CHAPTER Creating and Managing Users and Groups. Chapter Objectives Explain the use of Local Users and Groups Tool in the Systems Tools Option to create.

Slides:



Advertisements
Similar presentations
Chapter Five Users, Groups, Profiles, and Policies.
Advertisements

CREATING USER ACCOUNTS Group accounts simplify administration by organizing user accounts into a single administrative unit. They provide a convenient.
1 Module 3 Setting Up User Accounts. 2  Overview Introduction to User Accounts Planning New User Accounts Creating User Accounts Deleting and Renaming.
Module 6: Configuring Windows XP Professional to Operate in a Microsoft Network.
Managing User Settings with Group Policy
Chapter 9 Chapter 9: Managing Groups, Folders, Files, and Object Security.
Chapter 8 Chapter 8: Managing Accounts and Client Connectivity.
Fundamentals of Soft Resource Sharing By Nanda Ganesan, Ph.D. © Nanda Ganesan.
1 Configuring Web services (Week 15, Monday 4/17/2006) © Abdou Illia, Spring 2006.
CHAPTER Hard Resource (Printer) Sharing. Chapter Objectives Explain the concept of sharing a hard resource Present the step-by-step process of placing.
11 SUPPORTING LOCAL USERS AND GROUPS Chapter 3. Chapter 3: Supporting Local Users and Groups2 SUPPORTING LOCAL USERS AND GROUPS  Explain the difference.
Lesson 19 – ADMINISTERING WINDOWS 2000 SERVER : THE BASICS.
Chapter 6: Configuring Security. Group Policy and LGPO Setting Options Software Installation not available with LGPOs Remote Installation Services Scripts.
Chapter 5: Configuring Users and Groups. Windows Vista User Accounts User accounts are the primary means of authentication Built-in Accounts –Administrator:
Chapter 8 Chapter 8: Managing the Server Through Accounts and Groups.
Chapter 3 – Creating and Managing User Accounts MIS 431 – Created Spring 2006.
SETUP AND CONFIGURATIONS WEBLOGIC SERVER. 1.Weblogic Installation 2.Creating domain through configuration wizard 3.Creating domain using existing template.
1 Chapter Overview Creating User and Computer Objects Maintaining User Accounts Creating User Profiles.
Creating and Managing User Accounts. Overview Introduction to User Accounts Guidelines for New User Accounts Creating Local User Accounts Creating and.
11 WORKING WITH USER ACCOUNTS Chapter 6. Chapter 6: WORKING WITH USER ACCOUNTS2 CHAPTER OVERVIEW Understand the differences between local user and domain.
Module 2: Managing User and Computer Accounts
Module 2 Creating Active Directory ® Domain Services User and Computer Objects.
70-270: MCSE Guide to Microsoft Windows XP Professional Chapter 5: Users, Groups, Profiles, and Policies.
Using Group Policy to Manage User Environments. Overview Introduction to Managing User Environments Introduction to Administrative Templates Assigning.
September 18, 2002 Introduction to Windows 2000 Server Components Ryan Larson David Greer.
Database Security and Auditing: Protecting Data Integrity and Accessibility Chapter 3 Administration of Users.
1 Guide to Novell NetWare 6.0 Network Administration Chapter 12.
1 User Account Administration Introduction to User Accounts Planning New User Accounts Creating User Accounts Creating User Profiles Creating Home Directories.
Guide to Operating System Security Chapter 4 Account-based Security.
Managing User Accounts, Passwords and Logon Chapter 5 powered by dj.
6.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 6: Administering User Accounts.
User Manager for Domains.  Manages the user accounts in a domain  It is located in the PDC  While User Manager exists in each NT machine, but it is.
IOS110 Introduction to Operating Systems using Windows Session 7 1.
5.1 © 2004 Pearson Education, Inc. Lesson 5: Administering User Accounts Exam Microsoft® Windows® 2000 Directory Services Infrastructure Goals 
Windows Server 2003 Overview 1 Windows 2003 Server Overview Ayaz
Section 1: Introducing Group Policy What Is Group Policy? Group Policy Scenarios New Group Policy Features Introduced with Windows Server 2008 and Windows.
11 MANAGING AND DISTRIBUTING SOFTWARE BY USING GROUP POLICY Chapter 5.
11 WORKING WITH USER ACCOUNTS Chapter 6. Chapter 6: WORKING WITH USER ACCOUNTS2 UNDERSTANDING USER ACCOUNTS  Local user accounts  stored in the Security.
DIT314 ~ Client Operating System & Administration CHAPTER 5 MANAGING USER ACCOUNTS AND GROUPS Prepared By : Suraya Alias.
1 Chapter Overview Configuring Account Policies Configuring User Rights Configuring Security Options Configuring Internet Options.
8.1 © 2004 Pearson Education, Inc. Exam Designing a Microsoft ® Windows ® Server 2003 Active Directory and Network Infrastructure Lesson 8: Planning.
Chapter 13 Users, Groups Profiles and Policies. Learning Objectives Understand Windows XP Professional user accounts Understand the different types of.
September 18, 2002 Windows 2000 Server Active Directory By Jerry Haggard.
Overview Introduction to Managing User Environments Introduction to Administrative Templates Using Administrative Templates in Group Policy Assigning Scripts.
Module 2: Managing User and Computer Accounts. Overview Creating User Accounts Creating Computer Accounts Modifying User and Computer Account Properties.
Introduction to Microsoft Management Console (MMC) MMC is a common console framework for management applications. MMC provides a common environment for.
Module 6: Configuring User Environments Using Group Policy.
1 Chapter Overview Understanding User Accounts Planning New User Accounts Creating, Modifying, and Deleting User Accounts Setting Properties for User Accounts.
NT4 SP4 Security Jack Schmidt - Fermilab
Guide to MCSE , Second Edition, Enhanced1 The Windows XP Security Model User must logon with: Valid user ID Password User receives access token Access.
Chapter 10: Rights, User, and Group Administration.
Security Planning and Administrative Delegation Lesson 6.
Page 1 User Accounts Lecture 3 Hassan Shuja 09/21/2004.
Module 4 Planning for Group Policy. Module Overview Planning Group Policy Application Planning Group Policy Processing Planning the Management of Group.
Managing Local Users & Groups. OVERVIEW Configure and manage user accounts Manage user account properties Manage user and group rights Configure user.
Fall 2011 Nassau Community College ITE153 – Operating Systems Session 21 Administering User Accounts and Groups 1.
NetTech Solutions Security and Security Permissions Lesson Nine.
Module 10: Implementing Administrative Templates and Audit Policy.
CHAPTER 5 MANAGING USER ACCOUNTS & GROUPS. User Accounts Windows 95, 98 & Me do not need a user account like Windows XP Professional to access computer.
Chapter 7 Server Management Policies –User accounts –Groups Rights and permissions Examples.
CHAPTER Windows Server Management. Chapter Objectives Give an overview of the Server Manager Provide details of accessing the Server Manager Explain the.
Overview Microsoft Windows XP Pro (SP2) Microsoft Windows Server 2003 User accounts and groups File sharing and file permissions Password/Lockout Policy.
Chapter 17 Windows NT/2000 Domains Cisco Learning Institute Network+ Fundamentals and Certification Copyright ©2005 by Pearson Education, Inc. Upper Saddle.
Configuring the User and Computer Environment Using Group Policy Lesson 8.
19 Copyright © 2008, Oracle. All rights reserved. Security.
Managing User Desktops with Group Policy
Guide to Operating Systems, 5th Edition
Creating and Managing User Accounts
Chapter 8: Managing Accounts and Client Connectivity
Setting up home folders and roaming profiles
Presentation transcript:

CHAPTER Creating and Managing Users and Groups

Chapter Objectives Explain the use of Local Users and Groups Tool in the Systems Tools Option to create and manage user accounts Describe the various account related properties of a user Present different options that are available to define a user’s network environment

Chapter Modules User Manager in Windows NT Adding a User Setting Additional User Account Properties Adding Multiple Users Account Policy User Environment: Home Directory User Environment: User Profiles User Environment: Logon Scripts User Rights

Generic Networking Model Hardware Installation Network OS Installation User Configuration

© N. Ganesan, All rights reserved. MODULE User Manager of Windows NT

Module Objectives Authorized user managers The user manager module Ways of launching the user manager –From start, through shortcut and by running usrmgr Case study domain details Case study users in the domain

Who Can Create User Accounts? Administrators Domain Administrators Account Operators

User Manager The GUI module that enables user management Activation –Through the start menu –Through command level activation by running the command usrmgr –From an already created short-cut

Creating a Short Cut: The Steps Explorer C:\Winnt\Profiles\All Users\ Start Menu\Programs\ Administrative Tools\ User Manager for Domains Create Shortcut Drag and place on the desktop screen. Right Click

Creating a Shortcut to User Manager: Demonstration

Activating the User Manager: Demonstration From StartShortcut Running usrmgr

Domain Details US CanadaMexico NAFTA

Users in the Domain AdministratorCalifornia TexasNevada

END OF MODULE

© N. Ganesan, All rights reserved. MODULE Adding a User

Module Objectives The steps for adding a user Password options Demonstration of adding a user Further notes on the user

Adding a User: Steps User Manager User New User Username Full Name DescriptionPassword

Password Options User must change PW. User cannot change PW. PW never expires. Password Options Add User

Adding Users: Demonstration Adding the user California.

