Active Directory in Windows Server 2008 R2: What s New?



Similar documents
WELCOME TO TECH IMMERSION

WS 2008 R2 Active Directory: Diving in to the core

Windows Server 2008 R2: What's New in Active Directory

Microsoft. Jump Start. M11: Implementing Active Directory Domain Services

Configuring Windows Server 2008 Active Directory

Module 4. Managing Groups. Contents: Lesson 1: Overview of Groups 4-3. Lesson 2: Administer Groups Lab A: Administer Groups 4-36

6425C - Windows Server 2008 R2 Active Directory Domain Services

MS-6425C - Configuring Windows Server 2008 Active Directory Domain Services

R4: Configuring Windows Server 2008 Active Directory

70-417: Upgrading Your Skills to MCSA Windows Server 2012

Quality Management Consultancy

Course 6425C: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Active Directory Deployment and Management Enhancements

Exam : Administrating Windows Server 2012 R2. Course Overview

Installing, Configuring, and Managing a Microsoft Active Directory

PowerShell 3.0 Advanced Administration Handbook

Configuring and Troubleshooting Windows 2008 Active Directory Domain Services

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Course 6425C: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Automating Microsoft

Windows Server 2012 AD Backup and Disaster Recovery Procedures

NE-6425C Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

6425C: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Integrating LANGuardian with Active Directory

Windows 10 and Enterprise Mobility

Course 6425C: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Windows Server 2008R2 AD Backup and Disaster Recovery Procedures

MS 6419 Configuring, Managing and Maintaining Windows Server 2008-based Servers

Active Directory Friday: All Articles. Jaap Brasser

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain MOC 6425

Lesson Plans Microsoft s Managing and Maintaining a Microsoft Windows Server 2003 Environment

Symantec NetBackup Blueprints

Click Studios. Passwordstate. Password Discovery, Reset and Validation. Requirements

Course 6425C: Five days

Course 6425C: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Get Success in Passing Your Certification Exam at first attempt!

How to Create a Delegated Administrator User Role / To create a Delegated Administrator user role Page 1

Securing Active Directory Presented by Michael Ivy

Windows Server 2012 AD Backup and Disaster Recovery Procedures

Exam : Installing and Configuring Windows Server 2012

Introducing. Markus Erlacher Technical Solution Professional Microsoft Switzerland

EXAM Designing and Implementing a Server Infrastructure. Buy Full Product.

Outline SSS Microsoft Windows Server 2008 Hyper-V Virtualization

External Authentication with Citrix Secure Gateway - Presentation server Authenticating Users Using SecurAccess Server by SecurEnvoy

Cisco ASA. Administrators

SharePoint Backup Guide

Planning and Implementing Windows Server 2008

Configuring, Managing and Maintaining Windows Server 2008-based Servers

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Dell Recovery Manager for Active Directory 8.6. User Guide

System Compatibility. Enhancements. Security. SonicWALL Security Appliance Release Notes

Course 6419B: Configuring, Managing and Maintaining Windows Server 2008-based Servers

Step-by-Step Guide for Microsoft Advanced Group Policy Management 4.0

"Charting the Course to Your Success!" MOC B Configuring and Administering Microsoft SharePoint Course Summary

Windows 7, Enterprise Desktop Support Technician

LT Auditor Windows Assessment SP1 Installation & Configuration Guide

Updating Your Network Infrastructure and Active Directory Technology Skills to Windows Server 2008

OVERVIEW OF TYPICAL WINDOWS SERVER ROLES

Configuring Sponsor Authentication

Windows 7, Enterprise Desktop Support Technician Course 50331: 5 days; Instructor-led

OPAS Prerequisites. Prepared By: This document contains the prerequisites and requirements for setting up OPAS.

Documentation. CloudAnywhere. Page 1

About Recovery Manager for Active

Windows Server. Introduction to Windows Server 2008 and Windows Server 2008 R2

Course Description. Course Audience. Course Outline. Course Page - Page 1 of 12

Installation & Configuration Guide

CLI Commands and Disaster Recovery System

ADMT v3.1 Guide: Migrating and Restructuring Active Directory Domains

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

NETASQ SSO Agent Installation and deployment

Course 6425B: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

"Charting the Course to Your Success!" MOC D Windows 7 Enterprise Desktop Support Technician Course Summary

Dell Spotlight on Active Directory Deployment Guide

Dell Recovery Manager for Active Directory 8.6.0

Using Delphix Server with Microsoft SQL Server (BETA)

NetIQ Advanced Authentication Framework - Administrative Tools. Installation Guide. Version 5.1.0

Copyright

NetIQ Advanced Authentication Framework. Maintenance Guide. Version 5.1.0

Step-By-Step Guide to Deploying Lync Server 2010 Enterprise Edition

Security Provider Integration Kerberos Authentication

Websense Support Webinar: Questions and Answers

Windows" 7 Desktop Support

Implementing Microsoft Azure Infrastructure Solutions

המרכז ללימודי חוץ המכללה האקדמית ספיר. ד.נ חוף אשקלון טל' פקס בשיתוף עם מכללת הנגב ע"ש ספיר

