Microsoft ® Official Course Module 4 Automating Active Directory Domain Services Administration.

Slides:



Advertisements
Similar presentations
Implementing and Administering AD FS
Advertisements

Implementing Domain Name System
Module 5: Creating and Configuring Group Policy
Managing User Settings with Group Policy
Module 4: Implementing User, Group, and Computer Accounts
Module 3: Configuring Active Directory Objects and Trusts.
Group Policies (the day after) Group Policy Preferences Powershell.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 3: Creating and Managing User Accounts.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 4: Implementing and Managing Group and Computer Accounts.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 4: Implementing and Managing Group and Computer Accounts.
Lesson 14: Creating and Managing Active Directory Users and Computers
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 4: Implementing and Managing Group and Computer Accounts.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 3: Creating and Managing User Accounts.
Microsoft ® Official Course Module 7 Configuring File Access and Printers on Windows ® 8 Clients.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 3: Creating and Managing User Accounts.
Module 2: Managing User and Computer Accounts
Module 1: Installing Active Directory Domain Services
Implementing Dynamic Host Configuration Protocol
Overview Print and Document Services Print Management console Printer properties Troubleshooting PowerShell.
Module 2 Creating Active Directory ® Domain Services User and Computer Objects.
Module 1: Introduction to Administering Accounts and Resources
Advanced Deployment and Administration of AD DS
Securing Windows Servers Using Group Policy Objects
Deploying and Managing Windows Server 2012
Implementing DNS Module D 7: Implementing DNS
Implementing Dynamic Host Configuration Protocol
1 Week 3 Secure and Efficient Administration of Act. Dir. Work with Active Directory Snap-Ins Custom Consoles and Least Privilege Find Objects in Active.
Implementing File and Print Services
Securing Microsoft® Exchange Server 2010
Managing Active Directory Domain Services Objects
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Managing User and Service Accounts
Implementing Update Management
Deploying and Maintaining Server Images
Implementing Network Access Protection
Configuring Encryption and Advanced Auditing
Active Directory Administration (cmdlets) Microsoft Confidential1.
Module 15: Manage the Windows ® Small Business Server 2008 Environment Using Group Policy.
Securing AD DS Module A 3: Securing AD DS
Managing User Desktops with Group Policy
20411B 8: Installing, Configuring, and Troubleshooting the Network Policy Server Role Presentation: 60 minutes Lab: 60 minutes After completing this module,
Optimizing File Services
Maintaining Active Directory Domain Services
Module 3: Configuring Active Directory Objects and Trusts.
Module 6: Implementing Group Policy. Overview Implementing Group Policy Objects Implementing GPOs in a Domain Managing the Deployment of Group Policy.
Module 2: Managing User and Computer Accounts. Overview Creating User Accounts Creating Computer Accounts Modifying User and Computer Account Properties.
Microsoft ® Official Course Module 3 Managing Active Directory Domain Services Objects.
Module 6: Configuring User Environments Using Group Policy.
Monitoring Windows Server 2012
Module 3 Managing Recipient Objects. Module Overview Managing Mailboxes Managing Other Recipients Configuring Address Policies Configuring Address.
Module 3: Managing a Microsoft ® Windows ® Small Business Server Environment.
Module 2 Creating Active Directory ® Domain Services User and Computer Objects.
Introduction to Active Directory Domain Services
Module 1: Implementing Active Directory ® Domain Services.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 4: Implementing and Managing Group and Computer Accounts.
Module 5: Creating and Configuring Group Policies.
Implementing Group Policy
Module 7: Implementing Security Using Group Policy.
Implementing a Group Policy Infrastructure
Module 3 Planning for Active Directory®
Week 3 Objectives Manage User Accounts Manage Group Accounts Manage Computer Accounts Delegation Use Commandline Tools and Windows PowerShell for AD DS.
Microsoft ® Official Course Module 4 Automating Active Directory Domain Services Administration.
Module 6: Configuring User Environments Using Group Policies.
Module 8: Implementing Group Policy. Overview Multimedia: Introduction to Group Policy Implementing Group Policy Objects Implementing GPOs on a Domain.
Implementing Active Directory Domain Services
Automating Active Directory Domain Services Administration
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 4: Implementing and Managing Group and Computer Accounts.
Active Directory Bulk Operations
Implementing and Managing Group and Computer Accounts
Module 8: Implementing Group Policy
Presentation transcript:

Microsoft ® Official Course Module 4 Automating Active Directory Domain Services Administration

Module Overview Using Command-line Tools for AD DS Administration Using Windows PowerShell for AD DS Administration Performing Bulk Operations with Windows PowerShell

Lesson 1: Using Command-line Tools for AD DS Administration Benefits of Using Command-line Tools for AD DS Administration What Is Csvde? What Is Ldifde? What Are DS Commands?

