active directory fundamentals - aaneotech.com · • active directory concepts • domains, trees,...

64
Active Directory Fundamentals

Upload: phamthien

Post on 05-Jan-2019

235 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Active Directory Fundamentals

Page 2: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

What Will We Cover?

• Active Directory concepts

• Domains, trees, forests

• Domain controllers, sites

• Domain Naming Service

• Replication

• Operations masters

Page 3: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Helpful Experience

Level 200

• Experience with the Windows user interface

• Experience supporting Microsoft networks

Page 4: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Agenda

• Logical Concepts of Active Directory

• Physical Concepts of Active Directory

• DNS in 10 Minutes

• Overview of Active Directory Replication

• The role played by Operations Masters

Page 5: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

What Is a Directory Service?A service that helps track and locate objects on a network A service that helps track and locate objects on a network

Active Directory Management

Page 6: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

What Is a Directory Service?A service that helps track and locate objects on a network A service that helps track and locate objects on a network

Active Directory Management

UsersUsersServicesServicesWorkstationsWorkstations FilesFiles

Page 7: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Active Directory Domains

CONTOSO.COM

Page 8: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Active Directory Domains

Boundary of Authentication

CONTOSO.COM

Page 9: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Active Directory Domains

Boundary of Authentication

Boundary of Policies

CONTOSO.COM

Page 10: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Active Directory Domains

Boundary of Authentication

Boundary of Policies

CONTOSO.COM

Boundary of Replication

Page 11: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Active Directory Trees

CONTOSO.COM

US.CONTOSO.COM

OHIO.US.CONTOSO.COM

Page 12: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Active Directory Trees

CONTOSO.COM

US.CONTOSO.COM

SharedSchema

Configuration

Global CatalogOHIO.US.CONTOSO.COM

Page 13: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Transitive Trusts

US.CONTOSO.COM

UK.CONTOSO.COM

CONTOSO.COM

Page 14: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Transitive Trusts

US.CONTOSO.COM

UK.CONTOSO.COM

CONTOSO.COM

Page 15: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Active Directory Forests

US.CONTOSO.COM

FABRIKAM.COM

UK.FABRIKAM.COM

CONTOSO.COM

Schema ConfigurationGlobal Catalog

Page 16: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Demo

Reviewing Domains and Trusts

demonstration

Page 17: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Organizational Units

CONTOSO.COM

Page 18: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Organizational Units

CONTOSO.COM

OU Admin

Organized For:•Administration

•Same Requirements•Delegation

Organized For:•Administration

•Same Requirements•Delegation

Page 19: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Organizational Units

CONTOSO.COM

OU Admin

Organized For:•Administration

•Same Requirements•Delegation

•Group Policy•Configuration

Organized For:•Administration

•Same Requirements•Delegation

•Group Policy•Configuration

OU Policy

Page 20: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Organizational Units

CONTOSO.COM

OU Admin

Organized For:•Administration

•Same Requirements•Delegation

•Group Policy•Configuration•Security

Organized For:•Administration

•Same Requirements•Delegation

•Group Policy•Configuration•Security

OU PolicyOU Security

Page 21: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Organizational Unit Applications

Sales Department Marketing Department

Page 22: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Organizational Unit Applications

London New York

Page 23: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Organizational Unit Applications

Desktops Printers

Page 24: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Organizational Unit Applications

Hardware Devices

Desktops Printers

Page 25: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Demo

Using Organizational UnitsReview Organizational UnitsCreate New Organizational Units

demonstration

Page 26: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Agenda

• Logical Concepts of Active Directory

• Physical Concepts of Active Directory

• DNS in 10 Minutes

• Overview of Active Directory Replication

• The role played by Operations Masters

Page 27: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Domain Controllers

Windows NT 4.0

BDCBDC

PDC

Page 28: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Domain Controllers

Windows NT 4.0 Windows Server 2003

DC

DCBDCBDC DC

PDC

Page 29: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Active Directory Sites

WAN Link

Site B

Site A

Page 30: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Active Directory Sites

