PowerPoint slides created for the Course Configuring Windows Server 2008 Active Directory for Instructor use. Exam: 70-640
Basic administration of Active Directory is the main issue in this presentation
Configuration server 2008 70 640 course - chapter 2 administration
1. Configuring Windows
Server 2008 Active
Directory
Chapter 2 – Administration
NæringsAkademiet Fredrikstad
Jørn Jensen - jorn.jensen@na.no
2. AD - Administration
Microsoft Management Console
Mmc.exe
Add snapin to use differnt tools
AD administrations tools
Active Directory Users and Computers
Active Directory Sites and Services
Active Directory Domains and Trust
3. MMC modes
Author – kan tilpasse konsollet
User Mode – Full Mode
Kan bruke alle Snap-ins som er installert
User Mode – Limited Access, multiple window
User Mode – Limited Access, singe window
Du kan bruke Saved Queries for å lagre ferdig definerte
”søk”
Dsquery.exe kan brukes på kommandolinjen for å søke
etter objekter i AD
4. Delegation
AD is Delegation
An important task is to hand out the rights and distribute
the administrative responsibility
You must Enable Advanced Features in the View menu
to view all the ACL properties for the objects
6. Delegation
The rights to all objects are located in the ACL/Access
Control List
The different rights that the user have is called:
ACE/Access Control Entries
ACE are stored in the Discretionary Access Controle
List/DACL
Auditing settings are stored in the SACL/System Access
Controle List
You can view the ACL to an object under the Security tab in
Properties
Effective Permissions, the permission that the object finally
gets
Think delegation of administrative tasks in the AD structure