Microsoft ® Official Course Module 12 Monitoring, Managing, and Recovering AD DS.

Slides:



Advertisements
Similar presentations
Course 2786B Module 8: Implementing an Active Directory® Domain Services Monitoring Plan Presentation: 60 minutes Lab: 60 minutes This module helps students.
Advertisements

Copyright line. Maintaining an Active Directory Environment Exam Objectives Backup and Recovery Backup and Recovery Offline Maintenance Offline Maintenance.
Course 6425A Module 9: Implementing an Active Directory Domain Services Maintenance Plan Presentation: 55 minutes Lab: 75 minutes This module helps students.
Deploying and Managing Active Directory Certificate Services
Implementing and Administering AD FS
Managing User Settings with Group Policy
Active Directory Disaster Recovery Paul Simmons Support Engineer Directory Services Microsoft Corporation.
8.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 12: Managing and Implementing Backups and Disaster Recovery.
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 11 Managing and Monitoring a Windows Server 2008 Network.
Windows Server 2012 Richard Oertle Subject Matter Expert / Instructor October 25 th, 2012.
Implementing High Availability
Module 8 Implementing Backup and Recovery. Module Overview Planning Backup and Recovery Backing Up Exchange Server 2010 Restoring Exchange Server 2010.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
1 Directory Service Continuity Monitor Active Directory Manage the Active Directory Database Back Up and Restore AD DS and Domain Controllers.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 12: Managing and Implementing Backups and Disaster Recovery.
Module 8: Designing Active Directory Disaster Recovery in Windows Server 2008.
Module 1: Installing Active Directory Domain Services
Implementing Dynamic Host Configuration Protocol
Course 6425A Module 9: Implementing an Active Directory Domain Services Maintenance Plan Presentation: 55 minutes Lab: 75 minutes This module helps students.
Module 2 Creating Active Directory ® Domain Services User and Computer Objects.
Module 1 Introduction to Managing Microsoft® Windows Server® 2008 Environment.
CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
Module 18 Monitoring SQL Server 2008 R2. Module Overview Monitoring Activity Capturing and Managing Performance Data Analyzing Collected Performance Data.
Deploying and Managing Windows Server 2012
Overview of Access and Information Protection
10969A Active Directory® Services with Windows Server® Course 10699A
Microsoft ® Official Course Module 13 Troubleshooting and Recovering Windows 8.
Module 13: Configuring Availability of Network Resources and Content.
Implementing Dynamic Host Configuration Protocol
Implementing File and Print Services
Microsoft ® Official Course Module 8 Securing Windows 8 Desktops.
Module 8 Configuring and Securing SharePoint Services and Service Applications.
Managing Active Directory Domain Services Objects
Microsoft ® Official Course Module 10 Optimizing and Maintaining Windows ® 8 Client Computers.
Module 9: Active Directory Domain Services. Overview Describe new features in AD DS List manageability and reliability enhancements in AD DS.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 12: Managing and Implementing Backups and Disaster Recovery.
Chapter 18: Windows Server 2008 R2 and Active Directory Backup and Maintenance BAI617.
Managing User and Service Accounts
Chapter 8 Implementing Disaster Recovery and High Availability Hands-On Virtual Computing.
Implementing Update Management
Configuring Encryption and Advanced Auditing
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Securing AD DS Module A 3: Securing AD DS
Module 7: Fundamentals of Administering Windows Server 2008.
20411B 8: Installing, Configuring, and Troubleshooting the Network Policy Server Role Presentation: 60 minutes Lab: 60 minutes After completing this module,
Maintaining Active Directory Domain Services
Module 9 Planning a Disaster Recovery Solution. Module Overview Planning for Disaster Mitigation Planning Exchange Server Backup Planning Exchange Server.
Microsoft ® Official Course Module 3 Managing Active Directory Domain Services Objects.
Monitoring Windows Server 2012
Active Directory Maintenance, Troubleshooting, and Disaster Recovery Lesson 11.
Module 3: Preparing for and Recovering from Non- Mailbox Server Failures.
Module 13 Implementing Business Continuity. Module Overview Protecting and Recovering Content Working with Backup and Restore for Disaster Recovery Implementing.
Module 10: Maintaining Active Directory. Overview Introduction to Maintaining Active Directory Moving and Defragmenting the Active Directory Database.
11 DISASTER RECOVERY Chapter 13. Chapter 13: DISASTER RECOVERY2 OVERVIEW  Back up server data using the Backup utility and the Ntbackup command  Restore.
Microsoft ® Official Course Module 13 Implementing Windows Azure Active Directory.
Module 15 Managing Windows Server® 2008 Backup and Restore.
Module 14 Monitoring and Optimizing SharePoint Performance.
Module 8: Implementing an Active Directory Domain ® Services Monitoring Plan.
Module 1: Implementing Active Directory ® Domain Services.
Module 4 Planning for Group Policy. Module Overview Planning Group Policy Application Planning Group Policy Processing Planning the Management of Group.
System Center Lesson 4: Overview of System Center 2012 Components System Center 2012 Private Cloud Components VMM Overview App Controller Overview.
Implementing a Group Policy Infrastructure
Module 9 Planning and Implementing Monitoring and Maintenance.
Module 3 Planning for Active Directory®
Labs. Session 1 Lab 1: Designing an Active Directory Forest Infrastructure in Windows Server 2008 Exercise 1: Designing an Active Directory Forest Exercise.
QUESTION 1: Your role of Network Administrator at ABC.com includes the management of the Active Directory Domain Services (AD DS) domain named ABC.com.
Unit 10 ITT TECHNICAL INSTITUTE NT1330 Client-Server Networking II Date: 2/24/2016 Instructor: Williams Obinkyereh.
1 Microsoft Windows Server 2003 Active Directory Infrastructure Backing Up and Restoring Active Directory Goals  Use the.
Monitoring Windows Server 2012
Presentation transcript:

Microsoft ® Official Course Module 12 Monitoring, Managing, and Recovering AD DS

Module Overview Monitoring AD DS Managing the AD DS Database AD DS Backup and Recovery Options for AD DS and Other Identity and Access Solutions

Lesson 1: Monitoring AD DS Understanding Performance and Bottlenecks Overview of Monitoring Tools Performance Monitor Data Collector Sets Demonstration: How to Monitor Performance

Understanding Performance and Bottlenecks Key system resources: CPU Disk Memory Network A bottleneck is a resource that is currently at peak utilization

Overview of Monitoring Tools Windows Server 2012 provides the following tools to help with monitoring performance issues: Task Manager Resource Monitor Event Viewer Performance Monitor

You can use Performance Monitor to view current performance statistics or historical data gathered by using data collector sets

Data Collector Sets You can use data collector sets to gather performance-related information Data collector sets can contain the following types of data collectors: Performance counters Event trace data System configuration information

Demonstration: How to Monitor Performance In this demonstration, you will see how to: Create a data collector set Create a disk load on the server Analyze the resulting data in a report

Lab A: Monitoring AD DS Exercise 1: Monitoring AD DS with Performance Monitor Logon Information Virtual machine:10969A-LON-DC1 User name:Adatum\Administrator Password:Pa$$w0rd Estimated Time: 40 minutes

Lab Scenario Last month, the only domain controller in the Cambridge branch office failed. You now are required to monitor AD DS to help identify problems before they become critical.

Lab Review When analyzing the performance of a domain controller, aside from the AD DS–specific counters in Performance Monitor, what other factors can influence domain controller performance?

Lesson 2: Managing the AD DS Database Overview of the AD DS Database Managing the Database with NtdsUtil.exe Restartable AD DS Demonstration: Performing Database Management Managing AD DS Snapshots

Overview of the AD DS Database The AD DS database holds all domain-based information in four or more partitions AD DS Database Domain Controller Schema Partition Application Partitions (optional) Configuration Partition Domain Partition

Managing the Database with NtdsUtil.exe Manage and control single master operations Perform AD DS database maintenance: Perform offline defragmentation Create and mount snapshots Move database files Clean domain controller metadata: Domain controller removal or demotion while not connected to domain Reset Directory Services Restore Mode: password set dsrm

Restartable AD DS Use the Services console to start or stop AD DS Three states of AD DS: AD DS Started AD DS Stopped Directory Services Restore Mode It is not possible to perform a system state restore while AD DS is in Stopped state

