Professional Documents
Culture Documents
01 Introduction To Active Directory
01 Introduction To Active Directory
: PPT/2K403/02
Introduction to Active
Directory
(70-294)
Revision no.: PPT/2K403/02
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
Contd…
5
User
Directory Server
Server 1
Name : Server 1
OS: Windows 2000
Type: File Server
Location: 1st Floor
Printer 1 Name : Server 2
OS Novell Netware 4.0
? Type: File Server
Location: 2nd Floor
Name: Printer 1
Type: HP-4Si
Server 2
Color: No
Duplex: Yes
Location: 3rd Floor
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
Active
Active Directory
Directory
Objects
Objects
Printers
Attributes
Attributes
Printer1
Printer
Printer Name
Name
Printer Printer2
Printer Location
Location
Printers
Printers
Printer3 Attribute
Attribute
Value
Value
Users
Attributes
Attributes
First
First Name
Name Jane Doe
Last
Last Name
Name John Doe
Users
Users Logon
Logon Name
Name
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
Objects
Objects Active Directory Schema Is:
• Dynamically Available
Class
Class Examples
Examples • Dynamically Updateable
• Protected by DACLs
Attribute
Attribute
Examples
Examples
Computers
Computers
Attributes
Attributesof
ofUsers
Users List
Listof
ofAttributes
Attributes
Might
MightContain:
Contain:
accountExpires
accountExpires accountExpires
accountExpires
department
department department
department
distinguishedName
Users
Users distinguishedName
distinguishedName distinguishedName
directReports
middleName
middleName directReports
dNSHostName
dNSHostName
operatingSystem
operatingSystem
repsFrom
repsFrom
repsTo
repsTo
Printers
Printers middleName
middleName
……
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
• Logical Structures
• Physical Structures
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
Logical Structures
10
• Domains
• Ous
• Trees
• Forests
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
Domains
11
r1 Replication
Replication r1
Us e Us e
r2 r2
Us e Us e
Windows
WindowsServer
Server2003
2003
Domain
Domain
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
Organizational Units
12
microsoft.com
Orders OU
Admin
US
Computers
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
Trees
13
uk.microsoft.com us.microsoft.com
sls.uk.microsoft.com
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
Forests
14
microsoft.com msn.com
sls.uk.microsoft.com sls.uk.msn.com
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
Characteristics Of a Forest
15
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
Physical Structures
16
• Sites
• Domain Controllers
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
Sites
17
Seattle
New York
Chicago
Los Angeles
IP subnet
Site
• Sites: IP subnet
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
Domain Controllers
18
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
Domain A Domain B
2 DC3
1
DC2
4 3
DC3 GC
DC2 DC1
GC
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
• Replication
• Trust Relationships
• Group Policies
• DNS
• Object Naming
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
Replication
22
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
Contains:
Definitions
Definitions and
and rules
rules for
for
creating
creating and
and manipulating
manipulating
objects
objects and
and attributes
attributes
Forest Schema
Information
Information about
about the
the Active
Active
Directory
Directory structure
structure
Configuration
Information
Information about
about domain-
domain-
Domain specific
specific objects
objects
<Domain>
Configurable
replication Information
Information about
about applications
applications
<Application>
Active
Active Directory
Directory Database
Database
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
Contd…
24
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
• Intra-site Replication
• Inter-site Replication
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
Intra-Site Replication
26
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
Contd…
27
• The KCC determines which servers are best suited to replicate with
each other, and designates certain domain controllers as replication
partners on the basis of connectivity, history of successful
replication, and the matching of full and partial replicas.
• Domain controllers can have more than one replication partner.
• The KCC then builds connection objects that represent replication
connections between the replication partners.
• The ring structure ensures that there are at least two replication paths
from one domain controller to another; if one domain controller is
down temporarily, replication still continues to all other domain
controllers,
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
KCC
KCC A2 KCC
A1 A3
A8 A4
Automatic Generation of Replication Topology
KCC KCC
A7 A5
A6
KCC KCC
KCC
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
Inter-Site Replication
29
to occur.
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
Inter-Site Topology
30
Intersite
Intersite Topology
Topology Generator
Generator
A1
• Intersite topology Bridgehead
Bridgehead
IP
IP Subnet
Subnet Server
Server
generator defines A2
the replication
between sites on Replication
Replication
a network
IP
IP Subnet
Subnet
B1
IP
IP Subnet
Subnet
Replication
Replication
B2
Replication
Replication
IP
IP Subnet
Subnet
Bridgehead
Bridgehead Server
Server
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
Trust Relationships
31
Forest 1 Tree/Root
Tree/Root Forest
Forest Forest 2
Trust
Trust Trust
Trust
Parent/Child
Parent/Child
Trust
Trust Forest
Forest (root)
Domain D (root)
Shortcut
Shortcut Trust
Trust Realm
Realm External
External
Domain F Domain C Trust
Trust Trust
Trust
Kerberos Realm
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
tasks such as
computers
– Replacing computers
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
Group Policies
34
– Local GPO
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
DNS
35
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
sales research
Root Domain
Top-Level Domain server1 server2
Second-Level Domain
Third-Level Domain
Host Names
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
Types of Zones
37
• Standard Primary
• Standard Secondary
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
Object Naming
39
• Distinguished Name
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
• Design Tools
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
Active Directory
• Based on the technical aspects of design
Implementation
• Results in implementation guidelines
Plan
Active Directory
• Creates the forest and domain structure
Implementation
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
Design Tools
43
• Design Team
– Infrastructure Designers
– Staff Representatives
– Management Representatives
• Test Environment
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
Account
Account Site
Site
Strategy
Strategy Implementation
Implementation
Plan
Plan
Audit
Audit
Strategy
Strategy Software
Software
Deployment
Active
Deployment
Organizational
Organizational Plan
Plan Directory
Unit
Unit Implementation
Implementation
Implementation Server
Server Plan
Plan
Plan Placement
Placement Plan
Plan
Group
Group Policy
Policy
Plan
Plan
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
– Create:
• Organizational units and security groups
• Group Policies
– Implement sites
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute
Revision no.: PPT/2K403/02
47
© CMS INSTITUTE, 2004. All rights reserved. No part of this material may be reproduced, stored or emailed without the prior permission of Programme Director, CMS Institute