Podcast
Questions and Answers
What is the primary purpose of a global catalog (GC) server in Active Directory?
What is the primary purpose of a global catalog (GC) server in Active Directory?
What is the difference between adding a child domain and adding a new tree in an existing forest?
What is the difference between adding a child domain and adding a new tree in an existing forest?
Which feature of Active Directory Administrative Center (ADAC) allows you to manage organizational units?
Which feature of Active Directory Administrative Center (ADAC) allows you to manage organizational units?
How are commands executed in Active Directory Administrative Center (ADAC)?
How are commands executed in Active Directory Administrative Center (ADAC)?
Signup and view all the answers
What functionality does enabling the Active Directory Recycle Bin provide?
What functionality does enabling the Active Directory Recycle Bin provide?
Signup and view all the answers
What is the first step in configuring Active Directory after installation?
What is the first step in configuring Active Directory after installation?
Signup and view all the answers
Which option should be selected if it is the first Domain Controller in the network?
Which option should be selected if it is the first Domain Controller in the network?
Signup and view all the answers
What is the purpose of the Directory Services Restore Mode password?
What is the purpose of the Directory Services Restore Mode password?
Signup and view all the answers
What must be created in the DNS options window during the Active Directory installation?
What must be created in the DNS options window during the Active Directory installation?
Signup and view all the answers
Which of the following is NOT a capability that can be selected for a Domain Controller?
Which of the following is NOT a capability that can be selected for a Domain Controller?
Signup and view all the answers
What protocol is based on the X.500 Directory Access Protocol and uses TCP/IP?
What protocol is based on the X.500 Directory Access Protocol and uses TCP/IP?
Signup and view all the answers
What should you specify in the Additional Options window during Active Directory setup?
What should you specify in the Additional Options window during Active Directory setup?
Signup and view all the answers
Why does Microsoft recommend at least two Domain Controllers in every domain?
Why does Microsoft recommend at least two Domain Controllers in every domain?
Signup and view all the answers
Which component forms the core structural unit of an Active Directory?
Which component forms the core structural unit of an Active Directory?
Signup and view all the answers
Which of the following features is not offered by Active Directory?
Which of the following features is not offered by Active Directory?
Signup and view all the answers
What is the significant difference when installing an additional Domain Controller?
What is the significant difference when installing an additional Domain Controller?
Signup and view all the answers
What is the primary function of a domain controller in Active Directory?
What is the primary function of a domain controller in Active Directory?
Signup and view all the answers
In an Active Directory structure, a forest is best described as which of the following?
In an Active Directory structure, a forest is best described as which of the following?
Signup and view all the answers
Which of the following is a correct statement regarding organizational units (OUs)?
Which of the following is a correct statement regarding organizational units (OUs)?
Signup and view all the answers
What is a necessary step if DNS is not present on the network before installing Active Directory Domain Services (ADDS)?
What is a necessary step if DNS is not present on the network before installing Active Directory Domain Services (ADDS)?
Signup and view all the answers
What does the tree structure in Active Directory primarily represent?
What does the tree structure in Active Directory primarily represent?
Signup and view all the answers
Which of the following is true regarding the physical structure of Active Directory?
Which of the following is true regarding the physical structure of Active Directory?
Signup and view all the answers
Which of these statements about Active Directory's logical structure is correct?
Which of these statements about Active Directory's logical structure is correct?
Signup and view all the answers
What is the primary purpose of the Active Directory schema?
What is the primary purpose of the Active Directory schema?
Signup and view all the answers
Which of the following is NOT a type of container object in Active Directory?
Which of the following is NOT a type of container object in Active Directory?
Signup and view all the answers
Which statement most accurately describes the function of Organizational Units (OUs)?
Which statement most accurately describes the function of Organizational Units (OUs)?
Signup and view all the answers
What kind of objects do Folder Objects typically house in Active Directory?
What kind of objects do Folder Objects typically house in Active Directory?
Signup and view all the answers
In terms of Active Directory, which of the following best defines a leaf object?
