SlideShare a Scribd company logo
1 of 20
Christopher Chapman | MCT
Content PM, Microsoft Learning, PDG Planning , Microsoft
Meet Christopher Chapman
• Background
– IT manager and implementer focused on deploying,
maintaining and optimizing networks of all sizes (from
SMB to Enterprise)
– IT Consulting projects include Custom SharePoint for
Microsoft IT, Netware/Notes migration to AD/Exchange,
Transition to centralized management (250 clients)
– Instructor and Director of Instruction
• Contact
– christopherjs@microsoft.com
– @ChristopherMSL
Course Topics
Understanding Active Directory
01 | Introduction to Active Directory
02 | Active Directory Domain Services (DS)
03 | Active Directory Certificate Services (CS)
04 | Active Directory Federation Services (FS)
05 | Active Directory Rights Management Services (RMS)
06 | Active Directory Lightweight Directory Services (LDS)
Setting Expectations
• Target Audience
– IT Help Desk staff interested in moving into Network/Systems
Administration
– Anyone interested in learning more about Active Directory
• Suggested Prerequisites/Supporting Material
– Microsoft Technology Associate:
• Exam 98-349: Windows Operating System Fundamentals
• Exam 98-365: Windows Server Administration Fundamentals
• Exam 98-366: Networking Fundamentals
• Exam 98-367: Security Fundamentals
Microsoft
Virtual
Academy
Introduction to Active Directory
• Active Directory isn’t what it used to be!
• What is Active Directory?
• Active Directory Roles
Module Overview
• What is Active Directory?
– A collection of services (Server
Roles and Features) used to
manage identity and access
for and to resources on a
network
What is Active Directory
Domain
Services
• Internal
Accounts
• Authorization
• Authentication
Federation
Services
• Network
Access for
External
Resources
Certificate
Services
• Identity
• Non-
Repudiation
Rights
Management
Services
• Content
Security and
Control
Lightweight
Directory
Services
• Application
Templates
Active Directory
• Identity
• Access
• Centralized
Management
• AD Domain Services (AD DS)
– Users, Computers, Policies
• AD Certificate Services (AD CS)
– Service, Client, Server and User identification
• AD Federation Services (AD FS)
– Resource access across traditional boundaries
• AD Rights Management Services (AD RMS)
– Maintain security of data
• AD Lightweight Directory Services (AD LDS)
Active Directory Roles
• What is Active Directory
Domain Services?
– A directory service is both
the directory information
source and the service that
makes the information
available and usable
– A phone book…
What is AD DS?
Windows
Server
• Mgmt Profile
• Network Info
• Printers
• Shares
Windows
User
• Account
Information
• Privileges
• Profiles
• Policies
Windows
Client
• Mgmt Profile
• Network Info
• Policies
Email
Servers
• Mailbox
Information
• Address
Book
Applications
• Server
Config
• SSO
• App-Specific
Directory
Info
Network
Devices
• Config
• QoS Policy
• Security
Policy
Active Directory
Domain Services
• Manageability
• Security
• Interoperability
• Scalable, secure, and manageable infrastructure for user and
resource management
– stores and manages information about network resources
– provides support for directory-enabled applications such as
Microsoft® Exchange Server
– allows for centralized management
What does AD DS do?
• AD CS is the Microsoft
implementation of Public Key
Infrastructure (PKI)
• PKI is a set of hardware, software,
people, policies, and procedures
needed to create, manage,
distribute, use, store, and revoke
digital certificates
What is AD CS?
Revocation Request
Certificate
Revocation
List
CRL
Retrieval
5
x.509 Certificate Chain
Certificate
Retrieval 4
Certificate
Signing
Request Enrollment
3
Certificate
Repository
Certification
Revocation
Repository
2
End-Entities
(users or
computers)
1
• AD CS provides customizable services for issuing and managing
digital certificates
– Certification Authorities
– CA Web Enrollment
– Online Responders
– Network Device Enrollment Service (NDES)
– Certificate Enrollment Web Service
– Certificate Enrollment Policy Web Service
What does AD CS do?
• A software
component
that facilitates
the cross-
organizational
access of
systems and
applications
What is AD FS?
Web
Server
Resource
Federation
Server
Account Partner
Organization
Resource Partner
Organization
Account
Federation
Server
AD DS
Federation Trust
• The AD FS server role provides simplified, secured identity
federation and Web single sign-on (SSO) capabilities.
– enables the creation of trust relationships between two organizations
– provides access to applications between organizations
– provides Single Sign-on (SSO) between two different directories for
Web-based applications
What does AD FS do?
• Active Directory Rights
Management Services
(AD RMS) is an
information protection
technology that works
with applications to
safeguard digital
information
What is AD RMS?
RMS
Server
Information
Author
Recipient
• Allows individuals and administrators to specify access
permissions to documents, workbooks, and presentations
– prevent sensitive information from being printed, forwarded, or copied
by unauthorized people
– access and usage restrictions are enforced no matter where the
information is located
What does AD RMS do?
• AD LDS is a hierarchical
file-based directory store
• AD LDS is both the
directory information
source and the service that
makes the information
available and usable
What is AD LDS?
Windows
User
• Account
Information
• Privileges
• Profiles
• Policies
Email
Servers
• Mailbox
Information
• Address
Book
Applications
• Server
Config
• SSO
• App-Specific
Directory
Info
Network
Devices
• Config
• QoS Policy
• Security
Policy
Active Directory LDS
• Manageability
• Security
• Interoperability
• Lightweight Directory Access Protocol (LDAP)
– Directory service that provides flexible support for directory-enabled
applications, without the dependencies and domain-related restrictions
of AD DS
– provide directory services for directory-enabled applications without
incurring the overhead of domains and forests
– no requirement for a single schema throughout a forest
What does AD LDS do?
Thanks for Watching!
©2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Office, Azure, System Center, Dynamics and other product names are or may be registered trademarks and/or trademarks in the
U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft
must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after
the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

