Introduction to Active Directory Services Completely integrated with Microsoft Windows 2000 Server Integrates the Internet concept of namespace with the.

Slides:



Advertisements
Similar presentations
Chapter 6 Introducing Active Directory
Advertisements

Chapter 9 Chapter 9: Managing Groups, Folders, Files, and Object Security.
Chapter 4 Chapter 4: Planning the Active Directory and Security.
Introduction to Active Directory
6.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
CS603 Active Directory February 1, 2001.
1.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
Administering Active Directory
Hands-On Microsoft Windows Server 2003 Administration Chapter 1 Windows Server 2003 Network Administration.
Hands-On Microsoft Windows Server 2003 Administration Chapter 3 Administering Active Directory.
Chapter 4 Introduction to Active Directory and Account Management
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
Chapter 8: Network Operating Systems and Windows Server 2003-Based Networking Network+ Guide to Networks Third Edition.
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
Network+ Guide to Networks, Fourth Edition Chapter 8 Network Operating Systems and Windows Server 2003-Based Networking.
By Karan Oberoi.  A directory service (DS) is a software application- or a set of applications - that stores and organizes information about a computer.
Understanding Active Directory
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
Module 1: Introduction to Active Directory
A centralized system.  Active Directory is Microsoft's trademarked directory service, an integral part of the Windows architecture. Like other directory.
1 CSIT 320. Just as the combination of a database and a database management system collects and organizes information about an institution/company/… as.
Hands-On Microsoft Windows Server 2008
ADVANCED MICROSOFT ACTIVE DIRECTORY CONCEPTS
Overview of Active Directory Domain Services Lesson 1.
(ITI310) SESSIONS : Active Directory By Eng. BASSEM ALSAID.
BZUPAGES.COM An Introduction to. BZUPAGES.COM Introduction Large corporations today face the following problems Finding a certain file. Seeing everything.
Directory services Unit objectives
Windows Server 2008 Chapter 4 Last Update
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 3: Introducing Active Directory.
1 Group Account Administration Introduction to Groups Planning a Group Strategy Creating Groups Understanding Default Groups Groups for Administrators.
5.1 © 2004 Pearson Education, Inc. Lesson 5: Administering User Accounts Exam Microsoft® Windows® 2000 Directory Services Infrastructure Goals 
Chapter 7: WORKING WITH GROUPS
Chapter 6: Windows Servers
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 4: Active Directory Architecture.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
September 18, 2002 Windows 2000 Server Active Directory By Jerry Haggard.
1 Chapter Summary Understanding DNS Understanding Name Resolution Configuring a DNS Client Understanding Active Directory Understanding Active Directory.
Module 7 Active Directory and Account Management.
1 Introduction to Microsoft Windows 2000 Windows 2000 Overview Windows 2000 Architecture Overview Windows 2000 Directory Services Overview Logging On to.
Company Confidential 1 A Course on Global Catalog And Flexible Single Master Operations (Fsmo) Roles Prepared for: *Stars* New Horizons Certified Professional.
Active Directory Maryam Izadi. Topics Covered NT Vs 2000/2003 Active Directory LDAP MMC.
 Identify Active Directory functions and Benefits.  Identify the major components that make up an Active Directory structure.  Identify how DNS relates.
Page 1 Active Directory and DNS Lecture 2 Hassan Shuja 09/14/2004.
By Rashid Khan Lesson 6-Building a Directory Service.
Hands-On Microsoft Windows Server 2008 Chapter 4-Part 1 Introduction to Active Directory and Account Manager.
1 Chapter Overview Managing Object and Container Permissions Locating and Moving Active Directory Objects Delegating Control Troubleshooting Active Directory.
Active Directory Infrastructure Microsoft Windows 2003 Active Directory Infrastructure MCSE Exam
1 Active Directory Administration Tasks And Tools Active Directory Administration Tasks Active Directory Administrative Tools Using Microsoft Management.
OVERVIEW OF ACTIVE DIRECTORY
Introduction to Active Directory
Module 1: Introduction to Active Directory
Logical and Physical Network Design 1. Active Directory Objects Objects Represent Network Resources (Users,Groups,Computers,Printers) Attributes Store.
Hussain Ali Department of Computer Engineering KFUPM, Dhahran, Saudi Arabia Active Directory.
Active Directory. Computers in organizations Computers are linked together for communication and sharing of resources There is always a need to administer.
11 GLOBAL CATALOG AND FLEXIBLE SINGLE MASTER OPERATIONS (FSMO) ROLES Chapter 4.
CEG 2400 Fall 2012 Directory Services Active Directory Tree Domain.
Windows 2003 Architecture, Active Directory & DNS Lecture # 3 Hassan Shuja 02/14/2006.
1 Introduction to Active Directory Directory Services Uniquely identify users and resources on a network Provide a single point of network management.
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
Planning an Active Directory Deployment Lesson 1.
COMP1321 Digital Infrastructure Richard Henson March 2016.
Overview of Active Directory Domain Services
Active Directory Administration
(ITI310) SESSIONS 6-7-8: Active Directory.
Objectives Differentiate between the different editions of Windows Server 2003 Explain Windows Server 2003 network models and server roles Identify concepts.
Chapter 4: Planning the Active Directory and Security
Introduction to Active Directory Directory Services
Presentation transcript:

