SlideShare a Scribd company logo
ACTIVE DIRECTORY II
Basics of Active Directory in Windows Server 2003 Active Directory partitions Logical structures “Physical” structures Functional levels
Active Directory Partitions
Schema Logical partition in Active Directory database “ Template” for Active Directory database Forms the database structures in which data is stored Object classes Attributes Extensible Dynamic Protected by ACLs (Access Control Lists)- DACLs and SACLs (Discretionary ACLs and System ACLs) One schema per Active Directory forest
Schema Users Servers Attributes of Users  might contain: List of attributes accountExpires badPasswordTime mail cAConnect dhcpType eFSPolicy fromServer governsID Name …  accountExpires badPasswordTime mail name Attribute   Examples: Object Class Examples: Dynamically available, updateable, and protected  by DACLs Computers
Configuration Logical partition in Active Directory database “ Map” of Active Directory implementation Contains information used for replication, logon, searches Domains Trust relationships Sites & site links Subnets Domain controller locations
Domains Logical partition in Active Directory database Collections of users, computers, groups, etc. Units of replication Domain controllers in a domain replicate with each other and contain a full copy of the domain partition for their domain Domain controllers do not replicate domain partition information for other domains Windows  2000/WS03 Domain Replication User1 User2 User1 User2
Directory Partitions Configurable Replication Application Domain-wide replication Forest-wide replication (every DC in forest has a replica) All Partitions Together Comprise the Active Directory Database Zoom.com Configuration Schema Contains information about all domain-specific objects created in Active Directory  Contains information about Active Directory structure Contains definitions and rules for creating and manipulating all objects and attributes Contains application data ForestDNSZone DomainDNSZone
Logical Structures
Tree One or more domains that share a  contiguous  DNS namespace, e.g. ZOOM.COM MCSE.ZOOM.COM CCNA.ZOOM.COM
Forest One or more domains that share: Common schema Common configuration Automatic transitive trust relationships Common global catalog Forest can contain from as few as one domain to many domains and/or many trees First domain created is forest root- this cannot be changed without rebuilding the entire forest
Trust Relationship
Trust Relationships Secure communication paths that allow security principals in one domain to be authenticated and accepted in other domains Some trusts are automatically created Parent-child domains trust each other Tree root domains trust forest root domain Other trusts are manually created Forest-to-Forest transitive trust relationships can be created-Windows Server 2003 forests only
Default  - two-way- transitive Kerberos trusts (intraforest) Shortcut  - one or two-way – transitive Kerberos trusts (intraforest) Reduce authentication requests  Forest  – one or two-way – transitive Kerberos trusts* *.WS2003 Forests- Windows 2000 does not support forest trusts Only between Forest Roots Creates transitive domain relationships External  – one-way – non-transitive NTLM trusts Used to connect to/from Windows NT or external 2000 domains Manually created Realm  – one or two-way – non-transitive Kerberos trusts Connect to/from UNIX MIT Kerberos realms Trust Relationships in Windows Server 2003
Trees and Forests Tree Forest External One-Way  Non-Transitive Trust Tree Forest Forest Two-Way  Transitive Trusts (Forest/Tree Root) contoso.msft nwtraders.msft (Forest/Tree Root) japan. contoso.msft (Child Domain) tailspintoys.msft (Tree Root) japan. nwtraders.msft (Child Domain) china. nwtraders.msft (Child Domain) Windows NT Domain Tree
Functional Levels
Forest and Domain Functional Levels Functional levels determine Supported domain controller operating system Active Directory features available Domain functional levels can be raised independently of one another Raising forest functional level is performed by Enterprise Admin Requires all domains to be at Windows 2000 native or WS03 functional levels
