CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+

Slides:



Advertisements
Similar presentations
CN2140 Server II (V2) Kemtis Kunanuraksapong MSIS with Distinction MCT, MCITP, MCTS, MCDST, MCP, A+
Advertisements

Active Directory and Group Policy Blackhat Amsterdam Raymond Forbes.
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 6 Managing and Administering DNS in Windows Server 2008.
Lesson 16: Configuring Domain Controllers
Windows Server ® 2008 Active Directory ® Domain Services Infrastructure Planning and Design Series Published: February 2008 Updated: July 2009.
Chapter 6 Introducing Active Directory
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
Administering Active Directory
Hands-On Microsoft Windows Server 2003 Administration Chapter 3 Administering Active Directory.
Hands-On Microsoft Windows Server 2008
Vikram Thakur Introduction to Active Directory Structure.
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 10: Configuring and Maintaining the Active Directory Infrastructure.
Chapter 4: Active Directory Design and Security Concepts
ADVANCED MICROSOFT ACTIVE DIRECTORY CONCEPTS
Module 1: Installing Active Directory Domain Services
(ITI310) SESSIONS : Active Directory By Eng. BASSEM ALSAID.
BZUPAGES.COM An Introduction to. BZUPAGES.COM Introduction Large corporations today face the following problems Finding a certain file. Seeing everything.
11 REVIEWING MICROSOFT ACTIVE DIRECTORY CONCEPTS Chapter 1.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 7: Active Directory Replication.
Windows Server 2008 Chapter 4 Last Update
CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 3: Introducing Active Directory.
CN1176 Computer Support Kemtis Kunanuraksapong MSIS with Distinction MCT, MCTS, MCDST, MCP, A+
CN1276 Server (V3) Kemtis Kunanuraksapong MSIS with Distinction MCT, MCTS, MCDST, MCP, A+
CN1260 Client Operating System Kemtis Kunanuraksapong MSIS with Distinction MCT, MCITP, MCTS, MCDST, MCP, A+
Understand Active Directory Infrastructure
CN2140 Server II Kemtis Kunanuraksapong MSIS with Distinction MCT, MCITP, MCTS, MCDST, MCP, A+
Designing Active Directory for Security
Active Directory Boundaries - Purpose Replication Boundaries Security Boundaries.
CN2140 Server Kemtis Kunanuraksapong MSIS with Distinction MCT, MCITP, MCTS, MCDST, MCP, A+
Active Directory Operations Masters. Overview  Active Directory updates generally multimaster Changes can be made on any DC  Some exceptions — single.
Maintaining Active Directory Domain Services
CN1176 Computer Support Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
Designing Authentication for a Microsoft Windows 2000 Network Designing Authentication in a Microsoft Windows 2000 Network Designing Kerberos Authentication.
Module 7 Active Directory and Account Management.
Session 7 Windows Platform Eng. Dina Alkhoudari. Learning Objectives Active Directory review Managing users and groups Single Master Operations Delegation.
Company Confidential 1 A Course on Global Catalog And Flexible Single Master Operations (Fsmo) Roles Prepared for: *Stars* New Horizons Certified Professional.
Operations Master / FSMO Roles in Active Directory : Suhail Ashfaq Butt.
Global Catalog and Flexible Single Master Operations (FSMO) Roles
Page 1 Active Directory and DNS Lecture 2 Hassan Shuja 09/14/2004.
Module 1: Implementing Active Directory ® Domain Services.
CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
10.1 © 2004 Pearson Education, Inc. Exam Designing a Microsoft ® Windows ® Server 2003 Active Directory and Network Infrastructure Lesson 10: Planning.
Hands-On Microsoft Windows Server 2008 Chapter 4-Part 1 Introduction to Active Directory and Account Manager.
1 Chapter Overview Managing Object and Container Permissions Locating and Moving Active Directory Objects Delegating Control Troubleshooting Active Directory.
Chapter 4- Part3. 2 Implementing User Profiles A local user profile is automatically created at the local computer when you log on with an account for.
Installing a Domain Controller
OVERVIEW OF ACTIVE DIRECTORY
Module 12: Managing Operations Masters
Introduction to Active Directory
© Wiley Inc All Rights Reserved. MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition.
© Compiled by David Brewster Networking Diploma – Orange Group S Class Presentation: Operations Master Roles.
Global Catalog and Flexible Single Master Operations (FSMO) Roles BAI516.
11 GLOBAL CATALOG AND FLEXIBLE SINGLE MASTER OPERATIONS (FSMO) ROLES Chapter 4.
CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition (70-294) Chapter 1: Overview of the Active.
Module 9: Managing Operations Masters. Overview Introduction to Operations Master Roles Transferring and Seizing Operations Master Roles Planning the.
Active Directories: Purpose and Structure Chrystom Ciganko IFMG352 Final Presentation.
Active Directory Replication (Part 1) Paige Verwolf Support Professional Microsoft Corporation © 1999 Microsoft Corporation. All rights reserved.
Global Catalog and Flexible Single Master Operations (FSMO) Roles
Active Directory Fundamentals
Active Directory and Group Policy
(ITI310) SESSIONS 6-7-8: Active Directory.
Global Catalog and Flexible Single Master Operations (FSMO) Roles
Microsoft Windows Server 2003 Active Directory Infrastructure
FSMO Roles and Global Catalog Servers
Unit 5 NT1330 Client-Server Networking II Date: 7/12/2016
Global Catalog and Flexible Single Master Operations (FSMO) Roles
Presentation transcript:

CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+

Agenda Chapter 4: Global Catalog and Flexible Single Master Operations (FSMO) Roles Quiz Exercise

Global Catalog (GC) Four main functions: ▫Facilitating searches for objects in the forest ▫Resolving User Principal Names (UPNs) ▫Maintaining universal group membership information ▫Maintaining a copy of all objects in the domain

Global Catalog (Cont.) Universal group membership caching ▫Store universal group memberships on a local DC In Win 2k3 and 2k8, A user must have successfully logged on when a GC server was available and universal group membership caching was enabled Enabled on a per-site basis. By default, cache is refreshed every eight hours.

Additional GC servers Each site should contain a GC server to facilitate user logons When placing a GC at a remote site, you should consider the amount of bandwidth needed

Flexible Single Master Operations (FSMO) Roles Provides a critical task such as schema update to be assigned by a single DC in each domain or in a forest Five roles: ▫Domain specific (one per domain)  Relative Identifier Master  Infrastructure Master  Primary Domain Controller (PDC) Emulator ▫Forest-wide authoriy  Domain Naming Master  Schema Master

Relative Identifier (RID) Master Responsible for assigning relative identifiers to domain controllers in the domain Relative identifiers are assigned by a domain controller when a new object is created If RID Master is unavailable ▫unable to create new objects ▫Unable to move objects between domains

Infrastructure Master Responsible for reference updates from its domain objects to other domains ▫Assists in tracking which domains own which objects

Primary Domain Controller (PDC) Emulator Provides backward compatibility Manages time synchronization for the domain Manages password changes and account lockouts ▫it provides immediate replication to other domain controllers in the domain. Managing edits to Group Policy Objects (GPOs)

Domain Naming Master Has the authority to manage the creation and deletion of domains, domain trees, and application data partitions in the forest. ▫When any of these is created, the Domain Naming Master ensures that the name assigned is unique to the forest.

Schema Master Responsible for managing changes to the Active Directory schema.

Placing FSMO Role Holders When you install the first domain controller in a new forest, that domain controller holds all five of FSMO Roles ▫Number of domains that are or will be part of the forest ▫The physical structure of the network ▫The number of DCs in each domain

Managing FSMO Roles Role transfer ▫Used to move a FSMO role gracefully from one domain controller to another Role seizure ▫Used only when you have experienced a failure of a domain controller that holds a FSMO role and you forced an ungraceful transfer ▫After the seize, the original holder must be removed from AD before being returned to the network See Table 4-3 on Page 91

Viewing or transferring Domain-Wide FSMO Role Holders Open the AD Users and Computers Right-click the AD Users and Computers node - > All Tasks -> Operations Masters

Viewing or Transferring the Domain Naming Master FSMO Role Holder In AD Domains and Trusts Right-click the AD Domains and Trusts -> Change Operations Master

Viewing or Transferring the Schema Master FSMO Role Holder Open the AD Schema Right-click AD Schema -> Change Operations Master You need to register the schmmgmt.dll DLL file using the following syntax: regsvr32 schmmgmt.dll

Seizing a FSMO Role Use the ntdsutil command to access the fmso maintenance prompt and use the seize command. ▫*See full step on Page 96 or Lab 4

Assignment Fill in the blank ▫1-10 Multiple Choice ▫1-10 Online Lab 4