Introduction to Active Directory Services Completely integrated with Microsoft Windows 2000 Server Integrates the Internet concept of namespace with the operating system’s directory service Allows a single point of administration for all published resources

Understanding Active Directory Concepts Extensible schema Global catalog Namespace Naming conventions

Extensible Schema Extending the schema is an advanced operation, intended to be performed by experienced programmers and system administrators.

Global Catalog The global catalog is the central repository of information about objects in a domain tree or forest. The global catalog is a service as well as a physical storage location that contains a replica of selected attributes of every object in the Active Directory store. By default, the first domain controller is a global catalog server. Additional domain controllers can also be designated as global catalog servers by using the Active Directory Sites And Services snap-in.

Namespace

Naming Conventions Distinguished names (DNs) Relative distinguished names (RDNs) Globally unique identifiers (GUIDs) User principal names (UPNs)

Distinguished Names (DNs) Objects are located within Active Directory domains according to a hierarchical path. Every object in the Active Directory store has a DN, which uniquely identifies the object. The DN includes the name of the domain that holds the object as well as the complete path through the container hierarchy to the object. For example: DC=msft/DC=Contoso/CN=Users/CN=John Smith

Relative Distinguished Names (RDNs) The RDN is one of an object’s attributes. The RDN is part of the full DN. For example: CN=John Smith Active Directory services allows duplicate RDNs for objects, but no two objects with the same RDN can exist within the same OU.

Globally Unique Identifiers (GUIDs)

User Principal Names (UPNs) The UPN is a friendly name that is shorter than the DN and easier to remember. The UPN consists of a shorthand name that represents the user and usually the DNS name of the domain where the object resides. Example:

Structure of Active Directory Architecture Data model Schema Security model Administration model

Access to Active Directory Services Protocol Support Application programming interfaces (APIs) Virtual containers

Protocol Support LDAP is the Active Directory core protocol. Active Directory services supports remote procedure call (RPC) interfaces that support Messaging Application Programming Interface (MAPI) interfaces. The Active Directory information model is derived from the X.500 information model.

Application Programming Interfaces (APIs) Active Directory Service Interfaces (ADSI) LDAP C API Windows MAPI

Virtual Containers Active Directory services supports virtual containers, which allow any LDAP-compliant directory to be accessed transparently through Active Directory services. The virtual container is implemented via location information in the Active Directory store.

Directory Service Architecture Interfaces Directory System Agent (DSA) Database layer Extensible Storage Engine (ESE) Data store (Ntds.dit)

Active Directory Key Service Components

Interfaces LDAP provides the API for LDAP clients and exposes the ADSI so that additional applications can be written that can talk to the Active Directory services. REPL is used by the replication service to facilitate Active Directory replication via RPC over Internet Protocol (IP) or Simple Mail Transfer Protocol (SMTP). SAM Provides down-level compatibility to facilitate communication between Microsoft Windows 2000 and Microsoft Windows NT 4.0 domains. MAPI supports legacy MAPI clients.

Directory System Agent (DSA) Object identification Transaction processing Schema enforcement of updates Access control enforcement Support for replication Referrals

Database Layer Provides an object view of database information by applying schema semantics to database records Is an internal interface that is not exposed to the public Follows the parent references in the database and concatenates the successive RDNs to form DNs Translates each DN into an integer structure called the DN tag, which is used for internal access Is responsible for the creation, retrieval, and deletion of individual records, attributes, and values

Extensible Storage Engine (ESE) A new and improved version of the JET database Implements a transacted database system that uses log files to ensure that committed transactions are safe Stores all Active Directory objects Comes with a predefined schema that defines all the attributes required and allowed for a given object Stores attributes that can have multiple values

Introduction to Namespace Planning The Active Directory namespace is the top-level qualified domain name for the company. You must determine whether the internal and external namespaces will be the same or separate.