Benefits of Using Command-line Tools for AD DS Administration Command-line tools allow you to automate AD DS administration Benefits of using command-line tools: Faster implementation of bulk operations Customized processes for AD DS administration AD DS administration on server core

What Is Csvde? AD DS Import Export csvde.exe filename.csv Use csvde to export objects to a.csv file: Use csvde to create objects from a.csv file: -f filename -d RootDN -p SearchScope -r Filter -l ListOfAtrributes csvde –i –f filename –k

What Is Ldifde? Use ldifde to export objects to a LDIF file: Use ldifde to create, modify, or delete objects: -f filename -d RootDN -r Filter -p SearchScope -l ListOfAttributes -o ListOfAttributes ldifde –i –f filename –k Export ldifde.exe filename.ldif AD DS Import

What Are DS Commands? Windows Server 2012 includes command-line tools that are suitable for use in scripts Examples To modify the department of a user account, type: To display the of a user account, type: To delete a user account, type: To create a new user account, type: Dsmod user "cn=Joe Healy,ou=Managers, dc=adatum,dc=com" –dept IT Dsget user "cn=Joe Healy,ou=Managers, dc=adatum,dc=com" – Dsrm "cn=Joe Healy,ou=Managers,dc=adatum,dc=com" Dsadd user "cn=Joe Healy,ou=Managers,dc=adatum,dc=com"

Lesson 2: Using Windows PowerShell for AD DS Administration Using Windows PowerShell Cmdlets to Manage User Accounts Using Windows PowerShell Cmdlets to Manage Groups Using Windows PowerShell Cmdlets to Manage Computer Accounts Using Windows PowerShell Cmdlets to Manage OUs

Using Windows PowerShell Cmdlets to Manage User Accounts Cmdlet Description New-ADUserCreates user accounts Set-ADUserModifies properties of user accounts Remove-ADUserDeletes user accounts Set-ADAccountPasswordResets the password of a user account Set-ADAccountExpirationModifies the expiration date of a user account Unlock-ADAccount Unlocks a user account after it has become locked after too many incorrect login attempts Enable-ADAccountEnables a user account Disable-ADAccountDisables a user account New-ADUser "Sten Faerch" –AccountPassword (Read-Host –AsSecureString "Enter password") ‑ Department IT

Using Windows PowerShell Cmdlets to Manage Groups New-ADGroup –Name "CustomerManagement" –Path "ou=managers,dc=adatum,dc=com" –GroupScope Global –GroupCategory Security Add-ADGroupMember CustomerManagement –Members "Joe" Cmdlet Description New-ADGroupCreates new groups Set-ADGroupModifies properties of groups Get-ADGroupDisplays properties of groups Remove-ADGroupDeletes groups Add-ADGroupMemberAdds members to groups Get-ADGroupMemberDisplays membership of groups Remove-ADGroupMemberRemoves members from groups Add-ADPrincipalGroupMembershipAdds group membership to objects Get-ADPrincipalGroupMembershipDisplays group membership of objects Remove-ADPrincipalGroupMembershipRemoves group membership from an object

Using Windows PowerShell Cmdlets to Manage Computer Accounts New-ADComputer –Name LON-SVR8 -Path "ou=marketing,dc=adatum,dc=com" -Enabled $true Test-ComputerSecureChannel -Repair Cmdlet Description New-ADComputerCreates new computer accounts Set-ADComputer Modifies properties of computer accounts Get-ADComputer Displays properties of computer accounts Remove-ADComputerDeletes computer accounts Test-ComputerSecureChannel Verifies or repairs the trust relationship between a computer and the domain Reset-ComputerMachinePasswordResets the password for a computer account

