SlideShare a Scribd company logo
Module 1:
Introduction to
Active Directory
Overview
Introduction to Active Directory
Active Directory Logical Structure
Role of DNS in Active Directory
Active Directory Physical Structure
Methods for Administering a Windows
2000 Network
Introduction to Active Directory
What Is Active Directory?
Active Directory Objects
Active Directory Schema
Lightweight Directory Access Protocol
(LDAP)
What Is Active Directory?
Directory Service
Functionality
 Organize
 Manage
 Control
Resources
Centralized Management
 Single point of administration
 Full user access to directory
resources by a single logon
Active Directory Objects
Objects Represent Network
Resources
Attributes Store Information About
an Object
Attributes
First Name
Last Name
Logon Name
Attributes
Printer Name
Printer Location
Active Directory
Printers
Printer1
Printer2
Suzan Fine
Users
Don Hall
Attribute
Value
Objects
Printers
Users
Printer3
Active Directory Schema
Objects
Class Examples
Printers
Computers
Users
Attributes of Users
Might Contain:
accountExpires
department
distinguishedName
middleName
List of Attributes
accountExpires
department
distinguishedName
directReports
dNSHostName
operatingSystem
repsFrom
repsTo
middleName
…
Attribute
Examples
Active Directory Schema Is:
 Dynamically Available
 Dynamically Updateable
 Protected by DACLs
DNS and Active Directory
Namespaces
microsoft.com
sales. microsoft.com
training. microsoft.com
training
microsoft
DNS Namespace
Active Directory Namespace
= DNS node (domain or computer) = Active Directory domain
sales
computer1
(DNS root domain)
“.”
com.
Internet
Lightweight Directory Access
Protocol (LDAP)
LDAP Provides a Way to
Communicate with Active Directory
by Specifying Unique Naming
Paths for Each Object in the
Directory
LDAP Naming Paths Include:
 Distinguished names
 Relative distinguished names
CN=Suzan Fine,OU=Sales,DC=contoso,DC=msft
Suzan Fine
Active Directory Logical
Structure
Domains
Organizational Units
Trees and Forests
Global Catalog
Domains
A Domain Is a Security Boundary
 A domain administrator can administer
only within the domain, unless
explicitly granted administration rights
in other domains
A Domain Is a Unit of Replication
 Domain controllers in a domain
participate in replication and contain a
complete copy of the directory
information for their domain
Windows 2000
Replication
Organizational Units
Organizational Structure
Sales
Vancouver
Repair
Users
Sales
Computers
Network Administrative Model
Use OUs to Group Objects into a Logical
Hierarchy That Best Suits the Needs of
Your Organization
Delegate Administrative Control over the
Objects Within an OU by Assigning
Specific Permissions to Users and Groups
Trees and Forests
contoso.msft
au.
contoso.msft
asia.
contoso.msft
Tree
Two-Way Transitive Trusts
au.
nwtraders.msft
asia.
nwtraders.msft
nwtraders.msft
Forest
Tree
Two-Way Transitive Trust
Global Catalog
Global Catalog Server
Global Catalog
Subset of the
Attributes of All
Objects
Domain
Domain
Domain
Domain
Domain
Domain
Queries
Group membership
when user logs on
Introduction to the Role of DNS
in Active Directory
Name Resolution
 DNS translates computer names to IP addresses
 Computers use DNS to locate each other on the
network
Naming Convention for Windows 2000 Domains
 Windows 2000 uses DNS naming standards for
domain names
 DNS domains and Active Directory domains share a
common hierarchical naming structure
Locating the Physical Components of Active
Directory
 DNS identifies domain controllers by the services
they provide
 Computers use DNS to locate domain controllers and
global catalog servers
DNS Host Names and Windows
2000 Computer Names
 DNS host record and Active Directory
object represent the same physical
computer
 DNS allows computers to locate domain
controllers within Active Directory
Active Directory
training.microsoft.com
Builtin
Computers
Computer1
Computer2
“.”
com.
sales training
computer1
microsoft
FQDN = computer1.training.microsoft.com
Windows 2000 Computer Name = Computer1
DNS Requirements for Active
Directory
DNS Requirements to Support Active Directory
Support for SRV records (mandatory)
Support for the dynamic update
protocol (recommended)
Support for incremental zone transfers
(recommended)
What Is a Tree?
Parent Domain
Child Domain
Contiguous Namespace
sales.contoso.msft
Parent
Child
New
Domain
Tree Root Domain
contoso.msft
sales.contoso.msft
What Is a Forest?
nwtraders.msft
marketing.
nwtraders.msft
sales.
nwtraders.msft
contoso.msft
sales.
contoso.msft
All of The Domains in a
Forest Share a Common
Configuration, Schema, and
Global Catalog
A Forest is One or More Trees
Trees in a Forest Do Not Share a
Contiguous Namespace
Forest
Tree
Tree
What Is the Forest Root
Domain?
The Forest Root Domain Is
the First Domain Created
in a Forest
contoso.msft
Forest