Microsoft. Jump Start. M3: Managing Windows Server 2012 by Using Windows PowerShell 3.0

TestOut Course Outline for: Windows Server 2008 Active Directory

Installation and Deployment in Microsoft Dynamics CRM 2013

Active Directory Objectives

Course Outline. Course 6419 : Configuring, Managing and Maintaining Windows Server 2008-based Servers. Duration: 5 Days

SharePoint 2013 Logical Architecture

Transcription:

Active Directory in Windows Server 2008 R2: What s New? Siddharth Bhai Program Manager Microsoft Corporation Presented at Seattle Windows Networking User Group May 6, 2009

Tour the Active Directory features in Windows Server 2008 R2 Encourage you to want to learn more about these features Demonstrate the value Windows Server 2008 R2 offers

What s new in Active Directory? PowerShell Cmdlets Active Directory Administrative Center Best Practice Analyzer Active Directory Web Services Recycle Bin for AD Managed Service Accounts Offline Domain Join Authentication Assurance Health Model

C L I E N T GUI MM C ADUC/ADSS/ADDT DS RPC-Based Protocols SAM DSR ADSI.NET AD PowerShell LDAP BPA WSH WCF CLI AD Admin Center MUX WPF GUI.NET S E WCF AD Web Services.NET R V E DS RPC-Based Protocols SAM DSR.NET S.DS.P / S.DS.AM / S.DS.AD LDAP R AD Core

Past limitations Hodgepodge of command line tools for administration and configuration Difficult to compose to achieve complex tasks Feature takeaways Comprehensive set of AD cmdlets for AD DS and AD LDS administration and configuration Brings the power and flexibility of PowerShell core to AD Consistency with other server roles

Consistent vocabulary and syntax Verbs Add, New, Get, Set, Remove, Clear Nouns ADObject, ADUser, ADComputer, ADDomain, ADForest, ADGroup, ADAccount, ADDomainController, Easily discovered No need to find, install, or learn other tools, utilities or commands Flexible output Output from one cmdlet easily consumed by another Easily composed Create higher level tools for complex operations Leverage.Net Framework All the capabilities of.net Framework End-to-End manageability With other roles such as Exchange, Group Policy, etc

Add-ADComputerServiceAccount Add-ADDomainControllerPasswordReplicationPolicy Add-ADFineGrainedPasswordPolicySubject Add-ADGroupMember Add-ADPrincipalGroupMembership Clear-ADAccountExpiration Disable-ADAccount Disable-ADOptionalFeature Enable-ADAccount Enable-ADOptionalFeature Get-ADAccountAuthorizationGroup Get-ADAccountResultantPasswordReplicationPolicy Get-ADComputer Get-ADComputerServiceAccount Get-ADDefaultDomainPasswordPolicy Get-ADDomain Get-ADDomainController Get-ADDomainControllerPasswordReplicationPolicy Get- ADDomainControllerPasswordReplicationPolicyUsag e Get-ADFineGrainedPasswordPolicy Get-ADFineGrainedPasswordPolicySubject Get-ADForest Get-ADGroup Get-ADGroupMember Get-ADObject Get-ADOptionalFeature Get-ADOrganizationalUnit Get-ADPrincipalGroupMembership Get-ADRootDSE Get-ADServiceAccount Get-ADUser Get-ADUserResultantPasswordPolicy Install-ADServiceAccount Move-ADDirectoryServer Move-ADDirectoryServerOperationMasterRole Move-ADObject New-ADComputer New-ADFineGrainedPasswordPolicy New-ADGroup New-ADObject New-ADOrganizationalUnit New-ADServiceAccount New-ADUser Remove-ADObject Remove-ADComputer Remove-ADGroup Remove-ADUser Rename-ADObject Remove-ADComputerServiceAccount Remove-ADDomainControllerPasswordReplicationPolicy Remove-ADFineGrainedPasswordPolicy Remove-ADFineGrainedPasswordPolicySubject Remove-ADGroupMember Remove-ADOrganizationalUnit Remove-ADPrincipalGroupMembership Remove-ADServiceAccount Reset-ADServiceAccountPassword Restore-ADObject Search-ADAccount Set-ADAccountControl Set-ADAccountExpiration Set-ADAccountPassword Set-ADComputer Set-ADDefaultDomainPasswordPolicy Set-ADDomain Set-ADDomainMode Set-ADFineGrainedPasswordPolicy Set-ADForest Set-ADForestMode Set-ADGroup Set-ADObject Set-ADOrganizationalUnit Set-ADServiceAccount Set-ADUser Uninstall-ADServiceAccount Unlock-ADAccount

Past limitations Non task-oriented UI causes customer pain Representation in MMC not scalable for large datasets Limited to managing one domain at a time Feature takeaway Task oriented administration model, with support for larger datasets and progressive disclosure of data Consistency between CLI and UI capabilities Navigation experience designed to support multidomain, multi-forest environments Foundation for future UI enhancements

