Security Planning and Administrative Delegation Lesson 6.

Slides:



Advertisements
Similar presentations
By Rashid Khan Lesson 5-Directory Assistance: Administration Using Active Directory Users and Computers.
Advertisements

Module 6: Configuring Windows XP Professional to Operate in a Microsoft Network.
XP Tutorial 4 New Perspectives on Microsoft Windows XP 1 Microsoft Windows XP Personalizing Your Windows Environment Tutorial 4.
16.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.
Chapter 9 Chapter 9: Managing Groups, Folders, Files, and Object Security.
Chapter 11 Exploring Windows XP Vol. 1 Part One - Windows XP Professional: The Basics.
11.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
10.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
Hands-On Microsoft Windows Server 2003 Administration Chapter 5 Administering File Resources.
Lesson 19 – ADMINISTERING WINDOWS 2000 SERVER : THE BASICS.
Hands-On Microsoft Windows Server 2003 Administration Chapter 3 Administering Active Directory.
WINDOWS XP BACKNEXTEND 1-1 LINKS TO OBJECTIVES Starting Windows Using the Taskbar, opening & switching programs Using the Taskbar, opening & switching.
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
Performing Software Installation with Group Policy
Ch 9 Managing Active Directory User Accounts. Objectives Create Organizational Unit Creating User Accounts in Active Directory Disabling, Enabling, and.
Installing a New Windows Server 2008 Domain Controller in a New Windows Server 2008 R2.
1 Chapter Overview Creating User and Computer Objects Maintaining User Accounts Creating User Profiles.
Copyright 2007, EMC Paradigm Publishing Inc. WINDOWS XP BACKNEXTEND 1-1 LINKS TO OBJECTIVES Starting Windows Using the Taskbar, opening & switching programs.
Configuring Active Directory Certificate Services Lesson 13.
Configuring Task Scheduler Lesson 9. Skills Matrix Technology SkillObjective Domain SkillDomain # Understanding Task Scheduler Configure and manage the.
Guide to MCSE , Enhanced 1 Activity 10-1: Restarting Windows Server 2003 Objective: to restart Windows Server 2003 Start  Shut Down  Restart Configure.
Working with Drivers and Printers Lesson 6. Skills Matrix Technology SkillObjective DomainObjective # Understanding Drivers and Devices Install and configure.
9.1 © 2004 Pearson Education, Inc. Lesson 9: Implementing Group Policy in Windows 2000 Server Exam Microsoft® Windows® 2000 Directory Services Infrastructure.
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
Working with Workgroups and Domains
CH 12 Securing Windows Server Objectives Understand the security enhancements included in Windows Server 2008 Understand how Windows Server 2008.
Introduction to Group Policy
MCTS Guide to Microsoft Windows Server 2008 Applications Infrastructure Configuration (Exam # ) Chapter Two Deploying Windows Servers.
Using Windows Firewall and Windows Defender
8.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 8: Introducing Computer Accounts.
6.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 6: Administering User Accounts.
Using Group Policy Lesson 4. Skills Matrix Technology SkillObjective Domain SkillDomain # Creating and Understanding Group Policy Modeling and Group Policy.
Module 10: Configuring Windows XP Professional to Operate in Microsoft Networks.
1/28/2010 Network Plus Windows Networking Network Identification Identifies name and type of network. Installed adapters –Performed during Windows installation.
CIM6400 CTNW (04/05) 1 CIM6400 CTNW Lesson 6 – More on Windows 2000.
1 Chapter Overview Using the New Connection Wizard to configure network and Internet connections Using the New Connection Wizard to configure outbound.
Security Planning and Administrative Delegation Lesson 6.
Installing and Using Active Directory Written by Marc Zacharko.
SUSE Linux Enterprise Desktop Administration Chapter 2 Use the Linux Desktop.
PC Maintenance: Preparing for A+ Certification Chapter 23: Using a Windows Network.
DIT314 ~ Client Operating System & Administration CHAPTER 5 MANAGING USER ACCOUNTS AND GROUPS Prepared By : Suraya Alias.
MCTS Guide to Microsoft Windows Server 2008 Applications Infrastructure Configuration (Exam # ) Chapter Four Windows Server 2008 Remote Desktop Services,
Computing Fundamentals Module Lesson 3 — Changing Settings and Customizing the Desktop Computer Literacy BASICS.
Implementing Active Directory Lesson 2. Skills Matrix Technology SkillObjective DomainObjective # Installing a New Active Directory Forest Configure a.
Introduction to Microsoft Management Console (MMC) MMC is a common console framework for management applications. MMC provides a common environment for.
Key Applications Module Lesson 21 — Access Essentials
Planning a Microsoft Windows 2000 Administrative Structure Designing default administrative group membership Designing custom administrative groups local.
MCTS Guide to Microsoft Windows Server 2008 Applications Infrastructure Configuration (Exam # ) Chapter Five Windows Server 2008 Remote Desktop Services,
1 Chapter Overview Understanding User Accounts Planning New User Accounts Creating, Modifying, and Deleting User Accounts Setting Properties for User Accounts.
Configuring the User and Computer Environment Using Group Policy Lesson 8.
1 Part-1 Chap 5 Configuring Accounts Definitions.
Working with Users and Groups Lesson 5. Skills Matrix Technology SkillObjective DomainObjective # Introducing User Account Control Configure and troubleshoot.
Working with Active Directory Sites Lesson 3. Skills Matrix Technology SkillObjective DomainObjective # Introducing Active Directory Sites Configure sites2.3.
Working with Disks Lesson 4. Skills Matrix Technology SkillObjective DomainObjective # Configuring Data Protection Configure data protection6.4 Using.
Fall 2011 Nassau Community College ITE153 – Operating Systems Session 21 Administering User Accounts and Groups 1.
1 Chapter Overview Managing Object and Container Permissions Locating and Moving Active Directory Objects Delegating Control Troubleshooting Active Directory.
Creating and Managing Digital Certificates Chapter Eleven.
Working with Users and Groups Lesson 5. Skills Matrix Technology SkillObjective DomainObjective # Introducing User Account Control Configure and troubleshoot.
1 Chapter Overview Using Group Objects Understanding Default Groups Creating Group Objects Managing Administrative Access.
10.1 © 2004 Pearson Education, Inc. Lesson 10: Specifying Group Policy Settings Exam Microsoft® Windows® 2000 Directory Services Infrastructure.
11 SECURITY PLANNING AND ADMINISTRATIVE DELEGATION Chapter 6.
Unit 7 ITT TECHNICAL INSTITUTE NT1330 Client-Server Networking II Date: 2/3/2016 Instructor: Williams Obinkyereh.
CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
Computer Literacy BASICS
Assignment # 8.
SECURITY PLANNING AND ADMINISTRATIVE DELEGATION
Unit 7 NT1330 Client-Server Networking II Date: 7/26/2016
Planning a Group Policy Management and Implementation Strategy
Setting up home folders and roaming profiles
Security Planning and Administrative Delegation
Presentation transcript:

Security Planning and Administrative Delegation Lesson 6

Skills Matrix Technology SkillObjective DomainObjective # Creating an OU StructureMaintain Active Directory accounts 4.2

Lesson 6 Configuring Strong Passwords At least eight characters in length Contains uppercase and lowercase letters, numbers, and nonalphabetic characters At least one character from each of the previous character types Differs significantly from other previously used passwords

Lesson 6 Implementing Smart Cards for Authentication Users no longer need to remember passwords. All information is stored on the smart card, making it difficult for anyone except the intended user to use or access it. Security operations, such as cryptographic functions, are performed on the smart card itself rather than on the network server or local computer. This provides a higher level of security for sensitive transactions.

Lesson 6 Implementing Smart Cards for Authentication (cont.) Smart cards can be used from remote locations, such as a home office, to provide authentication services. The risk of remote attacks using a username and password is significantly reduced by smart cards.

Lesson 6 Installing Active Directory Certificate Services Click Start, and then select Server Manager. Click Roles, and then select Add roles. On the Select Server Roles screen, place a checkmark next to Active Directory Certificate Services and click Next. Click Next after you read the information displayed.

Lesson 6 Installing Active Directory Certificate Services (cont.) Select the Certification Authority component, and click Next to continue. Select Enterprise and click Next to continue.

Lesson 6 Installing Active Directory Certificate Services (cont.) Select Root CA, and click Next to continue. Select Create a new private key, and click Next to continue. On the Configure Cryptography for CA screen, click Next to accept the default values for the cryptographic service provider (CSP), key character length, and hash algorithm.

