Active Directory Admin Training
-
Upload
rajendra-patil -
Category
Documents
-
view
237 -
download
2
Transcript of Active Directory Admin Training
-
8/2/2019 Active Directory Admin Training
1/31
L A U R E N Information Technologies Pvt. Ltd.
Active Directory
Admin Training
-
8/2/2019 Active Directory Admin Training
2/31
L A U R E N Information Technologies Pvt. Ltd.
Agenda
Active Directory
Domain Name System (DNS)
Dynamic Host Configuration Protocol(DHCP)
Demonstration
Q & A
-
8/2/2019 Active Directory Admin Training
3/31
L A U R E N Information Technologies Pvt. Ltd.
Active Directory
Introduction
Domain, Trees, Forests (Logical)
Domain Controllers, Sites (Physical) Replication
Operations Masters
Group Policy
-
8/2/2019 Active Directory Admin Training
4/31
L A U R E N Information Technologies Pvt. Ltd.
Active Directory
Active Directory
Central component for Windows 2003Operating system.
Is a directory service which storesinformation about network object andmake them available and usable for
users, applications and computers.
-
8/2/2019 Active Directory Admin Training
5/31
L A U R E N Information Technologies Pvt. Ltd.
Active Directory - Benefits
Integrated Security By managing logon and authentication
By controlling access on the object
Ease of Management Can be managed centrally
Distributed management by delegatingcontrol
Single sign on User can access the permitted networkresources once logged on to the ActiveDirectory.
-
8/2/2019 Active Directory Admin Training
6/31
L A U R E N Information Technologies Pvt. Ltd.
Active Directory.
Ease of locating search resources As Active Directory is a central database for
storing objects, it provides enhanced searchcapabilities.
Scalability to size any network
Can be design for any network, because itcan include multiple domains.
-
8/2/2019 Active Directory Admin Training
7/31
L A U R E N Information Technologies Pvt. Ltd.
Active Directory LogicalConcepts
Domains Boundary of Security
Boundary of Authentication
Boundary of Replication Domain NC Replication
Boundary of DNS Namespace
Boundary of Administration
COMPANY.COM
-
8/2/2019 Active Directory Admin Training
8/31
L A U R E N Information Technologies Pvt. Ltd.
Active Directory Logical
Concepts
Trees Collection of Domain controllers
Transitive Trust Relationships
All Domains in a Tree share: Schema
Configuration
Global Catalog
COMPANY.COM
EUROPE.COMPANY.COAMERICA.COMPANY.COM
NICARAGUA.AMERICA.COMPANY.COM
-
8/2/2019 Active Directory Admin Training
9/31
L A U R E N Information Technologies Pvt. Ltd.
Collection Domain trees
Transitive Trust Relationships
All Domains in a Forest share: Schema
Configuration
Global Catalog DIVISION.COMCOMPANY.COM
AMERICA.COMPANY.COM
Active Directory Logical
Concepts
Forests
-
8/2/2019 Active Directory Admin Training
10/31
L A U R E N Information Technologies Pvt. Ltd.
Containers within Domains
Distinct Units of Administration Unique to Domains
Active Directory Logical
Concepts
Organizational Units
-
8/2/2019 Active Directory Admin Training
11/31
L A U R E N Information Technologies Pvt. Ltd.
Active Directory Physical Concepts
Domain ControllersPrimary Domain Controller (PDC)
Back-Up Domain Controller (BDC)
Domain Controllers (DC)
-
8/2/2019 Active Directory Admin Training
12/31
L A U R E N Information Technologies Pvt. Ltd.
What Is a Site?
A set of well-connected IP subnets
Site Usage Replication
Group policy application
Sites Are Connected with SiteLinks
Connects two or more sites
Active Directory Physical Concepts
Sites
-
8/2/2019 Active Directory Admin Training
13/31
L A U R E N Information Technologies Pvt. Ltd.
Active Directory Physical Concepts
Site Topology
Company.com
america.company.com europe.company.com
DC
Site A
Site B
Site C
DC
GC
GC
GC
DC
DC = Domain ControllerGC = Global Catalog
-
8/2/2019 Active Directory Admin Training
14/31
L A U R E N Information Technologies Pvt. Ltd.
A master, searchable index thatcontains information about everyobject in every domain in a forest
Active Directory Physical
Concepts
Global Catalog
-
8/2/2019 Active Directory Admin Training
15/31
L A U R E N Information Technologies Pvt. Ltd.
Intra-Site Replication: ADreplication between DCs within a site
Inter-Site Replication: ADreplication between sites
ReplicationReplication Topologies
-
8/2/2019 Active Directory Admin Training
16/31
L A U R E N Information Technologies Pvt. Ltd.