In terms of Active Directory, which of the following best defines a leaf object?
Signup and view all the answers
Which folder object is automatically created to house default user accounts?
Which folder object is automatically created to house default user accounts?
Signup and view all the answers
Which statement accurately describes domain objects in Active Directory?
Which statement accurately describes domain objects in Active Directory?
Signup and view all the answers
Active Directory allows the nesting of Organizational Units. What is the main advantage of this feature?
Active Directory allows the nesting of Organizational Units. What is the main advantage of this feature?
Signup and view all the answers
What does the attribute value refer to in the context of Active Directory?
What does the attribute value refer to in the context of Active Directory?
Signup and view all the answers
What are Managed Service Accounts primarily used for in Active Directory?
What are Managed Service Accounts primarily used for in Active Directory?
Signup and view all the answers
Which of the following statements about Group Policy Objects (GPOs) is true?
Which of the following statements about Group Policy Objects (GPOs) is true?
Signup and view all the answers
What is a characteristic of leaf objects in Active Directory?
What is a characteristic of leaf objects in Active Directory?
Signup and view all the answers
What feature allows administrators to control user computer environments in the User Configuration node?
What feature allows administrators to control user computer environments in the User Configuration node?
Signup and view all the answers
Which of the following is NOT a component of the Windows Settings in the User Configuration node?
Which of the following is NOT a component of the Windows Settings in the User Configuration node?
Signup and view all the answers
In Active Directory, what does enabling the AD Recycle Bin do?
In Active Directory, what does enabling the AD Recycle Bin do?
Signup and view all the answers
Which of the following best defines a domain in Active Directory?
Which of the following best defines a domain in Active Directory?
Signup and view all the answers
Which statement is true about directory partitions in Active Directory?
Which statement is true about directory partitions in Active Directory?
Signup and view all the answers
What do Administrative templates in Group Policy primarily facilitate?
What do Administrative templates in Group Policy primarily facilitate?
Signup and view all the answers
Which of the following is a benefit of using Group Policies in networks?
Which of the following is a benefit of using Group Policies in networks?
Signup and view all the answers
What happens to policies that are not defined or configured in Active Directory?
What happens to policies that are not defined or configured in Active Directory?
Signup and view all the answers
What is the primary function of a Group Policy Object (GPO)?
What is the primary function of a Group Policy Object (GPO)?
Signup and view all the answers
Which type of Active Directory zone is considered authoritative and contains a read/write master copy of resource records?
Which type of Active Directory zone is considered authoritative and contains a read/write master copy of resource records?
Signup and view all the answers
What is the difference between local and domain user accounts?
What is the difference between local and domain user accounts?
Signup and view all the answers
What type of replication occurs between two or more sites in Active Directory?
What type of replication occurs between two or more sites in Active Directory?
Signup and view all the answers
Which statement about directory partitions in Active Directory is true?
Which statement about directory partitions in Active Directory is true?
Signup and view all the answers
Which FSMO role is responsible for ensuring the uniqueness of names in a forest?
Which FSMO role is responsible for ensuring the uniqueness of names in a forest?
Signup and view all the answers
What happens when there is no trust relationship between two domains?
What happens when there is no trust relationship between two domains?
Signup and view all the answers
What does the Knowledge Consistency Checker (KCC) do?
What does the Knowledge Consistency Checker (KCC) do?
Signup and view all the answers
What main functions does a Global Catalog server perform?
What main functions does a Global Catalog server perform?
Signup and view all the answers
Which user configuration settings in GPO are enforced and cannot be overridden by users?
Which user configuration settings in GPO are enforced and cannot be overridden by users?
Signup and view all the answers
What is the purpose of the Administrative Templates folder in GPO?
What is the purpose of the Administrative Templates folder in GPO?
Signup and view all the answers
Which command is used in PowerShell to view forest-wide FSMO roles?
Which command is used in PowerShell to view forest-wide FSMO roles?
Signup and view all the answers
What is a characteristic of a secondary zone in Active Directory?
What is a characteristic of a secondary zone in Active Directory?