Lesson 6 Installing Active Directory Certificate Services (cont.) Click Next to accept the default values. On the Set the Certificate Validity Period screen, select a validity period of 2 years, and click Next to continue.

Lesson 6 Installing Active Directory Certificate Services (cont.) Click Next to accept the default values and continue. Click Install after you confirmed your installation choices. Click Close after the installation has completed.

Lesson 6 Enabling a User Account for Smart Card Authentication Open Active Directory Users and Computers. Navigate to the container holding the user you wish to modify. Right-click the user account, and select Properties.

Lesson 6 Enabling a User Account for Smart Card Authentication (cont.) In the Properties dialog box, select the Account tab. In the Account Options list, click Smart Card Is Required For Interactive Logon, and then click OK.

Lesson 6 Using Run As from the GUI From the Start button, navigate to the application you wish to run. Press and hold the Shift key, and right-click the desired application. Select the Run as administrator option.

Lesson 6 Using Run As from the GUI (cont.) If you are already logged on as an administrative user, you will be presented with a User Account Control confirmation dialog box. Click Continue to launch the selected program using administrative credentials.

Lesson 6 Delegating Administrative Control of an OU Open Active Directory Users and Computers. Right-click the object to which you wish to delegate control, and click Delegate Control. Click Next on the Welcome to the Delegation of Control Wizard page. Click Add on the Users or Groups page.

Lesson 6 Delegating Administrative Control of an OU (cont.) In the Select Users, Computers, or Groups dialog box, key the user or group to which you want to delegate administration in the Enter the object names to select box, and click OK. Click Next to proceed. Click Create a custom task to delegate, and click Next.

Lesson 6 Delegating Administrative Control of an OU (cont.) Click This folder, existing objects in this folder, and creation of new objects in this folder. Click Next to proceed.

Lesson 6 Delegating Administrative Control of an OU (cont.) On the Permissions page shown in Figure 6-9, set the delegated permissions according to your needs for the user or group that has delegated control. After selecting the appropriate permissions, click Next to proceed. Review your choices carefully, and click Finish.

Lesson 6 Verifying and Removing Delegated Permissions Open Active Directory Users and Computers. Click the View menu, and then click Advanced Features. Navigate in the left pane to the object for which you wish to verify delegated permissions, right- click the object, and select Properties. On the Security tab, click Advanced.

Lesson 6 Verifying and Removing Delegated Permissions (cont.) On the Permissions tab under Permissions entries, view the assigned permissions. Select the user or group for which you wish to remove delegated control privileges, and click Remove. Click OK twice to exit the Properties window.

Lesson 6 Moving an Object Between OUs Using Drag-and-Drop In Active Directory Users and Computers, select the object you wish to move.  If you wish to move multiple objects, press and hold the Ctrl key while selecting the objects you wish to move. While holding down the left mouse button, drag the object to the desired destination OU and release the mouse. The object will appear in its new location.

Lesson 6 Moving an Object Between OUs Using the Move Option In Active Directory Users and Computers, select the object you wish to move.  If you wish to move multiple objects, press and hold the Ctrl key while selecting the objects you wish to move. Right-click the selected object(s), and select Move from the shortcut menu.

Lesson 6 Moving an Object Between OUs Using the Move Option (cont.) In the Move dialog box, select the container object that is the destination for the selected objects, and click OK.

Summary You Learned Creating a naming standards document will assist in planning a consistent Active Directory environment that is easier to manage. Securing user accounts includes educating users to the risks of attacks, implementing a strong password policy, and possibly introducing a smart card infrastructure into your environment.

Summary You Learned (cont.) As part of creating a secure environment, you should create standard user accounts for administrators and direct them to use Run as administrator or runas when performing administrative tasks. When planning your OU structure, consider the business function, organizational structure, and administrative goals for your network. Delegation of administrative tasks should be a consideration in your plan.

Summary You Learned (cont.) Administrative tasks can be delegated for a domain, OU, or container to achieve a decentralized management structure. Permissions can be delegated using the Delegation of Control Wizard. Verification or removal of these permissions must be achieved through the Security tab in the Properties dialog box of the affected container.

Summary You Learned (cont.) Moving objects between containers and OUs within a domain can be achieved by using the Move menu command, the drag-and-drop feature in Active Directory Users and Computers, or the dsmove utility from a command line.