SlideShare a Scribd company logo
Introduction to Active
Directory
December 10th, 2008
1-3pm Daniels 407
What we are going to cover...
● The basics of Active Directory
● What AD is
● What AD isn't
● Tools
● Management Concepts
● Additional Services
● Q & A
Active Directory is...
A directory service that provides the ability for centralized:
● Authentication
● Authorization
● Management
 
Active Directory is based on LDAP.  LDAP is an industry standard method
to access information from a remote database.  LDAP does not define what
sorts of info are stored or how it should be stored, only how to access it.
Any type of data can be stored in a properly constructed LDAP service. In
fact, Active Directory Application Mode is just a stand-alone LDAP server.
Active directory stores copies of it's data on several Domain Controllers
(DC's).  If one fails, services are still available.
Tools
Remote Server Administration Toolkit (RSAT)  includes:
● Active Directory Users and Computers (ADUC)
● Group Policy Management Console (GPMC)
● Group Policy Editor 
● DFS Management Console
● Print Managment Console
Domain-wide Administration:
● Active Directory Sites and Services
● Active Directory Domains and Trusts
AD Objects
Organizational Units 
Users
Computers
Groups
Links (publishing):
● Shares
● Print Shares
What AD isn't
● A 100% solution
● A desktop environment
● Microsoft only 
● The same as Novell
● 100% Automatable
● A true identity management system
● Perfect 
 
Authentication
Native:
● Kerberos (Version 5)
● NTLMv2
● LDAP
● Smart Cards/Certificates
 
Extendable to include: 
● Biometrics
Client machines authenticate as well, not just user accounts
Supports dual factor authentication
Mac, Linux clients can auth against AD
Trusts
Trusts don't imply any sort of authorization or rights
assignment.  If Domain "A" trusts Domain "B" all it implies is
that accounts from "B" can be used in "A"  No rights
assignments of any kind are made automatically.
 
This makes it possible to access resources in multiple
domains using a single account. 
 
Trusts:
● Intra-Forest 
● Inter-Forest
● Cross Realm
Authorization
Delegation Wizard
 
Types of Permissions:
● Directory
○ GPO's
○ Manage Groups 
● Machine
○ Local/Remote Login
○ User vs. Admin
○ Group Policy allows
setting any local permission
 
Groups are key to any good permissions model
*AD supports Nested Groups*
Management Concepts
● Domain Structure
○ OU structure
○ User/Computer Locations
○ Grouping Strategy
● Group Policy
○ Linking
○ Filtering
■ Groups
■ WMI Filters
○ Starter GPO's
○ Copying GPO's
○ Group Policy Modelling 
Policies vs. Preferences
● Policies:
○ Policies usually cannot be changed by end user 
○ Configuring IE
○ Deploying Software
○ Configuring Desktop Experience 
● Preferences:
○ End user override  optional per setting
○ Pushing Files/Reg Keys/Shortcuts
○ Item-Level Targeting
 
Both have User and Computer Settings
Loopback - Process User settings using Computer location 
Group Policy Examples
● Remote Assistance - Policy
● Remote Administration - Policy
● Configure Wireless - Policy
● Configure Firewall  - Policy
● Deploy Printers - Policy or GPP
● Deploy Startup/Shutdown/Logon/Logoff Scripts - Policy
or GPP
● Deploy Software (.msi's) - Policy
● Deploy Scheduled Tasks - GPP
● Mapped Drives - GPP
● Power Settings - GPP
Windows Server Update Services (WSUS)
Unified Patch Management for MS Products - FREE
● Apply patches based on grouping
○ Server side groups 
○ *Client Side Targeting via Group Policy*
● Types of Patches:
○ Service Packs/Security Patches/Bugfixes
○ Drivers
○ Defender definitions 
○ Office Patches/Service Packs
○ Add-ons: Windows Media, Silverlight, GPP, etc.
○ Server Products: SQL, IIS 
● Ability to back out patches per group of machines (not
always supported by the patches) 
Distributed File System (DFS)
DFS is a Network File System
Core CAL Required 
● Roots (Namespaces)
○ Delegation 
● Folders
○ Create Arbitrary
structure
● Targets
○ Where the files are 
● Multi-Master Replication
 