Using Windows PowerShell Cmdlets to Manage OUs New-ADOrganizationalUnit –Name Sales –Path "ou=marketing,dc=adatum,dc=com" –ProtectedFromAccidentalDeletion $true Cmdlet Description New-ADOrganizationalUnitCreates organizational units Set-ADOrganizationalUnit Modifies properties of organizational units Get-ADOrganizationalUnitViews properties of organizational units Remove-ADOrganizationalUnitDeletes organizational units New-ADOrganizationalUnitCreates organizational units Set-ADOrganizationalUnit Modifies properties of organizational units Get-ADOrganizationalUnitViews properties of organizational units

Lesson 3: Performing Bulk Operations with Windows PowerShell What Are Bulk Operations? Demonstration: Using Graphical Tools to Perform Bulk Operations Querying Objects with Windows PowerShell Modifying Objects with Windows PowerShell Working with CSV Files Demonstration: Performing Bulk Operations with Windows PowerShell

What Are Bulk Operations? A bulk operation is a single action that changes multiple objects The process for performing a bulk operation is: You can perform bulk operations by using: Graphical tools Command-line tools Scripts 1.Define a query 2.Modify the objects defined by the query

Demonstration: Using Graphical Tools to Perform Bulk Operations In this demonstration, you will see how to: Create a query for all users Configure the Company attribute for all users Verify that the Company attribute has been modified

Show all the properties for a user account: Show all the user accounts in the Marketing OU and all its subcontainers: Show all of the user accounts with a last logon date older than a specific date: Show all of the user accounts in the Marketing department that have a last logon date older than a specific date: Get-ADUser Administrator -Properties * Get-ADUser –Filter * -SearchBase "ou=Marketing,dc=adatum,dc=com" -SearchScope subtree Get-ADUser -Filter {lastlogondate -lt "January 1, 2012"} Get-ADUser -Filter {(lastlogondate -lt "January 1, 2012") and (department -eq "Marketing")} Querying Objects with Windows PowerShell OperatorDescription -eqEqual to -neNot equal to -ltLess than -leLess than or equal to -gtGreater than -geGreater than or equal to -likeUses wildcards for pattern matching ParameterDescription SearchBaseDefines the AD DS path to begin searching. SearchScopeDefines at what level below the SearchBase a search should be performed. ResultSetSizeDefines how many objects to return in response to a query. PropertiesDefines which object properties to return and display.

Modifying Objects with Windows PowerShell Use the pipe character ( | ) to pass a list of objects to a cmdlet for further processing Get ‑ ADUser ‑ Filter {company ‑ notlike "*"} | Set ‑ ADUser ‑ Company "A. Datum" Get ‑ ADUser ‑ Filter {lastlogondate ‑ lt "January 1, 2012"} | Disable ‑ ADAccount Get-Content C:\users.txt | Disable-ADAccount

Working with CSV Files The first line of a.csv file defines the names of the columns A foreach loop processes the contents of a.csv that have been imported into a variable FirstName,LastName,Department Greg,Guzik,IT Robin,Young,Research Qiong,Wu,Marketing $users=Import-CSV C:\users.csv Foreach ($i in $users) { Write-Host "The first name is:" $i.FirstName }

Demonstration: Performing Bulk Operations with Windows PowerShell In this demonstration, you will see how to: Configure a department for users Create an OU Run a script to create new user accounts Verify that new user accounts were created

Lab: Automating AD DS Administration by Using Windows PowerShell Exercise 1: Creating User Accounts and Groups by Using Windows PowerShell Exercise 2: Using Windows PowerShell to Create User Accounts in Bulk Exercise 3: Using Windows PowerShell to Modify User Accounts in Bulk Logon Information Virtual machines20410B ‑ LON ‑ DC B ‑ LON ‑ CL1 User name Adatum\Administrator Password Pa$$w0rd Estimated Time: 45 minutes

Lab Scenario A. Datum Corporation is a global engineering and manufacturing company with a head office based in London, England. An IT office and a data center are located in London to support the London location and other locations. A. Datum has recently deployed a Windows Server 2012 infrastructure with Windows 8 clients. You have been working for A. Datum for several years as a desktop support specialist. In this role, you visited desktop computers to troubleshoot application and network problems. You have recently accepted a promotion to the server support team. One of your first assignments is configuring the infrastructure service for a new branch office. As part of configuring a new branch office, you need to create user and group accounts. Creating multiple users with graphical tools is inefficient, so, you will be using Windows PowerShell.

Lab Review By default, are new user accounts enabled or disabled when you create them by using the NewADUser cmdlet? What file extension do Windows PowerShell scripts use?

Module Review and Takeaways Review Questions