Module 8: Planning for Windows Server 2008 Active Directory Services.

Slides:



Advertisements
Similar presentations
Auditing Microsoft Active Directory
Advertisements

Module 14: Implementing an Active Directory Infrastructure.
How to Succeed with Active Directory Robert Williams, PhD CEO Secure Logistix Corporation.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 1: Introduction to Active Directory.
70-297: MCSE Guide to Designing a Microsoft Windows Server 2003 Active Directory and Network Infrastructure Chapter 2: Developing the Active Directory.
Chapter 6 Introducing Active Directory
Chapter 4 Chapter 4: Planning the Active Directory and Security.
Introduction to Active Directory
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
By Rashid Khan Lesson 4-Preparing to Serve: Understanding Microsoft Networking.
Chapter 4 Introduction to Active Directory and Account Management
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
Understanding Active Directory
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
A centralized system.  Active Directory is Microsoft's trademarked directory service, an integral part of the Windows architecture. Like other directory.
Hands-On Microsoft Windows Server 2008
Hands-On Microsoft Windows Server 2008
Active Directory Implementation Class 4
Module 1: Installing Active Directory Domain Services
Module 1: Installing Active Directory Domain Services
Overview of Active Directory Domain Services Lesson 1.
Overview of Active Directory Domain Services Lesson 1.
Nassau Community College
(ITI310) SESSIONS : Active Directory By Eng. BASSEM ALSAID.
11 REVIEWING MICROSOFT ACTIVE DIRECTORY CONCEPTS Chapter 1.
Chapter 4 Introduction to Active Directory and Account Management
Session 6 Windows Platform Dina Alkhoudari. Learning Objectives What is Active Directory Logical components of active directory Physical components of.
Windows Server 2008 Chapter 4 Last Update
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 3: Introducing Active Directory.
Working with domains and Active Directory
Module 6: Designing Active Directory Security in Windows Server 2008.
Designing Active Directory for Security
Introduction to Active Directory Domain Services
Active Directory Boundaries - Purpose Replication Boundaries Security Boundaries.
Module 2 Designing Microsoft® Exchange Server 2010 Integration with the Current Infrastructure.
September 18, 2002 Windows 2000 Server Active Directory By Jerry Haggard.
Designing Authentication for a Microsoft Windows 2000 Network Designing Authentication in a Microsoft Windows 2000 Network Designing Kerberos Authentication.
By Kevin Stevens. Scenario Prepare a presentation for the ADcorp company which has implemented Active Direcotory 2008 (adcorp.local) and how approximately.
Module 7 Active Directory and Account Management.
1 Windows 2008 Configuring Server Roles and Services.
Module 1: Introduction to Active Directory Infrastructure
Module 11: Read-Only Domain Controllers. Overview Describe the Read-Only Domain Controllers role Use Read-Only Domain Controllers.
Page 1 Active Directory and DNS Lecture 2 Hassan Shuja 09/14/2004.
Introduction to Active Directory Domain Services
Module 1: Implementing Active Directory ® Domain Services.
Module 4 Planning for Group Policy. Module Overview Planning Group Policy Application Planning Group Policy Processing Planning the Management of Group.
Hands-On Microsoft Windows Server 2008 Chapter 4-Part 1 Introduction to Active Directory and Account Manager.
Module 3 Creating Groups and Organizational Units.
70-412: Configuring Advanced Windows Server 2012 services
MCITP Guide to Microsoft Windows Server 2008 Enterprise Administration (Exam #70-647) Chapter 1 Designing Active Directory Domain Services.
Module 3 Planning for Active Directory®
Installing a Domain Controller
OVERVIEW OF ACTIVE DIRECTORY
Introduction to Active Directory
CEG 2400 Fall 2012 Directory Services Active Directory Tree Domain.
Windows 2003 Architecture, Active Directory & DNS Lecture # 3 Hassan Shuja 02/14/2006.
1 Introduction to Active Directory Directory Services Uniquely identify users and resources on a network Provide a single point of network management.
7.1 © 2004 Pearson Education, Inc. Exam Designing a Microsoft ® Windows ® Server 2003 Active Directory and Network Infrastructure Lesson 7: Planning.
MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition (70-294) Chapter 1: Overview of the Active.
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
Planning an Active Directory Deployment Lesson 1.
Overview of Active Directory Domain Services Lesson 1.
Implementing Active Directory Domain Services
(ITI310) SESSIONS 6-7-8: Active Directory.
Network Administration
Chapter 4: Planning the Active Directory and Security
Install Active Directory
Windows Active Directory Environment
Presentation transcript:

Module 8: Planning for Windows Server 2008 Active Directory Services

Overview Plan for a Windows Server 2008 Active Directory Domain Services deployment Identify considerations when upgrading from a Windows Server 2003 to a Windows Server 2008 Active Directory infrastructure

Lesson: Planning for AD DS Deployment List key considerations for designing a Forest infrastructure List key considerations for designing a Domain infrastructure List key considerations for designing a Site topology List key considerations for designing the administrative infrastructure List key considerations for designing for Group Policy

Designing a Forest Infrastructure HR IT Finance Marketing HR IT Finance

Designing a Domain Infrastructure Review the Domain Models Determine the Number of Domains Determine Whether or not to Upgrade

Logical AD Components Namespace for an AD forest is discontiguous Single Schema Single Global Catalog Complete Trust Domain Model Forests A tree is contiguous namespace Trees

Logical AD Components When to add To placeholder or not Domains Used for delegation Used for Group Policy Don’t just mirror business units Organizational Units

AD – Design challenges Long term impacts of the design Mergers and acquisitions Other products such as Exchange (number of forests and GC’s) Political Try not to let politics shape your design Get buy in from divisions, management and IT Failure to fully analyze networking and replication Nesting OUs or groups too deeply Overly complex group policies Poor performance during Logon

Forests – Design Considerations There are three main forest models Organizational, resource, restricted access model Why do we care? With Exchange the GAL is per forest Factors affecting forest design Organizational structure requirements Operational requirements Legal requirements

AD Building Block The Schema is the building block of AD Active Directory services is a catalog of objects that reside in the forest It is not static – it can easily be extended (be careful!) Global Catalog consists of selected attributes from every object in the enterprise

Domain Design There are two main domain models Single domain and Regional domain models Why do we care? Management, amount of hardware required Factors affecting domain design Decentralized Admin Geographic locations DNS namespace Differing security and password policies

Designing a Site Topology Collect Network Information Plan DC Placement Create a Site Design Create a Site Link Design Create a Site Bridge Design

Sites Why create sites? Optimizes replication between domain controllers Locate the closest domain controller for client logon and directory searches Other applications use it to allocate local resources Multiple sites Site link bridges Link costs Link redundancy

Site Links Site links Connection for Active Directory replication Automatically creates connections between DC’s in each site called Bridgehead Servers Site link bridges Enable DC’s not directly connected by means of a communication link to replicate with each other

Sites Links Link costs Assign a cost (arbitrary number) to each site link Lower-cost are favored over higher-cost site links Link redundancy AD has no awareness of your physical network (this is a good thing!) Create a single site link and leave WAN redundancy to the routers

Sites Topologies Basic AD Network / Site Topologies  Ring  Hub and Spoke  Complex Hub and Spoke and Complex require careful planning

Designing the Administrative Infrastructure Group Admins : Full Control Group File Svr Admins: Full Control Group Print Svr Admins: Full Control ACL Settings for ResourceOU ResourceOU Domain Controllers Users Builtin Company Domain

Designing for Group Policy OU Domain Site GPO

What’s new in Vista with GPOs With the release of Vista, Microsoft has added several new areas that can be managed via GPOs and has expanded several existing areas such as  Antivirus  Device Installation  Deployed Printer Connections  User Account Protection Network Location Awareness

Lesson 2: Upgrade Considerations List preliminary AD DS installation steps Identify upgrade considerations for Read-Only Domain Controllers Identify upgrade considerations for AD DS and Server Core Use Server Manager wizards

Preliminary AD DS Installation Steps Extend the schema using adprep /forestprep For a Windows 2000 Server domain: adprep /domainprep /gpprep For a Windows 2003 domain: adprep /domainprep RODC: adprep /rodcprep Extend the schema using adprep /forestprep For a Windows 2000 Server domain: adprep /domainprep /gpprep For a Windows 2003 domain: adprep /domainprep RODC: adprep /rodcprep Strong password Correct network settings Latest security updates Strong password Correct network settings Latest security updates New Forest Existing Forest

Active Directory Upgrade Sequence Guide Before the upgrade of domain controllers  Prepare the forest  Prepare the domains Before upgrading a Windows Server 2003 domain controller

Read-Only Domain Controller

AD DS and Server Core Server Core