Forest Root Domain
nwtraders.msft
Tree
Tree Root Domain
Global Catalog
Configuration
and Schema
Enterprise Admins
Schema Admins
marketing.nwtraders.msft sales.contoso.msft
Tree
Characteristics of Multiple
Domains
Reduce Replication Traffic
Maintain Separate and Distinct
Security Policies Between Domains
Preserve the Domain Structure of
Earlier Versions of Windows NT
Separate Administrative Control
Active Directory Physical
Structure
Domain Controllers
Sites
Domain Controllers
Domain
Controller
Domain
Controller
Domain
Replication
= A Writeable Copy of the Active Directory Database
Domain Controllers:
Participate in Active Directory replication
Perform single master operations roles in a domain
Sites
Sites:
 Optimize replication traffic
 Enable users to log on to a domain controller
by using a reliable, high-speed connection
Site
IP subnet
IP subnet
Los Angeles
Seattle
Chicago
New York
Introduction to Active Directory
Replication
Replication
Domain
Controller B
Domain
Controller C
Domain
Controller A
Multimaster Replication with
a Loose Convergence
Replication Components and
Processes
How Replication Works
Replication Latency
Resolving Replication Conflicts
Optimizing Replication
How Replication Works
Replication
Originating Update
Domain
Controller A
Domain
Controller B
Domain
Controller C
Replicated Update
Replicated Update
Active Directory
Update
 Move
 Delete
 Add
 Modify
Replication Latency
Replication
Originating Update
Domain
Controller A
Change Notification
Change Notification
Domain Controller C
Domain
Controller B
Replicated Update
Replicated Update
 Default Replication Latency (Change Notification) = 5 minutes
 When No Changes, Scheduled Replication = One Hour
 Urgent Replication = Immediate Change
Notification
Resolving Replication Conflicts
Domain Controller A
Originating Update
Domain Controller B
Conflict
Originating Update
Stamp Stamp
Conflict
Version Number Timestamp Server GUID
Stamp
Conflicts Can Be Due to:
 Attribute Value
 Adding/Moving Under a Deleted Container Object
or the Deletion of a Container Object
 Sibling Name
Replication Topology
Directory Partitions
What Is Replication Topology?
Global Catalog and Replication of
Partitions
Directory Partitions
Domain
Forest
Directory
Partitions
Active Directory
Database
contoso.msft
Configuration
Schema
Holds information about all
domain-specific objects
created in Active Directory
Contains information about
Active Directory structure
Contains definitions and rules
for creating and manipulating
all objects and attributes
B2
A2
A1
B1
B3
A4
A3
Domain Controllers
from Different Domains Domain A Topology
Domain B Topology
Schema/Configuration Topology
A2
A1
A4
A3
Domain Controllers
from the Same Domains
Domain A Topology
Schema/Configuration Topology
What Is Replication Topology?
A2
A1
A4
A3
Domain Controllers
from the Same Domains
Domain A Topology
Schema/Configuration Topology
B2
A2
A1
B1
B3
A4
A3
Domain Controllers
from Different Domains Domain A Topology
Domain B Topology
Schema/Configuration Topology
What Is Replication Topology?
Partial Directory
Partition Replica
Global Catalog
Server
contoso.msft
Configuration
Schema
Holds read only copy of all
domain directory partitions
namerica.contoso.msft
Global Catalog and Replication
of Partitions
B2
A2
A1
B1
B3
A4
A3
Domain A Topology
Domain B Topology
Schema/Configuration Topology
Global Catalog and Replication
of Partitions
Methods for Administering a
Windows 2000 Network
Using Active Directory for Centralized
Management
Managing the User Environment
Delegating Administrative Control
Using Active Directory for
Centralized Management
OU1
Domain
Computers
Users
OU2
Users
Printers
Computer1
User1
Printer1
User2
Domain
OU2
OU1
User1 Computer1 Printer1
User2
Search
Active Directory:
 Enables a single administrator to centrally manage
resources
 Allows administrators to easily locate information
 Allows administrators to group objects into OUs
 Uses Group Policy to specify policy-based settings
Managing the User
Environment
Use Group Policy to:
 Control and lock down what users can do
 Centrally manage software installation,
repairs, updates,
and removal
 Configure user data to follow users whether
they are online or offline
Windows 2000
Enforces Continually
Apply Group
Policy Once
1 2
3 Domain
OU1 OU2 OU3
1 2 3
Delegating Administrative
Control
Assign Permissions:
 For specific OUs to other
administrators
 To modify specific attributes of
an object in a single OU
 To perform the same task in all OUs
Customize Administrative Tools to:
 Map to delegated administrative tasks
 Simplify interface design
Domain
Admin1
Admin2
Admin3
OU2
OU3
OU1
Review
Introduction to Active Directory
Active Directory Logical Structure
Role of DNS in Active Directory
Active Directory Physical Structure
Methods for Administering a Windows
2000 Network

