What we are going to cover...



Similar documents
Introduction to Active Directory. December 10th, pm Daniels 407

WolfTech Active Directory: OU Administration

WolfTech Active Directory: SCCM 101

70-685: Enterprise Desktop Support Technician

Windows 7, Enterprise Desktop Support Technician

MS Exam Objectives Administering Windows Server 2012 R2

Planning for Windows Server 2008 Servers

MCTS Guide to Microsoft Windows 7. Chapter 13 Enterprise Computing

IT SYSTEMS ADMINISTRATOR PROGRAM

411-Administering Windows Server 2012

Installation Guide. . All right reserved. For more information about Specops Deploy and other Specops products, visit

Configuring, Managing and Maintaining Windows Server 2008 Servers

WolfTech Active Directory: SCCM 101

WolfTech Active Directory: Diagnostic Tools

Windows 7, Enterprise Desktop Support Technician Course 50331: 5 days; Instructor-led

Training Name Installing and Configuring Windows Server 2012

Implementing and Administering Windows Small Business Server 2008

"Charting the Course to Your Success!" MOC D Windows 7 Enterprise Desktop Support Technician Course Summary

This module explains how to configure and troubleshoot DNS, including DNS replication and caching.

MOC 20413C: Designing and Implementing a Server Infrastructure

Windows 7, Enterprise Desktop Support Technician

Configuring Managing and Maintaining Windows Server 2008 Servers (6419B)

Planning and Implementing Windows Server 2008

Administering Windows Server 2012

SINGLE COURSE. 136 Total Hours. After completing this course, students will be able to:

Designing and Implementing a Server Infrastructure

6419: Configuring, Managing, and Maintaining Server 2008

Administering Windows Server 2012

6445A - Implementing and Administering Windows Small Business Server 2008

MCITP MCITP: Enterprise Administrator on Windows Server 2008 (5 Modules)

70-417: Upgrading Your Skills to MCSA Windows Server 2012

MOC 6419: Configuring, Managing, and Maintaining Windows Server 2008

Windows" 7 Desktop Support

Designing and Implementing a Server Infrastructure

Module 3: Resolve Software Failure This module explains how to fix problems with applications that have problems after being installed.

Managing Windows Environments with Group Policy 50255D; 5 Days, Instructor-led

Designing and Implementing a Server Infrastructure

MS-50255: Managing, Maintaining, and Securing Your Networks Through Group Policy. Course Objectives. Required Exam(s) Price.

Designing and Implementing a Server Infrastructure

VNLINFOTECH JOIN US & MAKE YOUR FUTURE BRIGHT. mcsa (70-413) Microsoft certified system administrator. (designing & implementing server infrasturcure)

MOC 6435A Designing a Windows Server 2008 Network Infrastructure

Course Description. Course Audience. Course Outline. Course Page - Page 1 of 12

MCSA Instructor-led Live Online Training Program. Course Outline MCSA Deploying and Managing Windows Server 2012

Administering Windows Server 2012

Designing and Implementing a Server Infrastructure

INUVIKA OPEN VIRTUAL DESKTOP FOUNDATION SERVER

Configuring, Managing and Maintaining Windows Server 2008 Servers

Configuring, Managing and Maintaining Windows Server 2008 Servers

20413C: Designing and Implementing a Server Infrastructure

COURSE 20413C: DESIGNING AND IMPLEMENTING A SERVER INFRASTRUCTURE

Designing and Implementing a Server Infrastructure MOC 20413

OVERVIEW OF TYPICAL WINDOWS SERVER ROLES

M6419 Configuring, Managing and Maintaining Windows Server 2008 Servers

Charles Firth Managing Macs in a Windows World

Course 6419A: Configuring, Managing and Maintaining Windows Server 2008 Servers

R4: Configuring Windows Server 2008 Active Directory

Designing and Implementing a Server Infrastructure 20413C; 5 days, Instructor-led

Course Description. Course Page - Page 1 of 9. Administering Windows Server 2012 M Length: 5 days Price: $2,795.00

