Server 2008 R2 - Generic - Case Day 1 Task 1 Install the fllwing machines: DC01 Server2008 R2 Standard Editin WEB01 Server 2008 R2 Standard Editin WEB02 Server 2003 File01 Server 2008 R2 Standard Editin Client01 Windws 7 Enterprise Editin Client02 Windws 7 Enterprise Editin Name and cnfigure IP addresses by fllwing the tplgy drawing. Task 2 Install Active Directry n DC01. Dmain name: dmain.lcal. Make all machines members f the dmain.lcal dmain except Client02. Day 2 Task 3 The cmpany has the fllwing rganizatin. Try t make an effecient OU structure in Active Directry Users and Cmputers using Micrsft best practice. Department N. emplyees Management 2 Prductin 50 Administratin 6 IT 3 Sales 10 1
Users in every department must be created in their respective OU and must be member f a dmain glbal grup in every department. (In practical create ne user per department, name the users freely) The tw client machines must be placed in the management and prductin OU s respectivly) The five servers must als be rganized in the OU structure. Task 4 The cmpany has the fllwing requirements t shared flders and grups that can access them. Emplyees in dmain glbal grups Administratin Management Prductin Must have the fllwing level f access t flders: Administratin Management Prductin Sales Prject 1 Prject 2 Prject Assignments write delete wn write delete wn delete wn delete wn Sales Prject 1 Prject 2 delete wn delete wn delete wn Cmmn delete wn Any prject Furthermre, the dmain administratrer must have full cntrl t all flders. Yu must - Make a plan f which NTFS permissins needs t be effectuated and frm this plan determine: 2
Which dmain lcal grups must be created and their name. Which NTFS permissins the dmain lcal grups must be assigned. Which dmain glbal grups must be member f which dmain lcal grups. - Fllw Micrsft Best Practice fr Access Management. - Create the flders and shares n file01. Day 3 Task 5 Install the WINS feature n DC01 and cnfigure all servers and clients t use the WINS server. Task 6 Task 7 Install IIS 7.5 n WEB01 Create tw new websites: website1 and website2 each with their wn applicatin pl and physical path. On DC01 cnfigure a DNS recrd fr bth www.website1.cm and www.website2.cm and pint t the IP address f WEB01. On WEB01 under IIS bindings cnfigure s www.website1.cm can be reached n prt 80 and www.website2.cm can be reached n prt 81. Test frm CLIENT01. On WEB01 under IIS bindings set the prt number back t 80 fr bth websites. Nw cnfigure hst header s website1 can be reached by the name www.website1.cm and website2 can be reached by the name www.website2.cm. Test frm CLIENT01 On WEB01 set authenticatin methd fr website2 t Windws authenticatin (Integrated). Add www.website2.cm t lcal intranet zne n Client01. Test access frm CLIENT01 and test access frm CLIENT02 (Nt dmain jined) Install IIS 6.0 n WEB02 Create tw new websites: website3 and website4 each with their wn applicatin pl and physical path. On DC01 cnfigure a DNS recrd fr bth www.website3.cm and www.website4.cm and pint t the IP address f WEB02. On WEB02 cnfigure s www.website3.cm can be reached n prt 80 and www.website4.cm can be reached n prt 81. Test frm CLIENT01. On WEB02 set the prt numbers back t 80 fr bth websites. Nw cnfigure hst header s website3 can be reached by the name www.website3.cm and website4 can be reached by the name www.website4.cm. Test frm CLIENT01 3
On WEB02 set authenticatin methd fr website4 t Integrated Windws authenticatin. Add www.website4.cm t lcal intranet zne n Client01. Test access frm CLIENT01 and test access frm CLIENT02 (Nt dmain jined) Day 4 Task 8 Create a new service n DC01. ( e.g. sc.exe \\lcalhst create NewService binpath= c:\windws\system32\calc.exe) Cnfigure the service t start autmatically when windws starts. In case f failure, cnfigure the service t restart the first tw times and t run a prgram the third time. Try t stp and start the IIS service n WEB01 with the fllwing cmmands: net, stpservice/start-service (PwerShell), sc.exe (Yu must identify the name f the IIS service first) Task 9 Try t d the fllwing via Grup Plicy: The lcal administratr and guest accunt must be disabled n all client machines that are member f yur dmain. User passwrds must meet the fllwing requirements: The passwrd must be changed ne time every mnth minimum. The passwrd length must be minimum 9 characters. The passwrd must cntain three f the fllwing fur categries: special characters, uppercase characters, lwercase characters r numbers. If smene tries t brute frce a user accunt, the accunt must be lcked after fur attempts. Only an administratr must unlck the accunt then. Task 10 Enable Grup Plicy lpback prcessing (Hint. It s a Cmputer Cnfiguratin plicy) n FILE01 and try t see hw much yu can limit users wh lg n t FILE01. (Hint. User Cnfiguratin/Plicies/Administrative Templates) Day 5 Task 11 4
Each user must map a netwrk drive t the shares they have access t n FILE01. D this by creating lgn scripts and placing them in the default lcatin n DC01. Frm the user accunts in Active Directry Users and Cmputers, map the right lgn script fr each user. Test the lgn script n CLIENT01. (Hint. Net use) Task 12 Jin CLIENT02 t yur dmain. T create a raming prfile fr the user in the management department yu must d the fllwing. Create a GPO that applies t CLIENT01 and CLIENT02 name it Raming Pr Administratr Access. Edit the plicy and view the explanatin fr the setting Cmputer Cnfiguratin\Administrative Templates\System\User Pr\ Add the Administratrs security grup t raming user pr. Enable the setting. Create a new share n FILE01 and name it Pr$. NTFS shuld be cnfigured with the permissins described in Step 2 Table 1: http://technet.micrsft.cm/enus/library/jj649079.aspx#rup_step2createaharefrraminguserpr. Share permissins with Full Cntrl fr everyne is OK. Set the Prfile path, under prperties fr the user accunt in the management OU, t \\FILE01.dmain.lcal\Pr$\%username% Lg n t CLIENT01 with the user frm management. An empty flder shuld be created n \\FILE01\Pr$\Username. On CLIENT01 create a flder n the desktp and lgff. The user prfile shuld be cpied t the \\FILE01\Pr$\Username flder n FILE01. Lg n t CLIENT02 with the user frm management and the same prfile shuld be dwnladed and the created flder shuld be n the desktp. Task 13 Try t cnfigure flder redirectin fr the desktp flder fr the management user. Create a new share n FILE01 fr this purpse, with the same NTFS and share permissins as the Pr$ share. 5