Forest Functional Levels Windows Server 2003 Server family Windows Server 2003 Server family   Windows NT 4.0, Windows Server 2003 Server family  Windows Server 2003 Interim  Windows NT 4.0, Windows 2000, Windows Server 2003 Server family Windows 2000 (default) Domain Controllers Supported Forest Functional Level
Forest Functional Levels- Features Same as Windows Server 2003 Interim, plus: Schema de-/reactivation Domain rename Forest trust Windows Server 2003 Server Family Same as Windows 2000, plus: LVR replication (Linked Value Replication- new group structuring) Improved ISTG (Inter-Site Topology Generator- generates replication connections) Windows Server 2003 Interim Universal group caching Windows 2000 Features Supported Functional Level
Domain Functional Levels Windows 2000 Mixed Mode- NT4, Windows 2000 or WS03 DCs Domain Controller (Windows 2000) Domain controller (Windows NT 4.0) Domain Controller (Windows Server 2003) Windows 2000 Native Mode-  No NT 4 DCs Domain Controller (Windows Server 2003) Domain Controller (Windows 2000)
Domain Functional Levels Windows Server 2003 Interim-  No 2000 DCs Domain controller (Windows NT 4.0) Domain Controller (Windows Server 2003) Windows Server 2003 Server Level-  All WS03 DCs  Domain Controller (Windows Server 2003) Domain Controller (Windows Server 2003)
Domain Functional Levels- Features Same as Windows 2000 Native, plus: Kerberos KDC version numbers Domain Rename Windows 2003 Server Family Same as Windows 2000 mixed, plus: Group nesting and converting Universal security and distribution groups Universal group membership caching SID history Windows 2000 Native/Windows Server 2003 Interim Universal group caching Application directory partitions Windows 2000 mixed Features Supported Functional Level
Physical Components
“Physical” Components of Active Directory Sites Areas of “good” connectivity Single site may contain many domains Single domain may span many sites Domain Controllers Store replicas of the Active Directory database Associated with a given site Site Domain
Sites Subnets are defined and associated with sites Used by domain controllers to determine replication behavior Used by computers to locate close domain controllers for authentication and searches of the directory Chicago Seattle New York Los Angeles IP Subnet Site IP Subnet
Domain Controllers Domain controllers replicate common partitions Every DC in the forest has a replica of schema & configuration partitions Every DC in a domain has a replica of that domain’s domain partition DCs may contain replicas of application partitions
Roles of Active Directory
Roles of a Domain Controller Roles Global Catalog Server Domain Naming Master Schema Master  RID Master PDC Emulator Infrastructure Master Operation Masters   Forest Wide Roles Domain Wide Roles
Global Catalog Like a telephone book contains limited information about all people and businesses within a city, the global catalog contains limited information about every object in a forest Within the schema, certain attributes are marked for inclusion in the GC Searches are commonly performed against these attributes By searching against the GC, individual domains do not have to be queried in most cases- GC can resolve  Servers that hold a copy of the global catalog are called global catalog servers
Global Catalog Server Application Solaris.com Ccna.com Mcse.com Configuration Schema Holds read only copy of all other  domain directory partitions- all objects, but only attributes marked for GC inclusion Holds full copy of domain partition for own domain Holds full copy of configuration partition for forest Holds full copy of the schema partition for forest Contains application data if configured ForestDNSZone, DomainDNSZone, user-defined application partition(s)
Global Catalog Servers Global Catalog Server Universal Group  membership when user logs on Global Catalog Queries Include in GC Telephone Email Name …  Object  Attributes Domain Domain Domain