More Related Content

What's hot

CIS13: A Breakthrough in Directory Technology: Meet the Elephant in the Room ...
CIS13: A Breakthrough in Directory Technology: Meet the Elephant in the Room ...CIS13: A Breakthrough in Directory Technology: Meet the Elephant in the Room ...
CIS13: A Breakthrough in Directory Technology: Meet the Elephant in the Room ...CloudIDSummit
 
Active directory ds ws2008 r2
Active directory ds ws2008 r2Active directory ds ws2008 r2
Active directory ds ws2008 r2MICTT Palma
 
Con8836 leveraging the cloud to simplify your identity management implement...
Con8836   leveraging the cloud to simplify your identity management implement...Con8836   leveraging the cloud to simplify your identity management implement...
Con8836 leveraging the cloud to simplify your identity management implement...OracleIDM
 
Active Directory Services
Active Directory ServicesActive Directory Services
Active Directory ServicesVarun Arora
 
How a virtual directory works
How a virtual directory worksHow a virtual directory works
How a virtual directory worksmariekings001
 
BPM und SOA machen mobil - Ein Architekturüberblick
BPM und SOA machen mobil - Ein ArchitekturüberblickBPM und SOA machen mobil - Ein Architekturüberblick
BPM und SOA machen mobil - Ein ArchitekturüberblickOPITZ CONSULTING Deutschland
 
KoprowskiT_SQLSat230_Rheinland_SQLAzure-fromPlantoBackuptoCloud
KoprowskiT_SQLSat230_Rheinland_SQLAzure-fromPlantoBackuptoCloudKoprowskiT_SQLSat230_Rheinland_SQLAzure-fromPlantoBackuptoCloud
KoprowskiT_SQLSat230_Rheinland_SQLAzure-fromPlantoBackuptoCloudTobias Koprowski
 
