Documente Academic
Documente Profesional
Documente Cultură
Introduction to
Active Directory
Overview
Introduction
to Active Directory
Active Directory Logical Structure
Role of DNS in Active Directory
Active Directory Physical Structure
Methods for Administering a Windows 2000
Network
Is Active Directory?
Active Directory Objects
Active Directory Schema
Lightweight Directory Access Protocol
(LDAP)
Directory
Directory Service
Service
Functionality
Functionality
Organize
Organize
Manage
Manage
Control
Control
Centralized
Centralized Management
Management
Single
Single point
point of
of administration
administration
Resources
Resources
Full
Full user
user access
access to
to directory
directory
resources
resources by
by aa single
single logon
logon
Objects
Objects
Attributes
Attributes
Printers
Printers
Users
Users
Objects
Printer1
Printer
Printer Name
Name
Printer
Printer Location
Location
Printer2
Printer3
Attributes
Attributes
First
First Name
Name
Last
Last Name
Name
Logon
Logon Name
Name
Users
Attribute
Attribute
Value
Value
Don Hall
Suzan Fine
Attributes
Object
Printers
Objects
Objects
Class
Class Examples
Examples
Computers
Computers
Users
Users
Printers
Printers
Attribute
Attribute
Examples
Examples
Attributes
Attributes of
of Users
Users
Might
Might Contain:
Contain:
accountExpires
accountExpires
department
department
distinguishedName
distinguishedName
middleName
middleName
List
List of
ofAttributes
Attributes
accountExpires
accountExpires
department
department
distinguishedName
distinguishedName
directReports
directReports
dNSHostName
dNSHostName
operatingSystem
operatingSystem
repsFrom
repsFrom
repsTo
repsTo
middleName
middleName
com.
microsoft.com
training
sales
training. microsoft.com
computer1
sales. microsoft.com
a Way to
Communicate with Active Directory by
Specifying Unique Naming Paths for
Each Object in the Directory
LDAP Naming Paths Include:
Distinguished names
CN=Suzan
Suzan Fine,OU=Sales,DC=contoso,DC=msft
Fine
Relative distinguished names
Units
Trees and Forests
Global Catalog
Domains
A
Replication
Replication
Windows
Windows2000
2000
r1
Use
r2
Use
Organizational Units
Network
Network Administrative
Administrative Model
Model
Sales
Use
Organizational Structure
Structure
Vancouver
Users
Sales
Computers
Repair
Two-Way
Two-Way Transitive
Transitive Trust
Trust
Forest
contoso.msft
contoso.msft
Tree
nwtraders.msft
nwtraders.msft
au.
au.
contoso.msft
contoso.msft
Tree
asia.
asia.
nwtraders.msft
nwtraders.msft
asia.
asia.
contoso.msft
contoso.msft
au.
au.
nwtraders.msft
nwtraders.msft
Global Catalog
Subset
Subset of
of the
the
Attributes
Attributes of
ofAll
All
Objects
Objects
Domain
Domain
Domain
Global
Global Catalog
Catalog
Domain
Domain
Domain
Queries
Queries
Group
Group membership
membership
when
when user
user logs
logs on
on
Global Catalog Server
Resolution
Naming
Locating
Directory
.
com.
com.
Active Directory
microsoft
microsoft
sales
training.microsoft.com
training
Builtin
computer1
Computers
Computer1
Computer2
FQDN
FQDN==computer1.training.microsoft.com
computer1.training.microsoft.com
Windows
Windows2000
2000Computer
ComputerName
Name==Computer1
Computer1
What Is a Tree?
Tree Root Domain
Parent
Parent
Parent Domain
contoso.msft
Child
Child
Child Domain
sales.contoso.msft
Contiguous Namespace
sales.contoso.msft
New
Domain
What Is a Forest?
A Forest
Forest
contoso.msft
contoso.msft
Tree
nwtraders.msft
nwtraders.msft
sales.
of The Domainscontoso.msft
in asales.