Notes on the User A user created becomes a member of the built-in User group Additional user account properties can be set: –at the time of creation of the account –later through the User Properties feature

END OF MODULE

© N. Ganesan, All rights reserved. MODULE Setting Additional User Account Properties

Module Objectives Reaching user properties menu User optional properties Assignment to groups Profile Hours restriction Workstation access restriction Account properties Dial-in properties Demonstration of properties configuration

Reaching User Properties Menu The menu can be reached through the User Manager for Domain Window –Select user and double-click –Select user and select Properties from the User Option from the top

User Optional Properties Groups Hours Profile Logon To Dialin Account

Groups Enables the user to be assigned to a group –The user acquires the group privileges Enable a user to be removed from a group

Groups Demonstration Administrator Server Operator User Etc. California Default To be assigned

Profile User Profile Path Logon Script Name Local Path to Home Directory User environment profile is discussed later

Hours Restricting the user to a fixed time period for using the network For demonstration: –User California is restricted to logon to the network from 8:00 a.m. to 6:00 p.m., Monday to Friday

Logon To Restricting the user to a predefined number of workstations on the network –The network can be accessed only from these workstations

Demonstration of Logon To US CanadaMexico Others California

Account Account time limit –Never expires or –Specify expiry date Account type –Global for possible entry into other domains –Local for restricting to local resources For demonstration: –User California’s account will never expire

Dial-in Allows the user dial-in access to the network Provides callback for security verification For the purpose of demonstration: –User California will be given dial-in access privileges –Callback security will not be imposed

Dial-in Setup US CanadaMexico Modem California Dial-in with no callback security.

Additional Properties: Demonstration GroupsHoursLogon To AccountDial-in

END OF MODULE

© N. Ganesan, All rights reserved. MODULE Adding Multiple Users

Module Objectives Copying user account details –Overview, case example and demonstration Changing the account properties of multiple users Operation on multiple users

Copying User Account Details Can be copied from an existing user while creating a new user Properties can then be modified to customize the new user properties

Copying User Account Details: Case Example Copy account details to new user Nevada from California Modify Nevada, if required.

Copying User Account Details: Demonstration

Changing the Account Properties of Multiple Users Multiple users can be chosen for account property modification Example: –Enforcing the same logon time restriction on a group of users

Operation on Multiple Users: Case Example TexasNevada Administrator Addition to administrator group and then deletion from administrator group.

END OF MODULE

© N. Ganesan, All rights reserved. MODULE Account Policy

Module Objectives Account policy for all users in the domain Password protection Account lockout protection Other protection Account policy setting demonstration

User Account Policy for All Users in the Domain Major components –Password related –Account lockout related Password –Security against password guessing Account lockout –Thwart unauthorized attempt to access the network

Password Protection Maximum PW age.Minimum PW age. Maximum PW length. PW uniqueness.

Account Lockout Protection Lockout after ___ bad logon attempts Reset counter after ______ minutes. Lockout duration: Forever or in minutes.

Other Protection Disconnect remote users after logon time expires. Require users to logon to change password.

Account Policy Setting Demonstration

END OF MODULE

© N. Ganesan, All rights reserved. MODULE User Environment: Home Directory

Module Objectives User environment Overview of a home directory Creating a home directory: Case example The steps for creating a home directory Demonstration of home directory creation Linking the user to the home directory

User Environment Home Directory User Profile Login Script

Home Directory Often provided for each user The user often has exclusive right to the files in this directory

Creating a Home Directory: Case Example US CanadaMexico California \\US\Users\California Drive H:

Creating a Home Directory: Steps Create \\US\Users\California Set California for sharing. User Manager/User Environment Profile Select Connect To Drive Letter Path to the Home Directory. Specify

Home Directory Creation: The Two-Step Process Create a home directory on the server, through administrative share, if creating from a workstation. Assign the drive letter H for the user to connect to the home directory.

Creating a Home Directory on the Server: Demonstration

Linking the User to the Home Directory: Demonstration

END OF MODULE

© N. Ganesan, All rights reserved. MODULE User Environment: User Profiles

Module Objectives User profiles defined Types of user profiles Local profiles Network profiles Types of network profiles

User Profiles Defined Defines the network environment for the user A powerful means of customizing a user’s access to the network –Program groups –Network drives –Access to multi-user applications etc.

Types of User Profiles Profiles Local Profiles Roaming (Network) Profiles Personal User Profiles Mandatory User Profiles

Local Profiles Stored locally on the workstation Applies locally to the workstation for a user

Network Profiles Applies to a user irrespective of the workstation on which the user enters (Logon) the network Also know as the roaming profile

Types of Network Profiles Personal user profiles –Created and managed by the user Mandatory user profiles –Created and managed by the network administrator –Permitted changes made by the user are lost at the end of the network session

END OF MODULE

© N. Ganesan, All rights reserved. MODULE User Environment: Logon Scripts

Module Objectives Definition of logon script Usage

Logon Script Defined Executed during logon Sets network environmental variables for a user –Mapping a directory etc.

Usage Better suited for other network environments For NT profiles are preferred that would achieve the same effect with less programming

END OF MODULE

© N. Ganesan, All rights reserved. MODULE User Rights

Module Objectives Overview of user rights General procedure for specifying user rights Sample rights of built-in accounts

User Rights Can be defined independently In general: –Users are assigned to groups with predefined user rights Groups can be built-in groups or created groups

Specifying a User Right: The General Procedure Assign the user to a built-in group Customize, if required, to suit the application requirements of the user –Security concerns must also be enforced

Sample Rights of Built-in Accounts Add workstation to domain –Administrators and Account Operators Assign user rights –Administrators Allow and disallow sharing of directories –Administrators, Server Operators, Power Users Allow and disallow sharing of printers –Administrators, Server Operators, Print Operators and Power Users

END OF MODULE END OF CHAPTER