Cryptolab cse datasheet v1.1.pdf
Cryptolab cse datasheet v1.1.pdfCryptolab cse datasheet v1.1.pdf
Cryptolab cse datasheet v1.1.pdfMassimo Bertaccini
 
Msbi 2012 online training
Msbi 2012 online trainingMsbi 2012 online training
Msbi 2012 online trainingssmasters
 
Is Office 365 Right For You? Aptera Software presentation
Is Office 365 Right For You? Aptera Software presentationIs Office 365 Right For You? Aptera Software presentation
Is Office 365 Right For You? Aptera Software presentationAptera Inc
 
Open Source Data Services for Strategic SOA utilising WSO2 Data Services Server
Open Source Data Services for Strategic SOA  utilising WSO2 Data Services ServerOpen Source Data Services for Strategic SOA  utilising WSO2 Data Services Server
Open Source Data Services for Strategic SOA utilising WSO2 Data Services Serversumedha.r
 
The Enterprise File Fabric for OpenIO
The Enterprise File Fabric for OpenIOThe Enterprise File Fabric for OpenIO
The Enterprise File Fabric for OpenIOHybrid Cloud
 
The Enterprise File Fabric for Vecima MediaScaleX
The Enterprise File Fabric for Vecima MediaScaleXThe Enterprise File Fabric for Vecima MediaScaleX
The Enterprise File Fabric for Vecima MediaScaleXHybrid Cloud
 
The Enterprise File Fabric for Cloudian | GDPR ready File Sync and Share
The Enterprise File Fabric for Cloudian | GDPR ready File Sync and ShareThe Enterprise File Fabric for Cloudian | GDPR ready File Sync and Share
The Enterprise File Fabric for Cloudian | GDPR ready File Sync and ShareHybrid Cloud
 
Building Multi-tenant SaaS Applications using WSO2 Private PaaS
Building Multi-tenant SaaS Applications using WSO2 Private PaaSBuilding Multi-tenant SaaS Applications using WSO2 Private PaaS
Building Multi-tenant SaaS Applications using WSO2 Private PaaSSameera Jayasoma
 
6 Ways to Get More From Your Azure
6 Ways to Get More From Your Azure6 Ways to Get More From Your Azure
6 Ways to Get More From Your AzureHolly Plude
 

What's hot (20)

CIS13: A Breakthrough in Directory Technology: Meet the Elephant in the Room ...
CIS13: A Breakthrough in Directory Technology: Meet the Elephant in the Room ...CIS13: A Breakthrough in Directory Technology: Meet the Elephant in the Room ...
CIS13: A Breakthrough in Directory Technology: Meet the Elephant in the Room ...
 
Active directory ds ws2008 r2
Active directory ds ws2008 r2Active directory ds ws2008 r2
Active directory ds ws2008 r2
 
Con8836 leveraging the cloud to simplify your identity management implement...
Con8836   leveraging the cloud to simplify your identity management implement...Con8836   leveraging the cloud to simplify your identity management implement...
Con8836 leveraging the cloud to simplify your identity management implement...
 
Fox pass
Fox passFox pass
Fox pass
 
Active Directory Services
Active Directory ServicesActive Directory Services
Active Directory Services
 
How a virtual directory works
How a virtual directory worksHow a virtual directory works
How a virtual directory works
 
BPM und SOA machen mobil - Ein Architekturüberblick
BPM und SOA machen mobil - Ein ArchitekturüberblickBPM und SOA machen mobil - Ein Architekturüberblick
BPM und SOA machen mobil - Ein Architekturüberblick
 
Final domain control policy
Final domain control policy  Final domain control policy
Final domain control policy
 
KoprowskiT_SQLSat230_Rheinland_SQLAzure-fromPlantoBackuptoCloud
KoprowskiT_SQLSat230_Rheinland_SQLAzure-fromPlantoBackuptoCloudKoprowskiT_SQLSat230_Rheinland_SQLAzure-fromPlantoBackuptoCloud
KoprowskiT_SQLSat230_Rheinland_SQLAzure-fromPlantoBackuptoCloud
 