 
Windows Distribution Services (WDS)
Replaces Remote Installation Services (RIS) 
Core CAL Required
 
● Imaging  for XP/Vista/2K3 Server/2K8 Server
● Uses PXE for medialess install
● Uses WinPE (think Vista on a CD) as install environment
● Can have a library of drivers
● GUI tools for setting up:
○ Post-install scripts
○ Joining a domain
Additional Services
Core CAL Required (NCSU has a Site License!): 
Certificate Services - PKI
File Services (Clustering, iSCSI)
Print Services
IIS / Webdav
Sharepoint Services 3.0
 
Additional stuff we don't use: DNS/DHCP 
 
Additional CAL Required:
Terminal Services
 
Questions?

More Related Content

PDF
SQL Queries on Smalltalk Objects
PDF
EDF2012 Simon Riggs - Open Data, Open Database: PostgreSQL
PDF
Sync IT Presentation 3.16
PPTX
Netezza online training at GoLogica
PPT
Active directoryfinal
PDF
SQLDay2013_DennyCherry_GettingSQLServiceBrokerUp&Running
PPTX
Heterogeneous databases
PPTX
Data driven pages in a word press site - Srikanth Meenakshi
SQL Queries on Smalltalk Objects
EDF2012 Simon Riggs - Open Data, Open Database: PostgreSQL
Sync IT Presentation 3.16
Netezza online training at GoLogica
Active directoryfinal
SQLDay2013_DennyCherry_GettingSQLServiceBrokerUp&Running
Heterogeneous databases
Data driven pages in a word press site - Srikanth Meenakshi

What's hot (12)

PDF
Presentation on GNM-DMS
PPTX
Slidy widgets
PDF
BigData in IoT #iotconfua
PPTX
Globus Connect Server v5 Q&A Briefing
PPT
Database introduction
PPT
IWMW 1997: Web tools
PPTX
Big data and polyglot solutions
PDF
Introduction to the Globus SaaS (GlobusWorld Tour - STFC)
PPTX
Dbx converter1
PDF
Caltech DIBS: Digital Borrowing System
PPTX
Introduction to GXC-CMS
PDF
Backup aaS Solution Architecture
Presentation on GNM-DMS
Slidy widgets
BigData in IoT #iotconfua
Globus Connect Server v5 Q&A Briefing
Database introduction
IWMW 1997: Web tools
Big data and polyglot solutions
Introduction to the Globus SaaS (GlobusWorld Tour - STFC)
Dbx converter1
Caltech DIBS: Digital Borrowing System
Introduction to GXC-CMS
Backup aaS Solution Architecture
Ad

Similar to Introduction to active_directory (20)

PPT
A brief Introduction_of_Active_Directory
PPT
Introduction_to_Active_Directory and Windows Server
PDF
Integrating Linux Systems with Active Directory Using Open Source Tools
PPTX
Host Management active directory and domain services in windows server.pptx
PDF
Webinar slides: Free Monitoring (on Steroids) for MySQL, MariaDB, PostgreSQL ...
PPTX
Chapter Two.pptx
PDF
Enterprise Cloud Security
PDF
Final domain control policy
PDF
Server 2008 r2 ppt
PPT
Asish verma
PPTX
Automating using Ansible
PDF
[OW2con'21] Hosting Identity in the Cloud with OW2 free softwares
PDF
Devoxx Belgium 2017 - easy microservices with JHipster
PDF
Easy Microservices with JHipster - Devoxx BE 2017
PPTX
Scoping for BMC Discovery (ADDM) Deployment by Traversys Limited
PDF
[Pass the SALT 2021] Hosting Identity in the Cloud with free softwares
PDF
Scribe insight 04 insight 7.9.0
PDF
Data Analytics with DBMS
PPTX
Securing Your MongoDB Deployment
PPTX
Database workshop - Encode | Bhuvan Gandhi | Vishwas Ganatra
A brief Introduction_of_Active_Directory
Introduction_to_Active_Directory and Windows Server
Integrating Linux Systems with Active Directory Using Open Source Tools
Host Management active directory and domain services in windows server.pptx
Webinar slides: Free Monitoring (on Steroids) for MySQL, MariaDB, PostgreSQL ...
Chapter Two.pptx
Enterprise Cloud Security
Final domain control policy
Server 2008 r2 ppt
Asish verma
Automating using Ansible
[OW2con'21] Hosting Identity in the Cloud with OW2 free softwares
Devoxx Belgium 2017 - easy microservices with JHipster
Easy Microservices with JHipster - Devoxx BE 2017
Scoping for BMC Discovery (ADDM) Deployment by Traversys Limited
[Pass the SALT 2021] Hosting Identity in the Cloud with free softwares
Scribe insight 04 insight 7.9.0
Data Analytics with DBMS
Securing Your MongoDB Deployment
Database workshop - Encode | Bhuvan Gandhi | Vishwas Ganatra
Ad