More Related Content

Similar to MS_Active_Directory.ppt

Active directory and application
Active directory and applicationActive directory and application
Active directory and application
aminpathan11
 
Active Directory
Active DirectoryActive Directory
Active Directory
Jessica Henderson
 
Active Directory
Active Directory Active Directory
Active Directory
Sandeep Kapadane
 
Activedirecotryfundamentals
ActivedirecotryfundamentalsActivedirecotryfundamentals
Activedirecotryfundamentals
Shekhar Singh
 
Chapter01 Introduction To Windows Server 2003
Chapter01     Introduction To  Windows  Server 2003Chapter01     Introduction To  Windows  Server 2003
Chapter01 Introduction To Windows Server 2003
Raja Waseem Akhtar
 
Active directory slides
Active directory slidesActive directory slides
Active directory slides
Timothy Moffatt
 
Active diirecotry
Active diirecotryActive diirecotry
Active diirecotry
Pradeesh Stanislavose
 
Network and System Administration chapter 2
Network and System Administration chapter 2Network and System Administration chapter 2
Network and System Administration chapter 2
IgguuMuude
 
Ads Overview En
Ads Overview EnAds Overview En
Ads Overview En
raj240969
 
Ads Overview En
Ads Overview EnAds Overview En
Ads Overview En
raj240969
 
Administering computer accounts and resources in active directory
Administering computer accounts and resources in active directoryAdministering computer accounts and resources in active directory
Administering computer accounts and resources in active directory
Kavinda Prabhath
 
LESSON 2 - Active Directory and Domain Controller.pptx
LESSON 2 - Active Directory and Domain Controller.pptxLESSON 2 - Active Directory and Domain Controller.pptx
LESSON 2 - Active Directory and Domain Controller.pptx
ssuser0f6f05
 
Active directory installation windows 2003 1
Active directory installation windows 2003 1Active directory installation windows 2003 1
Active directory installation windows 2003 1
tameemyousaf
 
Active directory
Active directoryActive directory
Active directory
Prasanth Menon
 
Introduction
IntroductionIntroduction
Introduction
hajafaarukh
 
Server interview[1]
Server interview[1]Server interview[1]
Server interview[1]
sourav nanda
 
Ctive directory interview question and answers
Ctive directory interview question and answersCtive directory interview question and answers
Ctive directory interview question and answers
sankar palla
 
Active Directory component
Active Directory componentActive Directory component
Active Directory component
kuldeep singh shishodia
 
Final domain control policy
Final domain control policy  Final domain control policy
Final domain control policy
BhagyashriJadhav16
 
Directory services by SAJID
Directory services by SAJIDDirectory services by SAJID
Directory services by SAJID
Sajid khan
 

Similar to MS_Active_Directory.ppt (20)

Active directory and application
Active directory and applicationActive directory and application
Active directory and application
 
Active Directory
Active DirectoryActive Directory
Active Directory
 
Active Directory
Active Directory Active Directory
Active Directory
 
Activedirecotryfundamentals
ActivedirecotryfundamentalsActivedirecotryfundamentals
Activedirecotryfundamentals
 