Cryptolab cse datasheet v1.1.pdf
Cryptolab cse datasheet v1.1.pdfCryptolab cse datasheet v1.1.pdf
Cryptolab cse datasheet v1.1.pdf
 
Ad ds ws2008 r2
Ad ds ws2008 r2Ad ds ws2008 r2
Ad ds ws2008 r2
 
Msbi 2012 online training
Msbi 2012 online trainingMsbi 2012 online training
Msbi 2012 online training
 
Is Office 365 Right For You? Aptera Software presentation
Is Office 365 Right For You? Aptera Software presentationIs Office 365 Right For You? Aptera Software presentation
Is Office 365 Right For You? Aptera Software presentation
 
Open Source Data Services for Strategic SOA utilising WSO2 Data Services Server
Open Source Data Services for Strategic SOA  utilising WSO2 Data Services ServerOpen Source Data Services for Strategic SOA  utilising WSO2 Data Services Server
Open Source Data Services for Strategic SOA utilising WSO2 Data Services Server
 
The Enterprise File Fabric for OpenIO
The Enterprise File Fabric for OpenIOThe Enterprise File Fabric for OpenIO
The Enterprise File Fabric for OpenIO
 
The Enterprise File Fabric for Vecima MediaScaleX
The Enterprise File Fabric for Vecima MediaScaleXThe Enterprise File Fabric for Vecima MediaScaleX
The Enterprise File Fabric for Vecima MediaScaleX
 
The Enterprise File Fabric for Cloudian | GDPR ready File Sync and Share
The Enterprise File Fabric for Cloudian | GDPR ready File Sync and ShareThe Enterprise File Fabric for Cloudian | GDPR ready File Sync and Share
The Enterprise File Fabric for Cloudian | GDPR ready File Sync and Share
 
Building Multi-tenant SaaS Applications using WSO2 Private PaaS
Building Multi-tenant SaaS Applications using WSO2 Private PaaSBuilding Multi-tenant SaaS Applications using WSO2 Private PaaS
Building Multi-tenant SaaS Applications using WSO2 Private PaaS
 
6 Ways to Get More From Your Azure
6 Ways to Get More From Your Azure6 Ways to Get More From Your Azure
6 Ways to Get More From Your Azure
 
SSIS begineer
SSIS begineerSSIS begineer
SSIS begineer
 

Similar to 04232015094601

02-Active Directory Domain Services.pptx
02-Active Directory Domain Services.pptx02-Active Directory Domain Services.pptx
02-Active Directory Domain Services.pptxAdiWidyanto2
 
Active-Directory-Domain-Services.pptx
Active-Directory-Domain-Services.pptxActive-Directory-Domain-Services.pptx
Active-Directory-Domain-Services.pptxMeriemBalhaddad
 
Active Directory Domain Services.pptx
Active Directory Domain Services.pptxActive Directory Domain Services.pptx
Active Directory Domain Services.pptxsyedasadraza13
 
Win2KServer Active Directory
Win2KServer Active DirectoryWin2KServer Active Directory
Win2KServer Active DirectoryPhil Ashman
 
Introduction to System and network administrations
Introduction to System and network administrationsIntroduction to System and network administrations
Introduction to System and network administrationsgirmayou1
 
Active-Directory-Domain-Services.pptx
Active-Directory-Domain-Services.pptxActive-Directory-Domain-Services.pptx
Active-Directory-Domain-Services.pptxJavedAjmal1
 
Brian Desmond - Identity and directory synchronization with office 365 and wi...
Brian Desmond - Identity and directory synchronization with office 365 and wi...Brian Desmond - Identity and directory synchronization with office 365 and wi...
Brian Desmond - Identity and directory synchronization with office 365 and wi...Nordic Infrastructure Conference
 
17 roles of window server 2008 r2
17 roles of window server 2008 r217 roles of window server 2008 r2
17 roles of window server 2008 r2IGZ Software house
 