Signup and view all the answers
Flashcards
Adding a child domain
Adding a child domain
Adding a domain to an existing forest that shares the top-level and second-level domain name structure with an existing domain.
Adding a new tree
Adding a new tree
Adding a new domain to an existing forest using a separate naming structure.
Active Directory Administrative Center (ADAC)
Active Directory Administrative Center (ADAC)
Tool for managing Active Directory objects, like users, computers, and organizational units.
Domain functional level
Domain functional level
Signup and view all the flashcards
Read-only domain controller (RODC)
Read-only domain controller (RODC)
Signup and view all the flashcards
Active Directory
Active Directory
Signup and view all the flashcards
Domain Controller (DC)
Domain Controller (DC)
Signup and view all the flashcards
Organizational Unit (OU)
Organizational Unit (OU)
Signup and view all the flashcards
Domain
Domain
Signup and view all the flashcards
Tree
Tree
Signup and view all the flashcards
Forest
Forest
Signup and view all the flashcards
LDAP
LDAP
Signup and view all the flashcards
Site
Site
Signup and view all the flashcards
Active Directory Domain Services (ADDS)
Active Directory Domain Services (ADDS)
Signup and view all the flashcards
X.500
X.500
Signup and view all the flashcards
Active Directory Configuration
Active Directory Configuration
Signup and view all the flashcards
Promoting a Server
Promoting a Server
Signup and view all the flashcards
Deployment Configuration Options
Deployment Configuration Options
Signup and view all the flashcards
Fully Qualified Domain Name (FQDN)
Fully Qualified Domain Name (FQDN)
Signup and view all the flashcards
Forest Functional Level
Forest Functional Level
Signup and view all the flashcards
Domain Controller Capabilities
Domain Controller Capabilities
Signup and view all the flashcards
Directory Services Restore Mode (DSRM)
Directory Services Restore Mode (DSRM)
Signup and view all the flashcards
Additional Domain Controllers
Additional Domain Controllers
Signup and view all the flashcards
Active Directory Schema
Active Directory Schema
Signup and view all the flashcards
Active Directory Container Object
Active Directory Container Object
Signup and view all the flashcards
Folder Objects
Folder Objects
Signup and view all the flashcards
Domain Object
Domain Object
Signup and view all the flashcards
Active Directory Leaf Object
Active Directory Leaf Object
Signup and view all the flashcards
Schema classes
Schema classes
Signup and view all the flashcards
Schema attributes
Schema attributes
Signup and view all the flashcards
Attribute value
Attribute value
Signup and view all the flashcards
Security Account
Security Account
Signup and view all the flashcards
What's the difference between User Configuration and Computer Configuration?
What's the difference between User Configuration and Computer Configuration?
Signup and view all the flashcards
What does the 'Software Settings' node do?
What does the 'Software Settings' node do?
Signup and view all the flashcards
Where are GPOs applied?
Where are GPOs applied?
Signup and view all the flashcards
What does the 'Security Settings' subtree do?
What does the 'Security Settings' subtree do?
Signup and view all the flashcards
What's the purpose of 'Administrative Templates'?
What's the purpose of 'Administrative Templates'?
Signup and view all the flashcards
What happens if a policy is not defined?
What happens if a policy is not defined?
Signup and view all the flashcards
What's the order of GPO application?
What's the order of GPO application?
Signup and view all the flashcards
What is a directory service?
What is a directory service?
Signup and view all the flashcards
What is Active Directory built upon?
What is Active Directory built upon?
Signup and view all the flashcards
What does installing the first DC create?
What does installing the first DC create?
Signup and view all the flashcards
What is a GPO?
What is a GPO?
Signup and view all the flashcards
What are the two default GPOs?
What are the two default GPOs?
Signup and view all the flashcards
What is User Configuration?
What is User Configuration?
Signup and view all the flashcards
What is Computer Configuration?
What is Computer Configuration?
Signup and view all the flashcards
What's the difference between Policies and Preferences?
What's the difference between Policies and Preferences?
Signup and view all the flashcards
What's the purpose of Software Settings?