Demonstration: Performing Database Management In this demonstration, you will see how to: Stop AD DS Perform an offline defragmentation of the AD DS database Check the integrity of the AD DS database Start AD DS

Managing AD DS Snapshots Create a snapshot of AD DS with NTDSUtil Mount the snapshot with NTDSUtil Expose the snapshot: Right-click the root node of Active Directory Users and Computers, then and choose Connect to Domain Controller Enter serverFQDN:port View read-only snapshot: Cannot directly restore data from the snapshot Recover data: Connect to the mounted snapshot, and then export/reimport objects’ attributes with LDIFDE Restore a backup from the same date as the snapshot Manually reenter data

Lesson 3: AD DS Backup and Recovery Options for AD DS and Other Identity and Access Solutions Reanimating Deleted Objects Configuring the Active Directory Recycle Bin Demonstration: Implementing the Active Directory Recycle Bin Backup Technologies Backup and Recovery Tools AD DS Backup and Recovery Backup Options for AD CS Backup Options for AD RMS Backup Options for AD FS

Reanimating Deleted Objects Deleted objects are recovered through tombstone reanimation When an object is deleted, most of its attributes are cleared Authoritative restore requires AD DS downtime Live Tombstoned Physically Deleted Garbage Collection Delete Reanimate Tombstone/ Authoritative Restore

Configuring the Active Directory Recycle Bin Active Directory Recycle Bin provides a way to restore deleted objects without AD DS downtime Uses Active Directory module for Windows PowerShell or the Active Directory Administrative Center to restore objects Live Deleted Garbage Collection Delete Undelete/ Authoritative Restore Recycled Recycle Physically Deleted Object Lifetime Recycled Object Lifetime

Demonstration: Implementing the Active Directory Recycle Bin In this demonstration, you will see how to: Enable the Active Directory Recycle Bin Create and then delete test accounts Restore deleted accounts

Backup Technologies The VSS backup technology solves data consistency issues by creating shadow copies You can use streaming backups for older applications that are not VSS-aware

Backup and Recovery Tools Windows Server Backup Windows Azure Online Backup Data Protection Manager

AD DS Backup and Recovery Nonauthoritative or normal restore: Restore domain controller to previously known good state Domain controller updates by using standard replication from partners Authoritative restore: Restore domain controller to previously known good state Mark objects that you want to be authoritative Domain controller updates from its up-to-date-partners Domain controller sends authoritative updates to its partners Full server restore: Typically performed in Windows Recovery Environment Alternate location restore

Backup Options for AD CS Windows Server Backup CA Certutil.exe Tool DPM C:/

Backup Options for AD RMS Back up private keys and certificates Ensure that the AD RMS database is backed up regularly Export templates to back them up Run AD RMS server as a virtual machine, and perform full server backup

Backup Options for AD FS %systemdrive%\ADFS System state Servers running AD FS components must be backed up based on the information in the following table: ComponentsFiles to back up Federation Service TrustPolicy.xml file Web.config and other files under %SystemRoot%\ADFS System state Custom transform module (.dll) and related files Applicationhost.config Web Application Proxy Web.config and other files under %SystemRoot%\ADFS System state Applicationhost.config AD FS Web Agent %SystemRoot%\ADFS System state

Lab B: Recovering Objects in AD DS Exercise 1: Backing up and Restoring AD DS Exercise 2: Recovering Objects in AD DS Logon Information Virtual machines: 10969A-LON-DC A-LON-DC2 User name:Adatum\Administrator Password:Pa$$w0rd Estimated Time: 60 minutes

Lab Scenario You were notified yesterday that one user account was deleted by accident. A few days ago, additional user accounts were deleted accidentally. You want to recover these accounts. It is your responsibility to ensure that the directory service is backed up. Today, you noticed that last night's backup did not run as scheduled. You therefore decided to perform an interactive backup. Shortly after the backup, a domain administrator accidentally deletes the IT OU. You must recover this OU.

Lab Review When you restore a deleted user, or an OU with user objects, by using authoritative restore, will the objects be exactly the same as before? Which attributes might not be the same? In the lab, would it be possible to restore these deleted objects if they were deleted before Active Directory Recycle Bin has been enabled?

Module Review and Takeaways Review Question