Recently uploaded (20)

PPTX
Tartificialntelligence_presentation.pptx
PDF
Hybrid model detection and classification of lung cancer
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PPTX
TLE Review Electricity (Electricity).pptx
PDF
DP Operators-handbook-extract for the Mautical Institute
PDF
Encapsulation theory and applications.pdf
PDF
Getting Started with Data Integration: FME Form 101
PDF
project resource management chapter-09.pdf
PPTX
Programs and apps: productivity, graphics, security and other tools
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
A comparative analysis of optical character recognition models for extracting...
PPTX
A Presentation on Touch Screen Technology
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
WOOl fibre morphology and structure.pdf for textiles
PPTX
cloud_computing_Infrastucture_as_cloud_p
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PPTX
TechTalks-8-2019-Service-Management-ITIL-Refresh-ITIL-4-Framework-Supports-Ou...
PDF
Accuracy of neural networks in brain wave diagnosis of schizophrenia
PPTX
1. Introduction to Computer Programming.pptx
PDF
Web App vs Mobile App What Should You Build First.pdf
Tartificialntelligence_presentation.pptx
Hybrid model detection and classification of lung cancer
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
TLE Review Electricity (Electricity).pptx
DP Operators-handbook-extract for the Mautical Institute
Encapsulation theory and applications.pdf
Getting Started with Data Integration: FME Form 101
project resource management chapter-09.pdf
Programs and apps: productivity, graphics, security and other tools
Building Integrated photovoltaic BIPV_UPV.pdf
A comparative analysis of optical character recognition models for extracting...
A Presentation on Touch Screen Technology
Agricultural_Statistics_at_a_Glance_2022_0.pdf
WOOl fibre morphology and structure.pdf for textiles
cloud_computing_Infrastucture_as_cloud_p
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
TechTalks-8-2019-Service-Management-ITIL-Refresh-ITIL-4-Framework-Supports-Ou...
Accuracy of neural networks in brain wave diagnosis of schizophrenia
1. Introduction to Computer Programming.pptx
Web App vs Mobile App What Should You Build First.pdf

