CHAPTER Creating and Managing Users and Groups
Chapter Objectives Explain the use of Local Users and Groups Tool in the Systems Tools Option to create and manage user accounts Describe the various account related properties of a user Present different options that are available to define a user’s network environment
Chapter Modules User Manager in Windows NT Adding a User Setting Additional User Account Properties Adding Multiple Users Account Policy User Environment: Home Directory User Environment: User Profiles User Environment: Logon Scripts User Rights
Generic Networking Model Hardware Installation Network OS Installation User Configuration
© N. Ganesan, All rights reserved. MODULE User Manager of Windows NT
Module Objectives Authorized user managers The user manager module Ways of launching the user manager –From start, through shortcut and by running usrmgr Case study domain details Case study users in the domain
Who Can Create User Accounts? Administrators Domain Administrators Account Operators
User Manager The GUI module that enables user management Activation –Through the start menu –Through command level activation by running the command usrmgr –From an already created short-cut
Creating a Short Cut: The Steps Explorer C:\Winnt\Profiles\All Users\ Start Menu\Programs\ Administrative Tools\ User Manager for Domains Create Shortcut Drag and place on the desktop screen. Right Click
Creating a Shortcut to User Manager: Demonstration
Activating the User Manager: Demonstration From StartShortcut Running usrmgr
Domain Details US CanadaMexico NAFTA
Users in the Domain AdministratorCalifornia TexasNevada
END OF MODULE
© N. Ganesan, All rights reserved. MODULE Adding a User
Module Objectives The steps for adding a user Password options Demonstration of adding a user Further notes on the user
Adding a User: Steps User Manager User New User Username Full Name DescriptionPassword
Password Options User must change PW. User cannot change PW. PW never expires. Password Options Add User
Adding Users: Demonstration Adding the user California.
Notes on the User A user created becomes a member of the built-in User group Additional user account properties can be set: –at the time of creation of the account –later through the User Properties feature
END OF MODULE
© N. Ganesan, All rights reserved. MODULE Setting Additional User Account Properties
Module Objectives Reaching user properties menu User optional properties Assignment to groups Profile Hours restriction Workstation access restriction Account properties Dial-in properties Demonstration of properties configuration
Reaching User Properties Menu The menu can be reached through the User Manager for Domain Window –Select user and double-click –Select user and select Properties from the User Option from the top
User Optional Properties Groups Hours Profile Logon To Dialin Account
Groups Enables the user to be assigned to a group –The user acquires the group privileges Enable a user to be removed from a group
Groups Demonstration Administrator Server Operator User Etc. California Default To be assigned
Profile User Profile Path Logon Script Name Local Path to Home Directory User environment profile is discussed later
Hours Restricting the user to a fixed time period for using the network For demonstration: –User California is restricted to logon to the network from 8:00 a.m. to 6:00 p.m., Monday to Friday
Logon To Restricting the user to a predefined number of workstations on the network –The network can be accessed only from these workstations
Demonstration of Logon To US CanadaMexico Others California
Account Account time limit –Never expires or –Specify expiry date Account type –Global for possible entry into other domains –Local for restricting to local resources For demonstration: –User California’s account will never expire
Dial-in Allows the user dial-in access to the network Provides callback for security verification For the purpose of demonstration: –User California will be given dial-in access privileges –Callback security will not be imposed
Dial-in Setup US CanadaMexico Modem California Dial-in with no callback security.
Additional Properties: Demonstration GroupsHoursLogon To AccountDial-in
END OF MODULE
© N. Ganesan, All rights reserved. MODULE Adding Multiple Users
Module Objectives Copying user account details –Overview, case example and demonstration Changing the account properties of multiple users Operation on multiple users
Copying User Account Details Can be copied from an existing user while creating a new user Properties can then be modified to customize the new user properties
Copying User Account Details: Case Example Copy account details to new user Nevada from California Modify Nevada, if required.
Copying User Account Details: Demonstration
Changing the Account Properties of Multiple Users Multiple users can be chosen for account property modification Example: –Enforcing the same logon time restriction on a group of users
Operation on Multiple Users: Case Example TexasNevada Administrator Addition to administrator group and then deletion from administrator group.
END OF MODULE
© N. Ganesan, All rights reserved. MODULE Account Policy
Module Objectives Account policy for all users in the domain Password protection Account lockout protection Other protection Account policy setting demonstration
User Account Policy for All Users in the Domain Major components –Password related –Account lockout related Password –Security against password guessing Account lockout –Thwart unauthorized attempt to access the network
Password Protection Maximum PW age.Minimum PW age. Maximum PW length. PW uniqueness.
Account Lockout Protection Lockout after ___ bad logon attempts Reset counter after ______ minutes. Lockout duration: Forever or in minutes.
Other Protection Disconnect remote users after logon time expires. Require users to logon to change password.
Account Policy Setting Demonstration
END OF MODULE
© N. Ganesan, All rights reserved. MODULE User Environment: Home Directory
Module Objectives User environment Overview of a home directory Creating a home directory: Case example The steps for creating a home directory Demonstration of home directory creation Linking the user to the home directory
User Environment Home Directory User Profile Login Script
Home Directory Often provided for each user The user often has exclusive right to the files in this directory
Creating a Home Directory: Case Example US CanadaMexico California \\US\Users\California Drive H:
Creating a Home Directory: Steps Create \\US\Users\California Set California for sharing. User Manager/User Environment Profile Select Connect To Drive Letter Path to the Home Directory. Specify
Home Directory Creation: The Two-Step Process Create a home directory on the server, through administrative share, if creating from a workstation. Assign the drive letter H for the user to connect to the home directory.
Creating a Home Directory on the Server: Demonstration
Linking the User to the Home Directory: Demonstration
END OF MODULE
© N. Ganesan, All rights reserved. MODULE User Environment: User Profiles
Module Objectives User profiles defined Types of user profiles Local profiles Network profiles Types of network profiles
User Profiles Defined Defines the network environment for the user A powerful means of customizing a user’s access to the network –Program groups –Network drives –Access to multi-user applications etc.
Types of User Profiles Profiles Local Profiles Roaming (Network) Profiles Personal User Profiles Mandatory User Profiles
Local Profiles Stored locally on the workstation Applies locally to the workstation for a user
Network Profiles Applies to a user irrespective of the workstation on which the user enters (Logon) the network Also know as the roaming profile
Types of Network Profiles Personal user profiles –Created and managed by the user Mandatory user profiles –Created and managed by the network administrator –Permitted changes made by the user are lost at the end of the network session
END OF MODULE
© N. Ganesan, All rights reserved. MODULE User Environment: Logon Scripts
Module Objectives Definition of logon script Usage
Logon Script Defined Executed during logon Sets network environmental variables for a user –Mapping a directory etc.
Usage Better suited for other network environments For NT profiles are preferred that would achieve the same effect with less programming
END OF MODULE
© N. Ganesan, All rights reserved. MODULE User Rights
Module Objectives Overview of user rights General procedure for specifying user rights Sample rights of built-in accounts
User Rights Can be defined independently In general: –Users are assigned to groups with predefined user rights Groups can be built-in groups or created groups
Specifying a User Right: The General Procedure Assign the user to a built-in group Customize, if required, to suit the application requirements of the user –Security concerns must also be enforced
Sample Rights of Built-in Accounts Add workstation to domain –Administrators and Account Operators Assign user rights –Administrators Allow and disallow sharing of directories –Administrators, Server Operators, Power Users Allow and disallow sharing of printers –Administrators, Server Operators, Print Operators and Power Users
END OF MODULE END OF CHAPTER