Microsoft. Official Course. Introduction to Active Directory Domain Services. Module 2



Similar documents
Windows Server 2012 / Windows 8 Audit Fundamentals

Quality Management Consultancy

Microsoft. Jump Start. M11: Implementing Active Directory Domain Services

Introduction to Active Directory Services

Administering Windows Server 2012

411-Administering Windows Server 2012

Administering Windows Server 2012

Administering Windows Server 2012

Course 6425C: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

6425C - Windows Server 2008 R2 Active Directory Domain Services

Administering Windows Server 2012

COURSE 20411D: ADMINISTERING WINDOWS SERVER 2012

Administering Windows Server 2012

AV-006: Installing, Administering and Configuring Windows Server 2012

MS-6425C - Configuring Windows Server 2008 Active Directory Domain Services

20410: Installing and Configuring Windows Server 2012

COMPLETE COMPUTING, INC.

Administering Windows Server 2012

NE-20411D Administering Windows Server 2012

"Charting the Course... MOC D Administering Windows Server Course Summary

Course 6425C: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

MOC 20413C: Designing and Implementing a Server Infrastructure

Course: Configuring and Troubleshooting Windows Server 2008 Active Direct-ory Domain Services

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

M6425a Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Configuring and Troubleshooting Windows 2008 Active Directory Domain Services

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Course 20411D: Administering Windows Server 2012

How To Configure An Active Directory Domain Services

Administering Windows Server 2012

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Active Directory Services with Windows Server

ADMINISTERING WINDOWS SERVER 2012

Installing and Configuring Windows Server 2012 MOC 20410

Installing and Configuring Windows Server 2012

Designing Windows Server 2008 Active Directory Infrastructure and Services Course 6436B; 5 Days, Instructor-led

6425C: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain MOC 6425

Course 6425C: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

70-417: Upgrading Your Skills to MCSA Windows Server 2012

Administering Windows Server 2012

Designing a Windows Server 2008 Active Directory Infrastructure and Services

Active Directory Services with Windows Server MOC 10969

R4: Configuring Windows Server 2008 Active Directory

Implementing Microsoft Azure Infrastructure Solutions

MS 6419 Configuring, Managing and Maintaining Windows Server 2008-based Servers

Outline SSS Microsoft Windows Server 2008 Hyper-V Virtualization

MS Installing and Configuring Windows Server 2012

Course Active Directory Services with Windows Server

NE-6425C Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Active Directory Services with Windows Server 10969B; 5 days, Instructor-led

Course 6425C: Five days

Outline SSS Configuring and Troubleshooting Windows Server 2008 Active Directory

Designing and Implementing a Server Infrastructure

Course Outline: Course Installing and Configuring Windows Server 2012

This module explains how to configure and troubleshoot DNS, including DNS replication and caching.

Course 20411B: Administering Windows Server 2012

NOTE: Labs in this course are based on the General Availability release of Windows Server 2012 R2 and Windows 8.1.

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Course 6425B: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Configuring Windows Server 2008 Active Directory

Course 10969A Active Directory Services with Windows Server

Microsoft Active Directory Services with Windows Server

Designing and Implementing a Server Infrastructure

Configuring, Managing and Maintaining Windows Server 2008-based Servers

SETTING UP ACTIVE DIRECTORY (AD) ON WINDOWS 2008 FOR EROOM

Designing and Implementing a Server Infrastructure

COURSE 20413C: DESIGNING AND IMPLEMENTING A SERVER INFRASTRUCTURE

Course 6419B: Configuring, Managing and Maintaining Windows Server 2008-based Servers

Administering Windows Server 2012

VNLINFOTECH JOIN US & MAKE YOUR FUTURE BRIGHT. mcsa (70-413) Microsoft certified system administrator. (designing & implementing server infrasturcure)

9. Which is the command used to remove active directory from a domain controller? Answer: Dcpromo /forceremoval

Designing and Implementing a Server Infrastructure 20413C; 5 days, Instructor-led

Installing and Configuring Windows Server 2012

Course 20413: Designing and Implementing a Server Infrastructure

Installing and Configuring Windows Server 2012

MCSA Server (Exam )

Contents Introduction... 3 Introduction to Active Directory Services... 4 Installing and Configuring Active Directory Services...