Chapter01 Introduction To Windows Server 2003
Chapter01     Introduction To  Windows  Server 2003Chapter01     Introduction To  Windows  Server 2003
Chapter01 Introduction To Windows Server 2003
 
Active directory slides
Active directory slidesActive directory slides
Active directory slides
 
Active diirecotry
Active diirecotryActive diirecotry
Active diirecotry
 
Network and System Administration chapter 2
Network and System Administration chapter 2Network and System Administration chapter 2
Network and System Administration chapter 2
 
Ads Overview En
Ads Overview EnAds Overview En
Ads Overview En
 
Ads Overview En
Ads Overview EnAds Overview En
Ads Overview En
 
Administering computer accounts and resources in active directory
Administering computer accounts and resources in active directoryAdministering computer accounts and resources in active directory
Administering computer accounts and resources in active directory
 
LESSON 2 - Active Directory and Domain Controller.pptx
LESSON 2 - Active Directory and Domain Controller.pptxLESSON 2 - Active Directory and Domain Controller.pptx
LESSON 2 - Active Directory and Domain Controller.pptx
 
Active directory installation windows 2003 1
Active directory installation windows 2003 1Active directory installation windows 2003 1
Active directory installation windows 2003 1
 
Active directory
Active directoryActive directory
Active directory
 
Introduction
IntroductionIntroduction
Introduction
 
Server interview[1]
Server interview[1]Server interview[1]
Server interview[1]
 
Ctive directory interview question and answers
Ctive directory interview question and answersCtive directory interview question and answers
Ctive directory interview question and answers
 
Active Directory component
Active Directory componentActive Directory component
Active Directory component
 
Final domain control policy
Final domain control policy  Final domain control policy
Final domain control policy
 
Directory services by SAJID
Directory services by SAJIDDirectory services by SAJID
Directory services by SAJID
 

Recently uploaded

Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Speck&Tech
 
HCL Notes and Domino License Cost Reduction in the World of DLAU
HCL Notes and Domino License Cost Reduction in the World of DLAUHCL Notes and Domino License Cost Reduction in the World of DLAU
HCL Notes and Domino License Cost Reduction in the World of DLAU
panagenda
 
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAUHCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
panagenda
 
20240607 QFM018 Elixir Reading List May 2024
20240607 QFM018 Elixir Reading List May 202420240607 QFM018 Elixir Reading List May 2024
20240607 QFM018 Elixir Reading List May 2024
Matthew Sinclair
 
Introduction of Cybersecurity with OSS at Code Europe 2024
Introduction of Cybersecurity with OSS  at Code Europe 2024Introduction of Cybersecurity with OSS  at Code Europe 2024
Introduction of Cybersecurity with OSS at Code Europe 2024
Hiroshi SHIBATA
 
Project Management Semester Long Project - Acuity
Project Management Semester Long Project - AcuityProject Management Semester Long Project - Acuity
Project Management Semester Long Project - Acuity
jpupo2018
 
Choosing The Best AWS Service For Your Website + API.pptx
Choosing The Best AWS Service For Your Website + API.pptxChoosing The Best AWS Service For Your Website + API.pptx
Choosing The Best AWS Service For Your Website + API.pptx
Brandon Minnick, MBA
 
AI 101: An Introduction to the Basics and Impact of Artificial Intelligence
AI 101: An Introduction to the Basics and Impact of Artificial IntelligenceAI 101: An Introduction to the Basics and Impact of Artificial Intelligence
AI 101: An Introduction to the Basics and Impact of Artificial Intelligence
IndexBug
 
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development ProvidersYour One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
akankshawande
 
20240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 202420240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 2024
Matthew Sinclair
 
Generating privacy-protected synthetic data using Secludy and Milvus
Generating privacy-protected synthetic data using Secludy and MilvusGenerating privacy-protected synthetic data using Secludy and Milvus
Generating privacy-protected synthetic data using Secludy and Milvus
Zilliz
 
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdfUnlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Malak Abu Hammad
 
National Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practicesNational Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practices
Quotidiano Piemontese
 
OpenID AuthZEN Interop Read Out - Authorization
OpenID AuthZEN Interop Read Out - AuthorizationOpenID AuthZEN Interop Read Out - Authorization
OpenID AuthZEN Interop Read Out - Authorization
David Brossard
 
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with SlackLet's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
shyamraj55
 
Serial Arm Control in Real Time Presentation
Serial Arm Control in Real Time PresentationSerial Arm Control in Real Time Presentation
Serial Arm Control in Real Time Presentation
tolgahangng
 