Tree
contoso.msft
Forest Share a Common
Configuration, Schema, and
marketing.
sales.
marketing.
sales.
nwtraders.msft
nwtraders.msft
nwtraders.msft
nwtraders.msft Global Catalog
All
nwtraders.msft
nwtraders.msft
Tree
marketing.nwtraders.msft
Tree
Enterprise Admins
contoso.msft
contoso.msft
Schema Admins
sales.contoso.msft
Characteristics of Multiple
Domains
Reduce Replication Traffic
Controllers
Domain Controllers
Domain Controllers:
Participate in Active Directory replication
Perform single master operations roles in a domain
Domain
Controller
r1
Use
r2
Use
Replication
Replication
r1
Use
r2
Use
Domain
Controller
Domain
Domain
Sites
Seattle
Chicago
New York
Los Angeles
IP
IP subnet
subnet
Site
IP subnet
Sites:
Optimize
Enable
replication traffic
Domain
Controller B
Replication
Domain
Controller A
Domain
Controller C
Replication Works
Replication Latency
Resolving Replication Conflicts
Optimizing Replication
Add
Move
Modify
Delete
Originating Update
Domain
Controller B
Replicated Update
Replication
Domain
Controller A
Domain Replicated Update
Controller C
Replication Latency
Replicated Update
Domain
Controller B
Originating Update
Replication
Domain
Controller A
Change Notification
Replicated Update
Domain Controller C
Domain Controller B
Stamp
Originating Update
Stamp
Originating Update
Conflict
Conflict
Stamp
Version Number
Timestamp
Server GUID
Replication Topology
Directory
Partitions
What Is Replication Topology?
Global Catalog and Replication of
Partitions
Directory Partitions
Directory
Partitions
Forest
Schema
Configuration
Domain
contoso.msft
Active Directory
Database
Contains
Contains definitions
definitions and
and rules
rules for
for
creating
creating and
and manipulating
manipulating all
all objects
objects
and
and attributes
attributes
Contains
Contains information
information about
about Active
Active
Directory
Directory structure
structure
Holds
Holds information
information about
about all
all domaindomainspecific
specific objects
objects created
created in
in Active
Active
Directory
Directory
A2
B2
A3
A4
B3
B1
Domain Controllers
Controllers
Domain
fromthe
Different
from
SameDomains
Domains
Domain
DomainAATopology
Topology
Domain
DomainAATopology
Topology
Domain
Domain BBTopology
Topology
Schema/Configuration
Schema/ConfigurationTopology
Topology
Schema/Configuration
Schema/ConfigurationTopology
Topology
A2
B2
A3
A4
B3
B1
Domain
Domain Controllers
Controllers
from
Domains
fromDifferent
the Same Domains
Domain
DomainAATopology
Topology
Domain
DomainAATopology
Topology
Domain
Domain BBTopology
Topology
Schema/Configuration
Schema/ConfigurationTopology
Topology
Schema/Configuration
Schema/ConfigurationTopology
Topology
Schema
Configuration
Holds read
read only
only copy
copy of
of all
all
contoso.msft Holds
domain
domain directory
directory partitions
partitions
namerica.contoso.msft
Global Catalog
Server
A2
B2
A3
A4
B3
B1
Domain
DomainAATopology
Topology
Domain
Domain BBTopology
Topology
Schema/Configuration
Schema/ConfigurationTopology
Topology
Management
Managing the User Environment
Delegating Administrative Control
Search
OU1
Computers
Domain
Domain
Computer1
OU2
Users
User1
OU2
Active Directory:
Users
User2
Printers
Printer1
Domain
Domain
Apply
Apply Group
Group
Policy
Policy Once
Once
OU1
Windows
Windows 2000
2000
Enforces
Enforces Continually
Continually
OU2
OU3
1 2
Centrally
Configure
Delegating Administrative
Control
Domain
OU1
Assign Permissions:
For specific OUs to other
administrators
To modify specific attributes of
an object in a single OU
To perform the same task in all OUs
Simplify
interface design
Admin1
OU2
Admin2
OU3
Admin3
Review
Introduction
to Active Directory
Active Directory Logical Structure
Role of DNS in Active Directory
Active Directory Physical Structure
Methods for Administering a Windows 2000
Network