CEA242 Module 4 - Introduction To Active Directoty and Account Management
CEA242 Module 4 - Introduction To Active Directoty and Account Management
Active
Directory and
Account
Management
Module 4
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 4
Working with Local Users and Groups
(1 of 7)
• Local user account authentication
− Must provide valid user name and password
• Local user account assigned rights to the operating system
− Examples: change system time or shut down the system
• Local user account granted access to resources
− Based on the resource’s Access Control List (ACL)
• Local group accounts
− Simplify assigning rights and permissions to multiple local user accounts
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 5
Working with Local Users and Groups
(2 of 7)
• Security Accounts Manager (SAM) Registry database
− Stores local user and group accounts
• Local user accounts used to authenticate users following workgroup installation
− Administrator and Guest
• Local group accounts for assigning rights and permissions following system
installation
− Administrators, Guests, and Users
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 6
Working with Local Users and Groups
(3 of 7)
• To create local user and group accounts
− Use the Local Users and Groups MMC snap-in
• To create a new local user account
− Select the Users folder from Local Users and Groups MMC snap-in
▪ Choose appropriate user’s tasks after installation
• To create a new local group account
− Select the Groups folder from Local Users and Groups MMC snap-in
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 7
Working with Local Users and Groups
(4 of 7)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 8
Working with Local Users and Groups
(5 of 7)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 9
Working with Local Users and Groups
(6 of 7)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 10
Working with Local Users and Groups
(7 of 7)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 11
Active Directory Basics
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 13
Active Directory Forests, Trees, and Trusts
(1 of 4)
• Active Directory forests
− Provide for multiple domains within the same organization
− Forest root domain: first domain in a forest
• Using additional domain controllers
− Add them to the forest root domain
− Configure them to host an Active Directory database for another domain
within the same forest
• Active Directory tree has parent and child domains
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 14
Active Directory Forests, Trees, and Trusts
(2 of 4)
• Trust relationship (trust)
− Allows users to access resources within other domains
− Requires access within the resource’s ACL
− Trust relationships represented by arrow symbols in tree diagram
• Transitive property minimizes number of trust relationships needed
• Other types of trusts
− Shortcut trust speeds up resource access
− External trust, forest trust, realm trust
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 15
Active Directory Forests, Trees, and Trusts
(3 of 4)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 16
Active Directory Forests, Trees, and Trusts
(4 of 4)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 17
Active Directory Groups (1 of 2)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 18
Active Directory Groups (2 of 2)
Table: 4-1
Active Directory group
scopes
Group scope Allowed members Domains that can access the group
Global Objects located within the same domain Any domain in the forest
as the global group
Domain local Objects located within any domain in the Only the domain where the local group
forest resides
Universal Objects located within any domain in the Any domain in the forest
forest
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 19
Domain and Forest Functional Levels (1 of 3)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 21
Domain and Forest Functional Levels (3 of 3)
Windows Server 2008 No additional features beyond those within the Windows
Server 2008 domain functional level
Windows Server 2008 R2 The ability to create and use the Active directory Recycle
Bin to recover deleted objects
Windows Server 2012 No additional features beyond those within the Windows
Server 2012 domain functional level
Windows Server 2012 R2 No additional features beyond those within the Windows
Server 2012 R2 domain functional level
Windows Server 2016 The ability to use the Microsoft Identity Manager (MIM) to
restrict malicious access to Active Directory using
Privilege Access Management (PAM)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 22
Sites and Active Directory Replication
Schema Master 1 per forest Must be contacted in order to modify the Active
Directory schema. Any schema changes are then
replicated by the Schema Master to all other domain
controllers in the forest.
Domain Naming Master 1 per forest Must be contacted in order to add or remove
domains and trust relationships within the forest.
Any changes to the domain and trust configuration
of the forest are then replicated by the Domain
Naming Master to all other domain controllers in the
forest. For best performance, the domain controller
that holds the Domain Naming Master should also
hold a copy of the global catalog.
PDC Emulator 1 per domain In legacy Active Directory domains, this role
emulated a Windows NT4 PDC for backward
compatibility. However, in modern Active Directory
domains, the PDC Emulator coordinates user
password changes and sends time information to
each computer within the domain.