Programming Foundation Models with DSPy - Meetup Slides
Programming Foundation Models with DSPy - Meetup SlidesProgramming Foundation Models with DSPy - Meetup Slides
Programming Foundation Models with DSPy - Meetup Slides
Zilliz
 
GenAI Pilot Implementation in the organizations
GenAI Pilot Implementation in the organizationsGenAI Pilot Implementation in the organizations
GenAI Pilot Implementation in the organizations
kumardaparthi1024
 
How to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For FlutterHow to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For Flutter
Daiki Mogmet Ito
 
Mariano G Tinti - Decoding SpaceX
Mariano G Tinti - Decoding SpaceXMariano G Tinti - Decoding SpaceX
Mariano G Tinti - Decoding SpaceX
Mariano Tinti
 

Recently uploaded (20)

Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
 
HCL Notes and Domino License Cost Reduction in the World of DLAU
HCL Notes and Domino License Cost Reduction in the World of DLAUHCL Notes and Domino License Cost Reduction in the World of DLAU
HCL Notes and Domino License Cost Reduction in the World of DLAU
 
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAUHCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
 
20240607 QFM018 Elixir Reading List May 2024
20240607 QFM018 Elixir Reading List May 202420240607 QFM018 Elixir Reading List May 2024
20240607 QFM018 Elixir Reading List May 2024
 
Introduction of Cybersecurity with OSS at Code Europe 2024
Introduction of Cybersecurity with OSS  at Code Europe 2024Introduction of Cybersecurity with OSS  at Code Europe 2024
Introduction of Cybersecurity with OSS at Code Europe 2024
 
Project Management Semester Long Project - Acuity
Project Management Semester Long Project - AcuityProject Management Semester Long Project - Acuity
Project Management Semester Long Project - Acuity
 
Choosing The Best AWS Service For Your Website + API.pptx
Choosing The Best AWS Service For Your Website + API.pptxChoosing The Best AWS Service For Your Website + API.pptx
Choosing The Best AWS Service For Your Website + API.pptx
 
AI 101: An Introduction to the Basics and Impact of Artificial Intelligence
AI 101: An Introduction to the Basics and Impact of Artificial IntelligenceAI 101: An Introduction to the Basics and Impact of Artificial Intelligence
AI 101: An Introduction to the Basics and Impact of Artificial Intelligence
 
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development ProvidersYour One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
 
20240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 202420240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 2024
 
Generating privacy-protected synthetic data using Secludy and Milvus
Generating privacy-protected synthetic data using Secludy and MilvusGenerating privacy-protected synthetic data using Secludy and Milvus
Generating privacy-protected synthetic data using Secludy and Milvus
 
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdfUnlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
 
National Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practicesNational Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practices
 
OpenID AuthZEN Interop Read Out - Authorization
OpenID AuthZEN Interop Read Out - AuthorizationOpenID AuthZEN Interop Read Out - Authorization
OpenID AuthZEN Interop Read Out - Authorization
 
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with SlackLet's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
 
Serial Arm Control in Real Time Presentation
Serial Arm Control in Real Time PresentationSerial Arm Control in Real Time Presentation
Serial Arm Control in Real Time Presentation
 
Programming Foundation Models with DSPy - Meetup Slides
Programming Foundation Models with DSPy - Meetup SlidesProgramming Foundation Models with DSPy - Meetup Slides
Programming Foundation Models with DSPy - Meetup Slides
 
GenAI Pilot Implementation in the organizations
GenAI Pilot Implementation in the organizationsGenAI Pilot Implementation in the organizations
GenAI Pilot Implementation in the organizations
 
How to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For FlutterHow to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For Flutter
 
Mariano G Tinti - Decoding SpaceX
Mariano G Tinti - Decoding SpaceXMariano G Tinti - Decoding SpaceX
Mariano G Tinti - Decoding SpaceX
 