Today's Unified Communications: To upgrade, coexist, or go 'all in' with the ...
Today's Unified Communications: To upgrade, coexist, or go 'all in' with the ...Today's Unified Communications: To upgrade, coexist, or go 'all in' with the ...
Today's Unified Communications: To upgrade, coexist, or go 'all in' with the ...C/D/H Technology Consultants
 
ADDS (Active directory Domain Service) in side server
ADDS (Active directory Domain Service) in side serverADDS (Active directory Domain Service) in side server
ADDS (Active directory Domain Service) in side serverBilalMehmood44
 
AD Basic and Azure AD.pptx
AD Basic and Azure AD.pptxAD Basic and Azure AD.pptx
AD Basic and Azure AD.pptxSumTingWong8
 
Cause 2013: A Flexible Approach to Creating an Enterprise Directory
Cause 2013: A Flexible Approach to Creating an Enterprise DirectoryCause 2013: A Flexible Approach to Creating an Enterprise Directory
Cause 2013: A Flexible Approach to Creating an Enterprise Directoryrwgorrel
 
KoprowskiT_session1_SDNEvent_WASDforBeginners
KoprowskiT_session1_SDNEvent_WASDforBeginnersKoprowskiT_session1_SDNEvent_WASDforBeginners
KoprowskiT_session1_SDNEvent_WASDforBeginnersTobias Koprowski
 
Best practices When Migrating to Office 365
Best practices When Migrating to Office 365Best practices When Migrating to Office 365
Best practices When Migrating to Office 365Perficient, Inc.
 
Active Directoryptx sunday.pptx
Active Directoryptx sunday.pptxActive Directoryptx sunday.pptx
Active Directoryptx sunday.pptxUtPearls
 
Why a Data Services Marketplace is Critical for a Successful Data-Driven Ente...
Why a Data Services Marketplace is Critical for a Successful Data-Driven Ente...Why a Data Services Marketplace is Critical for a Successful Data-Driven Ente...
Why a Data Services Marketplace is Critical for a Successful Data-Driven Ente...Denodo
 
gkkCloudtechnologyassociate(cta)day 2
gkkCloudtechnologyassociate(cta)day 2gkkCloudtechnologyassociate(cta)day 2
gkkCloudtechnologyassociate(cta)day 2Anne Starr
 
Lecture 11 active directory
Lecture 11 active directoryLecture 11 active directory
Lecture 11 active directoryTanveer Malik
 
Microsoft Active Directory.pptx
Microsoft Active Directory.pptxMicrosoft Active Directory.pptx
Microsoft Active Directory.pptxmasbulosoke
 

Similar to 04232015094601 (20)

02-Active Directory Domain Services.pptx
02-Active Directory Domain Services.pptx02-Active Directory Domain Services.pptx
02-Active Directory Domain Services.pptx
 
Active-Directory-Domain-Services.pptx
Active-Directory-Domain-Services.pptxActive-Directory-Domain-Services.pptx
Active-Directory-Domain-Services.pptx
 
Active Directory Domain Services.pptx
Active Directory Domain Services.pptxActive Directory Domain Services.pptx
Active Directory Domain Services.pptx
 
Win2KServer Active Directory
Win2KServer Active DirectoryWin2KServer Active Directory
Win2KServer Active Directory
 
Introduction to System and network administrations
Introduction to System and network administrationsIntroduction to System and network administrations
Introduction to System and network administrations
 
Active-Directory-Domain-Services.pptx
Active-Directory-Domain-Services.pptxActive-Directory-Domain-Services.pptx
Active-Directory-Domain-Services.pptx
 
Brian Desmond - Identity and directory synchronization with office 365 and wi...
Brian Desmond - Identity and directory synchronization with office 365 and wi...Brian Desmond - Identity and directory synchronization with office 365 and wi...
Brian Desmond - Identity and directory synchronization with office 365 and wi...
 