Parallels Mac Management for Microsoft SCCM

Exam : Administrating Windows Server 2012 R2. Course Overview

Course 20413: Designing and Implementing a Server Infrastructure

MCSA Windows Server 2008 Active Directory, Configuring:

6445A - Implementing and Administering Small Business Server 2008

Table Of Contents. - Microsoft Windows - WINDOWS XP - IMPLEMENTING & SUPPORTING MICROSOFT WINDOWS XP PROFESSIONAL...10

Desingning and Implementing a Server Infrastructure

Managing Windows Environments with Group Policy

MCSA/MCITP: Enterprise Windows Server 2008 Course 9952; 14 Days, Instructor-led

Designing a Windows Server 2008 Network Infrastructure

SCCM How to guide deploying SCCM Client, setting up SUP and SCEP. Hans Chr. Andersen

Administering Windows Server 2012

AV-006: Installing, Administering and Configuring Windows Server 2012

Designing and Implementing a Server Infrastructure

Deploying BitDefender Client Security and BitDefender Windows Server Solutions

Module 1: Overview of Network Infrastructure Design This module describes the key components of network infrastructure design.

Administering Windows Server 2012

MS 20413A: Designing and Implementing a Server Infrastructure

Designing and Implementing a Server Infrastructure

Designing and Implementing a Server Infrastructure Course#20413B

MCSA Objectives. Exam : TS:Exchange Server 2007, Configuring

You need to recommend a monitoring solution to ensure that an administrator can review the availability information of Service1. What should you do?

Course 6331A: Deploying and Managing Microsoft System Center Virtual Machine Manager

Windows 7, Enterprise Desktop Support Technician

50331D Windows 7, Enterprise Desktop Support Technician (Windows 10 Curriculum)

Microsoft Exam

Administering Windows Server 2012

Implementing and Managing Microsoft Server Virtualization

COURSE 20411D: ADMINISTERING WINDOWS SERVER 2012

Windows Firewall Configuration with Group Policy for SyAM System Client Installation

Best Practices: Integrating Mac OS X with Active Directory. Technical White Paper April 2009

MCSE Objectives. Exam : TS:Exchange Server 2007, Configuring

Administering Windows Server 2012

Transcription:

Introduction to WolfTech Active Directory 6 October 2011 10am-12pm Daniels 201 http://activedirectory.ncsu.edu

What we are going to cover... What AD is and isn't The WolfTech implementation of AD Management Tools The basics of Active Directory Management Concepts Services Provided within WolfTech AD Additional Services Q & A

Active Directory is... A directory service that provides the ability for centralized: Authentication Authorization Management Active Directory is based on the MIT Athena model. It makes use of SMB, LDAP, and Kerberos. SMB (or CIFS) is a network file sharing protocol common to all recent Windows OS's. LDAP is an standard method to access information from a remote database, does not define what sorts of info are stored or how it should be stored, only how to access it. Kerberos is a network authentication protocol designed by MIT with strong cryptography and a limited attack surface. Active Directory uses multi-master replication to have all directory data on the Domain Controllers (DC's). If one fails, services are still available.

Active Directory isn't... A 100% solution A desktop environment Microsoft only The same as Novell 100% Automatable A true identity management system (as implemented at NCSU) Perfect

WolfTech Active Directory Implementation Framework Opt-in: Applications Imaging Remote Desktop/Assistance Defaults: OU Structure Enterprise Client Policies Patching Reports - WSUS and DNS Delegation Governance Community Support

Management Tools Remote Server Administration Toolkit (RSAT) includes: Active Directory Users and Computers (ADUC) Group Policy Management Console (GPMC) Group Policy Editor DFS Management Console Domain-wide Administration: Active Directory Sites and Services Active Directory Domains and Trusts Active Directory Certificate Services ADToolkit System Center Configuration Manager WDS/WSUS

AD Objects Organizational Units Computers Users Groups Links (publishing): File Shares Printer Shares

Authentication Natively supports: Kerberos (Version 5) NTLMv2 LDAP Smart Cards/Certificates Client machines authenticate as well, not just user accounts Extendable to include: Biometrics Mac, Linux clients can authenticate against AD Limitations: Can't access DFS, Group Policy Some specific authentication/authorization differences

