introduction to active directory in windows 2000/2003

15
Introduction to Active Directory in Windows 2000/2003

Upload: lee-fox

Post on 06-Jan-2018

233 views

Category:

Documents


0 download

DESCRIPTION

What Is Active Directory? Directory Service Functionality Organize Manage Control Organize Manage Control Resources Centralized Management Single point of administration Full user access to directory resources by a single logon Single point of administration Full user access to directory resources by a single logon

TRANSCRIPT

Page 1: Introduction to Active Directory in Windows 2000/2003

Introduction to Active Directory in

Windows 2000/2003

Page 2: Introduction to Active Directory in Windows 2000/2003

Overview

Introduction to Active Directory Active Directory Logical Structure Active Directory Physical Structure Methods for Administering a Windows 2000 Network

Page 3: Introduction to Active Directory in Windows 2000/2003

What Is Active Directory?

Directory Service Directory Service FunctionalityFunctionality

Organize Manage Control

Resources

Centralized ManagementCentralized Management

Single point of administration Full user access to directory

resources by a single logon

Page 4: Introduction to Active Directory in Windows 2000/2003

Active Directory Objects represents network resources, such as users, groups, computers, and printers

AttributesAttributesFirst NameLast NameLogon Name

AttributesAttributes

Printer NamePrinter Location

Active DirectoryActive Directory

Printers

Printer1

Printer2

Suzan Fine

Users

Don Hall

AttributeAttributeValueValue

ObjectsObjects

Printers

Users

Printer3

Page 5: Introduction to Active Directory in Windows 2000/2003

Active Directory Logical Structure includes:

Domains Organizational Units Tree and Forest

Page 6: Introduction to Active Directory in Windows 2000/2003

Domains

A Domain is a collection of computers that share a common database

A Domain Is a Security Boundary A domain administrator can administer only within the domain,

unless explicitly granted administration rights in other domains A Domain Is also a Unit of Replication

Domain controllers in a domain participate in replication and contain a complete copy of the directory information for their domain- NT??

Windows 2000Domain

User1

User2User1

User2ReplicationReplication

Page 7: Introduction to Active Directory in Windows 2000/2003

Organizational Units

Fire Dept

All Users

Police Dept

Network Administrative ModelNetwork Administrative Model

Use OUs to Group Objects into a Logical Hierarchy That Best Suits your needs for Administration Software Deployment Policies Delegation

Fire Dept

All Computers

Police Dept

Network Administrative ModelNetwork Administrative Model

Page 8: Introduction to Active Directory in Windows 2000/2003

Tree and Forest

Town.Belmont.ms.us

(root)

Police.town.belmont.ma.usFire.town.belmont.ma.us

Tree

Page 9: Introduction to Active Directory in Windows 2000/2003

Active Directory Physical Structure

Domain Controllers Sites

Page 10: Introduction to Active Directory in Windows 2000/2003

Domain Controllers

Domain Controller

Domain Controller

Domain

ReplicationReplicationUser1

User2User1

User2

= A Writeable Copy of the Active Directory Database

Domain Controllers: Participate in Active Directory replication You can have more than one

Page 11: Introduction to Active Directory in Windows 2000/2003

SITE LINK

28K

FIBER CONNECTION

WHY HAVE SEPARATE SITES

Page 12: Introduction to Active Directory in Windows 2000/2003

Methods for Administering a Windows 2000 Network

Using Active Directory for Centralized Management

Managing the User Environment

Page 13: Introduction to Active Directory in Windows 2000/2003

Using Active Directory for Centralized ManagementActive Directory:

Enables a single administrator to centrally manage resources Allows administrators to easily locate information Allows administrators to group objects into OUs Uses Group Policy to specify policy-based settings

Town.Belmont.Ma.US

All Users

Treasurer Water Assessors Retirement Library Personnell

All Computers

user user2 user3 user4 user5 user6

Water Assessor Retirement Library PersonnellTreasurer

computer computer2 computer3 computer4 computer5 computer6

Page 14: Introduction to Active Directory in Windows 2000/2003

Managing the User Environment

Use Group Policy to: Control and lock down what users can do Centrally manage software installation, repairs, updates,

and removal Configure user data to follow users whether they are online or

offline

Windows 2000 Enforces Continually

Apply Group Policy Once

1 2 3 Domain

OU1 OU2 OU3

1 2 3

Page 15: Introduction to Active Directory in Windows 2000/2003

Review

Introduction to Active Directory Active Directory Logical Structure Active Directory Physical Structure Methods for Administering a Windows 2000 Network