Active Directory Admin Training

download Active Directory Admin Training

of 31

Transcript of Active Directory Admin Training

  • 8/2/2019 Active Directory Admin Training

    1/31

    L A U R E N Information Technologies Pvt. Ltd.

    Active Directory

    Admin Training

  • 8/2/2019 Active Directory Admin Training

    2/31

    L A U R E N Information Technologies Pvt. Ltd.

    Agenda

    Active Directory

    Domain Name System (DNS)

    Dynamic Host Configuration Protocol(DHCP)

    Demonstration

    Q & A

  • 8/2/2019 Active Directory Admin Training

    3/31

    L A U R E N Information Technologies Pvt. Ltd.

    Active Directory

    Introduction

    Domain, Trees, Forests (Logical)

    Domain Controllers, Sites (Physical) Replication

    Operations Masters

    Group Policy

  • 8/2/2019 Active Directory Admin Training

    4/31

    L A U R E N Information Technologies Pvt. Ltd.

    Active Directory

    Active Directory

    Central component for Windows 2003Operating system.

    Is a directory service which storesinformation about network object andmake them available and usable for

    users, applications and computers.

  • 8/2/2019 Active Directory Admin Training

    5/31

    L A U R E N Information Technologies Pvt. Ltd.

    Active Directory - Benefits

    Integrated Security By managing logon and authentication

    By controlling access on the object

    Ease of Management Can be managed centrally

    Distributed management by delegatingcontrol

    Single sign on User can access the permitted networkresources once logged on to the ActiveDirectory.

  • 8/2/2019 Active Directory Admin Training

    6/31

    L A U R E N Information Technologies Pvt. Ltd.

    Active Directory.

    Ease of locating search resources As Active Directory is a central database for

    storing objects, it provides enhanced searchcapabilities.

    Scalability to size any network

    Can be design for any network, because itcan include multiple domains.

  • 8/2/2019 Active Directory Admin Training

    7/31

    L A U R E N Information Technologies Pvt. Ltd.

    Active Directory LogicalConcepts

    Domains Boundary of Security

    Boundary of Authentication

    Boundary of Replication Domain NC Replication

    Boundary of DNS Namespace

    Boundary of Administration

    COMPANY.COM

  • 8/2/2019 Active Directory Admin Training

    8/31

    L A U R E N Information Technologies Pvt. Ltd.

    Active Directory Logical

    Concepts

    Trees Collection of Domain controllers

    Transitive Trust Relationships

    All Domains in a Tree share: Schema

    Configuration

    Global Catalog

    COMPANY.COM

    EUROPE.COMPANY.COAMERICA.COMPANY.COM

    NICARAGUA.AMERICA.COMPANY.COM

  • 8/2/2019 Active Directory Admin Training

    9/31

    L A U R E N Information Technologies Pvt. Ltd.

    Collection Domain trees

    Transitive Trust Relationships

    All Domains in a Forest share: Schema

    Configuration

    Global Catalog DIVISION.COMCOMPANY.COM

    AMERICA.COMPANY.COM

    Active Directory Logical

    Concepts

    Forests

  • 8/2/2019 Active Directory Admin Training

    10/31

    L A U R E N Information Technologies Pvt. Ltd.

    Containers within Domains

    Distinct Units of Administration Unique to Domains

    Active Directory Logical

    Concepts

    Organizational Units

  • 8/2/2019 Active Directory Admin Training

    11/31

    L A U R E N Information Technologies Pvt. Ltd.

    Active Directory Physical Concepts

    Domain ControllersPrimary Domain Controller (PDC)

    Back-Up Domain Controller (BDC)

    Domain Controllers (DC)

  • 8/2/2019 Active Directory Admin Training

    12/31

    L A U R E N Information Technologies Pvt. Ltd.

    What Is a Site?

    A set of well-connected IP subnets

    Site Usage Replication

    Group policy application

    Sites Are Connected with SiteLinks

    Connects two or more sites

    Active Directory Physical Concepts

    Sites

  • 8/2/2019 Active Directory Admin Training

    13/31

    L A U R E N Information Technologies Pvt. Ltd.

    Active Directory Physical Concepts

    Site Topology

    Company.com

    america.company.com europe.company.com

    DC

    Site A

    Site B

    Site C

    DC

    GC

    GC

    GC

    DC

    DC = Domain ControllerGC = Global Catalog

  • 8/2/2019 Active Directory Admin Training

    14/31

    L A U R E N Information Technologies Pvt. Ltd.

    A master, searchable index thatcontains information about everyobject in every domain in a forest

    Active Directory Physical

    Concepts

    Global Catalog

  • 8/2/2019 Active Directory Admin Training

    15/31

    L A U R E N Information Technologies Pvt. Ltd.

    Intra-Site Replication: ADreplication between DCs within a site

    Inter-Site Replication: ADreplication between sites

    ReplicationReplication Topologies

  • 8/2/2019 Active Directory Admin Training

    16/31

    L A U R E N Information Technologies Pvt. Ltd.