More Related Content

PPTX
Microsoft Active Directory.pptx
PPTX
Introduction to Active Directory
PPTX
What is active directory
PPT
Microsoft Active Directory
PPT
Active Directory Services
PPT
Active Directory
PPTX
Active Directory
PPT
Active directory and application
Microsoft Active Directory.pptx
Introduction to Active Directory
What is active directory
Microsoft Active Directory
Active Directory Services
Active Directory
Active Directory
Active directory and application

What's hot (20)

PPTX
Web servers
PPT
Lecture 01 introduction to database
PPTX
Active directory domain service
PPT
Active directory
PPTX
Presentation of DBMS (database management system) part 1
PPTX
Functional dependencies in Database Management System
PPTX
Domain name system presentation
PPTX
Active directory architecture
PPTX
Functional dependency
PPT
Database Presentation
PPT
Active directory
PPT
Database concepts
PPTX
Administer Active Directory
PPTX
Relational Data Model Introduction
PPTX
Functional dependancy
PPTX
Introduction_of_ADDS
PPTX
SQL commands
PPTX
Introduction to database
PPTX
Data Manipulation Language (DML).pptx
PPT
active-directory-domain-services
Web servers
Lecture 01 introduction to database
Active directory domain service
Active directory
Presentation of DBMS (database management system) part 1
Functional dependencies in Database Management System
Domain name system presentation
Active directory architecture
Functional dependency
Database Presentation
Active directory
Database concepts
Administer Active Directory
Relational Data Model Introduction
Functional dependancy
Introduction_of_ADDS
SQL commands
Introduction to database
Data Manipulation Language (DML).pptx
active-directory-domain-services
Ad

Viewers also liked (18)

PPT
Active Directory Training
PPTX
Windows Server 2008 Active Directory
PPTX
Active directory ds ws2008 r2
PPT
70 640 Lesson01 Ppt 041009
PPTX
Windows session 5 : Basics of active directory
PDF
Lesson 5 security
PDF
Understanding DNSSEC in Windows DNS Server
PPTX
Remote desktop and print server
PDF
6425 c 01
PPTX
Print server
PPTX
Designing the active directory logical structure
PPT
Active directory installation windows 2003 1
DOC
Firewall
PPT
1.2 active directory
PPTX
Tutorial on dhcp
PDF
RARP, BOOTP, DHCP and PXE Protocols
Active Directory Training
Windows Server 2008 Active Directory
Active directory ds ws2008 r2
70 640 Lesson01 Ppt 041009
Windows session 5 : Basics of active directory
Lesson 5 security
Understanding DNSSEC in Windows DNS Server
Remote desktop and print server
6425 c 01
Print server
Designing the active directory logical structure
Active directory installation windows 2003 1
Firewall
1.2 active directory
Tutorial on dhcp
RARP, BOOTP, DHCP and PXE Protocols
Ad

Similar to Active directory ii (20)

PPTX
Activedirecotryfundamentals
PPT
70 640 Lesson02 Ppt 041009
PPT
Ads Overview En
PPT
Ads Overview En
PPT
Ads overview-en
PPT
PowerPoint Presentation
PPTX
Active Directory component
PPT
Active Directory Fundamentals Training.ppt
PPT
active directory fundamental for the beginner
PPTX
Windows server 2008 active directory
PDF
Active Directory
PDF
Ad domain n trust
PPT
MS_Active_Directory.ppt
PPTX
PPT
Active directory slides
PDF
29041329 interview-questions-for-server-2003
PPTX
Active-Directory-Domain-Services.pptx
DOC
Server interview[1]
PPT
Active diirecotry
PDF
Active directory interview_questions
Activedirecotryfundamentals
70 640 Lesson02 Ppt 041009
Ads Overview En
Ads Overview En
Ads overview-en
PowerPoint Presentation
Active Directory component
Active Directory Fundamentals Training.ppt
active directory fundamental for the beginner
Windows server 2008 active directory
Active Directory
Ad domain n trust
MS_Active_Directory.ppt
Active directory slides
29041329 interview-questions-for-server-2003
Active-Directory-Domain-Services.pptx
Server interview[1]
Active diirecotry
Active directory interview_questions

More from deshvikas (14)

PPT
Printers And Groups
PPT
New Diskmgmt
PPT
Networking & Intro 2003
PPT
PPT
PPT
Dhcp
PPT
Dfs And Disk Quota
PPT
Active Directory Ii
PPT
Active Directory I
PPT
Printers and groups
PPT
New diskmgmt
PPT
PPT
Dhcp
PPT
Dfs and disk quota
Printers And Groups
New Diskmgmt
Networking & Intro 2003
Dhcp
Dfs And Disk Quota
Active Directory Ii
Active Directory I
Printers and groups
New diskmgmt
Dhcp
Dfs and disk quota

Recently uploaded (20)

PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Chapter 3 Spatial Domain Image Processing.pdf
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PPTX
Cloud computing and distributed systems.
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Electronic commerce courselecture one. Pdf
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PPTX
Programs and apps: productivity, graphics, security and other tools
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Empathic Computing: Creating Shared Understanding
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Approach and Philosophy of On baking technology
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Chapter 3 Spatial Domain Image Processing.pdf
The AUB Centre for AI in Media Proposal.docx
The Rise and Fall of 3GPP – Time for a Sabbatical?
Network Security Unit 5.pdf for BCA BBA.
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Cloud computing and distributed systems.
Unlocking AI with Model Context Protocol (MCP)
Electronic commerce courselecture one. Pdf
MYSQL Presentation for SQL database connectivity
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
20250228 LYD VKU AI Blended-Learning.pptx
Mobile App Security Testing_ A Comprehensive Guide.pdf
NewMind AI Weekly Chronicles - August'25 Week I
Programs and apps: productivity, graphics, security and other tools
Advanced methodologies resolving dimensionality complications for autism neur...
Empathic Computing: Creating Shared Understanding
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Approach and Philosophy of On baking technology
Diabetes mellitus diagnosis method based random forest with bat algorithm

Active directory ii

  • 2. Basics of Active Directory in Windows Server 2003 Active Directory partitions Logical structures “Physical” structures Functional levels
  • 4. Schema Logical partition in Active Directory database “ Template” for Active Directory database Forms the database structures in which data is stored Object classes Attributes Extensible Dynamic Protected by ACLs (Access Control Lists)- DACLs and SACLs (Discretionary ACLs and System ACLs) One schema per Active Directory forest
  • 5. Schema Users Servers Attributes of Users might contain: List of attributes accountExpires badPasswordTime mail cAConnect dhcpType eFSPolicy fromServer governsID Name … accountExpires badPasswordTime mail name Attribute Examples: Object Class Examples: Dynamically available, updateable, and protected by DACLs Computers
  • 6. Configuration Logical partition in Active Directory database “ Map” of Active Directory implementation Contains information used for replication, logon, searches Domains Trust relationships Sites & site links Subnets Domain controller locations
  • 7. Domains Logical partition in Active Directory database Collections of users, computers, groups, etc. Units of replication Domain controllers in a domain replicate with each other and contain a full copy of the domain partition for their domain Domain controllers do not replicate domain partition information for other domains Windows 2000/WS03 Domain Replication User1 User2 User1 User2
  • 8. Directory Partitions Configurable Replication Application Domain-wide replication Forest-wide replication (every DC in forest has a replica) All Partitions Together Comprise the Active Directory Database Zoom.com Configuration Schema Contains information about all domain-specific objects created in Active Directory Contains information about Active Directory structure Contains definitions and rules for creating and manipulating all objects and attributes Contains application data ForestDNSZone DomainDNSZone
  • 10. Tree One or more domains that share a contiguous DNS namespace, e.g. ZOOM.COM MCSE.ZOOM.COM CCNA.ZOOM.COM
  • 11. Forest One or more domains that share: Common schema Common configuration Automatic transitive trust relationships Common global catalog Forest can contain from as few as one domain to many domains and/or many trees First domain created is forest root- this cannot be changed without rebuilding the entire forest
  • 13. Trust Relationships Secure communication paths that allow security principals in one domain to be authenticated and accepted in other domains Some trusts are automatically created Parent-child domains trust each other Tree root domains trust forest root domain Other trusts are manually created Forest-to-Forest transitive trust relationships can be created-Windows Server 2003 forests only
  • 14. Default - two-way- transitive Kerberos trusts (intraforest) Shortcut - one or two-way – transitive Kerberos trusts (intraforest) Reduce authentication requests Forest – one or two-way – transitive Kerberos trusts* *.WS2003 Forests- Windows 2000 does not support forest trusts Only between Forest Roots Creates transitive domain relationships External – one-way – non-transitive NTLM trusts Used to connect to/from Windows NT or external 2000 domains Manually created Realm – one or two-way – non-transitive Kerberos trusts Connect to/from UNIX MIT Kerberos realms Trust Relationships in Windows Server 2003