What's the purpose of Software Settings?
Signup and view all the flashcards
What's inside the Windows Settings node?
What's inside the Windows Settings node?
Signup and view all the flashcards
What's the role of Administrative Templates?
What's the role of Administrative Templates?
Signup and view all the flashcards
What is a primary zone?
What is a primary zone?
Signup and view all the flashcards
What is a secondary zone?
What is a secondary zone?
Signup and view all the flashcards
What is a stub zone?
What is a stub zone?
Signup and view all the flashcards
What is the purpose of Active Directory replication?
What is the purpose of Active Directory replication?
Signup and view all the flashcards
What are the types of Active Directory replication?
What are the types of Active Directory replication?
Signup and view all the flashcards
What is the Knowledge Consistency Checker (KCC)?
What is the Knowledge Consistency Checker (KCC)?
Signup and view all the flashcards
What are Directory Partitions?
What are Directory Partitions?
Signup and view all the flashcards
What's the role of an Operations Master?
What's the role of an Operations Master?
Signup and view all the flashcards
Study Notes
Windows Domain Administration - CST8200
- The course is CST8200 - Windows Domain Administration
- Professor: Denis Latremouille
- Week 3
Agenda
- No specific agenda is listed
The Role of a Directory Service
- A network directory service stores information about a computer network and offers features for retrieving and managing the information.
- It's primarily an administrative tool, but users also utilize it to find resources.
- Due to the complexity, careful planning is required before setting up the directory service.
Windows Active Directory
- Active Directory is a directory service based on industry standards to define, store, and access directory service objects.
- The X.500 standard forms its hierarchical structure.
- The Lightweight Directory Access Protocol (LDAP) is based on the X.500 Directory Access Protocol.
- TCP/IP protocol is used for efficiency.
- Integrating other OS's like Linux into an Active Directory network necessitates the use of LDAP.
- Active Directory first appeared in Windows 2000 Server.
Active Directory Features
- Hierarchical organization
- Centralized, but distributed database
- Scalability
- Security
- Flexibility
- Policy-based administration
Overview of the Active Directory Structure
- Physical structure consists of sites and servers configured as domain controllers.
- Logical structure patterns the directory service after the organization that uses it.
Active Directory's Physical Structure
- An Active Directory site is a physical location where domain controllers communicate and replicate information regularly.
- A domain controller (DC) is a computer running Windows Server 2016 with the Active Directory Domain Services role installed.
- Each domain controller holds a full replica of domain objects and manages data replication across all controllers.
- It handles data searches and retrieval requests.
- It provides authentication and authorization services for users accessing network resources.
Active Directory's Logical Structure
- Active Directory has four organizing components: Organizational Units (OUs), Domains, Trees, and Forests.
- An OU is an Active Directory container that logically groups users and resources for administrative purposes.
- An OU includes objects such as user, group, computer, printer, shared folder, application, server, and domain controller information.
Active Directory Domains, Trees, and Forests
- A domain is the core structural unit of Active Directory; it contains OUs and represents administrative, security, and policy boundaries.
- Small to medium-sized businesses usually have one domain.
- Larger organizations typically have multiple domains to separate geographical regions or management responsibilities.
- A tree is a grouping of domains that share a common naming structure.
- A tree may consist of a parent domain and additional child domains.
- A forest is a collection of one or more Active Directory trees that provide a common Active Directory environment, where all domains within the trees can communicate and share information.
- A forest may comprise of a single tree and a single domain, or several trees each with a parent and child domain hierarchy
Installing Active Directory
- Windows Active Directory service is commonly referred to as ADDS.
- To install ADDS use Server Manager.
- Ensure DNS is installed on the network.
- Configure Active Directory by promoting the server to a DC and selecting appropriate options in the Configuration window for adding (a) a domain controller to an existing domain, (b) a new domain to an existing forest, (c) a new forest
- FQDN (Fully Qualified Domain Name) needs to be specified for the new forest root.
- Specify NetBIOS domain name for backward compatibility (optional).
