Active directory bible

anku5757 385 views 205 slides May 10, 2010
Slide 1
Slide 1 of 205
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16
Slide 17
17
Slide 18
18
Slide 19
19
Slide 20
20
Slide 21
21
Slide 22
22
Slide 23
23
Slide 24
24
Slide 25
25
Slide 26
26
Slide 27
27
Slide 28
28
Slide 29
29
Slide 30
30
Slide 31
31
Slide 32
32
Slide 33
33
Slide 34
34
Slide 35
35
Slide 36
36
Slide 37
37
Slide 38
38
Slide 39
39
Slide 40
40
Slide 41
41
Slide 42
42
Slide 43
43
Slide 44
44
Slide 45
45
Slide 46
46
Slide 47
47
Slide 48
48
Slide 49
49
Slide 50
50
Slide 51
51
Slide 52
52
Slide 53
53
Slide 54
54
Slide 55
55
Slide 56
56
Slide 57
57
Slide 58
58
Slide 59
59
Slide 60
60
Slide 61
61
Slide 62
62
Slide 63
63
Slide 64
64
Slide 65
65
Slide 66
66
Slide 67
67
Slide 68
68
Slide 69
69
Slide 70
70
Slide 71
71
Slide 72
72
Slide 73
73
Slide 74
74
Slide 75
75
Slide 76
76
Slide 77
77
Slide 78
78
Slide 79
79
Slide 80
80
Slide 81
81
Slide 82
82
Slide 83
83
Slide 84
84
Slide 85
85
Slide 86
86
Slide 87
87
Slide 88
88
Slide 89
89
Slide 90
90
Slide 91
91
Slide 92
92
Slide 93
93
Slide 94
94
Slide 95
95
Slide 96
96
Slide 97
97
Slide 98
98
Slide 99
99
Slide 100
100
Slide 101
101
Slide 102
102
Slide 103
103
Slide 104
104
Slide 105
105
Slide 106
106
Slide 107
107
Slide 108
108
Slide 109
109
Slide 110
110
Slide 111
111
Slide 112
112
Slide 113
113
Slide 114
114
Slide 115
115
Slide 116
116
Slide 117
117
Slide 118
118
Slide 119
119
Slide 120
120
Slide 121
121
Slide 122
122
Slide 123
123
Slide 124
124
Slide 125
125
Slide 126
126
Slide 127
127
Slide 128
128
Slide 129
129
Slide 130
130
Slide 131
131
Slide 132
132
Slide 133
133
Slide 134
134
Slide 135
135
Slide 136
136
Slide 137
137
Slide 138
138
Slide 139
139
Slide 140
140
Slide 141
141
Slide 142
142
Slide 143
143
Slide 144
144
Slide 145
145
Slide 146
146
Slide 147
147
Slide 148
148
Slide 149
149
Slide 150
150
Slide 151
151
Slide 152
152
Slide 153
153
Slide 154
154
Slide 155
155
Slide 156
156
Slide 157
157
Slide 158
158
Slide 159
159
Slide 160
160
Slide 161
161
Slide 162
162
Slide 163
163
Slide 164
164
Slide 165
165
Slide 166
166
Slide 167
167
Slide 168
168
Slide 169
169
Slide 170
170
Slide 171
171
Slide 172
172
Slide 173
173
Slide 174
174
Slide 175
175
Slide 176
176
Slide 177
177
Slide 178
178
Slide 179
179
Slide 180
180
Slide 181
181
Slide 182
182
Slide 183
183
Slide 184
184
Slide 185
185
Slide 186
186
Slide 187
187
Slide 188
188
Slide 189
189
Slide 190
190
Slide 191
191
Slide 192
192
Slide 193
193
Slide 194
194
Slide 195
195
Slide 196
196
Slide 197
197
Slide 198
198
Slide 199
199
Slide 200
200
Slide 201
201
Slide 202
202
Slide 203
203
Slide 204
204
Slide 205
205

About This Presentation

Active Directory


Slide Content

ABOUT IDG BOOKS WORLDWIDE

Bator

Media Development €
Marisa Pearman

Preface Xi

xvi Content

coments xvii

| xVii Contents |

Contents

xix

contents xxi

CHARTER

In This Chapter

Exploring directory

Examining he Active
Dieciory feanxes

Understanding th
sve Directory
cal anıchre

Parsing forthe
ve Diecory

Part! + Planning an Active Directory Deployme

Chapter 1 + Introduction to Active Directory Technology and Deployment Planning

Part! + Planning an Active Directory Deployme

1 + Introduction to Active Directory Technology and Deployment

Part! + Planning an Active Directory Deployme

1 you have worked in a multple domain NT network you know a thing or two about trust
jonships Tut relationships enable a user in Doman Ato access resourcesin Domain