RPC Replication in a Site
No Compression
Assumes good network connections
ReplicationIntra-Site Replication
-
8/2/2019 Active Directory Admin Training
17/31
L A U R E N Information Technologies Pvt. Ltd.
Replication Between Sites DS-RPC (RPC over IP) or
SMTP Transports
SMTP Can Be Used
Compression
10 percent-20 percent of original size
Scheduled
ReplicationInter-Site Replication
-
8/2/2019 Active Directory Admin Training
18/31
L A U R E N Information Technologies Pvt. Ltd.
Site Links Link Two or More Sites
Cost and schedules can be specified
Bridgehead Servers
Master Replication Server in a site
ReplicationSite-Links & Bridgehead Servers
-
8/2/2019 Active Directory Admin Training
19/31
L A U R E N Information Technologies Pvt. Ltd.
Schema
Perform updates to schema
Sends updates to all DCs
One per forest
Default is the first DC installed
Domain
Performs add/remove of domains
and cross-references to external DS
One per forest
Default is the first DC installed
Operations MastersSchema and Domain
-
8/2/2019 Active Directory Admin Training
20/31
L A U R E N Information Technologies Pvt. Ltd.
Primary Domain Controller (PDC) Acts as a PDC for requests from
Microsoft Windows NT clients One per domain
Relative Identifier (RID) Generates pools of securityidentifiers to be distributed to DCsin the domain
One per domain
Infrastructure Updates security identifiers (SIDs)
and domains that are moved in andout of the domain
Operations MastersPDC, RID, and Infrastructure
-
8/2/2019 Active Directory Admin Training
21/31
L A U R E N Information Technologies Pvt. Ltd.
Group Policy OverviewDo More with Less Effort
ActiveDirectory
One Administrator
Action
New Policy
Group Policy enablesadmins to set and maintaina desired computing state
New Group PolicyManagement Console
(GPMC) makesadministration much easier
Many End UserResults Many Computer
Results
-
8/2/2019 Active Directory Admin Training
22/31
L A U R E N Information Technologies Pvt. Ltd.
Group Policy Processing
Site
Domain
OUOU
OU
GPO1
GPO2
GPO3
GPO4
-
8/2/2019 Active Directory Admin Training
23/31
L A U R E N Information Technologies Pvt. Ltd.
Using Group Policy to
Control the UserEnvironment
Use Group Policy to:Manage users and computers
Deploy software
Enforce security settings
Enforce a consistent desktop environment
-
8/2/2019 Active Directory Admin Training
24/31
L A U R E N Information Technologies Pvt. Ltd.
Software Installation
3 deployment options Assign to computer
App is installed at boot
Assign to user
App installed either on demand or (with XP and above) atuser logon
Publish to user
User chooses to install from add remove programs.
Requires MSI apps
Tips Make sure machine accounts have access to Software
Distribution points for machine assigned apps
No supported way to control install order within a GPO
-
8/2/2019 Active Directory Admin Training
25/31
L A U R E N Information Technologies Pvt. Ltd.
When Does GroupPolicy Get Applied?
Group PolicyApplies ComputerSettings
Startup ScriptsRun
Group PolicyApplies UserSettings
Logon Scripts Run
ComputerStarts
User Logs On
and at periodic intervals
-
8/2/2019 Active Directory Admin Training
26/31
L A U R E N Information Technologies Pvt. Ltd.
Foreground Versus Background
refresh Foreground refresh At boot and logon
Processing is synchronous
Logon prompt not displayed till computer processing complete
Desktop not displayed till user processing complete
Requires connectivity to domain
Background refresh
Approximately every 90 minutes Software installation and folder redirection settings
not processed
-
8/2/2019 Active Directory Admin Training
27/31
L A U R E N Information Technologies Pvt. Ltd.
Active Directory .
Active Directory console
-
8/2/2019 Active Directory Admin Training
28/31
L A U R E N Information Technologies Pvt. Ltd.
Domain Name System (DNS)
Is a TCP/IP based name resolutionservice
Is used to resolve a host name to its
associated IP address Is implemented using two software
components
DNS server DNS client (or resolver)
-
8/2/2019 Active Directory Admin Training
29/31
L A U R E N Information Technologies Pvt. Ltd.
Dynamic Host ConfigurationProtocol (DHCP)
Automate the assignment of IP addresses
Centrally managed by Network
Administrators
DHCP Scopes
Scope - A range of IP addresses that
can be assigned to clients that are onone subnet
Superscope - Is a collection of individualscopes
-
8/2/2019 Active Directory Admin Training
30/31
L A U R E N Information Technologies Pvt. Ltd.
Active Directory
Demonstration
-
8/2/2019 Active Directory Admin Training
31/31
L A U R E N Information Technologies Pvt. Ltd
Q & A