WAN Link

Site B

Site A

Sites Used To:•Locate Services

Sites Used To:•Locate Services

Page 31: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Active Directory Sites

WAN Link

Site B

Site A

Sites Used To:•Locate Services•Optimize Replication

Sites Used To:•Locate Services•Optimize Replication

Page 32: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Active Directory Sites

WAN Link

Site B

Site A

Sites Used To:•Locate Services•Optimize Replication•Define Policies

Sites Used To:•Locate Services•Optimize Replication•Define Policies

Page 33: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Sites and Domains

Site A

Site B

Page 34: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Sites and Domains

CONTOSO.COM

Site A

Site B

US.CONTOSO.COM

Page 35: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Global Catalog

• Spans all domains

• Contains object attributes

• Used for searches

• Exists on domain controllers

Page 36: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Demo

Using Sites and Global CatalogsCreate a SiteReview Global Catalog SettingsChoose Global Catalog Attributes

demonstration

Page 37: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Agenda

• Logical Concepts of Active Directory

• Physical Concepts of Active Directory

• DNS in 10 Minutes

• Overview of Active Directory Replication

• The role played by Operations Masters

Page 38: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

DNSDomain Naming System locates network services and resources.Domain Naming System locates network services and resources.

DNS Request Process

•Requested Service•Site Information

DCDCDNS ServerDNS Server

Page 39: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

DNSDomain Naming System locates network services and resources.Domain Naming System locates network services and resources.

DNS Request Process

•Requested Service•Site Information

•IP Addresses•SVR Records

DCDCDNS ServerDNS ServerCacheCache

Page 40: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

DNSDomain Naming System locates network services and resources.Domain Naming System locates network services and resources.

DNS Request Process

•Requested Service•Site Information

•IP Addresses•SVR Records

DCDCDNS ServerDNS ServerCacheCache

Page 41: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

DNS Systems and RequirementsBIND 8.1.2

Secure Update

SRV Records*

AD Integration

Dynamic Update*

* Required for Active Directory

Windows NT

Windows 2000

Windows Server 2003

Page 42: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

DNS Migration

• Upgrade to BIND 9.x

• Upgrade to Microsoft DNS

• Delegate to Microsoft DNS

Page 43: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Demo

Working with DNSReview DNS ZonesReview Host Records and Dynamic Update

demonstration

Page 44: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Agenda

• Logical Concepts of Active Directory

• Physical Concepts of Active Directory

• DNS in 10 Minutes

• Overview of Active Directory Replication

• The role played by Operations Masters

Page 45: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Replication Scope

Across Forest:•Schema NC

Page 46: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Replication Scope

Across Forest:•Schema NC•Configuration NC

Page 47: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Replication Scope

Across Forest:•Schema NC•Configuration NC

Across Domain•Domain NC

Page 48: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

More Replication Scope

Intrasite(Token Ring)

Page 49: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

More Replication Scope

Intersite(Compressed)

Intrasite(Token Ring)

Page 50: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Demo

Working with ReplicationEnable ReplicationReview Replication

demonstration

Page 51: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Agenda

• Logical Concepts of Active Directory

• Physical Concepts of Active Directory

• DNS in 10 Minutes

• Overview of Active Directory Replication

• The role played by Operations Masters

Page 52: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Operations Masters

• Performs operation exclusively

• Within designated scope

• Defaults to first domain controller

Page 53: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Operations Master RolesForest Roles

Schema MasterSchema Master

Domain MasterDomain Master

Page 54: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Operations Master RolesDomain RolesForest Roles

PDC EmulatorPDC EmulatorSchema MasterSchema Master

Domain MasterDomain Master

RID MasterRID Master

InfrastructureInfrastructure

Page 55: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Session Summary

• Manage and control your network resources more easily with OUs.

• Upgrade to the free Microsoft DNS package for enhanced integration.

• Active Directory replication protects data and optimizes network traffic.