Installing and Configuring Windows Server 2012

Administering Windows Server 2012

Administering Windows Server 2012 MOC 20411

Installing, Configuring, and Managing a Microsoft Active Directory

Upgrading Your Skills to MCSA Windows Server 2012

Installing and Configuring Windows Server 2012

TestOut Course Outline for: Windows Server 2008 Active Directory

Implementing Microsoft Azure Infrastructure Solutions

Administering Windows Server 2012

Course Outline. Course 6419 : Configuring, Managing and Maintaining Windows Server 2008-based Servers. Duration: 5 Days

Lesson Plans LabSim for Microsoft s Implementing a Server 2003 Active Directory Infrastructure

Transcription:

Microsoft Official Course Module 2 Introduction to Active Directory Domain Services

Module Overview Overview of AD DS Overview of Domain Controllers Installing a Domain Controller

Lesson 1: Overview of AD DS Overview of AD DS What Are AD DS Domains? What Are OUs? What Is an AD DS Forest? What Is the AD DS Schema? What Is New for Windows Server 2012 Active Directory? What Is New for Windows Server 2012 R2 Active Directory?

Overview of AD DS AD DS is composed of both logical and physical components Logical components Partitions Schema Domains Domain trees Forests Sites OUs Containers Physical components Domain controllers Data stores Global catalog servers RODCs

What Are AD DS Domains? AD DS requires one or more domain controllers All domain controllers hold a copy of the domain database, which is continually synchronized The domain is the context within which user accounts, computer accounts, and groups are created The domain is a replication boundary The domain is an administrative center for configuring and managing objects Any domain controller can authenticate any sign-in anywhere in the domain The domain provides authorization Computers Users AD DS Groups

What Are OUs? Containers that can be used to group objects within a domain Create OUs to: Configure objects by assigning GPOs Delegate administrative permissions OUs are represented by a folder with a book on it Containers are represented by a blank folder

What Is an AD DS Forest? Tree root domain fabrikam.com adatum.com Forest root domain atl.adatum.com Child domain

What Is the AD DS Schema? The schema defines the objects that can be stored in AD DS

What Is New for Windows Server 2012 Active Directory? In Windows Server 2012 AD, it is easier to Detect events such as a snapshot rollback Install and configure cloned virtual machines Prepare the system before installing or upgrading domain controllers Use Windows PowerShell scripts to automate multiple AD DS installations Control who can access resources Recover objects from the Active Directory Recycle Bin Use and manage the RID pool Defer index creation

What Is New for Windows Server 2012 R2 Active Directory? Improvements for using consumer devices Workplace Join in the enterprise: Allows consumer devices to participate in the domain Web Application Proxy Allows applications to be published to the Internet Multi-Factor Access Control Allows claims using different factors Multi-Factor Authentication Allows you to specify the use of multiple factors for authentication

Microsoft Official Course Thanks! 如 有 疑 问 请 与 我 联 系 :10804072

Lesson 2: Overview of Domain Controllers What Is a Domain Controller? What Is the Global Catalog? The AD DS Sign-in Process Demonstration: Viewing the SRV Records in DNS What Are Operations Masters?

