Page 1 Active Directory and DNS Lecture 2 Hassan Shuja 09/14/2004.

Slides:



Advertisements
Similar presentations
COMP091 OS1 Active Directory. Some History Early 1990s Windows for Workgroups introduced peer-to-peer networking based on SMB over netbios (tcp/ip still.
Advertisements

Active Directory: Final Solution to Enterprise System Integration
Chapter 6 Introducing Active Directory
Chapter 4 Chapter 4: Planning the Active Directory and Security.
1 Active Directory (Week 8, Monday 2/26/2007) © Abdou Illia, Spring 2007.
Introduction to Active Directory
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
CS603 Active Directory February 1, 2001.
1.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
Hands-On Microsoft Windows Server 2003 Administration Chapter 1 Windows Server 2003 Network Administration.
Chapter 4 Introduction to Active Directory and Account Management
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
Understanding Active Directory
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
Module 1: Introduction to Active Directory
1 CSIT 320. Just as the combination of a database and a database management system collects and organizes information about an institution/company/… as.
Hands-On Microsoft Windows Server 2008
Hands-On Microsoft Windows Server 2008
Vikram Thakur Introduction to Active Directory Structure.
ADVANCED MICROSOFT ACTIVE DIRECTORY CONCEPTS
Introduction to Active Directory Services Completely integrated with Microsoft Windows 2000 Server Integrates the Internet concept of namespace with the.
Overview of Active Directory Domain Services Lesson 1.
Nassau Community College
(ITI310) SESSIONS : Active Directory By Eng. BASSEM ALSAID.
Directory services Unit objectives
11 REVIEWING MICROSOFT ACTIVE DIRECTORY CONCEPTS Chapter 1.
Chapter 4 Introduction to Active Directory and Account Management
Session 6 Windows Platform Dina Alkhoudari. Learning Objectives What is Active Directory Logical components of active directory Physical components of.
Windows Server 2008 Chapter 4 Last Update
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 3: Introducing Active Directory.
Working with domains and Active Directory
Chapter 6: Windows Servers
KAPLAN SCHOOL OF INFORMATION SYSTEMS AND TECHNOLOGY Welcome to Unit 4 IT278 Network Administration Course Name – IT278 Network Administration Instructor.
SERVER I SLIDE: 6. SERVER I Topics: Objective 4.3: Deploy and configure the DNS service Objective 5.1: Install domain controllers.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
1 Chapter Summary Understanding DNS Understanding Name Resolution Configuring a DNS Client Understanding Active Directory Understanding Active Directory.
Module 7 Active Directory and Account Management.
Session 7 Windows Platform Eng. Dina Alkhoudari. Learning Objectives Active Directory review Managing users and groups Single Master Operations Delegation.
Company Confidential 1 A Course on Global Catalog And Flexible Single Master Operations (Fsmo) Roles Prepared for: *Stars* New Horizons Certified Professional.
Active Directory Maryam Izadi. Topics Covered NT Vs 2000/2003 Active Directory LDAP MMC.
 Identify Active Directory functions and Benefits.  Identify the major components that make up an Active Directory structure.  Identify how DNS relates.
Hands-On Microsoft Windows Server 2008 Chapter 4-Part 1 Introduction to Active Directory and Account Manager.
1 Chapter Overview Managing Object and Container Permissions Locating and Moving Active Directory Objects Delegating Control Troubleshooting Active Directory.
Active Directory Infrastructure Microsoft Windows 2003 Active Directory Infrastructure MCSE Exam
OVERVIEW OF ACTIVE DIRECTORY
Introduction to Active Directory
© Wiley Inc All Rights Reserved. MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition.
Module 1: Introduction to Active Directory
Logical and Physical Network Design 1. Active Directory Objects Objects Represent Network Resources (Users,Groups,Computers,Printers) Attributes Store.
Hussain Ali Department of Computer Engineering KFUPM, Dhahran, Saudi Arabia Active Directory.
11 GLOBAL CATALOG AND FLEXIBLE SINGLE MASTER OPERATIONS (FSMO) ROLES Chapter 4.
CEG 2400 Fall 2012 Directory Services Active Directory Tree Domain.
Windows 2003 Architecture, Active Directory & DNS Lecture # 3 Hassan Shuja 02/14/2006.
1 Introduction to Active Directory Directory Services Uniquely identify users and resources on a network Provide a single point of network management.
MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition (70-294) Chapter 1: Overview of the Active.
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
Overview of Active Directory Domain Services Lesson 1.
Essential Services Lesson 5. Objectives Naming Resolution In today’s networks, you assign logical addresses, such as with IP addressing. Unfortunately,
Active Directory Replication (Part 1) Paige Verwolf Support Professional Microsoft Corporation © 1999 Microsoft Corporation. All rights reserved.
Global Catalog and Flexible Single Master Operations (FSMO) Roles
Overview of Active Directory Domain Services
Active Directory Administration
(ITI310) SESSIONS 6-7-8: Active Directory.
Objectives Differentiate between the different editions of Windows Server 2003 Explain Windows Server 2003 network models and server roles Identify concepts.
Chapter 4: Planning the Active Directory and Security
Active Directory (November 7, 2016) © Abdou Illia, Fall 2016.
Introduction to Active Directory Directory Services
Presentation transcript:

Page 1 Active Directory and DNS Lecture 2 Hassan Shuja 09/14/2004

Page 2 Active Directory (AD) Active Directory Definitions/Features – Active Directory has two parts – A database with information about users and resources – A service that manages the database and enables users of computers on the network to access the database – Active Directory Features/Advantages – Security - Logon process and controlling access to objects – Administration – Hierarchical structure – Search capabilities – Search AD for an object – Scalable – Allows multiple domains, fits for any size network – Flexibility – Grows with your company, allows for additions

Page 3 Active Directory Structure – Objects and Classes – An object is the smallest component that you can have in AD – A class is a template of all attributes of an object when it is created – Schema – Schema governs the structure of the directory – Allows administrators to modify and add new object classes, objects and attributes as needed, making the schema extensible – Active Directory Schema is the name of the snap-in in MMC and can only be changed by Schema Admins – Global Catalog – A master searchable index that contains information about every object in a forest – Created by default on first DC in a domain – Contains a full copy of all objects in its own domain and a partial replica of all objects in all other domains in the forest – Serves as a central point for user authentication

Page 4 Active Directory AD Organization – Smallest component in AD is an object – Objects have attributes and are defined by classes – Objects have permissions ACL that contains information about who has access to it and what they can do with it – Controlling access to object is different than having access to the objects resources – Organizational Units (Container objects) – Substructure of domains and are arranged hierarchically – Used to organize related objects in AD, can also contain other OUs – Helps simplify administration

Page 5 Active Directory Object IDs – Globally Unique Identifier (GUID) – A 32 hex number assigned to an object at the time of creation and object is stored with it. This ensures uniqueness and avoids duplication – Security ID (SID) – A unique security ID created by the Security subsystem that is assigned to user, groups, and computers to grant or deny an object access to other objects

Page 6 Domain Controller (DC) DC Setup – All Domain Controllers are equal – A change on one DC will be replicated to all other DCs – Five Scenarios where a DC can have an additional role – Relative ID Master – Schema Master – Infrastructure Master – Domain Naming Master – PDC Emulator

Page 7 Domains AD Organization – Tree – Grouping of one or more domains that must have a single root domain – Parent child & child relationships – Defined by a common and contiguous name space – A hierarchy of domains sharing a common schema, security trust relationship, and a Global Catalog

Page 8 Domains AD Organization – Forest – A group of one or more Domain Trees linked together by a trust – Two different root domains – All Trees share a common schema and global catalog – Do not have contiguous DNS domain names

Page 9 Trusts NT Domains – Each domain had its own accounts – Need accounts in every domain that you need resources or need administrator to setup a trust between domains – Trust were setup explicitly as one-way or two-way trusts – These trusts are intransitive

Page 10 Trusts Trusts – A logical connection that allows users from one domain to access resources in another domain – Can be one way or two ways – Trusting domain and Trusted domain

Page 11 Trusts Intransitive Trusts – Domain C trusts Domain B and Domain B trusts Domain A – (B has access to resources in C and A has access to resources in B) – Domain C does not trust Domain A – Intransitive trusts are possible in Windows NT

Page 12 Trusts Transitive Trusts – A trust between two domains in the same Tree/Forest that can extend beyond two domains to other trusted domains within the same Tree/Forest – Always a 2 way trust – By default all Windows 2000 trusts within Tree/Forest are transitive – Domain A and C trust each other

Page 13 Trusts Explicit Trusts – A trust that is setup by an administrator – Connect domains directly to shorten the path between them – It can be either transitive or intransitive – Used to manage trusts between Windows 2000 and NT domains

Page 14 Domain Name System (DNS) DNS – DNS Structure – Based on a hierarchical naming structure (inverted tree) – A single root domain, underneath there are second-level domains – Every computer in a DNS domain is uniquely identified by a Fully Qualified Domain Name (FQDN) – Dynamic DNS is supported in W2K

Page 15 Domain Name System Zone Files and DNS Servers – Forward Lookup Zone – This contains host name to IP address resolution – Reverse Lookup Zone – This contains IP address to host name resolution – DNS Servers – Primary – Maintains the master copy of the zone files – Secondary – Keeps a back-up copy of the zone files – AD-integrated – DNS entries kept in AD data store instead of zone files – Scavenge Files – Finds and deletes records in a zone if they have been stale for a certain amount of time

Page 16 Active Directory & Domain Name System AD & DNS – Active Directory and DNS use the same hierarchical structure – Typically use the same FQDN – DNS records can be stored in Active Directory – Clients use DNS to locate Domain Controllers on the network

Page 17 Domain Name System Name Space – Active Directory is based on the concept of namespace, that is a name is used to resolve the location of an object – Active Directory names correspond to DNS domain names – Each name gives the location of the object in Active Directory

Page 18 Domain Name System Name Convention – Relative Distinguished Name (RDN) – A name that is assigned to the object by the administrator when it is created, a unique name – Example – hshuja1 – Distinguished Name (DN) – Defines the RDN and also location within Active Directory, such as OU that user belongs to – Example – – User Principal Name (UPN) – A more “easier” naming convention. Combines RDN with domain name, no OU is referenced – Example –