- Set location for Active Directory database, log files, and SYSVOL.
- Review selections in the Review Options window.
- A prerequisite check is conducted before starting installation.
- A password for DSRM (Directory Services Restore Mode) is required.
Installing Additional Domain Controllers
- Microsoft recommends at least two DCs in every domain for fault tolerance and load balancing.
- Installing an additional DC is similar to installing the first, but it's configured to join an existing domain.
Installing a New Domain in an Existing Forest
- Adding a child domain involves sharing the top-level and potentially second-level naming structure with an existing domain in the forest.
- Adding a new tree involves creating a new domain with a distinct naming structure that's separate from existing domains in the forest.
What's Inside Active Directory
- Explore Active Directory using ADAC or AD Users and Computers MMC.
- Use ADAC to create and manage user, group, and computer accounts; manage OUs; connect to various domain controllers; and change the domain functional level.
The Active Directory Schema
- An object is a group of data that describes a network resource.
- A schema defines the type, organization, and structure of data stored in Active Directory.
- Schema classes define object types (e.g., Computer account, Domain controller, Group).
- Schema attributes define the specific information for each object (e.g., Computer name, DNS name).
- Attribute values store detailed data about individual attributes.
Active Directory Container Objects
- A container object groups other objects for organization, management, and acting as administrative or security boundaries.
- The three container types are OUs, Folder objects, and Domain objects.
Organizational Units(OUs)
- OU is a primary container in a domain for organizing and managing resources.
- OUs logically group objects for administrative tasks and customized policies.
- OUs can be nested to form a hierarchical structure mimicking organizational units.
Folder Objects
- Folder objects are used for local domain specific tasks.
- They include built-in groups (created by Windows), computer accounts, security principals, and managed service accounts.
Domain Objects
- The domain is the core logical structure in AD, including OUs and folder objects.
- Larger organizations may use multiple domains for administration, security boundaries, and policy enforcement.
- Each domain has default GPO (Group Policy Object) linked to it affecting all objects within that domain.
- The domain object appears as an icon with three computer towers in Active Directory administrative tools.
Active Directory Leaf Objects
- Leaf objects are those that don't contain any other objects. They represent:
- Security accounts (users, groups, computers)
- Network resources (servers, domain controllers, file shares, printers)
- Group Policy Objects (GPOs)
- GPOs are managed via the Group Policy Management MMC (Microsoft Management Console).
User Accounts
- A user account object contains details like group memberships, account limitations, profile paths, and dial-in permissions.
- Authentication verifies user identity.
- Local user accounts are authorized to access resources on a specific computer only.
- Domain user accounts offer a single logon for access to all resources in the domain.
- Windows automatically creates an Administrator and Guest accounts.
Zone Types
- Active Directory uses three types of zones:
- Primary: read/write master copy of zone records
- Secondary: read-only backup copy of zone records
- Stub: read-only copy of SOA and NS records; not authoritative.
Groups
- A group represents a collection of users with similar privileges and access rights.
- Groups streamline permission management rather than assigning rights individually to every user.
Computer Accounts
- Computer accounts represent domain computers (members or controllers)
- Used for authentication, identification, and management of computers within a domain.
- They are automatically created when AD is set up on a server.
- The account name matches the actual computer name.
Locating Active Directory Objects
- Active Directory objects can be searched using the Find Users, Contacts, and Groups dialog box.
- Searching can be done for a single domain or the entire directory.
- Searchable objects depend on security settings and the container containing them.
Active Directory Terminology
- Active Directory terminology includes terms related to replication, directory partitions, operations masters, and trust relationships.
Active Directory Replication
- Replication maintains a consistent database across various locations when the database is distributed among locations.
- Replication occurs between domain controllers within the same site (intrasite).
- It also happens between different sites (intersite).
- Multimaster replication is used to replace AD objects.
- A Knowledge Consistency Checker runs on domain controllers to define the replication topology and ensure no more than three hops between any two domain controllers
Directory Partitions
- Directory partitions are sections of the Active Directory database.
