaneousManagement New AD Features and Enhancements Simplified Deployment Virtualization-Safe Technology Rapid Deployment Active Directory Platform Changes Recycle Bin User Interface Fine-Grained Password Policy User Interface Dynamic Access Control * More…

Background Simplified AD Deployment Using ADPREP had issues: Time consuming Error-prone Complex In the past, IT pros were required to: Get the correct (new) version Interactively logon at specific per-domain DCs Run the preparation tool in the correct sequence Wait for replication convergence

Solution Simplified AD Deployment Integrate Automate Validate Remoteable PowerShell Requirements Windows Server 2012 computer Windows Server 2003 functional level or greater

DC Deployment Demo

In the past, network glitches during DCPROMO could crash the entire process Simplified AD Deployment In Windows Server 2012, promotion now uses an indefinite retry loop Until administrator fixes network issue, or clicks “cancel”

In the past, Install From Media (IFM) used to perform a mandatory offline defrag of the DIT file On a large DIT, this could take hours, even days No one ever performs an offline defrag… Simplified AD Deployment In Windows Server 2012, NTDSUTIL > IFMprep eliminates the defragmentation pass (optional) Creating the IFM media file is very (!) fast

DC Deployment - IFM Demo

Simplified AD Deployment

Background Virtualization-Safe Technology Creating snapshots or copying VMs/VHDs can rollback the state of a virtual DC Lingering objects Inconsistent passwords Inconsistent attribute values Schema mismatches Duplicate SIDs

17 Timeline of events TIME: T2TIME: T3TIME: T4 Create Snapshot T1 Snapshot Applied! USN: 100 ID: ARID Pool: USN: 100 ID: ARID Pool: USN: 250 ID: ARID Pool: more users created = 200 DC2 receives updates: USNs >200 = 250 USN: 200 ID: ARID Pool: users added DC2 receives updates: USNs >100 DC1 DC2 TIME: T1 USN rollback NOT detected: only 50 users converge across the two DCs All others are either on one or the other DC 100 security principals (users in this example) with RIDs have conflicting SIDs How Domain Controllers are Impacted

Solution Virtualization-Safe Technology Virtual DCs use a VM GenerationID Whenever a snapshot is rolled back, GenerationID is changed DC checks during reboot, and for each write in DIT If changed, protection steps are initiated Requirements Windows Server 2012 DCs hosted on hypervisor platform that supports GenerationID: Hyper-V 3.0 3rd-party Hypervisors

Virtualization-Safe Technology

Background Rapid Deployment Deploying virtualized replica DCs is as labor-intensive as physical DCs Preparation & deployment of sysprep’d server image Manually promoting a DC Post-deployment configuration steps where necessary Virtualization brings capabilities that can simplify deployment

Solution Rapid Deployment: Domain Controller Cloning Create replicas of virtualized DCs by cloning existing ones A game-changer for disaster-recovery Enables elastic provisioning capabilities Requirements Windows Server 2012 DCs hosted on hypervisor platform that supports GenerationID PDC FSMO on Windows Server 2012 (cannot be cloned) Source DC must be authorized for cloning

DC Deployment – DC Cloning Demo

Rapid Deployment: Domain Controller Cloning

Background Recycle Bin User Interface Introduced with Windows Server 2008 R2 allows administrators to recover deleted objects such as users, groups, OUs Typically high-priority In the past, IT pros were required to enable and use the Recycle Bin through PowerShell commands Complex, not easy to remember or use

Solution Recycle Bin User Interface Simplify object recovery Easy to use graphical UI Reduces recovery time Restores all attributes and group memberships Requirements Windows Server 2008 R2 FFL Recycle Bin optional-feature must be switched on Windows Server 2012 Active Directory Administrative Center Objects must have been deleted within Deleted Object Lifetime (180 days)

Recycle Bin User Interface Demo

Recycle Bin User Interface

Background Fine-Grained Password Policy UI Introduced with Windows Server 2008, allows more granular management of password-policies Manually create password-settings objects (PSOs) In the past, IT pros were required to enable and use Fine-Grained Password Policies through ADSIEDIT or by importing LDIF files Complex, time consuming, not easy to remember or use

Solution Fine-Grained Password Policy UI Simplify creating, editing and assigning PSOs Easy to use graphical UI (No change – can be assigned only to users and/or groups) Requirements Windows Server 2008 DFL Windows Server 2012 Active Directory Administrative Center

Fine-Grained Password Policy UI Demo

Fine-Grained Password Policy UI

More (we didn’t have time for these…) + AD Features and Enhancements RID Improvements Active Directory Based Activation Dynamic Access Control (DAC) Group Managed Service Accounts (gMSA) AD Replication & Topology PowerShell Cmdlets PowerShell History Viewer Off-Premises Domain Join Connected Accounts Kerberos Enhancements Kerberos Constrained Delegation (KCD) Flexible Authentication Secure Tunneling (FAST) Enhanced LDAP logging New LDAP Controls/Behaviors

First Windows Server 2012 domain- member (or Windows 8 with RSAT installed) Summary of Minimum Requirements New Active Directory Administrative Center Windows PowerShell History Viewer Graphical Recycle Bin (2008 R2 FFL) and FGPP management (2008 DFL) Richer authorization through DAC & FCI Active Directory-based Activation Requires Windows Server 2012 Schema Active Directory Replication & Topology Cmdlets Installing this….… gives you this

Summary of Minimum Requirements Simplified Deployment and Preparation Dynamic Access Control policies and claims Group Managed Service Accounts Virtualization-Safe for the Windows Server 2012 DC Requires Hypervisor support for VM-Gen-ID First Windows Server 2012 DC Installing this….… gives you this

Summary of Minimum Requirements Windows Server 2012 DC PDC Emulator role Rapid virtual DC deployment through DC-cloning Requires Hypervisor support for VM-Gen-ID Installing this….… gives you this

Simplified Server Management Takeaways Virtualization That Just Works Simplified Management of Active Directory Simplified Deployment of Active Directory

Popcorn Challenge What AD Database parameter allows DCs to know that their replication partner has been restored? A.VM GenerationID B.DSA InvocationID C.RID Pool D.KUKU-ID

QUESTIONS?

DOWNLOAD WINDOWS SERVER 2012 RTM WHAT NEXT?