  • 15. Trees and Forests Tree Forest External One-Way Non-Transitive Trust Tree Forest Forest Two-Way Transitive Trusts (Forest/Tree Root) contoso.msft nwtraders.msft (Forest/Tree Root) japan. contoso.msft (Child Domain) tailspintoys.msft (Tree Root) japan. nwtraders.msft (Child Domain) china. nwtraders.msft (Child Domain) Windows NT Domain Tree
  • 17. Forest and Domain Functional Levels Functional levels determine Supported domain controller operating system Active Directory features available Domain functional levels can be raised independently of one another Raising forest functional level is performed by Enterprise Admin Requires all domains to be at Windows 2000 native or WS03 functional levels
  • 18. Forest Functional Levels Windows Server 2003 Server family Windows Server 2003 Server family   Windows NT 4.0, Windows Server 2003 Server family Windows Server 2003 Interim Windows NT 4.0, Windows 2000, Windows Server 2003 Server family Windows 2000 (default) Domain Controllers Supported Forest Functional Level
  • 19. Forest Functional Levels- Features Same as Windows Server 2003 Interim, plus: Schema de-/reactivation Domain rename Forest trust Windows Server 2003 Server Family Same as Windows 2000, plus: LVR replication (Linked Value Replication- new group structuring) Improved ISTG (Inter-Site Topology Generator- generates replication connections) Windows Server 2003 Interim Universal group caching Windows 2000 Features Supported Functional Level
  • 20. Domain Functional Levels Windows 2000 Mixed Mode- NT4, Windows 2000 or WS03 DCs Domain Controller (Windows 2000) Domain controller (Windows NT 4.0) Domain Controller (Windows Server 2003) Windows 2000 Native Mode- No NT 4 DCs Domain Controller (Windows Server 2003) Domain Controller (Windows 2000)
  • 21. Domain Functional Levels Windows Server 2003 Interim- No 2000 DCs Domain controller (Windows NT 4.0) Domain Controller (Windows Server 2003) Windows Server 2003 Server Level- All WS03 DCs Domain Controller (Windows Server 2003) Domain Controller (Windows Server 2003)
  • 22. Domain Functional Levels- Features Same as Windows 2000 Native, plus: Kerberos KDC version numbers Domain Rename Windows 2003 Server Family Same as Windows 2000 mixed, plus: Group nesting and converting Universal security and distribution groups Universal group membership caching SID history Windows 2000 Native/Windows Server 2003 Interim Universal group caching Application directory partitions Windows 2000 mixed Features Supported Functional Level
  • 24. “Physical” Components of Active Directory Sites Areas of “good” connectivity Single site may contain many domains Single domain may span many sites Domain Controllers Store replicas of the Active Directory database Associated with a given site Site Domain
  • 25. Sites Subnets are defined and associated with sites Used by domain controllers to determine replication behavior Used by computers to locate close domain controllers for authentication and searches of the directory Chicago Seattle New York Los Angeles IP Subnet Site IP Subnet
  • 26. Domain Controllers Domain controllers replicate common partitions Every DC in the forest has a replica of schema & configuration partitions Every DC in a domain has a replica of that domain’s domain partition DCs may contain replicas of application partitions
  • 27. Roles of Active Directory
  • 28. Roles of a Domain Controller Roles Global Catalog Server Domain Naming Master Schema Master RID Master PDC Emulator Infrastructure Master Operation Masters Forest Wide Roles Domain Wide Roles
  • 29. Global Catalog Like a telephone book contains limited information about all people and businesses within a city, the global catalog contains limited information about every object in a forest Within the schema, certain attributes are marked for inclusion in the GC Searches are commonly performed against these attributes By searching against the GC, individual domains do not have to be queried in most cases- GC can resolve Servers that hold a copy of the global catalog are called global catalog servers
  • 30. Global Catalog Server Application Solaris.com Ccna.com Mcse.com Configuration Schema Holds read only copy of all other domain directory partitions- all objects, but only attributes marked for GC inclusion Holds full copy of domain partition for own domain Holds full copy of configuration partition for forest Holds full copy of the schema partition for forest Contains application data if configured ForestDNSZone, DomainDNSZone, user-defined application partition(s)
  • 31. Global Catalog Servers Global Catalog Server Universal Group membership when user logs on Global Catalog Queries Include in GC Telephone Email Name … Object Attributes Domain Domain Domain