Windows NT, you had to configure each side of the trust—determining who was

and it gure and manage

ru relationships in Windows 2000. In Windows 2000
ments hat need more than one dom, automatic Kerberos transtve trust are established
hen you crece new domansin the ore ro. Keberosis the seu protocol n Windows
00, replacing NTLM in Windows NT. Kerberos provides superior secu technology and
‘many new socurty features, ke transe rst retionshipa A transtive trust simply means
that Domain A wuss Domain 8, and Domain Brute Domain C then Domain A automalı
ly tuss Domain Ce trantive nut rlaonsnis are automatically configured witha
‘other domains and domain tres within the forest. The forest sores as your boundary and

Chapter 1 + Introduction to Active Directory Technology and Deployment Planning

Part! + Planning an Active Directory Deployme

Chapter 1 + Introduction to Active Directory Technology and Deployment Planning 11

12 Pat + Panning an Active Di

Chapter 1 + Introduction to Active Directory Technology and Deployment Planning 13

14 Pat + Planningan Active Di

Chapter 1 + Introduction to Active Directory Technology and Deployment Planning 15

16 Pati + Planning an Active Directory Deployme

Chapter 1 + Introduction to Active Directory Technology and Deployment Planning 17

18 Part + Planning an Active Directory Deployme

cHarfer

In This Chapter

Descibing a
namespace

Exploring the
ONShierarchy

arcing and
signing fe forest
domain ro

20 Pati + Planning an Active Directory Deploymer

22 Pati + Planning an Active Directory Deploymer

Chapter 2 + The Active Directory

24 Pat! + Planning an Active Directory Deploymer

Directory Namespace 25

26 Pat! + Planningan Active D)

28 Pati + Planning an Active Directory Deploymer

fetve Directory. Suppose your company, Wison Dog Colas
but now wants to change

annot change the root domain thout comple aaling the Active
Directory is a great dire

Pat | + Planning an Active Directory Deploym

SEEN

When designing your Av Directory ro ¡gpesion isto use a name that is

representave 0! and encompasess your ente company and one ha is valable or oser
teme, Even i your company do n À presen
Inthe future, stil recommend thal ou pay the annual fee and ro

‘The nte is il evolving and changing the way we do business Lit because a company
‘means your Internet name and Active Directory names will have tobe diferent. So, my su
pesto 11 reger the name. I's rather insspensiv and can avoid many potenti eves
and problems in he future

Directory Namespace 31

32 Pati + Planning an Active Directory Deploymer

Chapter 2 + The Active Directory

34 Parti + Planning an Active Directory Deploymer

charter

In This Chapter

Understanding Act
Directory domains

Developing a
domain sucio

Organizasonal
Unit sucre

36 Pati + Planning an Active Directory Deploymer

rectory Structure,

Directory Srucure 39

ectory Sruaure 41

42 Pati + Panning an Active Directory Deÿ

ectorySruaure 43

48 Pati + Panning an Active D

ectory Sruaure 49

50 Pati + Planning an Activo D

ctor Sure 51

52 Pari + Planning an Active Directory Deploymer

lanning an Active Directory Structure

hile were on the subject of NT domain limitations, a more serious limit
aM database limit isthe POC. In Windows NT domains, only tne PDC ha

ofthe databace ll BDOS have a read-only copy of the database. This

uses two prob

1. Changes: Only the POC has a witble copy ofthe dtabase. Changes must
made on the PDC, or on BDC thal connecte with the PDC and makes the
the POC database. In large domain spread

several diferent bulléngs.r even

2. Load: The domain can grow only o large because the PO

load. ni can quickly become 100 a

Windows 2000 leaves this legacy behind wi

sole the implementation with your row, whieh soles alto! potential problems!