17 roles of window server 2008 r2
17 roles of window server 2008 r217 roles of window server 2008 r2
17 roles of window server 2008 r2
 
Today's Unified Communications: To upgrade, coexist, or go 'all in' with the ...
Today's Unified Communications: To upgrade, coexist, or go 'all in' with the ...Today's Unified Communications: To upgrade, coexist, or go 'all in' with the ...
Today's Unified Communications: To upgrade, coexist, or go 'all in' with the ...
 
ADDS (Active directory Domain Service) in side server
ADDS (Active directory Domain Service) in side serverADDS (Active directory Domain Service) in side server
ADDS (Active directory Domain Service) in side server
 
AD Basic and Azure AD.pptx
AD Basic and Azure AD.pptxAD Basic and Azure AD.pptx
AD Basic and Azure AD.pptx
 
Cause 2013: A Flexible Approach to Creating an Enterprise Directory
Cause 2013: A Flexible Approach to Creating an Enterprise DirectoryCause 2013: A Flexible Approach to Creating an Enterprise Directory
Cause 2013: A Flexible Approach to Creating an Enterprise Directory
 
KoprowskiT_session1_SDNEvent_WASDforBeginners
KoprowskiT_session1_SDNEvent_WASDforBeginnersKoprowskiT_session1_SDNEvent_WASDforBeginners
KoprowskiT_session1_SDNEvent_WASDforBeginners
 
Best practices When Migrating to Office 365
Best practices When Migrating to Office 365Best practices When Migrating to Office 365
Best practices When Migrating to Office 365
 
Active Directoryptx sunday.pptx
Active Directoryptx sunday.pptxActive Directoryptx sunday.pptx
Active Directoryptx sunday.pptx
 
Data Leakage Prevention
Data Leakage PreventionData Leakage Prevention
Data Leakage Prevention
 
Why a Data Services Marketplace is Critical for a Successful Data-Driven Ente...
Why a Data Services Marketplace is Critical for a Successful Data-Driven Ente...Why a Data Services Marketplace is Critical for a Successful Data-Driven Ente...
Why a Data Services Marketplace is Critical for a Successful Data-Driven Ente...
 
gkkCloudtechnologyassociate(cta)day 2
gkkCloudtechnologyassociate(cta)day 2gkkCloudtechnologyassociate(cta)day 2
gkkCloudtechnologyassociate(cta)day 2
 
Lecture 11 active directory
Lecture 11 active directoryLecture 11 active directory
Lecture 11 active directory
 
Microsoft Active Directory.pptx
Microsoft Active Directory.pptxMicrosoft Active Directory.pptx
Microsoft Active Directory.pptx
 