Page 56: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

For More Information

www.microsoft.com/technet/ADD-01or

technet.microsoft.com/ADD-01

Visit TechNet atwww.microsoft.com/technet

Visit the following URL for additional information

Page 57: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Microsoft Press Publications

For the latest titles, visitwww.microsoft.com/learning/books/itpro/

Page 58: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

These books can be purchased at all major bookstores and online retailers.

Non-Microsoft Publications

Page 59: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Course ID Title

2199 Jumpstart: Active Directory Fundamentals

2282 Designing a Microsoft Windows Server 2003 Active Directory and Network Infrastructure

For training information and availability www.microsoft.com/learning

Training Resources

Page 60: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Readiness with Skills Assessment• Self-study learning tool free to anyone• Determines skills gaps• Provides learning plans• Post your score; see how you stack up

Visitwww.microsoft.com/assessment

Page 61: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Become a Microsoft Certified Professional• What are MCP certifications?

Validation in performing critical IT functions• Why certify?

Worldwide recognition of skills gained through experienceMore effective deployments with reduced costs for your organizations

• What certifications are there for IT pros?MCP, MCSE, MCSA, MCDST, MCDBA

www.microsoft.com/learning/mcp

Page 62: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

www.microsoft.com/technet/subscriptions

Heard the News about TechNet?

• Software without time limits

• Complimentary technical support

• The most current resources on hand

Page 63: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

Find all these support options at www.microsoft.com/technet/supportMicrosoft offers a progressive series of support options starting with no-charge online support and developing through subscription, incident, and contract support.

1. No-Charge Online Support

Knowledge BaseSearch a vast database of articles to pinpoint the information you need.

NewsgroupsAccess over 20,000 active newsgroups on scores of topics.

Product Support CentersGet answers to frequently asked questions, plus how-to articles and step-by-step instructions organized by product.

DLL Help Database Search here to identify the software used to install a specific DLL version.

Events and Errors Message CenterResolve event and error messages fast with explanations, recommendations, and links to support and resources.

Support WebcastsTune in to live technical presentations by Microsoft experts and take part in real-time Q&A.

ChatsChat online with Microsoft specialists or search the transcript archives.

User Group ProgramAccess information and support for IT and other interest-specific user groups.

TechNet Security Resource CenterGet ahead of security risks with resources that keep you current, including security newsletters and the Microsoft notification service.

2. Subscription-Based Support

TechNet SubscriptionSubscribe to TechNet for a personal library of articles, service packs, how-tos, resource kits, tools, utilities, and more. Your subscription includes monthly updates delivered on CD or DVD, so you always have the latest information, straight from the source.

Upgrade to a TechNet Plus subscription and add all this:

1. Full-version evaluation software, including Microsoft Office System and Windows Server System™ products, without time restrictions.

2. Free support — two complimentary incidents, plus a discount on other support calls.

3. Unlimited, next-business-day access to reliable answers from the IT community and Microsoft Support Professionals through Managed Newsgroups (English only).

3. Assisted Incident Support

E-mail SupportGet online incident help via e-mail from a Microsoft Support Professional.

Phone SupportGet incident help over the phone from a Microsoft Support Professional.

Phone Support ContractSave with a discounted 5-Pack Phone Support contract.

Advisory ServicesAdd remotely delivered consultation options from Microsoft Advisory Services for proactive support that goes far beyond routine product maintenance.

4. Contract-Based Support

Premier SupportGet the flexibility to match support options to your organization and enjoy direct access to Microsoft technical experts at any time, day or night. Premier Support delivers customized options for businesses with complex needs, including dedicated technical professionals to overseeyour support, 24x7 problem resolution, and training and workshops that keep your IT staff up to date.

Essential SupportEssential Support offers prepackaged options specifically designed to meet the fundamental support requirements of any business, large or small. Includes account management, problem resolution, and information services.

Page 64: Active Directory Fundamentals - aaneotech.com · • Active Directory concepts • Domains, trees, forests • Domain controllers, sites • Domain Naming Service • Replication

• Free chats and webcasts• List of newsgroups• Microsoft community sites• Community events and columns

Where Else Can I Get Help?

www.microsoft.com/technet/community