53

54 Par + Planning an Activo D

ectory Srudure 55

56 Pati + Planning an Active Directory Deploym

ectory Srudure 57

58 Pari + Planning an Active Directory Deploymer

ctor Sruaure 59

60 Pati + Planning an Active Directory Deploymer

curler

In This Chapter

pared
NT dora

Migrating to the
sve Diecory

62 Pati + Planning an Active Directory Deploymer

The POC Emulator prior
atabase, but NT BDOs have no cono 4

ory dea to BOE a ala tre and em using LAN
Manager Replication Seve. (Wind

& funtion a PDG performed, the POC Emultor perorms as well
However, to other Windows 2000 doman controllers, the POC Emulator appears and lune
tions as jus another domain controller. You use the POC Emula her
omain controler to crete, mod. or delete Active Dir sin ac, Ine POC
Emulator role is invisible k a Sees

64

Part! + Planning an Active Directory Deployme

What you have a POC that is geting ld? You do not want to replace 1
ator upgrading 2000, you want Ja PDG as a emple Wi
Because your POC contains your user and group accounts

< thal 1 becomes a simple member server. Beca ory peer

‘computers
Xénon
Exchange 2000

70 Pat! + Planning an Active Directory De

72 Pari + Planing an Active Directory Deploymer

74

Part + Planning an Active Di

76 Pari + Planning an Active Directory Deploymer

78 Pari + Planning an Active Directory Deploymer

CHAPTER

In This Chapter

Understanding Act
Directory ates

Exploring the
necessity of ses

Understanding the
bridgehead

sidering the final
‘ite planning seps

80 Pati + Planning an Active Directory Deploymer

+ Planning Act

82 Pati + Planning an Active Directory Deploym

5 + Planning Act

88 Pati + Planning an Active Directory Deploymer

90 Pati + Planning an Active D)

94 Pat! + Planning an Active D)

5 + Planning Act

96 Pati + Planning an Active Directory Deploymer

CHAPTER

In This Chapter

Examining domain
controles

Understanding the
root domain

Exploring insalation
requirements

saling the root
domain

Directory

Chapter 6 + Installing the Root Domai

Ale system is ike a folder in ag cabinet. Te fe sytem provides a way for your
Operating system to ore daa in à logical, organized manner. Without à fle sytem, your
support FAT FAT, and NTFS

FAT (Fle Alocation Table) isan older le system. FAT was around when hard disks were
rather small In fat FAT should not be used on dicks larger than MB. (When was the at
time you saw a drive hat small You can use ton dvesup lo 4G but FAT does ot make

so of orage space once you move away tam the 51 ¡MB colin. an guess,
Fas provided in Windows 2000 for backward compatiblity,

Windows 95 OSF2 indows 98. FAT32 can make good use of space on larger
Windows 2000 senices and options will ot work on FAT or FAT, he FAT, RTS is pro

Finally the new NTFS with Windows 2000 makes excallent use of storage space and sup
of choice in Windows 2000 and is required for an Active Directory installation. |

Directory

enafren

In This Chapter

bostaling adaitonal
domain controles

Creating child
domains

Forming grandes

Consrucing a

Managing opera

Uninsaling the
Director

the Active Directory

128

the Active Directory

Directory

142

the Active Directory

charter

In This Chapter

domain mixed lo

Contguring must
relationships

Configuring ste links
and se link bridges

8 + Configuring Active Directory Domains and Sites 147

Directory

8 + Configuring Active Directory Domains and tes 149

Part I + Im the Active Directory

8 + Configuring Active Directory Domains and Sites

154

ing the Active Directory

8 + Configuring Active Directory Domains and Sites

=

8 + Configuring Active Directory Domains and Sites 157

Canale Window Y

+ Configuring Active Directory Dom:

8 + Configuring Active Directory Domains and Sites

Directory

8 + Configuring Active Directory Domains and Sites 163

8 + Configuring Active Directory Domains and Sites 165

166

the Active Directory

charter

In This Chapter

Creating and
‘managing user

managing group

a the Active Directory

‘hepter9 + Setting Up Users, Groups, and Computers 169

apler 9 + Setting Up Users, Groups, and Computers 171

Directory

Chapter 9 + Setting Up Users, Groups, and Computers

Seat new unts with the Adive Directory Users and Computers

The rt ut ma Separ DD wie pecto the
Acive Directory using a tet ile that can be imported tothe Atve Directory However, you
(an only create accounts with CSVDE—not deat or change the

The second utity is Lightweight Directory Access Protocol Interchange Format (LDIFD
hich enables to ou to create, delete, and manage bulk impor ao

Tolan more about either uty, just ype CSVDEor LDIFDE a the command prompt and

173

the Active Directory

Up Users, Groups, and Computers

H

Directory

apter 9 + Setting Up Users, Groups, and Computers

180

the Active Directory

aptor9 + Setting Up Users, Groups, and Computers 181

apter 8 + Setting Up Users, Groups, and Computers 183

Table 9-1
Windows 2000 Group Scopes

apler 9 + Setting Up Users, Groups, and Computers 185

a the Active Directory

apier9 + Setting Up Users, Groups, and Computers 187
Tags