Active Directory Lecture 3 – Domain Services Primer.

Slides:



Advertisements
Similar presentations
Microsoft Active Directory
Advertisements

How to Succeed with Active Directory Robert Williams, PhD CEO Secure Logistix Corporation.
Active Directory: Final Solution to Enterprise System Integration
1 Active Directory (Week 8, Monday 2/26/2007) © Abdou Illia, Spring 2007.
Introduction to Active Directory
6.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
Administering Active Directory
By Rashid Khan Lesson 4-Preparing to Serve: Understanding Microsoft Networking.
Windows Server WHAT IS ACTIVE DIRECTORY? FUNDAMENTALS OF THE ACTIVE DIRECTORY – Benefits of Using the Active Directory in an Enterprise Environment.
Hands-On Microsoft Windows Server 2003 Administration Chapter 3 Administering Active Directory.
Chapter 4 Introduction to Active Directory and Account Management
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
Enterprise Single Sign On Identity management for web applications.
By Karan Oberoi.  A directory service (DS) is a software application- or a set of applications - that stores and organizes information about a computer.
Understanding Active Directory
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
Chapter 7 WORKING WITH GROUPS.
Active Directory Implementation Class 4
ADVANCED MICROSOFT ACTIVE DIRECTORY CONCEPTS
Introduction to Active Directory Services Completely integrated with Microsoft Windows 2000 Server Integrates the Internet concept of namespace with the.
Lesson 17. Domains and Active Directory. Objectives At the end of this Presentation, you will be able to:
Nassau Community College
(ITI310) SESSIONS : Active Directory By Eng. BASSEM ALSAID.
BZUPAGES.COM An Introduction to. BZUPAGES.COM Introduction Large corporations today face the following problems Finding a certain file. Seeing everything.
Directory services Unit objectives
Chapter 4 Introduction to Active Directory and Account Management
Exploring Directory Services. Need for DS Multiple servers, multiple services in single network –Multiple servers for reliability, security, optimizing.
Session 6 Windows Platform Dina Alkhoudari. Learning Objectives What is Active Directory Logical components of active directory Physical components of.
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 3: Introducing Active Directory.
Working with domains and Active Directory
Chapter 7: WORKING WITH GROUPS
Windows 2003 Overview Lecture 1. Windows Networking Evolution Windows for Workgroups – peer-to-peer networking built into the OS Windows NT – separate.
Microsoft Active Directory(AD) A presentation by Robert, Jasmine, Val and Scott IMT546 December 11, 2004.
Designing Active Directory for Security
Chapter 6: Windows Servers
A detailed look at the Microsoft Windows Infrastructure at UWE including Active Directory (AD), MIIS, Exchange, SMS, IIS, SQL Server, Terminal Services.
Windows 2000 Operating System -- Active Directory Service COSC 516 Yuan YAO 08/29/2000.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 5: Active Directory Logical Design.
Step By Step Windows Server 2003 Installation Guide Step By Step Windows Server 2003 Installation Guide.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
Active Directory Windows2003 Server. Agenda What is Active Directory What is Active Directory Building an Active Directory Building an Active Directory.
September 18, 2002 Windows 2000 Server Active Directory By Jerry Haggard.
Designing Authentication for a Microsoft Windows 2000 Network Designing Authentication in a Microsoft Windows 2000 Network Designing Kerberos Authentication.
Module 7 Active Directory and Account Management.
Active Directory Maryam Izadi. Topics Covered NT Vs 2000/2003 Active Directory LDAP MMC.
Secure Networking Windows 2000 Distributed Security Services Sandeep Joshi Group 4.
Introduction to Microsoft Windows 2000 Integrated support for client/server and peer-to-peer networks Increased reliability, availability, and scalability.
Page 1 Active Directory and DNS Lecture 2 Hassan Shuja 09/14/2004.
Introduction to Microsoft Windows 2000 Welcome to Chapter 1 Windows 2000 Server.
Permissions Lesson 13. Skills Matrix Security Modes Maintaining data integrity involves creating users, controlling their access and limiting their ability.
OVERVIEW OF ACTIVE DIRECTORY
Introduction to Active Directory
1 Active Directory Service in Windows 2000 Li Yang SID: November 2000.
Module 1: Introduction to Active Directory
Active Directory CNS 4650 Fall 2004 Rev. 2. Active Directory Introduced with Windows 2000 Server X.500 based Can emulate NT-style network environments.
Hussain Ali Department of Computer Engineering KFUPM, Dhahran, Saudi Arabia Active Directory.
Active Directory. Computers in organizations Computers are linked together for communication and sharing of resources There is always a need to administer.
Module 8: Planning for Windows Server 2008 Active Directory Services.
CEG 2400 Fall 2012 Directory Services Active Directory Tree Domain.
Windows 2003 Architecture, Active Directory & DNS Lecture # 3 Hassan Shuja 02/14/2006.
Directory Services CS5493/7493. Directory Services Directory services represent a technological breakthrough by integrating into a single management tool:
MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition (70-294) Chapter 1: Overview of the Active.
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
Planning an Active Directory Deployment Lesson 1.
Windows Active Directory – What is it? Definition - Active Directory is a centralized and standardized system that automates network management of user.
(ITI310) SESSIONS 6-7-8: Active Directory.
Active Directory Stored collection of information about objects
Presentation transcript:

Active Directory Lecture 3 – Domain Services Primer

Learning Goals I will be able to install a functionally operable domain server for a Windows Active Directory Domain I will be able to organize a Windows Domain to maximize logical design and Security I will be able to distinguish between different types of Domain Objects

What is AD A directory server – a common place for information about groups, people, workstations and security to reside One ring to rule them all – The borg collective – Once joined to the domain one trusts the domain and all the security settings that goes with it.

Why do we care? Single most effective tool for managing security in a distributed environment If setup correctly can control users, servers, workstations and audit everything

Evolution of AD Windows NT 4 Windows 2000 – Domain Services – DNS Windows 2003 – Internet Integration Windows 2008 – Federated Management and Sharing Windows 2012 – The clouds are coming!

Standards Like the OSI model, AD is built on standards X.500 LDAP Compatable

Understanding Domains Single Domain One spot for a organization Container for user and company records Trees including domains and sub domains organize different parts of the company together

Some Rules Domains are designed to be built around internet names – DNS is an important part of Active Directory Public namespace names should be avoided unless you actually own the domain name – otherwise name resolution problems will crop up DNS Management – Either create a new subdomain for AD (ad.company.com) and let AD run it. Or create a new DNS name and let AD run it.

AD Authentication Modes NTLM – Legacy system which included hashes of passwords being sent over the network Kerberos – No sending of hashes over the network Because of it’s ability to send usernames and passwords quickly, in a central store and securely AD becomes the favorite of any single sign on container

LDAP Naming Convention Logical Flow

Trusting Relationships Explicit Trust - Works between domains to create trust between the two Partners – External Entities Different organizations within the same forest

Shortcut Trusts

OU’s Units for Organizing Users and Objects in the Domain Security Organization Can create OU’s inside OU’s

Some More Rules OU’s should not follow a managerial or political structure of the organization. Organize for the user separation for top level departments Organize between different types of Objects (Computers, Servers and Users)

Groups Groups are created to manage security on a specific level Used for assigning permissions or distributing information (exchange groups) Enterprises will have a TON of these – unrealistic for IT to manage Managers organize via political levels IT manages for permissions Managed Groups vs Standard Groups

Domain Controllers Domain Controllers Control the Domain – When a domain is created a database is installed that contains all the information about objects in the domain This database is replaced to all domain controllers inside the domain Domain controllers should be placed in physical locations of the same domain Remember to follow WAN Segments When the database is changed on one domain controller the changes are replicated on the other DC’s For security you may wish to install a domain controller as a “read only” domain controller. This would allow associated applications to read information without being able to make changes