What Is a Domain Controller? Domain controllers Servers that host the AD DS database (Ntds.dit) and SYSVOL Kerberos authentication service and KDC services perform authentication Best practices: Availability: At least two domain controllers in a domain Security: RODC and BitLocker

What Is the Global Catalog? Schema Configuration Domain A Domain B Schema Configuration Domain A The global catalog: Hosts a partial attribute set for other domains in the forest Supports queries for objects throughout the forest Schema Configuration Global catalog server Domain B Schema Configuration AD DS Domain B

The AD DS Sign-in Process The AD DS sign-in process: 1. The user account is authenticated to the domain controller. 2. The domain controller returns a TGT back to client. 3. The client uses TGT to apply for access to the workstation. 4. The domain controller grants access to the workstation. 5. The client uses TGT to apply for access to the server. 6. The domain controller returns access to the server. Workstation Domain controller Server

Demonstration: Viewing the SRV Records in DNS In this demonstration, you will see how to use DNS Manager to view SRV records

What Are Operations Masters? In the multi-master replication model, some operations must be single master Many terms are used for single master operations in AD DS, including: Operations master (or operations master roles) Single master roles Flexible single master operations (FSMOs) The five FSMOs are: Forest: Domain naming master Schema master Domain: RID master Infrastructure master PDC Emulator master

Microsoft Official Course Thanks! 如 有 疑 问 请 与 我 联 系 :10804072

Lesson 3: Installing a Domain Controller Installing a Domain Controller from Server Manager Installing a Domain Controller on a Server Core Installation of Windows Server 2012 Upgrading a Domain Controller Installing a Domain Controller by Using Install from Media What Is Windows Azure Active Directory? Deploying Domain Controllers in Windows Azure

Installing a Domain Controller from Server Manager Deployment Configuration section of the Active Directory Domain Services Configuration Wizard

Installing a Domain Controller on a Server Core Installation of Windows Server 2012 Installing AD DS is a two-step process regardless of which installation method you use Method 1, use Server Manager on a Windows 2012 server with a GUI interface to connect to the system 1. Install the files by installing the Active Directory Domain Services role 2. Install the domain controller role by running the Active Directory Domain Services Configuration Wizard Method 2, Use Windows PowerShell locally, or remotely using WinRM 1. Install the files by running the command Install-WindowsFeature AD-Domain-Services 2. Install the domain controller role by running the command Install-ADDSDomainController

Upgrading a Domain Controller Options to upgrade AD DS to Windows Server 2012: In-place upgrade from Windows Server 2008 to Windows Server 2012 Benefit: Except for the prerequisite checks, all the files and programs stay in place and there is no additional work required Risk: May leave legacy files and DLLs Introduce a new Windows Server 2012 server into the domain and promote it to be a domain controller This option is usually preferable Benefit: The new server has no accumulated legacy files and settings Risk: May need additional work to migrate administrators files and settings

Installing a Domain Controller by Using Install from Media Install from Media section on the Additional Options page of the Active Directory Domain Services Configuration Wizard

What Is Windows Azure Active Directory? Exchange Online SharePoint Online Office 365 Windows Azure Active Directory Lync Online Windows Azure Apps Internet On-premises AD DS Internet connected apps

Deploying Domain Controllers in Windows Azure Windows Server 2012 is cloud-ready and virtualization safe Considerations for deploying in Windows Azure include: Rollback Resource limitations Virtualization considerations for deploying AD DS Time synchronization Single point of failure

Lab: Installing Domain Controllers Exercise 1: Installing a Domain Controller Exercise 2: Installing a Domain Controller by Using IFM Logon Information Virtual machines User name Password 20410D-LON-DC1 20410D-LON-SVR1 20410D-LON-RTR 20410D-LON-SVR2 Adatum\Administrator Pa$$w0rd Estimated Time: 50 minutes

Lab Scenario Your manager has asked you to install a new domain controller in the datacenter to improve sign-in performance and to create a new domain controller for a branch office by using IFM

Lab Review Why did you use Server Manager and not dcpromo when you promoted a server to be a domain controller? What are the three operations masters found in each domain? What are the two operations masters that are present in a forest? What is the benefit of performing an IFM install of a domain controller?

Module Review and Takeaways Review Questions

Microsoft Official Course Thanks! 如 有 疑 问 请 与 我 联 系 :10804072