PowerShell based Task Oriented Multi-Domain Multi-Forest Foundational Progressive Disclosure

Past Limitations LDAP/RPC protocol used for administration and configuration Lack of developer experience in Visual Studio Feature Takeaways Built using WCF and WS* protocols WS-Enum, WS-Transfer, IMDA Replaces LDAP and RPC for remote administration Not intended for developer consumption in this release Simpler firewall management Web Service listening on port 9389

Feature takeaways Analyzes AD settings that cause most unexpected behavior in customer environments Flags settings/configurations that violate recommended best practices Provides guidance only, does not modify settings User initiates scan, not a monitoring solution Scan can be initiated through Server Manager or from PowerShell directly BPA scan can be initiated from client using PS remoting

Import-Module BestPractices Invoke-BpaModel Microsoft/BestPractices/DirectoryServices Get-BpaResult Microsoft/BestPractices/DirectoryServices

Windows Server 2008 R2 introduces a new Forest and Domain functional level Recycle bin requires WS08 R2 Forest Functional level Required in order to ensure that all DCs preserve attributes necessary for complete object recovery Raising functional level alone has no effect other than allowing optional features to be enabled Assures customer that they can raise functional level without unforeseen side effects Functional level can be lowered only if all optional features are disabled (recycle bin cannot be disabled) Optional features can be enable individually Enable-ADOptionalFeature Target {target} Recycle Bin Feature Scope Forest

Past limitations Accidental deletions are the number #1 cause of AD Disaster\Recovery scenarios Feature takeaways Allows recovery of deleted users, groups, etc Locate deleted object: Get-ADObject Filter {} -IncludeDeletedObjects Recover deleted object: Restore-ADObject -Identity {id} All attributes are automatically restored Including well know & problematic Linked Attributes Description, password, group membership, etc.

Windows Server 2008 No Recycle bin feature Live Object Tombstone Object Garbage Collection Windows Server 2008 R2 with Recycle Bin enabled Live Object Deleted Object Recycled Object Garbage Collection

What s the impact on DIT size? Anticipate growth of 5-10% when new DC is installed Subsequent growth depends on size and frequency of object deletions Deleted Object Lifetime (DOL) DOL = TSL = 180 days (by default) Both can be modified independently Attributes: msds-deletedobjectlifetime, tombstonelifetime How does this affect my back up strategy? Backups remain valid for the lesser of DOL or TSL How do I permanently delete an object? Delete the object from the Deleted Objects container Get-ADObject Filter {} IncludeDeletedObjects Remove-ADObject

Past limitations Running multiple services under Built in accounts does not provide service isolation Running service under user account requires cumbersome password management Feature takeaways Managed Service Accounts provide the isolation that services need along with automatic password management Lowers TCO through reduced service outages (for manual password resets and related issues) Use one Managed Service Account per Service per Server Service account can not be shared by multiple machines Better SPN management available with in WS08 R2 Domain Functional Mode Example: On server renaming, SPNs on installed service accounts updated accordingly.

Requires one WS08 R2 domain controller Create necessary Managed Service Accounts New-ADServiceAccount Name {name} Path {path} Optionally delegate management of service account Install service accounts on local server Install-ADServiceAccount Identity {id} Configure services to use managed service accounts No need to manage service account passwords Traditionally a reoccurring and time consuming operation

Past limitations Inability to prepare the machine to be domain joined while offline Feature takeaways Ability to pre-provision machine accounts in the domain to prepare OS images for mass deployment Machines are domain joined on initial boot without network connectivity Reduces steps and time needed to deploy in the data center Requires Win7 client and only one WS08 R2 member server

Past limitations Customers cannot use authentication type or authentication strength to protect corporate data Example: control access to resources based on claims such as use of smartcard for logon or the certificate used 2048 bit encryption Feature takeaways Administrators can map certificate issuance policies to groups which applications can then use to control access to resources Based on information obtained during authentication, these additional credential attributes are added to Kerberos tickets and used by claims aware applications as authorization data Requires Windows Server 2008 R2 domain functional level All domain controllers in the domain need to be WS 2008 R2 DCs

Past limitations Diagnostic information is often incomplete and inconsistent Feature takeaways Continued investment towards completing the health model Track event viewer A single authoritative source for information used in Management Packs, Best Practice Analyzer and online documentation

Upgrading to Windows 7 client while keeping existing servers, you can use: Offline domain join Once AD Web-service is available for existing servers, if you upgrade to Windows 7 client, you can use: AD PowerShell and ADAC for remote management of your servers Upgrading to Windows 7 client while installing one or more Windows Server 2008 R2 (one per domain), you can use: Managed Service Accounts If you change the domain functional level to Windows Server 2008 R2, you can use: Authentication Mechanism Assurance Managed service account with an enhanced SPN management experience If you change the Forest functional level to Windows Server 2008 R2, you can use: Recycle Bin

http://technet.microsoft.com/en-us/library/dd378801.aspx