MS_Active_Directory.ppt

  • 2. Overview Introduction to Active Directory Active Directory Logical Structure Role of DNS in Active Directory Active Directory Physical Structure Methods for Administering a Windows 2000 Network
  • 3. Introduction to Active Directory What Is Active Directory? Active Directory Objects Active Directory Schema Lightweight Directory Access Protocol (LDAP)
  • 4. What Is Active Directory? Directory Service Functionality  Organize  Manage  Control Resources Centralized Management  Single point of administration  Full user access to directory resources by a single logon
  • 5. Active Directory Objects Objects Represent Network Resources Attributes Store Information About an Object Attributes First Name Last Name Logon Name Attributes Printer Name Printer Location Active Directory Printers Printer1 Printer2 Suzan Fine Users Don Hall Attribute Value Objects Printers Users Printer3
  • 6. Active Directory Schema Objects Class Examples Printers Computers Users Attributes of Users Might Contain: accountExpires department distinguishedName middleName List of Attributes accountExpires department distinguishedName directReports dNSHostName operatingSystem repsFrom repsTo middleName … Attribute Examples Active Directory Schema Is:  Dynamically Available  Dynamically Updateable  Protected by DACLs
  • 7. DNS and Active Directory Namespaces microsoft.com sales. microsoft.com training. microsoft.com training microsoft DNS Namespace Active Directory Namespace = DNS node (domain or computer) = Active Directory domain sales computer1 (DNS root domain) “.” com. Internet
  • 8. Lightweight Directory Access Protocol (LDAP) LDAP Provides a Way to Communicate with Active Directory by Specifying Unique Naming Paths for Each Object in the Directory LDAP Naming Paths Include:  Distinguished names  Relative distinguished names CN=Suzan Fine,OU=Sales,DC=contoso,DC=msft Suzan Fine
  • 9. Active Directory Logical Structure Domains Organizational Units Trees and Forests Global Catalog
  • 10. Domains A Domain Is a Security Boundary  A domain administrator can administer only within the domain, unless explicitly granted administration rights in other domains A Domain Is a Unit of Replication  Domain controllers in a domain participate in replication and contain a complete copy of the directory information for their domain Windows 2000 Replication
  • 11. Organizational Units Organizational Structure Sales Vancouver Repair Users Sales Computers Network Administrative Model Use OUs to Group Objects into a Logical Hierarchy That Best Suits the Needs of Your Organization Delegate Administrative Control over the Objects Within an OU by Assigning Specific Permissions to Users and Groups
  • 12. Trees and Forests contoso.msft au. contoso.msft asia. contoso.msft Tree Two-Way Transitive Trusts au. nwtraders.msft asia. nwtraders.msft nwtraders.msft Forest Tree Two-Way Transitive Trust
  • 13. Global Catalog Global Catalog Server Global Catalog Subset of the Attributes of All Objects Domain Domain Domain Domain Domain Domain Queries Group membership when user logs on
  • 14. Introduction to the Role of DNS in Active Directory Name Resolution  DNS translates computer names to IP addresses  Computers use DNS to locate each other on the network Naming Convention for Windows 2000 Domains  Windows 2000 uses DNS naming standards for domain names  DNS domains and Active Directory domains share a common hierarchical naming structure Locating the Physical Components of Active Directory  DNS identifies domain controllers by the services they provide  Computers use DNS to locate domain controllers and global catalog servers
  • 15. DNS Host Names and Windows 2000 Computer Names  DNS host record and Active Directory object represent the same physical computer  DNS allows computers to locate domain controllers within Active Directory Active Directory training.microsoft.com Builtin Computers Computer1 Computer2 “.” com. sales training computer1 microsoft FQDN = computer1.training.microsoft.com Windows 2000 Computer Name = Computer1
  • 16. DNS Requirements for Active Directory DNS Requirements to Support Active Directory Support for SRV records (mandatory) Support for the dynamic update protocol (recommended) Support for incremental zone transfers (recommended)
  • 17. What Is a Tree? Parent Domain Child Domain Contiguous Namespace sales.contoso.msft Parent Child New Domain Tree Root Domain contoso.msft sales.contoso.msft
  • 18. What Is a Forest? nwtraders.msft marketing. nwtraders.msft sales. nwtraders.msft contoso.msft sales. contoso.msft All of The Domains in a Forest Share a Common Configuration, Schema, and Global Catalog A Forest is One or More Trees Trees in a Forest Do Not Share a Contiguous Namespace Forest Tree Tree