04232015094601

  • 1. Christopher Chapman | MCT Content PM, Microsoft Learning, PDG Planning , Microsoft
  • 2. Meet Christopher Chapman • Background – IT manager and implementer focused on deploying, maintaining and optimizing networks of all sizes (from SMB to Enterprise) – IT Consulting projects include Custom SharePoint for Microsoft IT, Netware/Notes migration to AD/Exchange, Transition to centralized management (250 clients) – Instructor and Director of Instruction • Contact – christopherjs@microsoft.com – @ChristopherMSL
  • 3. Course Topics Understanding Active Directory 01 | Introduction to Active Directory 02 | Active Directory Domain Services (DS) 03 | Active Directory Certificate Services (CS) 04 | Active Directory Federation Services (FS) 05 | Active Directory Rights Management Services (RMS) 06 | Active Directory Lightweight Directory Services (LDS)
  • 4. Setting Expectations • Target Audience – IT Help Desk staff interested in moving into Network/Systems Administration – Anyone interested in learning more about Active Directory • Suggested Prerequisites/Supporting Material – Microsoft Technology Associate: • Exam 98-349: Windows Operating System Fundamentals • Exam 98-365: Windows Server Administration Fundamentals • Exam 98-366: Networking Fundamentals • Exam 98-367: Security Fundamentals
  • 6. • Active Directory isn’t what it used to be! • What is Active Directory? • Active Directory Roles Module Overview
  • 7. • What is Active Directory? – A collection of services (Server Roles and Features) used to manage identity and access for and to resources on a network What is Active Directory Domain Services • Internal Accounts • Authorization • Authentication Federation Services • Network Access for External Resources Certificate Services • Identity • Non- Repudiation Rights Management Services • Content Security and Control Lightweight Directory Services • Application Templates Active Directory • Identity • Access • Centralized Management
  • 8. • AD Domain Services (AD DS) – Users, Computers, Policies • AD Certificate Services (AD CS) – Service, Client, Server and User identification • AD Federation Services (AD FS) – Resource access across traditional boundaries • AD Rights Management Services (AD RMS) – Maintain security of data • AD Lightweight Directory Services (AD LDS) Active Directory Roles
  • 9. • What is Active Directory Domain Services? – A directory service is both the directory information source and the service that makes the information available and usable – A phone book… What is AD DS? Windows Server • Mgmt Profile • Network Info • Printers • Shares Windows User • Account Information • Privileges • Profiles • Policies Windows Client • Mgmt Profile • Network Info • Policies Email Servers • Mailbox Information • Address Book Applications • Server Config • SSO • App-Specific Directory Info Network Devices • Config • QoS Policy • Security Policy Active Directory Domain Services • Manageability • Security • Interoperability
  • 10. • Scalable, secure, and manageable infrastructure for user and resource management – stores and manages information about network resources – provides support for directory-enabled applications such as Microsoft® Exchange Server – allows for centralized management What does AD DS do?
  • 11. • AD CS is the Microsoft implementation of Public Key Infrastructure (PKI) • PKI is a set of hardware, software, people, policies, and procedures needed to create, manage, distribute, use, store, and revoke digital certificates What is AD CS? Revocation Request Certificate Revocation List CRL Retrieval 5 x.509 Certificate Chain Certificate Retrieval 4 Certificate Signing Request Enrollment 3 Certificate Repository Certification Revocation Repository 2 End-Entities (users or computers) 1
  • 12. • AD CS provides customizable services for issuing and managing digital certificates – Certification Authorities – CA Web Enrollment – Online Responders – Network Device Enrollment Service (NDES) – Certificate Enrollment Web Service – Certificate Enrollment Policy Web Service What does AD CS do?
  • 13. • A software component that facilitates the cross- organizational access of systems and applications What is AD FS? Web Server Resource Federation Server Account Partner Organization Resource Partner Organization Account Federation Server AD DS Federation Trust
  • 14. • The AD FS server role provides simplified, secured identity federation and Web single sign-on (SSO) capabilities. – enables the creation of trust relationships between two organizations – provides access to applications between organizations – provides Single Sign-on (SSO) between two different directories for Web-based applications What does AD FS do?
  • 15. • Active Directory Rights Management Services (AD RMS) is an information protection technology that works with applications to safeguard digital information What is AD RMS? RMS Server Information Author Recipient
  • 16. • Allows individuals and administrators to specify access permissions to documents, workbooks, and presentations – prevent sensitive information from being printed, forwarded, or copied by unauthorized people – access and usage restrictions are enforced no matter where the information is located What does AD RMS do?
  • 17. • AD LDS is a hierarchical file-based directory store • AD LDS is both the directory information source and the service that makes the information available and usable What is AD LDS? Windows User • Account Information • Privileges • Profiles • Policies Email Servers • Mailbox Information • Address Book Applications • Server Config • SSO • App-Specific Directory Info Network Devices • Config • QoS Policy • Security Policy Active Directory LDS • Manageability • Security • Interoperability
  • 18. • Lightweight Directory Access Protocol (LDAP) – Directory service that provides flexible support for directory-enabled applications, without the dependencies and domain-related restrictions of AD DS – provide directory services for directory-enabled applications without incurring the overhead of domains and forests – no requirement for a single schema throughout a forest What does AD LDS do?
  • 20. ©2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Office, Azure, System Center, Dynamics and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Editor's Notes

