Professional Documents
Culture Documents
Windows Server 2016
Windows Server 2016
Schema
Forest
Domeniu
- domain admin
- RID master - creaza un pool de sid-uri
- Infrastructure master – face manage la obiectele over-domain /din afara domeniului
- PDC emulator master – tine timpul la nivel de domeniu
OU
Containere
Azure AD
AD DS administration tools
- domain controller
- database/ntds.dit + sysvol (contine templaturi de gpo + scripts)
- servicii Kerberos + KDC
- read-only DC /bitlocker
- global catalog
- tine o parte di atribute la nivel de forest + pt.search
SRV
AD DS sign-in process
- AS + TGS (ticket granting service) + database
- TGT
Managing objects
Planning OUs
3. Advanced AD DS deployements
AD DS sites
- Scope
- WMI filtering
- item targeting
- inheritance
- enforced
- slow link
- RSoP
- GPO Wizard
- Administrative templates – admx
- Security templates
- Folder redirection
- Software distribution
- Preferences
Securing AD DS
- Securing DCs
- service accounts
- password policies
- kerberos policies
- protecting groups
Monitoring AD DS
- perfmon
- ntdsutil – intervenim la baza de date AD – offline
o clean DC metadata
o reset DSRM
AD backup + restore