Download as pptx, pdf, or txt
Download as pptx, pdf, or txt
You are on page 1of 34

ACTIVE DIRECTORY

INFORMATION SHEET 3.1-2

www.facebook.com/itsmeismael
LEARNING OBJECTIVES

Define briefly what Active Directory is,


Describe what three primary types of objects that active directory
provides.
Describe what happens when you log in to an active directory
network.
Define what domain controller is.
Describe forest.
Describe a domain.
Define briefly what a server role is.
Install active directory.
www.facebook.com/itsmeismael
INTRODUCTION

www.facebook.com/itsmeismael
In Windows NT, administrators were introduced to the concept of
domains. Active Directory Domain Services (AD DS) builds on that
concept by creating a dynamic, easily accessible structure through
which directory and management information can be stored and
accessed centrally throughout an organization.

By using AD DS, you create a structure for managing your


equipment and the people who use that equipment, which is a
helpful feature for all but the smallest of operations.

www.facebook.com/itsmeismael
What is Active Directory and
Why Should I care?

Active Directory is the brain of a Window Server


Network.
It is a database that keeps track of a huge amount of
stuff and gives us a centralized way to manage all
our network machine, users, and resources.

www.facebook.com/itsmeismael
Type of that active directory provides

Resources (Printer, Shared Folders,


etc.)

Services (i.e. Email, etc.) Users and groups

These items are objects in the active directory database.

www.facebook.com/itsmeismael
As a matter of fact, every time
you login in to a corporate
network, you’re using an Active
Directory.

www.facebook.com/itsmeismael
Domain Controller

A domain controller is a
machine that runs Active
Directory Services.

www.facebook.com/itsmeismael
Domain

It is a logical group of
computers that share a
central directory database.
The machine is all named
with part of domain name
like itsmeismael.com (also
called a “suffix”) and
registered in the active
directory database so they
can be managed.

www.facebook.com/itsmeismael
Forest

Forest is comprised of all


the domains in your
enterprise. Your forest may
only one domain.

www.facebook.com/itsmeismael
Server Role

Server role is a major job that a server can perform.


It’s recommended that a server not have too many roles
Common role

active directory domain


domain name services
services
If you are trying to create some other roles, you can use another domain
controller to prevent over population of roles in a single domain controller
that may cause less productivity.
www.facebook.com/itsmeismael
Domain name service

It is a service provided by a server that allows you to find other


computers in your network.

Allows you to type a friendly name of a machine instead of its IP


address, allowing your client to get the IP address from the DNS
server and go find the resources.
If you are trying to create some other roles, you can use another domain
controller to prevent over population of roles in a single domain controller
that may cause less productivity.
www.facebook.com/itsmeismael
configuring active directory

www.facebook.com/itsmeismael
Open Server Manager and click on roles, this will bring up
the Roles Summary on the right side where you can click on
the Add Roles link.

www.facebook.com/itsmeismael
Select server role. Check
Active Directory Domain
Services then click install (see
Figure 1.1) from the list, you
will be told that you need to
add some features, click on the
Add Required Features (see
Figure 2.2) button and click
next to move on.

Figure 2.1: Selecting server role

www.facebook.com/itsmeismael
Figure 2.2: Add features requirements

www.facebook.com/itsmeismael
A brief introduction to
Active Directory will be
displayed as well as a few
links to additional
resources, you can just
click next to skip past
here and click install to
start installing the
binaries for Active
Directory.

Figure 3: Confirm installation

www.facebook.com/itsmeismael
When the installation is
finished you will be shown a
message of successful
configuration, just click
Close.

Figure 4: Installation Result

www.facebook.com/itsmeismael
domain controller promotion

www.facebook.com/itsmeismael
Open Server Manager, expand Roles (click +) and click on Active Directory
Domain Services. On the right side click on the Run the Active Directory
Domain Services Installation Wizard (dcpromo.exe) link that show in Figure
1.6a or you can use an alternative method shows in Figure 1.6b.

Figure 1.6a Setting up active directory domain services

www.facebook.com/itsmeismael
Figure 1.6b Using dcpromo.exe

www.facebook.com/itsmeismael
It will show another wizard,
this time to configure the
settings for your domain,
click next to continue.

Figure 1.7 Active Directory Domain Services


Installation Wizard
www.facebook.com/itsmeismael
The message that is shown
now relates to older clients
that do not support the new
cryptographic algorithms
supported by Server 2008 R2,
these are used by default in
Server 2008 R2, click next to
move on.

Figure 1.8 Operating System Compatibility


www.facebook.com/itsmeismael
Choose to create a new
domain in a new forest.

www.facebook.com/itsmeismael
Figure 1.9 Deployment Configuration
You are now able to create
name for your domain, in this
lesson, I will be using a .com
suffix.

Figure 1.10 Naming the forest root domain


www.facebook.com/itsmeismael
Change forest
functional level to
Server 2008 R2.

www.facebook.com/itsmeismael
Figure 1.11 Set forest functional level
Include DNS in our
installation as this will
allow us to have an AD
Integrated DNS Zone,
when you click next you
will be prompted with a
message just click yes to
continue.

Figure 1.12 Additional domain controller options


www.facebook.com/itsmeismael
A delegation for this DNS server
cannot be created because the
authoritative parent zone cannot be
found or it does not run Windows
DNS server. If you are integrating
with an existing DNS infrastructure,
you should manually create a
delegation to this DNS server in the
parent zone to ensure reliable name
resolution from outside the domain
“itsmeismael.com”. Otherwise, no
action is required.
 
If you are installing a forest root
domain controller that is using
Active Directory-integrated DNS,
you typically do not need to be
concerned about this warning
message.
Figure 1.13 A warning message for active
directory domain service installation
www.facebook.com/itsmeismael
You will need to choose a place to
store log files, it is a best practice
to store the database and SYSVOL
folder on one drive and the log files
on a separate drive, but since this
is in a lab environment, just leave
them all on the same drive.

Figure 1.14 Location for database, Log Files, and


SYSVOL
www.facebook.com/itsmeismael
Assign password for
Administrator account that will
be used when this domain
controller is started in Directory
Service Restore Mode.
 
Choose a STRONG Active
Directory Restore Mode
Password and click next
twice to continue the
Figure 1.15 Directory Services Restore Mode
configuration.
www.facebook.com/itsmeismael Administrator’s Password
Review the summary of the
configure services

Review Summary
www.facebook.com/itsmeismael
You will be able to see what
components are being
installed by looking in the
following box. If the reboot
on completion check box was
not checked you will proceed
to manual reboot shows in
Figure 1.16b
Figure 1.16a Completing active directory domain
services
www.facebook.com/itsmeismael
Figure 1.16b Completing the Active Directory Domain
Services Installation Wizard
www.facebook.com/itsmeismael

You might also like