- Five partition types are:
- Domain directory partition: holds objects (users, groups, computers).
- Schema directory partition: defines AD objects and attributes.
- Global catalog partition: partial replica of all objects in the forest.
- Application directory partition: used by applications for stored information.
- Configuration directory partition: holds configurations affecting the entire forest.
Operations Master Roles
- Some operations require a single domain controller (operations master).
- The initial domain controller in a forest often becomes the operations master.
- Role responsibilities can be transferred, if necessary, to another domain controller (using Flexible Single Master Operations, FSMO, roles).
- FSMO Roles include Schema Master, Infrastructure Master, Domain Naming Master, RID Master, and PDC Emulator master
Trust Relationships
- Trust relationships determine if security principals from one domain can access resources in another domain.
- Trusts are automatically established among domains in a forest.
- Trust does not equal permission. Resources may still need specific permissions, even if a trust relationship exists.
- No access is possible between domains lacking a trust relationship.
The Role of Forests
- Domains in a forest share a single schema and forest-wide administrative accounts.
- Global Catalog domains exist for searching and accessing information across the whole forest.
- Trusts and replication between domains allow seamless operation.
The Importance of the Global Catalog server
- The first domain controller created in a forest usually acts as the Global Catalog server, facilitating domain-wide and forest-wide searches and logins using user principal names (UPNs).
- Additional Global Catalog servers can be configured for improved performance and redundancy.
- Global Catalog servers help with user searches across different domains.
Introducing Group Policies
- A Group Policy Object (GPO) is a collection of settings that administrators use to remotely configure user and computer settings.
- The scope defines which objects are affected by a GPO.
- Installing Active Directory creates Default Domain Policy and other default domain controllers' policies.
- GPMC (Group Policy Management Console) enables viewing, creating, and managing GPOs.
GPO application
- GPOs apply locally, on the computer.
- GPOs apply under specific sites.
- GPOs apply under specific OUs.
- GPOs can apply under the domain.
The Computer Configuration Node
- The Computer Configuration node in a GPO manages settings applied to computers.
- This involves software settings, Windows settings (including name resolution), scripts, security, policy-based QoS settings, and administrator templates (templates from various control panels, network services, printers, and system tools).
- The computer configuration settings in a GPO affect all computers in the related container that includes domain controllers.
The User Configuration Node
- The User Configuration node in a GPO manages settings applied to every user within its linked domain.
- This involves managing settings across the operating systems for users, like software settings, scripts, security, folder redirection, and policy-based QoS.
- User configuration GPO settings affect domain users within the scope of the related container or OU.
How Group Policies Are Applied
- GPOs apply in four places:
- Local Computer, Site, Domain, or Organizational Unit
- Policies apply in the order mentioned above. A later policy might overwrite earlier ones.
- Policies that are not defined will not be applied
- The precedence is from last policy to be defined first.
Chapter Summary
- Active Directory is a database managing users, computers, and resources.
- Active Directory uses the X.500 standard and LDAP.
- Server Manager facilitates Active Directory Domain Services (ADDS) installation.
- Installing the first domain controller creates a new forest, establishing a domain and a forest root
- Data in Active Directory is structured in objects.
- Objects include container and leaf objects: Container objects include OUs, folders, and domains. Leaf objects include security accounts, network resources, and GPOs.
- AD Recycle Bin can be enabled and disabled.
- Large organizations might use multiple domains, trees, and forests.
- Directory partitions are segments of the Active Directory database.
- A forest is the broadest logical Active Directory component
- A domain is the primary identifying and administrative unit of Active Directory.
- GPOs are sets of settings that configure user and computer environments.
- Policies in the Computer Configuration node affect all computers.
- Policies in the User Configuration node affect all domain users within the boundary.
Studying That Suits You
Use AI to generate personalized quizzes and flashcards to suit your learning preferences.
Related Documents
Description
Test your knowledge of Active Directory with this quiz covering essential concepts, server roles, and configuration steps. From understanding global catalogs to the functionality of ADAC, this quiz will challenge your expertise in Active Directory management.