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 26
FSMO Roles (3 of 3)
Table: 4-4 Active Directory
FSMO roles
FSMO Role Number per Domain or Forest Function
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 27
Azure Active Directory
• Open Server Manager and select the Active Directory Domain Services role
• Progress through the Add Roles and Features Wizard
− Installs files necessary to create a domain controller, management tools, and
Windows PowerShell cmdlets
• Select Promote this server to a domain controller from the Add Roles and
Features Wizard
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 29
Installing Active Directory (2 of 3)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 30
Installing Active Directory (3 of 3)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 31
Installing a Forest Root Domain (1 of 5)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 33
Installing a Forest Root Domain (3 of 5)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 34
Installing a Forest Root Domain (4 of 5)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 35
Installing a Forest Root Domain (5 of 5)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 36
Installing a Domain within an Existing Forest
(1 of 2)
• Start the Active Directory Domain Services Configuration Wizard
− Select Add a new domain to an existing forest
− Adding a child domain
▪ Specify name of the parent domain and name of the new child domain
− Adding a new parent domain for a new tree
▪ Select Tree Domain and specify the name of the parent domain
− Authenticate as a user within a forest that is part of Enterprise Admins group
− Progress through Wizard as if configuring a new forest root domain
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 37
Installing a Domain within an Existing Forest
(2 of 2)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 38
Installing a Domain Controller within an
Existing Domain (1 of 2)
• Start the Active Directory Domain Services Configuration Wizard
− Select Add a domain controller to an existing domain
▪ Specify the existing domain name within the Domain text box
− Authenticate within the domain that is part of the Domain Admins group
▪ Click Change and supply credentials
− Progress through Wizard as if configuring a new forest root domain
▪ No need to set the forest or domain functional levels
▪ Can select where to obtain initial copy of Active Directory database
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 39
Installing a Domain Controller within an
Existing Domain (2 of 2)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 40
Raising Functional Levels (1 of 3)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 41
Raising Functional Levels (2 of 3)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 42
Raising Functional Levels (3 of 3)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 43
Creating Trust Relationships (1 of 2)
• Use conditional forwarder to ensure DNS servers can resolve the DNS records
• Open the Active Directory Domains and Trusts tool
− Select the domain within the navigation pane
− Click More Actions, Properties from the Actions pane
• Domain window opens
− Select the Trusts tab and click New Trust to start the New Trust Wizard
− Choose options: external or forest; one-way outgoing or incoming or two-
way; transitive or non-transitive, etc.
− Select the trust and click Properties to validate or change trust settings
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 44
Creating Trust Relationships (2 of 2)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 45
Managing FSMO Roles
• Command to view all FSMO roles held by domain controllers within your forest
− netdom query fsmo command
• Other commands show domain controllers holding the forest-wide and domain-
wide FSMO roles
• Fault tolerance may require movement of FSMO roles from one domain
controller to another
− Move one or multiple FSMO roles from one domain controller to another
− If source domain controller offline, add the -Force option to the command
▪ Move-ADDirectoryServerOperationMasterRole
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 46
Configuring Sites and Replication (1 of 6)
• Configuring sites
− Open Active Directory Sites and Services tool
− Right-click Default-First-Site-Name and rename
− Right-click Sites folder to create additional sites
− Supply site name and select the appropriate site link
− Specify appropriate IP network and select the associated site
• Two protocols perform Active Directory replication
− IP and Simple Mail Transfer Protocol (SMTP)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 47
Configuring Sites and Replication (2 of 6)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 48
Configuring Sites and Replication (3 of 6)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 49
Configuring Sites and Replication (4 of 6)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 50
Configuring Sites and Replication (5 of 6)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 51
Configuring Sites and Replication (6 of 6)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 52
Configuring Global Catalog and UGMC
(1 of 3)
• Configure a domain controller to host a copy of the global catalog
• Open Active Directory Sites and Services and click Properties
− Right-click NTDS Settings under the server object for the domain controller
− Select the Global Catalog option to place a copy of the global catalog on the
domain controller
• UGMC can host a copy of the global catalog if replication concerns exist
− Allows universal groups to be cached on domain controllers within the site
− Allows fast logon
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 53
Configuring Global Catalog and UGMC
(2 of 3)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 54
Configuring Global Catalog and UGMC
(3 of 3)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 55
Working with Organizational Units (1 of 3)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 56
Working with Organizational Units (2 of 3)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 57
Working with Organizational Units (3 of 3)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 58
Working with User Objects (1 of 4)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 60
Working with User Objects (3 of 4)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 61
Working with User Objects (4 of 4)
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 62
Working with Group Objects
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 65
Read-Only Domain Controllers
• Contains a read-only copy of the Active Directory database for the domain
• Object creation and management replicated from large office
− Primary concern during replication is security
− Replicate password attributes for users within the branch office only
• Install RODC using Active Directory Domain Services Configuration Wizard
• Can prestage a RODC computer account using the Active Directory Domain
Services Installation Wizard
• Can delete RODC if stolen and reset computer account for stolen computers
Eckert/triOS College, Hands-On Microsoft Windows Server, 3rd Edition. ©2021 Cengage. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole
or in part. 66
Summary