AD Objects: Groups Groups are key to any good permissions model Active Directory supports Nested Groups Concepts: Identity Groups Resource Groups Users -> Identity Group -> Resource Group -> Permissions Examples of Default Groups (Users vs. Computers): Computers: Software Groups Computers: Enable Remote Desktop/Assistance Users: ACS Users Users: OU/Computer Admins

Authorization Delegation Wizard: Types of Permissions: Directory GPO's Manage Groups Machine Local/Remote Login User vs. Admin Group Policy allows setting any local permission ADUC - Demo

Management Concepts Domain Structure OU structure User/Computer Locations Grouping Strategy Group Policy Linking Filtering Groups WMI Filters Copying GPO's Group Policy - Resultant Set of Policy

Policies vs. Preferences Policies: Policies usually cannot be changed by end user Configuring IE Deploying Software Configuring Desktop Experience Preferences: End user override optional per setting Pushing Files/Reg Keys/Shortcuts/Drive Mappings Item-Level Targeting Hardware, Software AD Info, Networking Both have User and Computer Settings Loopback - Process User settings using Computer location GPMC - Demo

Group Policy Examples Remote Assistance - Policy Remote Administration - Policy Configure Wireless - Policy Configure Firewall - Policy Configure FileSystem/Registry/Service Permissions - Policy Deploy Printers - Policy or GPP Deploy Software - Policy (.msi's) or SCCM Deploy Scheduled Tasks - GPP Startup/Shutdown/Logon/Logoff Scripts - Policy or GPP Mapped Drives - GPP Power Settings - GPP or SCCM

Services Provided within WolfTech AD Domain Controllers - Accounts, Group Policy, DR, etc. Distributed File System Certificate Services Windows Deployment Services Application Packaging Windows Software Update Services ADToolkit: Reporting / WTMG System Center Configuration Manager

ADToolkit http://www.wolftech.ncsu.edu/adtoolkit/ Software Provided by WolfTech IT to assist OU Admins: Reporting DNS Errors, Patch Status, Naming Convention issues, Group Changes, Bitlocker usage, etc... On-Demand and can be Automated for daily/weekly reports to you or your Remedy queue. Tools to manage / monitor your software deployments User / Group Search Management of WT Managed Groups (groups automatically updated from HR + Registration/Records) Statistics (and pretty pie charts) Unlock Accounts

Distributed File System (DFS) DFS is a Network File System Roots (Namespaces) Delegation Folders Create Arbitrary structure Targets Where the files really are Multi-Master Replication Groups

Windows Distribution Services (WDS) Imaging service for Windows 7, 2008 R2 Server, or custom images Uses PXE (F12) for medialess install Must use one of the following DHCP templates in QIP: WDS-Main, WDS-Centennial, PXE-all Uses WinPE (think Win7 on a CD) as install environment Library of drivers available to all images Additional/New drivers added by OU Admin request GUI tools for setting up: Post-install scripts Joining the domain http://activedirectory.ncsu.edu/services/imaging/windows-deployment-services/

Windows Server Update Services (WSUS) Unified Patch Management for MS Products Apply patches based on grouping Client Side Targeting via Group Policy Early, Normal and Late patch schedules Types of Patches: Service Packs/Security Patches/Bugfixes MS Defender definitions MS Office Patches/Service Packs Add-ons: Windows Media, Silverlight, GPP, etc. Server Products: SQL, IIS, Sharepoint Ability to back out patches per group of machines (not always supported by the patches and rarely utilized) Reporting: ADToolkit Report - Demo http://activedirectory.ncsu.edu/services/patching/

System Center Configuration Manager Inventory Application Deployment Mandatory Self Service Patch Management Microsoft Custom and Third-Party Imaging Power Management Mobile Device Management

Where Can I Go for Help? AD Site http://activedirectory.ncsu.edu Mailing Lists activedirectory@lists.ncsu.edu activedirectory-patches@lists.ncsu.edu wds@lists.ncsu.edu Jabber "activedirectory" on conference.jabber.eos.ncsu.edu Remedy wolftech_ad_technical@remedy.ncsu.edu

Questions?