    RPC Replication in a Site

    No Compression

    Assumes good network connections

    ReplicationIntra-Site Replication

  • 8/2/2019 Active Directory Admin Training

    17/31

    L A U R E N Information Technologies Pvt. Ltd.

    Replication Between Sites DS-RPC (RPC over IP) or

    SMTP Transports

    SMTP Can Be Used

    Compression

    10 percent-20 percent of original size

    Scheduled

    ReplicationInter-Site Replication

  • 8/2/2019 Active Directory Admin Training

    18/31

    L A U R E N Information Technologies Pvt. Ltd.

    Site Links Link Two or More Sites

    Cost and schedules can be specified

    Bridgehead Servers

    Master Replication Server in a site

    ReplicationSite-Links & Bridgehead Servers

  • 8/2/2019 Active Directory Admin Training

    19/31

    L A U R E N Information Technologies Pvt. Ltd.

    Schema

    Perform updates to schema

    Sends updates to all DCs

    One per forest

    Default is the first DC installed

    Domain

    Performs add/remove of domains

    and cross-references to external DS

    One per forest

    Default is the first DC installed

    Operations MastersSchema and Domain

  • 8/2/2019 Active Directory Admin Training

    20/31

    L A U R E N Information Technologies Pvt. Ltd.

    Primary Domain Controller (PDC) Acts as a PDC for requests from

    Microsoft Windows NT clients One per domain

    Relative Identifier (RID) Generates pools of securityidentifiers to be distributed to DCsin the domain

    One per domain

    Infrastructure Updates security identifiers (SIDs)

    and domains that are moved in andout of the domain

    Operations MastersPDC, RID, and Infrastructure

  • 8/2/2019 Active Directory Admin Training

    21/31

    L A U R E N Information Technologies Pvt. Ltd.

    Group Policy OverviewDo More with Less Effort

    ActiveDirectory

    One Administrator

    Action

    New Policy

    Group Policy enablesadmins to set and maintaina desired computing state

    New Group PolicyManagement Console

    (GPMC) makesadministration much easier

    Many End UserResults Many Computer

    Results

  • 8/2/2019 Active Directory Admin Training

    22/31

    L A U R E N Information Technologies Pvt. Ltd.

    Group Policy Processing

    Site

    Domain

    OUOU

    OU

    GPO1

    GPO2

    GPO3

    GPO4

  • 8/2/2019 Active Directory Admin Training

    23/31

    L A U R E N Information Technologies Pvt. Ltd.

    Using Group Policy to

    Control the UserEnvironment

    Use Group Policy to:Manage users and computers

    Deploy software

    Enforce security settings

    Enforce a consistent desktop environment

  • 8/2/2019 Active Directory Admin Training

    24/31

    L A U R E N Information Technologies Pvt. Ltd.

    Software Installation

    3 deployment options Assign to computer

    App is installed at boot

    Assign to user

    App installed either on demand or (with XP and above) atuser logon

    Publish to user

    User chooses to install from add remove programs.

    Requires MSI apps

    Tips Make sure machine accounts have access to Software

    Distribution points for machine assigned apps

    No supported way to control install order within a GPO

  • 8/2/2019 Active Directory Admin Training

    25/31

    L A U R E N Information Technologies Pvt. Ltd.

    When Does GroupPolicy Get Applied?

    Group PolicyApplies ComputerSettings

    Startup ScriptsRun

    Group PolicyApplies UserSettings

    Logon Scripts Run

    ComputerStarts

    User Logs On

    and at periodic intervals

  • 8/2/2019 Active Directory Admin Training

    26/31

    L A U R E N Information Technologies Pvt. Ltd.

    Foreground Versus Background

    refresh Foreground refresh At boot and logon

    Processing is synchronous

    Logon prompt not displayed till computer processing complete

    Desktop not displayed till user processing complete

    Requires connectivity to domain

    Background refresh

    Approximately every 90 minutes Software installation and folder redirection settings

    not processed

  • 8/2/2019 Active Directory Admin Training

    27/31

    L A U R E N Information Technologies Pvt. Ltd.

    Active Directory .

    Active Directory console

  • 8/2/2019 Active Directory Admin Training

    28/31

    L A U R E N Information Technologies Pvt. Ltd.

    Domain Name System (DNS)

    Is a TCP/IP based name resolutionservice

    Is used to resolve a host name to its

    associated IP address Is implemented using two software

    components

    DNS server DNS client (or resolver)

  • 8/2/2019 Active Directory Admin Training

    29/31

    L A U R E N Information Technologies Pvt. Ltd.

    Dynamic Host ConfigurationProtocol (DHCP)

    Automate the assignment of IP addresses

    Centrally managed by Network

    Administrators

    DHCP Scopes

    Scope - A range of IP addresses that

    can be assigned to clients that are onone subnet

    Superscope - Is a collection of individualscopes

  • 8/2/2019 Active Directory Admin Training

    30/31

    L A U R E N Information Technologies Pvt. Ltd.

    Active Directory

    Demonstration

  • 8/2/2019 Active Directory Admin Training

    31/31

    L A U R E N Information Technologies Pvt. Ltd

    Q & A