Introduction to active_directory

  • 1. Introduction to Active Directory December 10th, 2008 1-3pm Daniels 407
  • 2. What we are going to cover... ● The basics of Active Directory ● What AD is ● What AD isn't ● Tools ● Management Concepts ● Additional Services ● Q & A
  • 3. Active Directory is... A directory service that provides the ability for centralized: ● Authentication ● Authorization ● Management   Active Directory is based on LDAP.  LDAP is an industry standard method to access information from a remote database.  LDAP does not define what sorts of info are stored or how it should be stored, only how to access it. Any type of data can be stored in a properly constructed LDAP service. In fact, Active Directory Application Mode is just a stand-alone LDAP server. Active directory stores copies of it's data on several Domain Controllers (DC's).  If one fails, services are still available.
  • 4. Tools Remote Server Administration Toolkit (RSAT)  includes: ● Active Directory Users and Computers (ADUC) ● Group Policy Management Console (GPMC) ● Group Policy Editor  ● DFS Management Console ● Print Managment Console Domain-wide Administration: ● Active Directory Sites and Services ● Active Directory Domains and Trusts
  • 5. AD Objects Organizational Units  Users Computers Groups Links (publishing): ● Shares ● Print Shares
  • 6. What AD isn't ● A 100% solution ● A desktop environment ● Microsoft only  ● The same as Novell ● 100% Automatable ● A true identity management system ● Perfect   
  • 7. Authentication Native: ● Kerberos (Version 5) ● NTLMv2 ● LDAP ● Smart Cards/Certificates   Extendable to include:  ● Biometrics Client machines authenticate as well, not just user accounts Supports dual factor authentication Mac, Linux clients can auth against AD
  • 8. Trusts Trusts don't imply any sort of authorization or rights assignment.  If Domain "A" trusts Domain "B" all it implies is that accounts from "B" can be used in "A"  No rights assignments of any kind are made automatically.   This makes it possible to access resources in multiple domains using a single account.    Trusts: ● Intra-Forest  ● Inter-Forest ● Cross Realm
  • 9. Authorization Delegation Wizard   Types of Permissions: ● Directory ○ GPO's ○ Manage Groups  ● Machine ○ Local/Remote Login ○ User vs. Admin ○ Group Policy allows setting any local permission   Groups are key to any good permissions model *AD supports Nested Groups*
  • 10. Management Concepts ● Domain Structure ○ OU structure ○ User/Computer Locations ○ Grouping Strategy ● Group Policy ○ Linking ○ Filtering ■ Groups ■ WMI Filters ○ Starter GPO's ○ Copying GPO's ○ Group Policy Modelling 
  • 11. Policies vs. Preferences ● Policies: ○ Policies usually cannot be changed by end user  ○ Configuring IE ○ Deploying Software ○ Configuring Desktop Experience  ● Preferences: ○ End user override  optional per setting ○ Pushing Files/Reg Keys/Shortcuts ○ Item-Level Targeting   Both have User and Computer Settings Loopback - Process User settings using Computer location 
  • 12. Group Policy Examples ● Remote Assistance - Policy ● Remote Administration - Policy ● Configure Wireless - Policy ● Configure Firewall  - Policy ● Deploy Printers - Policy or GPP ● Deploy Startup/Shutdown/Logon/Logoff Scripts - Policy or GPP ● Deploy Software (.msi's) - Policy ● Deploy Scheduled Tasks - GPP ● Mapped Drives - GPP ● Power Settings - GPP
  • 13. Windows Server Update Services (WSUS) Unified Patch Management for MS Products - FREE ● Apply patches based on grouping ○ Server side groups  ○ *Client Side Targeting via Group Policy* ● Types of Patches: ○ Service Packs/Security Patches/Bugfixes ○ Drivers ○ Defender definitions  ○ Office Patches/Service Packs ○ Add-ons: Windows Media, Silverlight, GPP, etc. ○ Server Products: SQL, IIS  ● Ability to back out patches per group of machines (not always supported by the patches) 
  • 14. Distributed File System (DFS) DFS is a Network File System Core CAL Required  ● Roots (Namespaces) ○ Delegation  ● Folders ○ Create Arbitrary structure ● Targets ○ Where the files are  ● Multi-Master Replication    
  • 15. Windows Distribution Services (WDS) Replaces Remote Installation Services (RIS)  Core CAL Required   ● Imaging  for XP/Vista/2K3 Server/2K8 Server ● Uses PXE for medialess install ● Uses WinPE (think Vista on a CD) as install environment ● Can have a library of drivers ● GUI tools for setting up: ○ Post-install scripts ○ Joining a domain
  • 16. Additional Services Core CAL Required (NCSU has a Site License!):  Certificate Services - PKI File Services (Clustering, iSCSI) Print Services IIS / Webdav Sharepoint Services 3.0   Additional stuff we don't use: DNS/DHCP    Additional CAL Required: Terminal Services