Defining a Namespace Architecture Introduction Root domain First-layer domains Second-layer domains

Introduction to OU Planning OUs should reflect the details of the organization’s business structure. Create OUs to delegate administrative control over smaller groups of users, groups, and resources. OUs eliminate the need to provide users with administrative access at the domain level. OUs inherit security policies from the parent domain and parent OU unless inheritance is specifically disabled.

Creating the OU Structure You should begin your OU design by creating an OU structure for the first domain in the namespace. When you create an OU, you should determine who will be able to view and control certain objects and what level of administration each administrator will have over the objects.

OU Design Guidelines Create OUs to delegate administration. Create a logical and meaningful OU structure that allows OU administrators to complete their tasks efficiently. Create OUs to apply security policies. Create OUs to manage the visibility of published resources. Create OU structures that are relatively static. OUs also give the namespace flexibility to adapt to changing needs of the enterprise. Avoid allocating too many child objects to any OU.

Structure the OU Hierarchy Administration-based or object-based OUs Geographical-based OUs Business function–based OUs Department-based OUs Project-based OUs

Introduction to Site Planning The physical design of a Windows 2000 network is demarcated by site. The Active Directory replication engine allows you to differentiate between replication over a LAN and replication over a WAN. How you set up your sites affects Windows 2000 with respect to workstation logon and directory replication. In Active Directory services, sites are not part of the namespace. Properly planned sites ensure that network links are not saturated by replication traffic, that Active Directory services stay current, and that client computers access resources that are closest to them. When planning how to group subnets into sites, consider the connection speed between the subnets.

Optimizing Workstation Logon Traffic When planning sites, consider which domain controllers workstations should use. To have a particular workstation log on to a specific set of domain controllers, define the sites so that only those domain controllers are on the same site as the workstation.

Optimizing Directory Replication When planning sites, consider where the domain controllers will be located. Configure sites so that replication occurs at times or intervals that will not interfere with network performance. When implementing sites in branch offices, base your planning on the size of the branch office.

Introduction to the Active Directory Installation Wizard

Adding or Creating a Domain Controller If you add a domain controller to an existing domain, you create a peer domain controller. If you create the first domain controller for a new domain, you are creating not only the domain controller but also a new domain.

Adding a Domain Controller to an Existing Domain

Creating a New Child Domain

Creating a New Domain Tree

Adding a Domain Tree to a Forest

The Active Directory Database and the Shared System Volume Created when Active Directory Services is installed

The Active Directory Database The database is a file named Ntds.dit, which is the directory for the new domain. The default location for the database and the database log files is %systemroot%\Ntds, although you can specify a different location. The database contains all the information stores in the Active Directory store. The Ntds.dit file is an ESE database that contains the entire schema, the global catalog, and all the objects stored on that domain controller.

The Shared System Volume The shared system volume is a folder structure that exists on all Windows 2000 domain controllers. The shared system volume stores scripts and some of the group policy objects for the current domain as well as the enterprise. Replication of the shared system volume occurs on the same schedule as Active Directory replication.

Domain Modes Mixed mode Native mode

Introduction to OUs and their Objects Each Active Directory object is a distinct named set of attributes that represents a specific network resource. Before objects are added to Active Directory services, you should create the OUs that will contain those objects.

Creating Ous

Adding Objects to OUs ContactGroupUser Shared Folder Printer Computer

Locating Objects

Modifying Attributes and Deleting Objects You can modify the attributes of an object to change or add information. You can modify an object’s attribute by opening the properties for that object in the Active Directory Users And Computers snap-in. To maintain security, delete objects when they are no longer needed.

Moving Objects You can move objects from one location in the Active Directory store to another location. You should move objects when organization or administrative functions change.

Managing Active Directory Permissions Use Active Directory permissions to determine who has the permissions to gain access to the object and what type of access is allowed. The object type determines which permissions you can select. Permissions inheritance minimizes the number of times you need to assign permissions for objects.

Delegating Administrative Control of Objects You can delegate administrative control of objects to individuals. Use the Delegation Of Control wizard to delegate control of objects. An administrator can delegate specific types of control. The most common method of delegating control is to assign permissions at the OU level. To delegate administrative control, you should try to follow specific guidelines. You can access the Delegation Of Control wizard through the Active Directory Users And Computers snap-in.

Guidelines for Administering Active Directory Services Coordinate Active Directory structure with other administrators. Complete all attributes when creating objects. Use deny permissions sparingly. Ensure that at least one user has Full Control permission for each object. Ensure that delegated users take responsibility and can be held accountable. Provide training for users who control objects.