  • 19. What Is the Forest Root Domain? The Forest Root Domain Is the First Domain Created in a Forest contoso.msft Forest Forest Root Domain nwtraders.msft Tree Tree Root Domain Global Catalog Configuration and Schema Enterprise Admins Schema Admins marketing.nwtraders.msft sales.contoso.msft Tree
  • 20. Characteristics of Multiple Domains Reduce Replication Traffic Maintain Separate and Distinct Security Policies Between Domains Preserve the Domain Structure of Earlier Versions of Windows NT Separate Administrative Control
  • 22. Domain Controllers Domain Controller Domain Controller Domain Replication = A Writeable Copy of the Active Directory Database Domain Controllers: Participate in Active Directory replication Perform single master operations roles in a domain
  • 23. Sites Sites:  Optimize replication traffic  Enable users to log on to a domain controller by using a reliable, high-speed connection Site IP subnet IP subnet Los Angeles Seattle Chicago New York
  • 24. Introduction to Active Directory Replication Replication Domain Controller B Domain Controller C Domain Controller A Multimaster Replication with a Loose Convergence
  • 25. Replication Components and Processes How Replication Works Replication Latency Resolving Replication Conflicts Optimizing Replication
  • 26. How Replication Works Replication Originating Update Domain Controller A Domain Controller B Domain Controller C Replicated Update Replicated Update Active Directory Update  Move  Delete  Add  Modify
  • 27. Replication Latency Replication Originating Update Domain Controller A Change Notification Change Notification Domain Controller C Domain Controller B Replicated Update Replicated Update  Default Replication Latency (Change Notification) = 5 minutes  When No Changes, Scheduled Replication = One Hour  Urgent Replication = Immediate Change Notification
  • 28. Resolving Replication Conflicts Domain Controller A Originating Update Domain Controller B Conflict Originating Update Stamp Stamp Conflict Version Number Timestamp Server GUID Stamp Conflicts Can Be Due to:  Attribute Value  Adding/Moving Under a Deleted Container Object or the Deletion of a Container Object  Sibling Name
  • 29. Replication Topology Directory Partitions What Is Replication Topology? Global Catalog and Replication of Partitions
  • 30. Directory Partitions Domain Forest Directory Partitions Active Directory Database contoso.msft Configuration Schema Holds information about all domain-specific objects created in Active Directory Contains information about Active Directory structure Contains definitions and rules for creating and manipulating all objects and attributes
  • 31. B2 A2 A1 B1 B3 A4 A3 Domain Controllers from Different Domains Domain A Topology Domain B Topology Schema/Configuration Topology A2 A1 A4 A3 Domain Controllers from the Same Domains Domain A Topology Schema/Configuration Topology What Is Replication Topology?
  • 32. A2 A1 A4 A3 Domain Controllers from the Same Domains Domain A Topology Schema/Configuration Topology B2 A2 A1 B1 B3 A4 A3 Domain Controllers from Different Domains Domain A Topology Domain B Topology Schema/Configuration Topology What Is Replication Topology?
  • 33. Partial Directory Partition Replica Global Catalog Server contoso.msft Configuration Schema Holds read only copy of all domain directory partitions namerica.contoso.msft Global Catalog and Replication of Partitions
  • 34. B2 A2 A1 B1 B3 A4 A3 Domain A Topology Domain B Topology Schema/Configuration Topology Global Catalog and Replication of Partitions
  • 35. Methods for Administering a Windows 2000 Network Using Active Directory for Centralized Management Managing the User Environment Delegating Administrative Control
  • 36. Using Active Directory for Centralized Management OU1 Domain Computers Users OU2 Users Printers Computer1 User1 Printer1 User2 Domain OU2 OU1 User1 Computer1 Printer1 User2 Search Active Directory:  Enables a single administrator to centrally manage resources  Allows administrators to easily locate information  Allows administrators to group objects into OUs  Uses Group Policy to specify policy-based settings
  • 37. Managing the User Environment Use Group Policy to:  Control and lock down what users can do  Centrally manage software installation, repairs, updates, and removal  Configure user data to follow users whether they are online or offline Windows 2000 Enforces Continually Apply Group Policy Once 1 2 3 Domain OU1 OU2 OU3 1 2 3
  • 38. Delegating Administrative Control Assign Permissions:  For specific OUs to other administrators  To modify specific attributes of an object in a single OU  To perform the same task in all OUs Customize Administrative Tools to:  Map to delegated administrative tasks  Simplify interface design Domain Admin1 Admin2 Admin3 OU2 OU3 OU1
  • 39. Review Introduction to Active Directory Active Directory Logical Structure Role of DNS in Active Directory Active Directory Physical Structure Methods for Administering a Windows 2000 Network