  1. 1
  2. 1 minute
  3. 1 minute
  4. 1 minute
  5. 2 minutes Active Directory is a collection of services (Server Roles and Features) used to manage identity and access for and to resources on a network.
  6. 2 minutes In the next few slides you will cover each of these Windows Roles with a summary of what each is and what each does.
  7. 5 Minutes Use the phone book
  8. End-entity - the end-user consumers of PKI services. This could be a person, or a computer. Certificate Authority (CA) – Trusted party responsible for the management of digital certificates. The CA is the center of the PKI trust model. A CA is responsible for issuing signed digital certificates, maintaining a certificate repository, and managing revoked certificates and the public list of those certificates, the certificate revocation list (CRL). Certificate Signing Request (CSR) - a document generated by an end-entity used to enroll for a certificate. The request contains information about the user such as distinguished name and public key (signature). Public Digital Certificate and Certificate Path - a digital certificate is the public component in PKI. A public certificate represents the credentials for a given end-entity by connecting an entity to a specific public key. The end-entity represented holds the private key that corresponds to that certificate. Certificates can be used for a number of security measures such as digital signatures to verify the origin, integrity of information, and non-repudiation. Certificate Revocation List (CRL) - a list of revoked certificates. This list is checked during certificate verification by a certificate holder to verify the revocation status for a given certificate. Online Certificate Status Protocol (OCSP) is a CRL alternative that can be used to retrieve revocation and status information for a certificate as well.
  9. By using Server Manager, you can install the following components of AD CS: Certification authorities (CAs) CAs issue certificates to users, computers, and services, and manage certificate validity CA Web enrollment Web enrollment allows users to connect to a CA by means of a Web browser in order to request certificates and retrieve certificate revocation lists (CRLs) Online Responder The Online Responder service sends a signed response containing requested certificate status information to clients Network Device Enrollment Service The Network Device Enrollment Service allows network devices to obtain certificates when they don’t have domain accounts Certificate Enrollment Web Service The Certificate Enrollment Web Service allows for certificate enrollment by users and computers using SSL to enables policy-based certificate enrollment for disconnected or non-domain-joined computers and users Certificate Enrollment Policy Web Service Delivers certificate enrollment policy information to computers and users to enable the Certificate Enrollment Web Service
  10. AD FS simplifies end-user access to systems and applications by using a claims-based access authorization mechanism to maintain application security. You can deploy AD FS to: Provide your employees or customers with seamless access to Web-based resources in any federation partner organization on the Internet without requiring employees or customers to log on more than once Retain complete control over your employee or customer identities without using other sign-on providers (Windows Live ID, Liberty Alliance, and others) Provide your employees or customers with a Web-based, SSO experience when they need remote access to internally hosted Web sites or services Provide your employees or customers with a Web-based, SSO experience when they access cross-organizational Web sites or services from within the firewalls of your network Identity Federation allows for separate authentication domains or realms to be able to share resources without having to provide complete access to each of the authentication domains. In the real world everyone has a number of usernames and passwords that they must remember, even in the same organizations or within partner organizations. Identity federation allows for different authentication domains/realms to provide single sign-on (SSO) services. This can be done without creating a full Active Directory trust between the organizations.
  11. A rights-management solution protects information stored in documents, e-mail messages, and Web sites from unauthorized viewing, modification, or use. Features typically include: Protecting sensitive information from being accessed or shared with unauthorized users by preventing users from forwarding or copying content Ensuring that data content is protected and tamper-resistant using encryption and digital signatures Controlling when data will expire based on time requirements, even when that information is sent over the Internet to other individuals - ensuring that the most current information is used
  12. The image here was also used in the slide regarding AD DS. It was left in place here intentionally to demonstrate the similarities between AD DS and AD LDS.
  13. Active Directory Lightweight Directory Services (AD LDS) provides a Lightweight Directory Access Protocol (LDAP) compliant directory and associated services. It is used to provide authentication and directory services for custom written, third-party and other enterprise applications.
  14. 19