Active Directory Administration Lesson 5. Skills Matrix Technology SkillObjective DomainObjective # Creating Users, Computers, and Groups Automate creation.

Slides:



Advertisements
Similar presentations
Managing User, Computer and Group Accounts
Advertisements

MOAC : Installing and Configuring Windows Server 2012
Module 4: Implementing User, Group, and Computer Accounts
Module 3: Configuring Active Directory Objects and Trusts.
11 WORKING WITH GROUPS Chapter 7. Chapter 7: WORKING WITH GROUPS2 CHAPTER OVERVIEW  Understand the functions of groups and how to use them.  Understand.
6.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
MCDST : Supporting Users and Troubleshooting a Microsoft Windows XP Operating System Chapter 6: Configure and Troubleshoot Local User and Group Accounts.
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 5: Account Management.
Administering Active Directory
LAN Management © Abdou Illia, Spring 2007 School of Business Eastern Illinois University 3/6/2007 Lab.
Hands-On Microsoft Windows Server 2003 Administration Chapter 3 Administering Active Directory.
Chapter 5: Configuring Users and Groups. Windows Vista User Accounts User accounts are the primary means of authentication Built-in Accounts –Administrator:
Lesson 14: Creating and Managing Active Directory Users and Computers
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
Group Accounts; Securing Resources with Permissions
Understanding Active Directory
1 Chapter Overview Creating User and Computer Objects Maintaining User Accounts Creating User Profiles.
Module 8: Implementing Administrative Templates and Audit Policy.
Creating and Managing User Accounts. Overview Introduction to User Accounts Guidelines for New User Accounts Creating Local User Accounts Creating and.
Chapter 7 WORKING WITH GROUPS.
Hands-On Microsoft Windows Server 2008
Overview of Active Directory Domain Services Lesson 1.
70-270: MCSE Guide to Microsoft Windows XP Professional Chapter 5: Users, Groups, Profiles, and Policies.
Working with Workgroups and Domains
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 3: Introducing Active Directory.
1 Group Account Administration Introduction to Groups Planning a Group Strategy Creating Groups Understanding Default Groups Groups for Administrators.
CN1276 Server (V3) Kemtis Kunanuraksapong MSIS with Distinction MCT, MCTS, MCDST, MCP, A+
Managing Active Directory Domain Services Objects
6.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 6: Administering User Accounts.
5.1 © 2004 Pearson Education, Inc. Lesson 5: Administering User Accounts Exam Microsoft® Windows® 2000 Directory Services Infrastructure Goals 
Module 6: Designing Active Directory Security in Windows Server 2008.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 10: Managing Users, Groups, Computers and Resources.
Chapter 7: WORKING WITH GROUPS
C HAPTER 6 NTFS PERMISSIONS & SECURITY SETTING. INTRODUCTION NTFS provides performance, security, reliability & advanced features that are not found in.
Windows Server 2003 Overview 1 Windows 2003 Server Overview Ayaz
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
Security Planning and Administrative Delegation Lesson 6.
Managing Groups, Folders, Files and Security Local Domain local Global Universal Objects Folders Permissions Inheritance Access Control List NTFS Permissions.
1 Chapter Overview Configuring Account Policies Configuring User Rights Configuring Security Options Configuring Internet Options.
Module 3: Configuring Active Directory Objects and Trusts.
Active Directory Administration Lesson 5. Skills Matrix Technology SkillObjective DomainObjective # Creating Users, Computers, and Groups Automate creation.
Module 7 Active Directory and Account Management.
© Wiley Inc All Rights Reserved. MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition.
Microsoft ® Official Course Module 3 Managing Active Directory Domain Services Objects.
70-270: MCSE Guide to Microsoft Windows XP Professional 1 Windows XP Professional User Accounts Designed for use as a network client for: Windows NT Windows.
Introduction to Microsoft Management Console (MMC) MMC is a common console framework for management applications. MMC provides a common environment for.
Planning a Microsoft Windows 2000 Administrative Structure Designing default administrative group membership Designing custom administrative groups local.
1 Chapter Overview Understanding User Accounts Planning New User Accounts Creating, Modifying, and Deleting User Accounts Setting Properties for User Accounts.
Chapter 10: Rights, User, and Group Administration.
Working with Workgroups and Domains Lesson 9. Objectives Understand users and groups Create and manage local users and groups Understand the difference.
Working with Users and Groups Lesson 5. Skills Matrix Technology SkillObjective DomainObjective # Introducing User Account Control Configure and troubleshoot.
Windows Server 2003 La migrazione da Windows NT 4.0 a Windows Server 2003 Relatore: MCSE - MCT.
Security Planning and Administrative Delegation Lesson 6.
Managing Local Users & Groups. OVERVIEW Configure and manage user accounts Manage user account properties Manage user and group rights Configure user.
Administering Groups Chapter Eight. Exam Objectives In this Chapter:  Plan a security group hierarchy based upon delegation requirements  Plan a security.
Working with Users and Groups Lesson 5. Skills Matrix Technology SkillObjective DomainObjective # Introducing User Account Control Configure and troubleshoot.
MIS Chapter 41 Chapter 4 – Implementing and Managing Group and Computer Accounts MIS 431 – Created Spring 2006.
1 Chapter Overview Using Group Objects Understanding Default Groups Creating Group Objects Managing Administrative Access.
6/19/2016 أساسيات الأتصال و الشبكات Communication & Networks Fundamentals lab 4.
Implementing Active Directory Domain Services
ACTIVE DIRECTORY ADMINISTRATION
ACTIVE DIRECTORY ADMINISTRATION
Active Directory Administration
Creating and Managing User Accounts
BACHELOR’S THESIS DEFENSE
BACHELOR’S THESIS DEFENSE
BACHELOR’S THESIS DEFENSE
Windows Server 2003 使用者群組管理
Unit 6 NT1330 Client-Server Networking II Date: 7/19/2016
Presentation transcript:

Active Directory Administration Lesson 5

Skills Matrix Technology SkillObjective DomainObjective # Creating Users, Computers, and Groups Automate creation of Active Directory accounts 4.1 Creating Users, Computers, and Groups Maintain Active Directory accounts 4.2

Lesson 5 Understanding User Accounts Local accounts Domain accounts Built-in user accounts

Lesson 5 Understanding Group Accounts Distribution groups Security groups

Lesson 5 Working with Default Groups Account Operators Administrators Backup Operators Certificate Services DCOM Access Cryptographic Operators

Lesson 5 Working with Default Groups (cont.) Distributed COM Users Event Log Readers Guests IIS_IUSRS Incoming Forest Trust Builders

Lesson 5 Working with Default Groups (cont.) Network Configuration Operators Performance Log Users Performance Monitor Users Pre-Windows 2000 Compatible Access Print Operators

Lesson 5 Working with Default Groups (cont.) Remote Desktop Users Replicator Server Operators Terminal Server License Servers

Lesson 5 Working with Default Groups (cont.) Users Windows Authorization Access Group Allowed RODC Password Replication Group Cert Publishers Denied RODC Password Replication Group

Lesson 5 Working with Default Groups (cont.) DnsAdmins DnsUpdateProxy Domain Admins Domain Computers Domain Controllers

Lesson 5 Working with Default Groups (cont.) Domain Guests Domain Users Enterprise Admins Enterprise Read-Only Domain Controllers Group Policy Creator Owners

Lesson 5 Working with Default Groups (cont.) RAS and IAS Servers Read-Only Domain Controllers Schema Admins

Lesson 5 Understanding Special Identity Groups and Local Groups Anonymous Logon Authenticated Users Batch Creator Group Creator Owner

Lesson 5 Understanding Special Identity Groups and Local Groups (cont.) Dial-up Digest Authentication Enterprise Domain Controllers Everyone Interactive

Lesson 5 Understanding Special Identity Groups and Local Groups (cont.) IUSR Local Service Network Network Service Remote Interactive Logon

Lesson 5 Understanding Special Identity Groups and Local Groups (cont.) Restricted Self Service System Terminal Server User

Lesson 5 Developing a Group Implementation Plan Group implementation plan:  A plan that states who has the ability and responsibility to create, delete, and manage groups  A policy that states how domain local, global, and universal groups are to be used

Lesson 5 Developing a Group Implementation Plan (cont.) Group implementation plan (cont.):  A policy that states guidelines for creating new groups and deleting old groups  A naming standards document to keep group names consistent  A standard for group nesting

Lesson 5 Creating Users and Groups Batch files Comma-Separated Value Directory Exchange (CSVDE) LDAP Data Interchange Format Directory Exchange (LDIFDE) Windows Script Host (WSH)

Summary You Learned Three types of user accounts exist in Windows Server 2008: local user accounts, domain user accounts, and built-in user accounts. Local user accounts reside on a local computer and are not replicated to other computers by Active Directory. Domain user accounts are created and stored in Active Directory and replicated to all domain controllers within a domain. Built-in user accounts are automatically created when the operating system is installed and when a member server is promoted to a domain controller.

Summary You Learned (cont.) The Administrator account is a built-in domain account that serves as the primary supervisory account in Windows Server It can be renamed, but it cannot be deleted. The Guest account is a built-in account used to assign temporary access to resources. It can be renamed, but it cannot be deleted. This account is disabled by default, and the password can be left blank.

Summary You Learned (cont.) Windows Server 2008 group options include two types: security and distribution, and three scopes: domain local, global, and universal. Domain local groups are placed on the ACL of resources and assigned permissions. They typically contain global groups in their membership list.

Summary You Learned (cont.) Global groups are used to organize domain users according to their resource access needs. Global groups are placed in the membership list of domain local groups, which are then assigned the desired permissions to resources.

Summary You Learned (cont.) Universal groups are used to provide access to resources anywhere in the forest. Their membership lists can contain global groups and users from any domain. Changes to universal group membership lists are replicated to all global catalog servers throughout the forest.

Summary You Learned (cont.) The recommended permission assignment strategy places users needing access permissions in a global group, the global group in a universal group, and the universal group in a domain local group and then assigns permissions to the domain local group.

Summary You Learned (cont.) Group nesting is the process of placing group accounts in the membership of other group accounts for the purpose of simplifying permission assignments. Multiple users and groups can be created in Active Directory by using several methods. Windows Server 2008 offers the ability to use batch files, CSVDE, LDIFDE, and WSH to accomplish your administrative goals.